EU AI Act change log
EU AI Act what changed: a dated log since the Digital Omnibus
A dated table of what changed in the EU AI Act, who is affected and where each date was read, plus what to do this quarter.
Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force on 27 July 2026. It sets the high-risk dates at 2 December 2027 for Annex III systems and 2 August 2028 for systems in Annex I products, and the pages we read show no postponement of the earlier prohibition, literacy, general-purpose AI or Article 50 dates. This page is the dated change log. The timeline page is the full schedule.
Last verified 2026-10-07. Sources are listed at the end of the page.
What changed in the EU AI Act, and when?
Every row was read on the AI Act Service Desk timeline or article pages, or on the European Commission pages listed under sources, on 2026-10-07. Dates are in date order.
| Date | What applies or changed | Who is affected | Source |
|---|---|---|---|
| 2 February 2025 | Chapters I and II apply: definitions, AI literacy and the prohibited practices. | All providers and deployers. | Service Desk timeline, Article 113 |
| 2 August 2025 | Rules for general-purpose AI models apply, and governance must be in place. Member States must designate competent authorities and adopt penalty laws. | General-purpose AI model providers, and Member States. | Service Desk timeline |
| 27 July 2026 | The Digital Omnibus enters into force. The Article 113 text on the Service Desk applies Articles 102 to 110 from this date. | Everyone: it is the amending act that set the later dates. | Commission news item, Article 113 |
| 2 August 2026 | The majority of rules apply and enforcement starts. Article 50 transparency applies. Enforcement begins for general-purpose AI, prohibitions, transparency and AI literacy. | Providers and deployers with transparency duties, general-purpose AI providers, and anyone using a prohibited practice. | Service Desk timeline, Commission AI Act page |
| 2 December 2026 | New prohibitions on non-consensual deepfakes and child abuse material apply. Providers of generative systems placed on the market before 2 August 2026 must comply with Article 50(2), machine-readable marking of synthetic content, by this date. | Providers of systems that generate synthetic audio, image, video or text, if on the market before 2 August 2026. | Article 111, Article 113, Service Desk timeline |
| 2 August 2027 | Member States should have at least one AI regulatory sandbox operational. Providers of general-purpose AI models placed on the market before 2 August 2025 must take the necessary steps to comply by this date. | Member States, and providers of general-purpose AI models placed on the market before 2 August 2025. | Service Desk timeline, Article 111 |
| 2 December 2027 | Rules for high-risk AI systems in Annex III apply (Chapter III Sections 1 to 3, for systems under Article 6(2) and Annex III). | Providers and deployers of Annex III high-risk systems. | Article 113, Commission AI Act page |
| 2 August 2028 | Rules for high-risk AI embedded in regulated products covered by Annex I apply (Article 6(1)). | Providers and deployers of AI in Annex I products, such as machinery, toys and lifts. | Article 113, Commission news item |
Read on 2026-10-07. The Service Desk timeline page shows no last-updated date; the Commission AI Act page showed "3 August 2026" as its last update.
How did the Digital Omnibus get to 27 July 2026?
The Commission AI Act page lists the path: the Digital Package on Simplification proposed the amendments on 19 November 2025, political agreement followed on 7 May 2026, and the Omnibus entered into force on 27 July 2026. The final text is Regulation (EU) 2026/1744.
The Service Desk marks three timeline entries as amended by the Omnibus: the December 2026 entry, the December 2027 entry for Annex III and the August 2028 entry for Annex I. It also marks Article 4 on AI literacy as amended. The amended Article 4 requires providers and deployers to "take measures to support" the development of AI literacy, and says the requirement does not mandate any specific competency level for individuals. The page does not state a separate application date for that wording, so this page does not either.
What did not move?
The prohibitions and AI literacy have applied since 2 February 2025, general-purpose AI rules since 2 August 2025, and Article 50 transparency from 2 August 2026. The pages we read show no postponement of any of these. Only the December 2026 entry and the two high-risk entries carry the Omnibus marker on the timeline page.
Article 50 has four parts: tell people when they interact with an AI system, mark synthetic content in a machine-readable format, notify people exposed to emotion recognition or biometric categorisation, and disclose deepfakes and AI-generated text on matters of public interest. Exceptions apply, so read the article for your case.
What should you do this quarter?
This is a planning list, not legal advice. It assumes today is 7 October 2026, so the 2 December 2026 dates are about eight weeks away.
Check Article 50(2) marking if you provide a generative system
If a system that generates synthetic audio, image, video or text was on the market before 2 August 2026, Article 111 sets 2 December 2026 for machine-readable marking. If you placed it later, Article 50(2) already applied.
Screen use cases against the new prohibitions
From 2 December 2026 the new prohibitions on non-consensual deepfakes and child abuse material apply. Confirm no feature, prompt template or agent skill can produce them, and record how you checked.
Build the inventory before the high-risk dates
A list of AI systems with owner, purpose and role is the starting point for every later duty. See AI inventory management and the high-risk checklist.
Review AI literacy measures
Under the amended Article 4 you take measures to support literacy of staff and others who operate AI on your behalf. Write down what you did and for whom. See AI literacy under Article 4.
