Skip to content

EU AI Act

Amended European Union · In force Aug 1, 2024 · next deadline Dec 2, 2026 (in 2 months)

Deadlines

DateWhat happens
Aug 1, 2024AI Act enters into force2.1 years ago
Feb 2, 2025Prohibited practices and AI literacy apply20 months ago
Aug 2, 2025GPAI, governance, notified bodies and penalties apply14 months ago
Jul 27, 2026Digital Omnibus on AI enters into force59 days ago
Aug 2, 2026General application: transparency obligations, GPAI fines, most other rules53 days ago
Dec 2, 2026New bans on sexual deepfakes and CSAM generation; Art 50(2) grace period endsin 2 months
Aug 2, 2027Legacy GPAI models must comply; national AI sandboxes operationalin 10 months
Dec 2, 2027High-risk obligations apply to Annex III systemsin 14 months
Aug 2, 2028High-risk obligations apply to Annex I product-embedded systemsin 22 months
Aug 2, 2030Public-authority high-risk systems must complyin 3.9 years
Dec 31, 2030Large-scale EU IT systems must complyin 4.3 years

Summaries for reference, not legal advice. Check the official text.

What it does

A risk-based product-safety regime for AI. It bans certain AI practices, imposes strict requirements on high-risk AI systems (risk management, data governance, documentation, human oversight, conformity assessment), sets transparency duties for chatbots, deepfakes and AI-generated content, and sets obligations for general-purpose AI model providers. The Digital Omnibus on AI (Regulation (EU) 2026/1744, in force 27 July 2026) pushed the high-risk dates back to 2 December 2027 (Annex III) and 2 August 2028 (Annex I). It also softened the AI literacy duty and added bans on non-consensual sexual deepfakes and child sexual abuse material (CSAM) generation.

Who it applies to
Providers placing AI systems or general-purpose AI models on the EU market (wherever established), deployers of AI systems in the EU, importers, distributors, and non-EU providers/deployers whose AI output is used in the EU. GPAI models trained with more than 10^25 FLOPs are presumed to have systemic risk.
Penalties
Prohibited practices: up to EUR 35M or 7% of worldwide annual turnover, whichever is higher. Most other operator obligations: up to EUR 15M or 3%. Incorrect or misleading information to authorities: up to EUR 7.5M or 1%. For SMEs, and since the 2026 Omnibus also small mid-caps (SMCs), the lower of the two amounts applies. GPAI providers: Commission fines up to EUR 15M or 3% (Art 101).
Enforced by
National market surveillance authorities and notifying authorities; European Commission AI Office (GPAI models and AI systems built on them); European AI Board
Official name
Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act), as amended by Regulation (EU) 2026/1744 (Digital Omnibus on AI)
Citation
OJ L, 2024/1689, 12.7.2024; amended by OJ L, 2026/1744, 24.7.2026
Topics
ai, biometrics, children
Research notes

The Digital Omnibus on AI (Commission proposal 19 Nov 2025; EP position 16 June 2026; Council decision 29 June 2026; signed 8 July 2026) was published in the OJ on 24 July 2026 as Regulation (EU) 2026/1744 and has been in force since 27 July 2026. The high-risk delays are therefore legally binding, not tentative. Other Omnibus changes: Art 4 AI literacy recast as 'take measures to support' AI literacy (no guaranteed level); SME relief extended to small mid-caps; registration for Art 6(3) non-high-risk systems simplified; machinery moved from Annex I Section A to Section B; Commission guidance on post-market monitoring due 2 Sep 2027. Existing high-risk systems placed on the market before the relevant Chapter III date are covered only if significantly changed afterwards (Art 111(2)). The AI Act Service Desk article pages had not yet been updated to show the Omnibus text when checked.

Related

Questions about EU AI Act
What are the EU AI Act compliance deadlines?
Aug 1, 2024: AI Act enters into force. Feb 2, 2025: Prohibited practices and AI literacy apply. Aug 2, 2025: GPAI, governance, notified bodies and penalties apply. Jul 27, 2026: Digital Omnibus on AI enters into force. Aug 2, 2026: General application: transparency obligations, GPAI fines, most other rules. Dec 2, 2026: New bans on sexual deepfakes and CSAM generation; Art 50(2) grace period ends. Aug 2, 2027: Legacy GPAI models must comply; national AI sandboxes operational. Dec 2, 2027: High-risk obligations apply to Annex III systems. Aug 2, 2028: High-risk obligations apply to Annex I product-embedded systems. Aug 2, 2030: Public-authority high-risk systems must comply. Dec 31, 2030: Large-scale EU IT systems must comply.
When does EU AI Act take effect?
EU AI Act took effect on Aug 1, 2024. The next milestone is Dec 2, 2026: New bans on sexual deepfakes and CSAM generation; Art 50(2) grace period ends.
Who does EU AI Act apply to?
Providers placing AI systems or general-purpose AI models on the EU market (wherever established), deployers of AI systems in the EU, importers, distributors, and non-EU providers/deployers whose AI output is used in the EU. GPAI models trained with more than 10^25 FLOPs are presumed to have systemic risk.
What are the penalties under EU AI Act?
Prohibited practices: up to EUR 35M or 7% of worldwide annual turnover, whichever is higher. Most other operator obligations: up to EUR 15M or 3%. Incorrect or misleading information to authorities: up to EUR 7.5M or 1%. For SMEs, and since the 2026 Omnibus also small mid-caps (SMCs), the lower of the two amounts applies. GPAI providers: Commission fines up to EUR 15M or 3% (Art 101).

When the rules change: new data, privacy and AI laws and deadlines, the next morning.