EU AI Act

EU AI Act timeline: verified dates and what applies to you

The Digital Omnibus on AI (Regulation (EU) 2026/1744) moved the high-risk dates. Prohibitions, AI literacy and general-purpose AI duties already apply. Article 50 transparency applies from 2 August 2026. Annex III high-risk obligations apply from 2 December 2027 and Annex I product-embedded obligations from 2 August 2028.

sources

Who this applies to

Providers of AI systems
Anyone who develops an AI system or has one developed and places it on the EU market or puts it into service under their own name.
Deployers
Organisations that use an AI system under their own authority in a professional capacity. Deployer duties start with literacy, transparency and, for high-risk systems, Article 26.
GPAI model providers
Providers of general-purpose AI models placed on the EU market. Their duties have applied since 2 August 2025, with Commission enforcement from 2 August 2026.
Non-EU organisations
The Act reaches providers and deployers outside the EU where the system is placed on the EU market or its output is used in the EU. Check Article 2 with counsel for your case.

The verified timeline

Dates below follow the Commission AI Act Service Desk timeline, which reflects the Digital Omnibus, and the text of Regulation (EU) 2026/1744 on EUR-Lex. Where a date moved, the original date is shown.

DateWhat appliesStatus
1 Aug 2024The AI Act enters into force.Done
2 Feb 2025Definitions, AI literacy (Art. 4) and prohibited practices (Art. 5).Applies now
2 Aug 2025General-purpose AI model obligations (Chapter V), governance bodies, and the duty on Member States to designate national authorities and set penalty rules.Applies now
2 Aug 2026Most remaining rules, including Article 50 transparency. Commission enforcement powers over GPAI providers, including fines, begin.Applies now
2 Dec 2026New Article 5 prohibitions on AI that generates non-consensual intimate imagery or child sexual abuse material. Grace period ends for Article 50(2) machine-readable marking by generative systems already on the market before 2 Aug 2026.Upcoming
2 Aug 2027Each Member State should have at least one AI regulatory sandbox operational (moved from 2 Aug 2026). GPAI models placed on the market before 2 Aug 2025 must comply by this date.Upcoming (moved)
2 Dec 2027Annex III high-risk obligations (Chapter III, Sections 1 to 3). Originally 2 Aug 2026.Upcoming (moved)
2 Aug 2028High-risk obligations for AI in products covered by Annex I. Originally 2 Aug 2027.Upcoming (moved)

The Omnibus replaced the Commission's earlier proposal of a conditional trigger tied to the availability of standards with fixed calendar dates. Per the Regulation (EU) 2026/1744 text on EUR-Lex, it was adopted on 8 July 2026, published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026.

What the Omnibus changed, and what it did not

Changed (verified in the EUR-Lex text):

  • Annex III high-risk obligations moved to 2 December 2027 and Annex I to 2 August 2028.
  • Article 4 AI literacy now requires providers and deployers to "take measures to support" AI literacy. It no longer requires them to guarantee any specific level for any individual, and the Commission, Member States and the AI Board are to support them, especially SMEs.
  • Simplified technical documentation (Article 11) and proportionate quality management (Article 17) now reach small mid-cap enterprises, and quality-management simplification extends from microenterprises to all SMEs.
  • A new Article 4a allows processing of special-category personal data for bias detection and correction where strictly necessary and under safeguards.
  • Article 5 gains two prohibitions: non-consensual intimate imagery and child sexual abuse material, applying from 2 December 2026.
  • The "safety component" notion in Article 6 was narrowed, so AI used only for assistance, optimisation, efficiency, automation, convenience or quality control is not a safety component unless its failure would endanger health or safety.
  • The AI Office gets exclusive supervision of AI systems built on a general-purpose model by the same provider, and of AI integrated into very large online platforms and search engines.
  • The deadline for Member States to have an operational sandbox moved to 2 August 2027.

Not changed: the prohibited practices that already apply, the GPAI obligations, the Article 50 transparency duties, and the fine tiers in Article 99.

Registration of Annex III systems that a provider self-assesses as not high-risk (Articles 6(4) and 49(2)) was kept, according to commentary on the final deal; the Commission had proposed removing it. Treat that point as secondary-sourced and check the final text with counsel.

What applies to you, by role

If you are a...Already appliesApplies nextApplies from the high-risk dates
Provider of an AI systemArt. 4 literacy; Art. 5 prohibitions; Art. 50(1) and (2) from 2 Aug 2026.2 Dec 2026: new Art. 5 prohibitions and the end of the Art. 50(2) grace period for systems already on the market.If high-risk: Arts. 9 to 15, QMS (Art. 17), conformity assessment, registration, post-market monitoring. 2 Dec 2027 (Annex III) or 2 Aug 2028 (Annex I).
Deployer of an AI systemArt. 4 literacy; Art. 5 prohibitions; Art. 50(3) and (4) disclosure duties from 2 Aug 2026.Prepare logs, oversight roles and worker information.If high-risk: Art. 26 (use per instructions, oversight, monitoring, logs of at least six months, worker information, informing affected people), and Art. 27 FRIA where it applies.
GPAI model providerChapter V duties since 2 Aug 2025. Commission fines possible from 2 Aug 2026 for models placed after 2 Aug 2025.Models placed before 2 Aug 2025 must comply by 2 Aug 2027.Not tied to the high-risk dates. A downstream product built on a GPAI model may still be high-risk.
Both provider and deployer (build and use your own system)All of the above rows apply to the relevant system.Check Art. 25: changing the intended purpose, branding or substantially modifying a system can make you the provider.The provider duties apply to you for that system.