Diarise 2 August 2027 if you provide a general-purpose model
Models placed on the market before 2 August 2025 have until 2 August 2027. See GPAI obligations.
Do not treat the Annex III delay as a pause
Inventory, classification and logging take time. Article 12 requires high-risk systems to allow automatic recording of events over their lifetime, and Article 26 asks deployers of high-risk systems to keep logs for a period appropriate to the purpose, of at least six months.
What could not be verified, and what this page does not cover
These items are left out of the table on purpose.
- Adoption and publication dates of the Omnibus. Existing Swfte EU pages cite 8 July 2026 and 24 July 2026. The EUR-Lex page for Regulation (EU) 2026/1744 could not be opened by our tooling on 2026-10-07, and the Commission pages we read give the entry-into-force date of 27 July 2026 but not these two. They are not in the table.
- The previous high-risk dates. The earlier dates for Annex III and Annex I are on the timeline page. The Article 113 text we read shows only the amended dates, so this page does not restate the old ones.
- Penalties. See AI Act penalties. Standards, guidelines and national enforcement are also outside this page.
- Other law. GDPR, NIS2, DORA, the Data Act and non-EU rules are not covered here. Start at the EU AI Act guide.
How is this page different from the timeline page?
| Page | Use it when | Format |
|---|---|---|
| This page | You want to know what moved or changed, and on what date, since the Omnibus. | A dated change log with a source on each row, and a quarter plan. |
| EU AI Act timeline | You want the full schedule, by role, with what applies now. | A role-based timeline with status for each date. |
| EU AI Act guide | You want an overview of what the Act asks of AI systems. | A topic guide. |
Where Swfte fits
Swfte does not decide your role or risk class, perform a conformity assessment or register a system for you. Those are legal and organisational decisions. What a platform can do is produce records that support them, such as audit events, approvals and policy decisions. The Trust Profile, one record per AI system, is a design for the inventory that those records hang off, and it is design intent, not a shipped single record.
You do not need Swfte for this change log. A dated checklist and an owner for each row is enough. Swfte provides the technical controls, governance mechanisms and evidence you need to deploy AI within your applicable regulatory, security and policy requirements. The exact posture depends on your use case, jurisdiction, deployment and configuration.
Sources and last verified
Every dated or technical fact on this page was read from the pages below on 2026-10-07. Anything that could not be confirmed is left out or marked as not verified.
- AI Act Service Desk: implementation timeline (European Commission). Every dated milestone in the table, with the Digital Omnibus amendment markers.
- AI Act Service Desk: Article 113, entry into force and application. The amended application dates for Annex III and Annex I, the December 2026 prohibitions and 27 July 2026.
- AI Act Service Desk: Article 111, transitional provisions. The 2 December 2026 Article 50(2) transition and the 2 August 2027 date for earlier general-purpose models.
- AI Act Service Desk: Article 4, AI literacy. The amended literacy wording.
- AI Act Service Desk: Article 50, transparency obligations. The four transparency duties.
- AI Act Service Desk: Article 12, record-keeping. Automatic recording of events for high-risk systems.
- AI Act Service Desk: Article 26, deployer obligations. The log retention period of at least six months for deployers of high-risk systems.
- European Commission: AI Act regulatory framework. The Omnibus path (19 November 2025, 7 May 2026, 27 July 2026), the high-risk dates and the page update date of 3 August 2026.
- European Commission: AI Omnibus enters into force. Entry into force on 27 July 2026 and the 2027 and 2028 high-risk dates.
Frequently asked questions
When do the EU AI Act high-risk rules apply now?
Rules for high-risk AI systems in Annex III apply from 2 December 2027, and rules for high-risk AI embedded in products covered by Annex I apply from 2 August 2028. Both dates are in Article 113 as shown on the AI Act Service Desk, and the Commission lists them on its AI Act page.
Did the Digital Omnibus delay Article 50 transparency?
No page we read says so. The Service Desk timeline lists the Article 50 transparency rules as taking effect on 2 August 2026. The Omnibus did add a transition: providers of generative systems placed on the market before that date must comply with Article 50(2) by 2 December 2026.
What applies on 2 December 2026?
Two things. New prohibitions on non-consensual deepfakes and child abuse material commence, and the transition for Article 50(2) machine-readable marking ends for generative systems that were already on the market before 2 August 2026. Both appear on the Service Desk timeline and in Articles 111 and 113.
Did the Omnibus change AI literacy under Article 4?
Yes, the wording. The Service Desk shows Article 4 as amended: providers and deployers take measures to support AI literacy of their staff and others operating AI on their behalf, and the requirement does not mandate any specific competency level for individuals. The page gives no separate application date for it.
Which date applies to general-purpose AI models placed on the market before August 2025?
Providers of general-purpose AI models placed on the market before 2 August 2025 must take the necessary steps to comply with the Act by 2 August 2027, according to Article 111(3) on the Service Desk. Models placed after that date were already within the 2 August 2025 rules.
Is this legal advice on the EU AI Act?
No. It is an explainer that restates dates from the Commission and the AI Act Service Desk. Whether a rule applies to you depends on your role, your systems and your facts, so take advice from counsel before you rely on any date for a decision.