Regulation EU 2024/1689, Post-Omnibus Phased Timeline

EU AI Act Phased Enforcement Timeline, What Applies When

After the Digital Omnibus (adopted by Parliament 16 June 2026, Council adoption 29 June 2026), the EU AI Act now applies in four distinct phases between 2 August 2026 and 2 August 2028. Some obligations still hit this August; others moved to December 2026, December 2027, and August 2028. Here is what applies when, and what must be in place by each date.

→ Not sure how this affects your AI system?

Take the free 5-minute Risk Classifier, article-grounded scoring against Article 5, 6, Annex III, and Article 50.

Run the classifier →

What Changed on 7 May 2026, Direct Answer

In the early hours of Thursday 7 May 2026, Council and Parliament negotiators reached a provisional political agreement on the Digital Omnibus on AI. The headline change: Annex III standalone high-risk obligations move from 2 August 2026 to 2 December 2027. The deal remains provisional until both institutions formally adopt the consolidated text and the Official Journal publishes it ahead of 2 August 2026, but both institutions have stated intent to complete adoption in time.

Three deadlines still apply on 2 August 2026. The Omnibus is targeted. Article 50 transparency obligations (most parts), Article 49 EU database registration, and national market surveillance authority enforcement powers all apply from 2 August 2026 as originally enacted. Article 5 prohibitions remain in force since February 2025. GPAI obligations remain in force since August 2025. Article 4 AI literacy remains applicable.

Full Phased Enforcement Timeline

12 July 2024
Regulation EU 2024/1689 Published in EU Official Journal
The EU AI Act was formally published. The 20-day period before entry into force began. Organisations could begin preparing compliance programmes from this date.
1 August 2024
Regulation Entered Into Force
The AI Act became binding EU law. The European AI Office was formally constituted. National competent authorities in each Member State began building supervisory infrastructure.
2 February 2025, IN FORCE
Article 5 Prohibited Practices + Article 4 AI Literacy
All listed prohibited AI practices became fully enforceable. Maximum penalty: €35 million or 7% of global annual turnover. Article 4 AI literacy obligation on providers and deployers applicable from this date (final landing position post-Omnibus consolidated text TBD).
2 August 2025, IN FORCE
GPAI Obligations (Articles 51–56) Enforceable
General-Purpose AI model providers must comply with documentation, transparency, copyright compliance policies, and training data summaries. Models above 10²⁵ FLOPs face additional systemic risk obligations including adversarial testing and incident reporting to the European AI Office.
2 August 2026, STILL APPLIES
Article 50 Transparency (Most) + Article 49 Registration + MSA Powers
Article 50 transparency obligations (chatbot disclosure, deepfake disclosure to users, emotional-recognition disclosure) apply as enacted. Article 49 EU AI database registration applies. National market surveillance authority enforcement powers commence. Only Article 50(2) watermarking shifted under the Omnibus deal.
2 December 2026, NEW UNDER OMNIBUS
Article 50(2) Watermarking + New Article 5 CSAM/NCII Prohibition
Providers of generative AI systems must mark synthetic audio, image, video and text content as machine-readable (shifted from 2 August 2026 to 2 December 2026, four-month extension). New Article 5 prohibition on AI generating non-consensual intimate imagery or CSAM applies from this date. Affects every generative AI provider regardless of Annex III status.
2 December 2027, PRIMARY ANNEX III DEADLINE (POSTPONED FROM 2 AUG 2026)
Annex III High-Risk AI: Full Enforcement
All Annex III standalone high-risk AI systems must comply: Article 9 risk management system, Article 10 data governance, Article 11 + Annex IV technical documentation, Article 12 automatic logging, Article 13 transparency to deployers, Article 14 human oversight, Article 15 accuracy/robustness/cybersecurity, Article 17 quality management, Article 27 FRIA, Article 43 conformity assessment, Article 72 post-market monitoring, Article 73 serious-incident reporting. 16-month deferral from the original date.
2 August 2028, POSTPONED FROM 2 AUG 2027
Annex I Embedded High-Risk AI
AI embedded as safety components in regulated products under Annex I, medical devices, machinery, vehicles, aviation, marine equipment, must comply. 12-month deferral from the original date under the Omnibus.
2 August 2030
Public Sector Legacy Systems (Article 111)
Legacy AI systems already in operation by public authorities before the regulation entered into force benefit from an extended transition until August 2030, provided they are not significantly modified.

Who Is Affected by Annex III (2 December 2027)?

The 2 December 2027 Annex III deadline applies to providers and deployers of AI systems in the eight Annex III high-risk domains:

  • Biometric identification and categorisation systems, including post-prohibition biometric systems and emotion recognition
  • Critical infrastructure AI, safety components for utilities, transport, and digital infrastructure
  • Education AI, systems determining access, assessing students, or monitoring examination integrity
  • Employment AI, recruitment, selection, performance monitoring, task allocation, and termination tools
  • Essential services AI, credit scoring, insurance risk, public benefit eligibility, emergency dispatch
  • Law enforcement AI, risk assessment, profiling, evidence reliability, predictive policing
  • Migration and border AI, risk assessment, document verification, asylum processing
  • Justice and democratic process AI, judicial assistance, electoral influence, political advertising

The deadline applies equally to EU-based and non-EU organisations providing or deploying these systems for EU users or in EU-affecting contexts.

What Must Be in Place by 2 December 2027?

