EU AI Act 2025–2028 timeline featuring an EU flag, AI technology symbol, legal gavel, AI Act book, and compliance timeline calendar.

Artificial Intelligence Regulation Is No Longer Theoretical

Image AI-generated. All  text human -written.

For most of 2025, the EU AI Act existed for many organisations as a compliance project with a distant horizon — something to plan around, not something actively in force. That framing is no longer accurate. Several obligations under the Act are already live, enforcement bodies already have investigative and sanctioning powers, and the legislative picture itself has changed materially in the past few weeks. Any internal guidance, client-facing memo, or public commentary still describing the Act’s timeline in pre-summer-2026 terms should be treated as out of date and re-checked before it goes out the door again.

The EU AI Act (Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744) is the world’s first comprehensive, horizontal AI regulatory framework — meaning it applies across sectors and use cases, rather than being limited to a single industry the way some earlier proposals were. It does not take effect on a single date. Instead, it applies in stages between 2 February 2025 and 2 August 2028, with different chapters, articles, and annexes activating at different points along that timeline. Organisations that treat the Act as a single compliance deadline risk both of the two most common mistakes at once: assuming obligations that are already binding are still far off, and assuming obligations that are genuinely years away are already binding.

The instrument

In November 2025, the European Commission proposed a legislative package known informally as the Digital Omnibus on AI, intended to simplify and re-sequence parts of the Act’s implementation timeline. At the time, that package was exactly what its name suggested: a proposal, subject to negotiation and possible amendment before adoption.

That is no longer the case. The proposal was adopted and entered into force as Regulation (EU) 2026/1744, effective 27 July 2026. It is now part of the binding legal framework governing AI in the EU, not a pending or contingent one. Among its most consequential changes, the Omnibus deferred the compliance deadline for Annex III high-risk systems and made targeted amendments elsewhere in the Act, including to Article 5’s list of prohibited practices (discussed below).

Any material — internal or external — that still describes the Omnibus as “proposed,” “pending,” “not yet adopted,” or something that “could” happen is factually incorrect as of this writing and should be corrected before further distribution. This is the single highest-priority fix in this review, because it is the error that most directly misleads readers about what is currently legally required and by when.

Application dates

The Act’s staged rollout is best understood as six distinct milestones, each activating a different slice of the regulation. Getting these in the right order — and not conflating them — is the difference between an accurate compliance calendar and a misleading one.

  • 2 February 2025 — Article 5 prohibited-practices obligations began applying. This is the Act’s “floor”: a small set of AI uses (such as certain manipulative or exploitative systems, and untargeted scraping for facial-recognition databases) are banned outright, with no risk-tiering or conformity-assessment pathway available. These obligations have been in force for well over a year and are not affected by the staged timeline that applies to everything else.

  • 2 August 2025 — General-purpose AI (GPAI) provider obligations began applying. This covers foundation-model providers specifically — documentation, transparency toward downstream deployers, and (for models deemed to carry systemic risk) additional risk-assessment and incident-reporting duties. This is a distinct obligation set from the high-risk-system rules described below, and the two are sometimes conflated in commentary.

  • 2 August 2026 — Article 50 transparency obligations go live, alongside the Commission’s expanded Chapter IX market-surveillance and AI Office enforcement powers. Article 50 covers disclosure duties for AI systems that interact directly with people, generate synthetic media, or produce content that could be mistaken for human-generated — think chatbot disclosure requirements and labelling of AI-generated or manipulated audio, image, and video content. This date is frequently — and incorrectly — cited as “the” AI Act deadline. It is not the high-risk deadline; it is the transparency and enforcement-infrastructure deadline.

  • 2 December 2026 — Two additional Article 5 prohibited practices, added by the Digital Omnibus (new Art 5(1)(ba) and (bb)), begin applying. These extend the prohibited-practices list beyond what was originally in the 2024 text.

  • 2 December 2027 — Annex III high-risk obligations (Chapter III, Sections 1–3) apply, per the amended Article 113. Annex III covers high-risk use cases such as employment/HR screening, access to essential services, law enforcement, migration and border control, and administration of justice. This is the deadline most organisations building or deploying high-risk systems actually need to plan around — and it was pushed back from the original 2 August 2026 date specifically by the Omnibus.


  • 2 August 2028 — Annex I high-risk obligations apply. Annex I covers AI systems that are safety components of, or are themselves, products already regulated under existing EU product-safety legislation (machinery, medical devices, toys, lifts, and similar categories) — a smaller and more specialised set of systems than Annex III.

Put simply: high-risk AI systems that cannot demonstrate compliance are barred from the EU market from 2 December 2027 (Annex III) and 2 August 2028 (Annex I) — not from 2 August 2026. What genuinely does bind organisations from 2 August 2026 is the Article 50 transparency regime and the Commission’s expanded enforcement and market-surveillance powers. Confusing these two dates is the single most common error in AI Act commentary right now, and it runs in both directions: it understates what’s actually due in August 2026 (transparency, not high-risk conformity) while overstating urgency around the high-risk deadline by roughly sixteen months.

Penalties

Coverage of the Act’s penalty regime tends to collapse it into a single headline figure — “up to 7% of global turnover” — which understates both the structure and, in most real-world cases, the actual exposure. The Act sets four separate fine tiers, scaled to the severity of the underlying violation, each expressed as “whichever is higher” of a flat euro cap or a percentage of global annual turnover:

  • €35 million or 7% — reserved for the most serious category: breaches of Article 5’s prohibited practices (Art 99(3)). This is the ceiling, not the norm, and applies only to the outright-banned uses described above.

  • €15 million or 3% — the Art 99(4) list of operator obligations. This is a broader bucket than it’s often given credit for: it covers the general run of high-risk-system compliance failures and Article 50 transparency violations. Commentary that labels this tier simply “high-risk non-compliance” is incomplete — transparency failures fall here too.

