Search pages, courses, and articles
The EU AI Act applies in six phases. Article 4 AI literacy and Article 5 prohibited practices are live since 2 February 2025. GPAI provider obligations since 2 August 2025. The high-risk Annex III standalone obligations apply from 2 December 2027 (delayed from 2 August 2026 by the Digital Omnibus deal of 7 May 2026). Annex I embedded high-risk from 2 August 2028. Click any phase to see the articles, deadlines, and source citations.
Source: Article 113 of Regulation (EU) 2024/1689 as amended by the Regulation (EU) 2026/1744 (the Digital Omnibus on AI), in force since 27 July 2026. Not legal advice.
Standalone high-risk AI systems under Article 6 + Annex III come under full Article 8-49 obligations. Categories include biometrics, critical infrastructure, education and vocational training, employment and worker management, access to essential services (credit, benefits, healthcare, emergency dispatch), law enforcement, migration / asylum / border control, administration of justice and democratic processes. Article 26 deployer obligations + Article 27 fundamental rights impact assessment apply in full.
Get a copy of your result plus a short, practical action plan for what to do next. One email, and the occasional EU AI Act update. Unsubscribe anytime.
We'll email your result and occasional EU AI Act updates. No spam. See our privacy policy.
The EU Council and Parliament reached a provisional agreement (the Digital Omnibus on AI) to amend Regulation (EU) 2024/1689 in five substantive ways. The headline change is a 16-month delay on the high-risk obligations: Annex III standalone moves from 2 August 2026 to 2 December 2027, Annex I embedded from 2 August 2026 to 2 August 2028. The other changes are: SME relaxations extended to small mid-caps (SMCs), Article 10 amended to allow processing of sensitive personal data for bias detection, AI Office powers reinforced, and a new ban on “nudification” apps added to Article 5. The agreement has since been adopted as Regulation (EU) 2026/1744, in force since 27 July 2026.
In phases. Article 4 AI literacy and Article 5 prohibited practices have applied since 2 February 2025, and Article 4 has been enforceable since August 2026, when national supervisory powers kicked in. General-purpose AI provider obligations (Chapter V, Articles 51 to 56) became enforceable on 2 August 2025. The high-risk Annex III standalone obligations apply from 2 December 2027 (delayed from 2 August 2026 by the Digital Omnibus, Regulation (EU) 2026/1744, in force 27 July 2026). High-risk AI embedded in regulated products under Annex I applies from 2 August 2028. The Article 99 penalty regime applies to the obligations Article 99 enumerates. Article 4 is not among them and is enforced under national rules made under Article 99(1).
Yes, for the high-risk obligations. On 7 May 2026 the EU Council and Parliament reached a provisional agreement (the Digital Omnibus on AI), since adopted as Regulation (EU) 2026/1744 and in force since 27 July 2026, that delayed the high-risk Annex III standalone deadline from 2 August 2026 to 2 December 2027 (a 16-month shift) and the Annex I embedded high-risk deadline to 2 August 2028. The rest of the regulation timeline is unchanged: Article 4 AI literacy, Article 5 prohibited practices, GPAI provider obligations under Articles 51 to 56, and the Article 99 penalty regime all continue on their original schedule.
Two of the most important obligations of the EU AI Act began to apply. Article 4 AI literacy requires every organisation deploying AI in the EU to take measures that support role-proportionate AI literacy among staff. Article 5 prohibits specific AI practices, including social scoring by public authorities, manipulative AI, untargeted facial-image scraping, emotion recognition in workplaces and schools, real-time biometric mass surveillance, predictive policing based solely on profiling, and biometric categorisation for sensitive characteristics. Both obligations are live today. Article 5 carries the heaviest Article 99 fine tier; Article 4 sits outside the Article 99 tiers and is penalised under national rules made under Article 99(1).
Annex III standalone high-risk AI systems come under the full Article 8-49 obligation stack. The eight Annex III categories are: biometrics, critical infrastructure, education and vocational training, employment and worker management, access to essential services (credit, benefits, healthcare, emergency dispatch), law enforcement, migration / asylum / border control, administration of justice and democratic processes. Deployers face Article 26 obligations (human oversight, transparency, incident reporting) and Article 27 fundamental rights impact assessments. Providers face Article 8-22 conformity assessment obligations. National market surveillance authorities begin active supervision on this date.
High-risk AI embedded in regulated products under Annex I becomes subject to the AI Act regime on top of existing sectoral conformity assessment. Annex I covers AI used as safety components of lifts, toys, medical devices, in-vitro diagnostic devices, machinery, vehicles, marine equipment, civil aviation security, and similar regulated product categories. The AI Act layers on top of the existing sectoral frameworks (MDR, IVDR, Machinery Regulation 2023/1230, etc.); providers must demonstrate conformity with both regimes simultaneously.
It already is law. The provisional agreement of 7 May 2026 was formally adopted by the European Parliament and the Council on 8 July 2026, published in the Official Journal as Regulation (EU) 2026/1744 on 24 July 2026, and entered into force on 27 July 2026. The new deadlines (December 2027 and August 2028) are therefore fixed in law, and organisations can plan around them with certainty.
No. The timeline tool surfaces the dates set out in Article 113 of Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744 (the Digital Omnibus on AI), in force since 27 July 2026. For binding interpretation of how those dates apply to a specific AI system, organisation, or use case, consult a qualified EU technology lawyer or your national market surveillance authority. Member State implementations may add specific national procedures on top of the EU framework.
Knowing the timeline is not enough. The Compliance Scorecard turns the dates into a 0-100 readiness number against the 10-step framework, and tells you which step to work on next.