


Updated July 2026
The EU AI Act is now in force, with its requirements taking effect in phases.
It applies to public and private organisations that develop, provide, deploy, import or distribute AI systems in the EU. It can also apply to organisations based outside the EU, where an AI system or its output is used within the EU.
The timeline has recently changed following the finalisation of the Digital Omnibus on AI, including revised application dates for high-risk AI systems.
Understanding your organisation’s role, how its AI systems are classified, and which requirements apply is essential to maintaining compliance.
In this blog, we provide an overview of the updated timeline and what organisations need to prepare for.
Some AI Act requirements already apply, while others take effect between August 2026 and August 2028.
The timeline below gives an at-a-glance overview of the key dates. The sections that follow explain each deadline and what already should already be in place and the actions affected organisations need to take next.

The AI Act was formally adopted on 21 May 2024, published on 12 July 2024, and officially entered into force on 1 August 2024. Its requirements have since been introduced in phases.
What should already be in place: An up-to-date inventory of AI systems, clear ownership of AI governanceThe framework of policies, processes, and roles that ensure Artificial Intelligence (AI) is developed and used responsibly, ethically, and in compliance with applicable laws, societal expectations, and corporate values. , and an initial assessment of your organisation’s role and obligations.
Prohibitions on unacceptable risk AI systems and AI literacy obligations began to apply on 2 February 2025. These include certain forms of harmful manipulation, social scoring, and untargeted scraping of facial images.
Read Compliance with the AI Act Part 2 for more details on prohibited applications.
Providers and deployers must also take measures to support the development of AI literacy among employees and others using or operating AI systems on their behalf. Following the Digital Omnibus changes, the obligation to provide appropriate support remains, though organisations are not required to guarantee a specific level of AI literacy.
What should already be in place: Checks for prohibited AI practices, supported by appropriate AI training, guidance and oversight.
Providers placing GPAI models on the EU market from 2 August 2025 must meet requirements, including technical documentation, information for downstream providers, copyright compliance and publication of a summary of the content used to train the model.
General Purpose AI (GPAI) models can perform a wide range of tasks and may be integrated into different AI systems. These include high-compute models where training contains more than 10^25 FLOPS, such as ChatGPT.
Providers of GPAI models with systemic risk face additional requirements covering model evaluation, risk assessment, incident reporting, and cybersecurity.
In July 2025, the commission published the Guidelines for providers of general-purpose AI models.
What should already be in place: Providers placing GPAI models on the market from 2 August 2025 should GPAI providers should have the required documentation, policies and risk controls.
The Digital Omnibus on AI introduces targeted changes to simplify and clarify the implementation of the AI ActThe EU Artificial Intelligence Act was approved by the EU Council on 21 March 2024. A world-first comprehensive AI law, intended to harmonise rules for the development, deployment, and use of artificial intelligence systems across the EU.. Most notably it moves the deadlines for stand-alone high-risk AI systems to 2 December 2027, and high-risk systems embedded in regulated products to 2 August 2028.
It also introduces additional prohibited AI practice, transitional arrangements for certain existing generative AI systems and changes to regulatory oversight, sandboxes, and the interaction between the AI Act and product safety legislation.
What organisations need to do: Review existing AI Act compliance plans against amended dates and requirements, without assuming all obligations have been delayed.
Most of the AI Act’s remaining provisions apply from 2 August 2026. The main exception is the detailed requirements for high-risk AI systems, which have been postponed to <date> under the EU’s Digital Omnibus on AI.
From this date, Article 50 transparency requirements apply, depending on your organisation’s role and AI system. These include:
The Commission published several resources in June and July 2026 to support compliance with transparency and high-risk obligations:
Code of Practice on Transparency of AI-Generated Content
Article 50 transparency guidelines on 20 July 2026
Guidelines for providers and deployers of high-risk systems
What organisations need to do: Identify which transparency requirements apply to each AI system and ensure that the necessary notices, content-making measures, labels and supporting processes are in place.
Additional prohibited practices introduced through the Digital Omnibus apply from 2 December 2026. These cover certain AI systems that generate non-consensual sexually explicit or intimate content, or child sexual abuse material.
Providers of AI systems, including general-purpose AI systems, that generate synthetic audio, images, video or text and were placed on the market before 2 August 2026 must also comply with Article 50(2) machine-readable marking requirements by this date.
This is a limited transitional arrangement and does not postpone the wider transparency requirements applying from 2 August 2026.
What organisations need to do: Identify any existing generative AI systems covered by the transition and implement the required content-making and detection measures.
By 1 August 2027 the Commission must publish guidance to help organisations apply the AI Act alongside the product legislation listed in Section A of Annex I.
What organisations need to do: Review the guidance when published and update relevant risk management, quality management and conformity assessment plans.
Providers of GPAI models placed on the market before 2 August 2025 must comply with the relevant GPAI requirements by 2 August 2027.
What organisations need to do: Address any remaining gaps in technical documentation, copyright compliance, training-content summaries and systemic risk controls.
By 2 September 2027, the Commission must publish guidance, including a template, for the post-market monitoring plans required from providers of high-risk AI systems.
What organisations need to do: Review the guidance when published and ensure post-market monitoring plans reflect the expected approach.
The requirements for stand-alone high-risk systems classified under Article 6(2) and listed in Annex III apply from 2 December 2027.
These include certain AI systems used is areas such as biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration and border management, and the administration of justice.
What organisations need to do: Identify potential high-risk systems and begin implementing the required governance, documentation, testing, monitoring and human oversight.
Read Part 2 of our blog series: What is high-risk activity?
High-risk requirements for AI systems that are safety components of, or are themselves, products covered by specific EU product legislation under Annex I applies from 2 August 2028.
This can include AI systems incorporated into products such as medical devices, toys, lifts and watercraft. The exact requirements depend on the relevant product legislation and conformity assessment processA series of actions or steps taken in order to achieve a particular end..
What organisations need to do: Determine whether AI is incorporated into a regulated product and align AI Act preparations with existing product safety, quality management and conformity assessment processes.
A longer transition applies to a narrow group of existing systems.
Providers and deployers of certain existing high-risk AI systems intended for use by public authorities must comply by 2 August 2030. Certain AI systems that form part of specified large-scale EU IT systems must be brought into compliance by 31 December 2030
What organisations need to do: Confirm whether a system qualifies for one of these limited arrangements and document the relevant deadline and compliance plan.
David Smith, DPO and AI Sector Lead explains:
‘In many cases the AI Act and the GDPR will complement each other. The AI Act is essentially a product safety legislation designed to ensure the responsible and non-harmful deployment of AI systems. The GDPR is a principles-based law, protecting fundamental human privacy rights.’
You must ensure that if you process personal dataInformation which relates to an identified or identifiable natural person. using an AI system, you comply with all relevant provisions of both the GDPR and the AI Act
Explore the other blogs in our Compliance with the AI Act series:
______________________________________________________________________________________________________________________________
The DPO Centre’s AI governance services can help you understand your obligations, assess AI risks and put appropriate oversight in place. This includes AI Impact Assessments and support from an Outsourced AI Officer.
______________________________________________________________________________________________________________________________
In case you missed it…
______________________________________________________________________________________________________________________________
For more news and insights about data protection and AI governance, follow The DPO Centre on LinkedIn
Fill in your details below and we’ll get back to you as soon as possible