  • €15 million or 3% — a separate tier for GPAI-provider obligations under Article 101, covering foundation-model providers who fail to meet their documentation, transparency, or systemic-risk duties. This tier is easy to miss because it’s structurally identical in amount to the Art 99(4) tier but rests on a different legal basis and applies to a different category of entity (model providers rather than deployers/operators generally).

  • €7.5 million or 1% — the lowest tier, for providing incorrect, incomplete, or misleading information to national authorities or notified bodies (Art 99(5)).

Two structural points are worth flagging explicitly because they’re easy to get backwards. First, every figure above is a ceiling calculated as whichever is higher of the euro amount or the percentage — for a large multinational, the percentage figure will typically dominate; for a smaller company, the flat euro figure will. Second, for SMEs and small mid-cap companies specifically, that logic inverts: the applicable cap is whichever is lower, not higher — a deliberate proportionality mechanism that’s frequently omitted from summaries and that changes the real-world exposure calculation substantially for smaller organisations.

Compliance obligations and conformity assessment

Beyond the headline deadlines, the Act sets out a specific compliance architecture for high-risk systems, running from Article 9 through Article 71. Confirmed against the consolidated legislative text (CELEX 02024R1689-20260727):

  • Risk management (Article 9), data governance (Article 10), technical documentation (Article 11, detailed in Annex IV), logging and traceability (Article 12), transparency and instructions for deployers (Article 13), human oversight (Article 14), and accuracy, robustness and cybersecurity (Article 15) together form the substantive requirements a high-risk system must meet.

  • Quality management systems (Article 17) and conformity assessment (Articles 43–44) govern how providers demonstrate that those substantive requirements have actually been met, culminating in an EU Declaration of Conformity, CE marking, and registration in the EU database (Article 71).

Conformity assessment itself splits into two routes. Internal (self-)assessment under Annex VI is the default path and covers most Annex III high-risk use cases, provided the relevant harmonised standards have been applied. Third-party assessment under Annex VII, involving an independent notified body, is required for biometric identification and categorisation systems (Annex III, point 1) and for any system where harmonised standards haven’t been fully applied. Providers should not assume self-assessment is available by default — the biometric carve-out is the main scenario where a notified body becomes mandatory rather than optional.

One caution for planning purposes: the specific time required for conformity assessment isn’t set out in the Act itself, and estimates from practitioners vary widely — internal assessments are commonly described as taking a few months once documentation is in place, while third-party assessments involving a notified body range anywhere from a few months to well over a year depending on system complexity and notified-body capacity, which itself remains a developing area as designations continue. Organisations should treat any specific timeline estimate with caution and build in buffer time rather than planning to a fixed number.

On penalties specifically: mitigation is not irrelevant. Article 99 requires enforcement authorities to weigh a defined set of aggravating and mitigating factors — including the degree of cooperation with authorities, whether the infringement was self-reported, and what technical and organisational measures the operator had in place — when setting the actual fine within the applicable tier. This doesn’t create an exemption from liability, but it does mean documented, good-faith compliance efforts genuinely affect exposure, not just optics.

By comparison, GDPR fines top out at up to 4% of global turnover under a single tier. The comparison is a useful reference point for readers already familiar with GDPR enforcement, but the EU AI Act’s four-tier, violation-specific structure is materially different in design and shouldn’t be reduced to a single side-by-side number — doing so tends to understate the top tier and overstate the bottom one.

What this means for compliance planning

Organisations building or deploying high-risk systems have more runway than a 2 August 2026 deadline would suggest — but that runway isn’t idle time, and it isn’t uniform across obligation types. A more accurate way to plan is to treat the Act as four overlapping compliance tracks rather than one deadline:

  1. Already binding, ongoing. Article 5’s original prohibited practices (since Feb 2025) and GPAI-provider obligations (since Aug 2025) are live now and require continuous compliance, not a one-time fix.
  2. Binding from 2 August 2026. Article 50 transparency and labelling duties, plus the Commission’s expanded enforcement and market-surveillance powers. Any organisation deploying user-facing AI, chatbots, or systems that generate synthetic media should treat this as the near-term priority — it is the obligation genuinely tied to the date most commentary (incorrectly) attaches to high-risk compliance.
  3. Binding from 2 December 2026. The two new Article 5 prohibitions added by the Omnibus. Legal and product teams should confirm now whether any existing or planned systems fall within the newly prohibited categories, since this gives only a few months’ lead time from the Omnibus’s entry into force.
  4. The high-risk runway: December 2027 and August 2028. Annex III systems (employment, essential services, law enforcement, migration, justice administration, and similar) have until 2 December 2027; Annex I systems (safety components of already-regulated products) have until 2 August 2028. This is genuinely more time than the original 2 August 2026 date allowed — the Omnibus added roughly sixteen months of runway for Annex III specifically — but conformity assessment, technical documentation, quality-management-system build-out, and (where applicable) third-party assessment routes are not fast processes. The additional time should be used to build durable compliance infrastructure, not treated as a reason to delay starting.

The practical risk in most organisations right now isn’t that they’ll miss a deadline that’s already passed — it’s that internal messaging, client communications, or public content still anchored to the old 2 August 2026 high-risk framing will either create false urgency around the wrong date or, worse, cause teams to deprioritise the transparency and enforcement obligations that actually are live today. Both directions of error are corrected by working from the staged timeline above rather than a single headline date.

Disclaimer: This article is for general informational purposes only and does not constitute legal or compliance advice. EU AI Act requirements may vary depending on your organisation, AI system, and use case. For advice on EU AI Act compliance, visit www.exclevelai.eu