The EU AI Act is already law, but its requirements are taking effect in stages. It entered into force on 1 August 2024; some rules have applied since 2025, while later milestones run through 2 August 2028. The Digital Omnibus on AI, which entered into force on 27 July 2026, amended parts of the regime and set dates for later high-risk obligations—it did not repeal the Act or make every AI system high-risk.
This account reflects the European Commission’s implementation timeline and AI Act overview available on 8 October 2026. The timeline is a live regulatory fact and may change.
What “the AI Act is done” means
The AI Act entered into force on 1 August 2024, but entry into force is not the same as every provision applying at once. Its obligations are phased according to the kind of system, its intended use and the actor involved. Under the Commission’s current implementation timeline, the main rollout reaches 2 August 2028.
The Digital Omnibus was adopted by the Commission on 19 November 2025, reached political agreement on 7 May 2026 and entered into force on 27 July 2026, according to the Commission’s AI Act overview. It changed parts of the implementation framework and specified obligations. It did not reset the Act’s start date: provisions had already begun applying in 2025.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →#1 Best Overall
When each part of the AI Act applies
These are the dates in the Commission’s current timeline. “Applies” does not mean every organisation or AI system has a new duty on that date; the relevant provision and the system’s classification determine who is affected.
| Date | Milestone | Who or what it concerns |
|---|---|---|
| 1 August 2024 | The Act entered into force. | The legal framework began; this was not the date when all its requirements started applying. |
| 2 February 2025 | Definitions, AI literacy provisions and prohibitions began to apply. The Commission overview says prohibitions 1–8 became effective. | Relevant providers, deployers and other actors covered by those provisions. |
| 2 August 2025 | Rules for general-purpose AI (GPAI) models and governance provisions began to apply. | GPAI providers have model-related duties. Member States were to designate national competent authorities and adopt national penalty laws; EU governance bodies were to be set up. |
| 2 August 2026 | Article 50 transparency requirements apply, and enforcement begins for applicable rules. | Actors and systems covered by the relevant transparency provisions and other rules already in application. |
| 2 December 2026 | The timeline lists additional prohibitions concerning generation of non-consensual sexual deepfakes and child sexual abuse material. It also lists the transition deadline for certain systems already on the market before 2 August 2026 to meet Article 50(2)’s marking and detection obligation. | The additional prohibitions and the specified transition case; this is not a general delay of Article 50. |
| 2 August 2027 | At least one AI regulatory sandbox should be operational in each Member State. | Member States, for the sandbox requirement. |
| 2 December 2027 | Rules for Annex III high-risk AI systems apply. | Systems that fall within the relevant Annex III use cases. |
| 2 August 2028 | Rules for Annex I high-risk AI systems embedded in regulated products apply. | Systems classified as high-risk through their connection to products covered by the relevant EU product-safety legislation. |
The dates are drawn from the Commission’s timeline. In particular, the December 2026 Article 50(2) transition is limited to certain systems already placed on the market before 2 August 2026; it should not be read as postponing transparency requirements generally.
Rank #2
What the Digital Omnibus changed—and what it did not
The Omnibus amended parts of the AI Act framework. The Commission says it set dates for later high-risk obligations, introduced the additional prohibition applying in December 2026, reinforced the AI Office’s powers and centralised oversight in specified areas. It also extended certain simplified requirements for small and medium-sized enterprises to small mid-cap companies, broadened access to regulatory sandboxes and clarified how the AI Act interacts with EU product-safety law.
These changes are not a repeal or a wholesale replacement of the Act. Nor should every proposed simplification be treated as an enacted rule: the Commission Service Desk’s Digital Omnibus FAQ includes proposal-stage descriptions. For the current schedule, use the enacted dates in the timeline; the exact final detail behind every simplification is not established by the Commission pages cited here.
Recommended Free Tools
Which AI systems count as high-risk?
The Act uses four broad risk levels: unacceptable risk, high risk, transparency risk, and minimal or no risk. The Commission says minimal- or no-risk applications generally face no additional AI Act rules. The Act therefore does not classify every AI feature or product as high-risk simply because it uses AI.
The Commission’s overview gives examples of prohibited practices, including harmful manipulation or exploitation of vulnerabilities, social scoring, certain predictions about an individual’s likelihood of committing a criminal offence, specified facial-recognition database scraping, emotion recognition in workplaces and education, certain biometric categorisation, and specified real-time remote biometric identification for law enforcement. The additional prohibition on generating non-consensual sexually explicit or intimate content or child sexual abuse material is listed for application from 2 December 2026.
High-risk examples in the Commission overview include AI used in critical infrastructure, education decisions, safety components of products, recruitment and worker management, certain essential services such as credit scoring, biometrics, law enforcement, migration, asylum and border control, justice, and democratic processes. These are examples, not a complete classification test. The intended use and the applicable provisions matter.
Why credit scoring is relevant to personal finance
The Commission identifies certain credit-scoring uses among its high-risk examples. That does not establish that every algorithm used by a lender, every financial product, or every AI-assisted decision is automatically high-risk under the Act. A provider or deployer needs to assess the specific system and use against the Act’s categories. The AI Act’s risk classification is also distinct from any other rules that may govern a financial decision.
Best Value
What high-risk rules require
For high-risk systems, the Commission lists requirements including risk assessment and mitigation, high-quality datasets, activity logging, technical documentation, adequate information for deployers, human oversight, and robustness, cybersecurity and accuracy. The application date depends on the route by which the system is high-risk: Annex III uses the 2 December 2027 date, while systems embedded in Annex I regulated products have the 2 August 2028 date.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What applies to GPAI providers and what applies to transparency
General-purpose AI models
GPAI model rules have applied since 2 August 2025. The Commission describes provider duties concerning transparency and copyright, and assessment and mitigation of systemic risks for models that may pose them. These model-provider duties should not be collapsed into the obligations of every downstream provider or deployer that uses a model.
AI-generated content and interactions
Article 50 transparency requirements apply from 2 August 2026. They include disclosure in relevant interactions and identification or labelling for certain AI-generated content. The scope depends on the particular requirement; the existence of AI-generated content alone does not mean that every output must carry the same label. For the limited Article 50(2) transition concerning certain systems already on the market, the Commission timeline gives 2 December 2026 as the deadline.
How to work out whether a date affects you
For a business, institution or person assessing a particular system, use four questions rather than treating the Act as a single deadline:
- What is the system’s intended use and risk category? Check whether the use falls under a prohibition, a high-risk category, a transparency requirement, or generally minimal- or no-risk treatment.
- What is your role? The relevant duties may differ for a provider, a deployer or a GPAI model provider. A model provider’s obligations do not automatically become the same obligations for every organisation using that model.
- Which application date applies? Match the specific obligation to its date in the Commission’s timeline; do not assume the 2026, 2027 or 2028 milestone is a general start date for the whole Act.
- If the system is high-risk, which route makes it high-risk? Distinguish an Annex III use case, with the 2 December 2027 date, from an Annex I regulated-product system, with the 2 August 2028 date.
The Commission’s AI Act overview frames the goal this way: “The AI Act ensures that Europeans can trust what AI has to offer.” For practical purposes, the key is to identify the relevant use, actor and provision before relying on a date or assuming a particular duty applies.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




