Library
EU AI Act: Timeline & Current Status
As of 13 August 2026, Regulation (EU) 2026/1744 has moved Annex III high-risk duties to 2 December 2027 and Annex I product-safety high-risk duties to 2 August 2028. Article 5 prohibitions, GPAI Chapter V, and Article 50 transparency are not part of that deferral.
Last reviewed
MikeFounder & developer
- EU AI Act
- AI governance
- Compliance
On this page
Who this is for
- Operators who place AI systems on the EU market, or whose output is used in the Union
- Deployers of vendor tools (chatbots, copilots, scoring, recruitment) that touch EU staff or customers
- Compliance owners who heard “the AI Act was delayed” and need the dated split
- Readers of The Clock Didn't Stop who want the full table
The two instruments
The AI Act is Regulation (EU) 2024/1689, adopted 13 June 2024, in force 1 August 2024. Obligations apply on staggered dates under Article 113.
The Digital Omnibus on AI is Regulation (EU) 2026/1744, dated 8 July 2026, published 24 July 2026, in force 27 July 2026. It amends 2024/1689 (and, separately, aviation and machinery rules). It does not repeal the Act.
A different “Digital Omnibus” file touching GDPR and ePrivacy is not this instrument. Do not mix the two.
Live versus deferred, as of 13 August 2026
| Date | Obligation | Status | Citation |
|---|---|---|---|
| 1 August 2024 | AI Act enters into force | Live | 2024/1689 Art. 113 |
| 2 February 2025 | Prohibited practices (original Article 5 list); AI literacy (Article 4) | Live | 2024/1689 Art. 113, third paragraph, point (a); Art. 4 as amended by 2026/1744 |
| 2 August 2025 | GPAI model duties (Chapter V, Arts 51–55); governance bodies; most penalty provisions | Live | 2024/1689 Art. 113 |
| 27 July 2026 | Digital Omnibus on AI enters into force | Live | 2026/1744 Art. 4 |
| 2 August 2026 | Article 50 transparency; general application of the Act; AI Office enforcement powers over GPAI providers | Live | 2024/1689 Art. 50 and Art. 113; 2026/1744 (transparency date unchanged) |
| 2 December 2026 | Article 50(2) machine-readable marking for generative systems already on the market before 2 August 2026; new Article 5 points (ba) and (bb) (non-consensual intimate imagery; AI-generated CSAM) | Upcoming | 2026/1744 amendments to Arts 111 and 113 |
| 2 August 2027 | GPAI models placed on the market before 2 August 2025 must comply; national AI regulatory sandboxes operational | Upcoming | 2024/1689 Art. 111; Art. 57 as amended by 2026/1744 |
| 2 December 2027 | Chapter III Sections 1–3 high-risk duties for systems classified under Article 6(2) and Annex III | Deferred (was 2 August 2026) | 2026/1744 amendment to Art. 113 |
| 2 August 2028 | Chapter III Sections 1–3 high-risk duties for systems classified under Article 6(1) and Annex I | Deferred (was 2 August 2027) | 2026/1744 amendment to Art. 113 |
| 2 August 2030 | Providers and deployers of high-risk systems intended to be used by public authorities must comply | Upcoming | 2024/1689 Art. 111(2) as amended by 2026/1744 |
| 31 December 2030 | Obligations for certain large-scale IT systems listed in Annex X | Upcoming. Not amended in the 2026/1744 text we checked | 2024/1689 Art. 113 original |
Warning: “The AI Act was delayed” is false as a general statement. Chapter III high-risk duties for Annex III systems were deferred to 2 December 2027. Article 5, Chapter V, and Article 50 were not.
What is already live (do not wait)
Article 5: prohibited practices. Social scoring by public authorities, untargeted scraping of facial images to build a recognition database, emotion recognition in the workplace or education except narrow medical/safety uses, real-time remote biometric identification in publicly accessible spaces except the listed law-enforcement cases. From 2 December 2026 the list also covers AI systems that generate or manipulate non-consensual intimate imagery of real people, and AI systems that generate or manipulate child sexual abuse material.