Art. 9, Risk Management System

Continuous, documented risk identification, evaluation, mitigation, and residual risk assessment. Must cover the entire AI system lifecycle.

Art. 10, Data Governance

Training, validation and testing datasets must be relevant, representative, and error-free. Documented governance practices required.

Art. 11 + Annex IV, Technical Documentation

Complete Annex IV documentation: system description, design specs, training methodology, datasets, testing results, performance metrics, post-market monitoring plan.

Art. 12, Automatic Logging

Built-in automatic logging enabling traceability. Minimum 6-month log retention.

Art. 13, Transparency to Deployers

Instructions for use covering capabilities, limitations, accuracy, oversight requirements, and output interpretation.

Art. 14, Human Oversight

Designed-in mechanisms for humans to monitor, interpret, override, and interrupt the system. Cannot be purely procedural.

Art. 27, Fundamental Rights Impact Assessment

Mandatory before deployment for public-sector and essential-service high-risk AI deployers.

Art. 43, Conformity Assessment

Internal self-assessment for most Annex III systems; notified body assessment for biometric identification systems.

EU AI Database Registration (Art. 49)

Registration of all high-risk AI systems in the EU AI public database before deployment. Article 6(3) self-assessed non-high-risk determinations must also be registered (reinstated under the Omnibus deal).

Arts. 72, 73, Post-Market Monitoring + Incident Reporting

Tiered serious-incident reporting (2-day / 10-day / 15-day). Post-market monitoring plan.

Compliance Action Plan, Runway to 2 December 2027

From May 2026 to 2 December 2027 is approximately 18 months. CEN/CENELEC harmonised standards are still being drafted (expected end-2026 at earliest). Realistic working time after standards land is roughly 12 months. That is enough time to build a defensible compliance programme, but it is not abundant time.

  1. Now, Generative AI providers focus on 2 December 2026: Watermarking technical architecture (Article 50(2)) and new Article 5 CSAM/NCII safety-filter documentation. Seven months out.
  2. Now, All organisations focus on what still hits 2 August 2026: Article 50 transparency (chatbot/deepfake/emotional-recognition disclosure), Article 49 registration readiness.
  3. Q3 2026, AI Inventory: Catalogue all AI systems including shadow AI. Apply Annex III criteria systematically. Document Article 6(3) classification decisions.
  4. Q4 2026 – Q1 2027, Risk Management + Policy Foundation: Build the Article 9 risk management system. Draft AI Risk Management Policy. Designate AI Risk Officer.
  5. Q1 – Q2 2027, Gap Analysis + Documentation: Assess against Articles 9–15, 17, 27 using structured checklist. Begin Annex IV technical documentation builds.
  6. Q2 – Q3 2027, Conformity Assessment Preparation: Internal conformity assessment for most Annex III systems; notified body engagement for biometric systems.
  7. By 2 December 2027, Registration and Launch: Register in EU AI database. Deploy with compliant systems, human oversight, and post-market monitoring in place.

Common Mistakes to Avoid

  • Assuming the Omnibus deferred everything to 2 December 2027. It didn't. Article 50 transparency, Article 49 registration, and GPAI enforcement still apply 2 August 2026. New Article 5 CSAM/NCII prohibition and Article 50(2) watermarking hit 2 December 2026.
  • Pausing work because the Annex III deadline moved. The runway after CEN/CENELEC standards publish is roughly 12 months. That is realistic time but not abundant time.
  • Treating compliance as a documentation exercise rather than a technical and governance programme
  • Confusing provider and deployer obligations, both have distinct requirements
  • Ignoring third-party AI in your supply chain, deployers must verify vendor compliance
  • Treating classification as final, risk tier must be reassessed when the system's purpose or context changes

Frequently Asked Questions

Yes, in part. On 7 May 2026, Council and Parliament reached a provisional political agreement on the Digital Omnibus on AI. Annex III high-risk obligations move from 2 August 2026 to 2 December 2027. Annex I embedded high-risk obligations move from 2 August 2027 to 2 August 2028. Article 50(2) watermarking moves from 2 August 2026 to 2 December 2026. However, Article 50 transparency obligations (most parts), Article 49 EU database registration, GPAI enforcement, Article 5 prohibitions, and Article 4 AI literacy continue to apply on their original dates. The Omnibus remains provisional until formally adopted by both institutions.

Article 50 transparency obligations (chatbot disclosure, deepfake disclosure to users, emotional-recognition disclosure), Article 49 EU database registration, and national market surveillance authority enforcement powers all apply from 2 August 2026 as originally enacted. Article 5 prohibitions remain in force from February 2025. GPAI obligations remain in force from August 2025. Article 4 AI literacy remains applicable.

Pre-existing high-risk AI systems must still comply by 2 December 2027 under the Omnibus deal, unless they qualify for the Article 111 public sector legacy exception. There is no general grandfathering for existing commercial systems. Compliance programme efforts will be considered in any penalty assessment.

← Complete EU AI Act Guide

Free Resource

Where Does Your AI Stand Against the New Phased Timeline?
Find Out in 5 Minutes

Download our EU AI Act 5-Point Express Compliance Check, a structured self-assessment covering risk classification, Annex III applicability, documentation gaps, and board-level exposure. Delivered as a PDF immediately after submit.

No spam. No marketing lists. PDF delivered immediately after submit. Privacy Policy

✓   Your checklist is downloading now. Check your inbox for a copy.