EU AI Act Timeline 2026–2028: Every Deadline After the Digital Omnibus

The short answer: yes, part of the EU AI Act has been delayed — but not the part most AI startups need to worry about this year. The EU’s “Digital Omnibus on AI” — agreed in May 2026 and in force since July 2026 — pushed high-risk obligations back to December 2, 2027 (and August 2, 2028 for AI embedded in regulated products). But the Article 50 transparency rules — covering chatbots, AI-generated content, and deepfakes — still take effect on August 2, 2026. If your product talks to users or generates content, that deadline is under three weeks away.

Here is the full, updated timeline — what changed, what didn’t, and what to do about it.

The EU AI Act timeline at a glance (post-Omnibus)

DateObligationStatus
Aug 1, 2024AI Act enters into force✔ In force
Feb 2, 2025Prohibited AI practices (Art. 5) — social scoring, manipulative techniques, real-time remote biometric ID in public spaces for law enforcement (narrow exceptions)Applies now
Feb 2, 2025AI literacy duty (Art. 4) — staff training for providers and deployersApplies now
Aug 2, 2025General-purpose AI (GPAI) model obligations (Chapter V); governance; penalties frameworkApplies now
Aug 2, 2026Article 50 transparency: chatbot disclosure, AI-content marking, deepfake labellingUnchanged — 3 weeks away
Dec 2, 2026Machine-readable watermarking under Art. 50(2) — only for systems already on the EU market as of Aug 2, 2026 (grace period)⏳ Partial deferral
Dec 2, 2026New prohibitions added by the Omnibus: AI systems generating child sexual abuse material or non-consensual intimate content🆕 Added 2026
Dec 2, 2027High-risk systems under Annex III (recruitment, credit scoring, education, essential services, law enforcement…)🕐 Delayed from Aug 2, 2026
Aug 2, 2028High-risk AI embedded in regulated products under Annex I (medical devices, machinery, vehicles…)🕐 Delayed from Aug 2, 2027

Source: the Digital Omnibus on AI — political agreement of 6–7 May 2026, adopted by the European Parliament on 16 June 2026 and by the Council on 29 June 2026, in force following publication in the Official Journal in July 2026.

Is the EU AI Act delayed? What “delayed” actually means

If you’ve seen headlines that the AI Act was “delayed” or “postponed,” here is the precise picture:

What was delayed. The compliance deadlines for high-risk AI systems — the heaviest part of the Act, with requirements for risk management systems, data governance, technical documentation, human oversight, and conformity assessments. Standalone high-risk systems (Annex III) moved from August 2, 2026 to December 2, 2027. High-risk AI built into products that already have EU safety regimes (Annex I — medical devices, machinery, vehicles) moved from August 2027 to August 2, 2028.

What was not delayed. Everything already in force stays in force: the bans on prohibited practices, the AI literacy duty, and the GPAI model obligations that took effect in August 2025. And critically for most startups, Article 50 transparency obligations were not postponed — they apply from August 2, 2026, exactly as originally scheduled. The only softening: machine-readable watermarking of AI-generated content (Art. 50(2)) gets a four-month grace period, to December 2, 2026, and only for systems already on the EU market on August 2, 2026. New systems placed on the market after that date must comply in full from day one.

Formal status: this is now law. The Omnibus was agreed at political level on 6–7 May 2026 and confirmed by member state representatives on May 13. The European Parliament approved it on June 16, 2026, the Council on June 29, 2026, and the amending regulation entered into force following its publication in the Official Journal in July 2026. The new dates are no longer a proposal — they are the binding timeline.

What the Digital Omnibus changed — in plain English

The Digital Omnibus on AI is the first package of amendments to the AI Act since its adoption in 2024. Beyond moving deadlines, three things matter for founders:

  1. Breathing room on high-risk, not an exemption. If your system falls under Annex III — hiring tools, credit scoring, education proctoring, insurance pricing, critical infrastructure — you now have until December 2027. That is not a reason to stop; conformity assessment pipelines, documentation, and data-governance work realistically take 9–18 months. It is a reason to plan instead of panic.
  2. Simplification measures. The package trims some documentation duties for SMEs and clarifies overlaps with other EU digital laws. Useful, but marginal for most early-stage companies.
  3. The transparency deadline became the deadline. With high-risk pushed out, August 2, 2026 — Article 50 — is now the single most relevant date for the vast majority of AI startups selling into Europe.
  4. The prohibited list grew. The Omnibus is not only relief: it adds two new Article 5 prohibitions — AI systems generating child sexual abuse material and AI systems generating non-consensual sexual or intimate content — applicable from December 2, 2026. If anything in your product’s generative surface could be misused this way, safeguards are now a legal requirement, not just trust & safety hygiene.

