The EU AI Act enforcement timeline: what applies when
Regulation (EU) 2024/1689 applies in stages: prohibited practices since February 2025, GPAI obligations and penalties since August 2025, and broad transparency duties from August 2026. The most demanding high-risk obligations were pushed back by the 2026 ‘Digital Omnibus’ amendment — to December 2027 for standalone Annex III systems. This overview sets out the deadlines and fine ceilings for regulated teams.
Entry into force and staggered application
Regulation (EU) 2024/1689 (the EU AI Act) entered into force on 1 August 2024, but it does not take effect as a single block. Article 113 sets out a staggered timeline under which individual chapters become applicable on different dates, and a 2026 amendment (the ‘Digital Omnibus on AI’) pushed several high-risk deadlines further out. For regulated organisations this means some obligations already bind today, while others follow in clearly defined steps through 2028.
- 2 Feb 2025Prohibited practices (Art. 5) and staff AI literacy (Art. 4)
- 2 Aug 2025GPAI-model obligations, governance bodies and the penalty framework
- 2 Aug 2026Transparency obligations under Article 50
- 2 Dec 2026NewProvider labelling (Art. 50(2)) and new prohibitions: nudifiers and CSAM (Art. 5)
- 2 Dec 2027High-risk obligations for standalone Annex III systems
- 2 Aug 2028High-risk obligations for embedded Annex I systems (Art. 6(1))
What already applies: February and August 2025
Two milestones already bind. Since 2 February 2025, the prohibitions on certain AI practices (Article 5) and the AI-literacy duty for staff (Article 4) have applied. Since 2 August 2025, the obligations for providers of GPAI models, the governance bodies at EU and national level, and the penalty framework have taken effect.
- 2 Feb 2025 — Prohibited practices (Art. 5) and AI literacy (Art. 4)
- 2 Aug 2025 — GPAI-model obligations, governance bodies and penalties
What is still to come: 2026, 2027 and 2028
The next milestone is 2 August 2026, when the transparency obligations under Article 50 begin to apply — for example, disclosing that users are interacting with AI and labelling AI-generated content — with the provider watermarking duty (Article 50(2)) following on 2 December 2026. The most consequential duties, however, moved. The 2026 ‘Digital Omnibus’ amendment postponed the core obligations for standalone high-risk AI systems under Annex III — risk management, data governance, logging, technical documentation and human oversight — from 2 August 2026 to 2 December 2027. High-risk AI acting as a safety component of already-regulated products under Annex I (Article 6(1)) follows on 2 August 2028.
This shift is now settled law, not a proposal: the Digital Omnibus on AI was endorsed by the European Parliament on 16 June 2026 and given final approval by the Council on 29 June 2026, with publication in the Official Journal following. It reshaped the calendar but left the substance of the obligations — and the penalty regime — intact. The authoritative reference remains the adopted text of Regulation (EU) 2024/1689 as amended.
The Digital Omnibus did not only defer deadlines — it also added new prohibitions: Article 5 now expressly bans AI systems that generate non-consensual intimate imagery ("nudifiers") and child sexual abuse material (CSAM). These new prohibited practices apply from 2 December 2026.
Fine ceilings and what to do now
Article 99 sets three fine tiers, in each case whichever is higher: up to EUR 35M or 7% of worldwide annual turnover for prohibited practices under Article 5; up to EUR 15M or 3% for most other breaches; and up to EUR 7.5M or 1% for supplying incorrect, incomplete or misleading information to authorities or notified bodies. Because penalties have applied since August 2025, this framework is not a future concern but already-binding law.
In practice: build an inventory of every AI system you operate or procure, map each to the Regulation's risk categories, and prioritise Annex III use cases. Embed AI-literacy training, document data provenance and human oversight, and clarify your role per system (provider, deployer, importer or distributor), since obligations are calibrated to that role.
- EUR 35M / 7% — prohibited practices (Art. 5)
- EUR 15M / 3% — most other breaches
- EUR 7.5M / 1% — incorrect information to authorities
Build a risk-classified inventory of your AI systems now: the transparency duties arrive in 2026, and the Annex III high-risk obligations must be demonstrably met by 2 December 2027.