What is still uncertain

  • Harmonised standards. The Commission FAQ (updated 10 March 2026) says the first standards were expected in 2026 and that the Commission reviews them before citing them in the Official Journal. Trackers report the first dedicated quality-management standard approved in July 2026 with citation pending. Until a standard is cited, it gives no presumption of conformity. Verify the current list before relying on any standard.
  • Commission Article 6 guidelines. The guidelines on high-risk classification were due earlier and, according to commentary from Bird & Bird, the Commission published draft guidelines for consultation on 19 May 2026. Final text may differ.
  • National authorities. Member States were due to designate authorities by 2 August 2025. A tracker survey on 17 June 2026 found only nine had designated both required authorities. Check your Member State on the Commission governance page.
  • The GDPR half of the Digital Omnibus. A separate proposal to amend GDPR and ePrivacy has not been adopted. It does not change the AI Act dates.

How the platform supports it

Each row maps a requirement to a platform control, the evidence artifact it produces, and the Trust & Governance Fabric facets involved. Swfte provides the controls and the evidence. You remain responsible for the decisions.

RequirementPlatform controlEvidence artifactFabric facets
An inventory of AI systems with role and risk tier, ready before the high-risk datesTrust Profile per AI system: identity, owner, risk level, approved models, data classification, permitted systems.Trust Profile export and AI system inventory.Identity, Risk, Compliance
Prohibited-practice screening (Art. 5) and Article 50 disclosurePolicy that denies, filters or requires disclosure for configured use cases.Policy configuration and decision records.Policy, Auditability
Logs of operation to retain for at least six months where you are a high-risk deployer (Art. 26(6))Action trace across gateway, agents and workflows, tied to identity and policy.Exportable audit log.Auditability, Traceability, Evidence
Human oversight by competent, trained, authorised people (Art. 14, 26(2))Approval rules and escalation by autonomy level, L1 Assist to L5 Adaptive.Approval records.Human oversight, Access

Compliance-by-design. Swfte provides the technical controls, governance mechanisms and evidence to support deployment within applicable requirements. The exact posture depends on your use case, jurisdiction, deployment and configuration. This is not legal advice.

Hosting today: customer data is stored in AWS eu-west-1 (Ireland), as stated on the trust page. EU region, in-country, dedicated and on-prem options are the platform position: what it is designed to let you do, scoped with you through a dedicated deployment engagement, not self-serve.

What this does not cover

  • Swfte does not classify your AI systems or decide your role. That is a legal determination for you and your counsel.
  • It does not perform a conformity assessment, affix CE marking or register a system in the EU database for you.
  • It does not give a presumption of conformity. No harmonised standard supports one yet, and platform records are evidence, not certification.
  • Control over upstream model training (a GPAI provider duty) stays with the model provider. Swfte lets you record which approved models you use and obtain their documentation.

Frequently asked questions

When do the EU AI Act high-risk rules apply after the Digital Omnibus?

Annex III high-risk obligations apply from 2 December 2027, and Annex I product-embedded high-risk obligations from 2 August 2028, according to Regulation (EU) 2026/1744 and the Commission AI Act Service Desk timeline. They were originally 2 August 2026 and 2 August 2027.

What already applies today?

The Article 5 prohibitions and Article 4 AI literacy since 2 February 2025, the general-purpose AI model obligations since 2 August 2025, and Article 50 transparency and Commission GPAI enforcement from 2 August 2026.

Did the Digital Omnibus delay the GPAI obligations or the fines?

No. GPAI obligations and the Commission's power to fine GPAI providers (from 2 August 2026 for models placed on the market after 2 August 2025) were not delayed. Legacy models placed before 2 August 2025 have until 2 August 2027.

Is the 2 December 2027 date final?

It is set in a regulation in force since 27 July 2026, which replaced the earlier conditional approach with fixed dates. It could be amended only by a further legislative act. We re-verify this page and stamp the date above.

Does the AI Act apply to a company outside the EU?

It can. The Act applies to providers placing systems on the EU market and to deployers whose output is used in the EU. Whether it applies to you depends on Article 2 and your facts, so take legal advice.

Can Swfte meet our AI Act obligations for us?

No platform can. Swfte is built compliance-by-design: it provides the technical controls, governance mechanisms and evidence to support deployment within applicable requirements. The exact posture depends on your use case, jurisdiction, deployment and configuration.

Sources

Last verified 2026-10-06. Primary sources are EUR-Lex and European Commission pages. Items marked as secondary are commentary or trackers; check the primary text before relying on them.

Across the platform

The controls on this page are part of the Trust & Governance Fabric that runs through every layer of the Sovereign Intelligence Platform.

Build EU-first AI with the evidence already running

Start with one entry point. Add governance, in-region options and evidence as your requirements grow.

Ready to build with Swfte?

One platform for the agents, models and workflows your team ships. Free to start, no card required.