August 2, 2026: what Article 50 requires

Article 50 is about honesty at the interface. From August 2, 2026, if your product is available to users in the EU:

  • Chatbots and conversational AI must make clear to users that they are interacting with an AI system — unless it’s already obvious from context.
  • AI-generated and AI-manipulated content (text published to inform the public, images, audio, video) must be identifiable as such; synthetic content needs machine-readable marking (watermarking component: grace until Dec 2, 2026 for systems already on the market).
  • Deepfakes must be visibly labelled.
  • Emotion recognition and biometric categorisation systems must inform the people exposed to them.

Two facts founders routinely miss:

  • It applies to non-EU companies. Like the GDPR, the AI Act is extraterritorial. A Delaware C-corp with EU users is in scope; “we have no EU entity” is not a defence.
  • Penalties are real. Non-compliance with transparency obligations can draw fines of up to €15 million or 3% of global annual turnover, whichever is higher — for SMEs and startups, the cap is the lower of the two, which is still real money. (Prohibited practices go up to €35M/7%.)

For a practical walkthrough of disclosure patterns — where the notice goes in the UI, what counts as “obvious from context,” how to watermark — see our Article 50 compliance guide.

Already in force: the obligations startups forget

The 2027–2028 headlines hide the fact that three sets of duties apply today:

  • Prohibited practices (since Feb 2025). Social scoring, exploitative manipulation, emotion inference in workplaces and schools (with narrow exceptions), untargeted scraping for facial recognition databases. If any feature flirts with this list, it is a launch blocker, not a roadmap item.
  • AI literacy (since Feb 2025). Providers and deployers must ensure staff dealing with AI systems have adequate AI literacy. A documented internal training counts; nothing counts if nothing is documented.
  • GPAI obligations (since Aug 2025). If you train or substantially fine-tune general-purpose models, Chapter V applies: technical documentation, copyright policy, training-data summaries — and more if your model crosses the systemic-risk threshold.

What your startup should do now: a 3-week plan

Week 1 — map yourself. Inventory every AI touchpoint: user-facing chat, generated content, decision-making features. Classify against Article 50 and the prohibited list. (Our fixed-fee Europe Risk Scan does exactly this in one week.)

Week 2 — close the Article 50 gaps. Add AI-interaction disclosures to conversational interfaces; implement content labelling; specify watermarking approach for synthetic media; label any deepfake functionality.

Week 3 — document and calendar. Write down what you did (regulators ask for records, not intentions); document AI literacy training; if anything falls under Annex III, put a high-risk readiness plan on the calendar with a Q1 2027 start.

If high-risk applies to you, the December 2027 date is your runway — use it. Conformity assessment is a project, not a form.

FAQ

Is the EU AI Act delayed?

Partially. High-risk obligations moved to December 2, 2027 (Annex III) and August 2, 2028 (Annex I). The Article 50 transparency rules were not delayed and apply from August 2, 2026. Prohibitions, AI literacy, and GPAI duties already apply.

What is the Digital Omnibus on AI?

The EU’s first amendment package to the AI Act — agreed in May 2026, adopted by the Parliament and Council in June 2026, and in force since July 2026. It defers high-risk deadlines, simplifies some documentation duties, adds two new prohibitions on AI-generated CSAM and non-consensual intimate content, and keeps the transparency timeline intact.

Does the EU AI Act apply to US companies?

Yes — it applies to any company placing an AI system on the EU market or whose system’s output is used in the EU, regardless of where the company is established.

What happens on August 2, 2026?

Article 50 transparency obligations take effect: chatbots must disclose they are AI, synthetic content must be identifiable, deepfakes must be labelled. Watermarking under Art. 50(2) has a grace period to December 2, 2026 — but only for systems already on the EU market by August 2, 2026.

What are the penalties for non-compliance?

Up to €35M or 7% of global turnover for prohibited practices; up to €15M or 3% for most other violations, including transparency; up to €7.5M or 1% for supplying incorrect information to authorities. For SMEs and startups, each cap applies at the lower of the fixed amount or the percentage.

My product uses a chatbot. Do I need to change anything?

Almost certainly yes, if EU users can access it: an unambiguous disclosure that the user is interacting with AI, unless that is obvious from context. The safe pattern is an explicit notice at the start of the interaction.

Need certainty before August 2?

Montaire & Co. runs a fixed-fee EU AI Act compliance scan for AI startups: classification against Article 50, the prohibited list, and Annex III — with a written action plan in one week. No hourly billing, no BigLaw process.

30 minutes · senior advisor · no charge, no obligation

This article is general information, not legal advice. Regulatory status as of July 16, 2026; we update this page after every significant development.