Chapter V: GPAI providers. If you develop and place a general-purpose model on the market, Articles 53 (and 55 if systemic risk) already apply. Most Lathestone readers are deployers, not providers. See GPAI model obligations.
Article 50: transparency. From 2 August 2026: disclose AI interaction unless obvious; label deepfakes and certain public-interest synthetic text; providers mark synthetic output. Grace to 2 December 2026 applies only to Article 50(2) marking for systems already on the market before 2 August 2026.
Article 4: AI literacy. In force since 2 February 2025. The Omnibus rewrote it from a duty to ensure a sufficient level of literacy into a duty to take measures to support its development. Still binding. Still evidence-based.
What was deferred (high-risk Chapter III)
Sections 1, 2 and 3 of Chapter III: classification, the requirements in Articles 8–15 (including human oversight in Article 14), and the provider/deployer obligations that hang off those requirements, apply from:
- 2 December 2027 for Annex III / Article 6(2) systems
- 2 August 2028 for Annex I / Article 6(1) systems (safety components in already-regulated products)
Existing high-risk systems already on the market before those dates are caught only if they undergo significant design changes, except public-authority systems which must comply by 2 August 2030 (Art. 111 as amended).
Article 5 remains applicable throughout. A prohibited practice does not become lawful because Chapter III moved.
For the category list and the Article 6(3) filter, see What counts as high-risk under Annex III.
Territorial reach
Article 2 was not narrowed by the Omnibus. The Act applies to providers placing systems or models on the Union market, deployers established in the Union, and providers and deployers in third countries where the output is used in the Union. A UK company whose chatbot answers EU customers is in scope for the duties that have applied, even if the servers sit in London.
How to use this page
- Inventory the systems you run, including vendor copilots. Building an AI system inventory.
- Name provider versus deployer for each row.
- Check prohibited practices first. Then Article 50. Then whether Annex III is even in play.
- Put the dates that apply to you on the global calendar.
The argument behind the split, and why “delayed” is the dangerous word, is in The Clock Didn't Stop.
Questions
Was the whole EU AI Act delayed?
No. Regulation (EU) 2026/1744 deferred Chapter III Sections 1–3 for Annex III systems to 2 December 2027 and for Annex I systems to 2 August 2028. Article 5, Chapter V and Article 50 stay on their original (or newly added) dates.
Does the delay help if we use a prohibited practice?
No. Article 5 has applied since 2 February 2025. The Omnibus added two further prohibitions from 2 December 2026. It did not create a grace period for the original bans.
We only deploy a US vendor's model. Are we a GPAI provider?
Usually not. GPAI Chapter V binds the provider of the model. You may still be a deployer of an AI system built on that model, with Article 50 and, later, high-risk duties if the use-case sits in Annex III. See GPAI model obligations.
Where is the consolidated text?
The Act is 2024/1689. The amendments are 2026/1744. As of 13 August 2026, operators should read them together. A single official consolidated print may lag; do not treat a pre-July 2026 commentary as current on dates.
What changed
- 13 August 2026: First publication against 2024/1689 and 2026/1744. Cadence: high-risk / fast-moving (30–90 days). Next review due 13 October 2026. Off-cycle update if the Commission or Official Journal moves a date.
Note: This is compliance consulting and training, not legal advice. We work alongside your legal counsel, translating regulation into operational reality rather than replacing them. For a structured pass, see AI compliance.
Was this helpful?
Also in the library
- What Counts as High-Risk Under Annex IIIAnnex III is a use-case list, not a model list. Most Lathestone clients who over-classify do it because the tool is 'AI'; most who under-classify miss internal HR and customer-decision systems. Article 6(3) exemptions exist. They are narrow, and profiling is not one of them.
- GPAI Model Obligations, ExplainedIf you did not train and place the model on the market, you are probably a deployer, not a GPAI provider, and Chapter V is not your chapter. Providers have been on the clock since 2 August 2025: transparency, copyright policy, a training-content summary, and extra duties above 10^25 FLOPs.
- The AI Vendor Risk ChecklistA procurement list you can actually use. Data handling, training-on-your-data, sub-processors, audit rights, and model-change notifications: the clauses that decide whether a vendor is safe to put on a live path.