The date everyone memorised is no longer the date
2 August 2026 stood for the high-risk regime for two years. Regulation (EU) 2026/1744 moved it to 2 December 2027. What did not move is the part that binds almost everyone — and most summaries published since July still have the old table.
The timeline as it now stands
- 1 August 2024Entry into force
- The Act is law. Everything below is a staged application date rather than a separate instrument.
- 2 February 2025Prohibitions and AI literacy
- Article 5 prohibitions bind. So does Article 4 on AI literacy — for every organisation deploying AI, with no exemption by size or risk class. Neither was touched by the Omnibus.
- 2 August 2025General-purpose AI and penalties
- Obligations for providers of general-purpose AI models, the penalty regime, and designation of national authorities.
- 27 July 2026Digital Omnibus enters into force
- Regulation (EU) 2026/1744, published 24 July 2026. It postpones the high-risk dates, rewrites Article 4, and adds one prohibition to Article 5. What already applied stays.
- 2 August 2026Article 50 transparency
- Disclosure to people interacting with AI, machine-readable marking of synthetic content, deepfake disclosure. Not postponed — this is the date that actually landed in 2026.
- 2 December 2026Two transition periods close
- The prohibition added by the Omnibus takes full effect. The four-month watermarking grace period under Article 50(2) ends for systems placed on the market before 2 August 2026.
- 2 August 2027Regulatory sandboxes
- Deadline for Member States to establish national AI regulatory sandboxes — also moved by the Omnibus. Obligation on states, not on companies.
- 2 December 2027Annex III high-risk
- Postponed from 2 August 2026. Standalone high-risk systems: employment, creditworthiness, education, critical infrastructure, law enforcement. This is the date that older summaries still show as 2026.
- 2 August 2028Annex I embedded high-risk
- Postponed from 2 August 2027. AI as a safety component in products already covered by Union harmonisation law.
- 2 August 2030Legacy public-sector systems
- Separate transitional rules for high-risk systems put into service by public authorities before the cut-off.
Source for the amended dates: Regulation (EU) 2026/1744, published in the Official Journal on 24 July 2026, in force since 27 July 2026.
Does this reach a company outside the EU?
On two independent grounds, and either is enough.Placing a system on the Union market brings a provider in scope regardless of where it is established.Using a system outside the EU whose output is used inside the EU brings a deployer in scope on its own.
There is no revenue threshold for scope. The SME provisions in the Act concern how a penalty is calculated, not whether the obligations apply — a distinction that is regularly collapsed in vendor material and that matters, because the first question an authority asks is not about turnover.
For a company selling software into the EU, the practical consequence of the postponement is narrower than it looks. Your customers will start asking conformity questions long before December 2027, because their own preparation runs on the same clock — and a supplier who cannot answer in 2026 gets replaced rather than waited for.
What the sixteen months are actually for
Not for waiting. Annex IV documentation is written over quarters: risk management as a continuous process under Article 9, data governance under Article 10, technical documentation under Article 11, logging under Article 12, human oversight under Article 14. None of that compresses into a final sprint, because the evidence has to be produced while the system is being built, not reconstructed afterwards.
The more immediate item sits earlier in the calendar. Article 50 has applied since 2 August 2026 and is the one obligation that arrived in 2026 rather than moving out of it. If you run a chatbot, generate synthetic media, or publish AI-assisted text on matters of public interest, that is a live obligation now — and it is the one almost nobody checked, because the attention went to the part that was postponed.
The second item is classification. Whether a use case falls under Annex III changes what you buy and what you write into supplier contracts, and those contracts run for years. Determining it in 2027 means renegotiating agreements signed in 2026.
Frequently asked
Was the EU AI Act delayed?+
Parts of it. Regulation (EU) 2026/1744 — the Digital Omnibus on AI — was published on 24 July 2026 and entered into force on 27 July 2026. It moved Annex III high-risk obligations from 2 August 2026 to 2 December 2027, and Annex I from 2 August 2027 to 2 August 2028. Nothing was repealed: the requirements themselves are unchanged, only their application dates.
What was not delayed?+
Article 5 prohibitions, in force since 2 February 2025. Article 4 on AI literacy, same date. General-purpose AI obligations, in force since 2 August 2025. And Article 50 transparency, which took effect on 2 August 2026 as originally scheduled. For most deploying organisations these four are the entire practical picture — and none of them moved.
Does the Act apply to a company outside the EU?+
Yes, on two independent grounds. Placing an AI system on the Union market brings you in scope regardless of establishment. So does using a system outside the EU where its output is used inside the EU. There is no revenue threshold and no small-company carve-out for scope — the SME relief in the Act concerns penalty calculation, not applicability.
What changed in Article 4?+
The wording. Providers and deployers previously had to "take measures to ensure, to their best extent, a sufficient level of AI literacy"; they now have to "take measures to support the development of AI literacy", with an explicit clarification that no specific level of literacy needs to be guaranteed for any individual. The duty to act survives; the standard against which it is measured is lower.
Is the postponement likely to be extended again?+
Nobody can answer that honestly, and for planning it matters less than it appears. What moved was the high-risk regime, which does not apply to most deployers anyway. What binds the majority — prohibitions, AI literacy, transparency — survived both rounds untouched. Planning around a further delay means planning around the part you probably do not need.
Where does the sixteen months actually go?+
Into conformity work that takes quarters rather than weeks: risk management as a continuous process under Article 9, data governance under Article 10, technical documentation under Article 11 and Annex IV, logging under Article 12, human oversight under Article 14. Organisations that treat the delay as a pause typically rediscover in mid-2027 that supplier contracts signed in 2026 now have to be renegotiated.
Which date should a deployer put in the plan?+
2 August 2026 — because Article 50 already applies and most organisations have not checked whether their chatbots and published AI-assisted content comply. The December 2027 date belongs in the plan only if a use case actually falls under Annex III, and that is worth determining now rather than in 2027, because it changes what you buy.