The AI Act timeline runs from its entry into force on 1 August 2024 through August 2028, with obligations applying in stages rather than all at once. Since the "Digital Omnibus" package was given final approval by the Council of the EU on 29 June 2026, several deadlines have shifted: rules for standalone high-risk systems are now pushed back to 2 December 2027. Here are all the binding dates, what applies at each one, and what changed.
Read the full guide
EU AI Act 2026: The Complete Compliance Guide for SMEs and Nonprofits
Answer a few questions and get a personalized assessment with recommendations tailored to your industry.
Assess my AI maturityRelated articles
Dive deeper with these complementary articles.
The EU AI Act (Regulation 2024/1689) applies to your SME or nonprofit as soon as you use an AI tool, even a simple ChatGPT subscription. Since February 2025 you must train your teams; on 2 August 2026 the transparency obligations and the penalty regime take effect.
The AI Act timeline runs from its entry into force on 1 August 2024 through August 2028, with obligations applying in stages rather than all at once. Since the "Digital Omnibus" package was given final approval by the Council of the EU on 29 June 2026, several deadlines have shifted: rules for standalone high-risk systems are now pushed back to 2 December 2027. Here are all the binding dates, what applies at each one, and what changed.
This article is part of our compliance cluster. For the full picture of your obligations, read the AI Act compliance guide for SMEs and nonprofits.
The AI Act does not take effect all at once: it rolls out obligations over roughly four years, block by block. That is the design of Regulation (EU) 2024/1689, published in the Official Journal of the European Union and in force since 1 August 2024. From that reference date, each category of obligation has its own compliance window.
This staggered approach has a logic. Practices deemed unacceptable are banned very early, while high-risk systems, which require heavy technical documentation and a conformity assessment, get longer lead times. A small business using a mainstream language model to draft emails does not face the same deadlines as a vendor placing a CV-screening tool classified as high-risk on the market.
The timeline saw its first major revision in 2026. The Digital Omnibus, the first substantive amendment to the text since its adoption, postponed the most costly obligations for companies. We break these changes down below.
Here are the key dates in chronological order, with the obligation that becomes binding at each one.
| Date | What becomes applicable | Legal basis |
|---|---|---|
| 1 August 2024 | Regulation enters into force | Regulation (EU) 2024/1689 |
| 2 February 2025 | Ban on unacceptable practices; AI literacy duty | Articles 5 and 4 |
| 2 August 2025 | Obligations for general-purpose AI models (GPAI); governance and national authorities | Chapter V |
| 2 August 2026 | Transparency obligations; full enforcement powers for authorities | Article 50, Article 99 |
| 2 December 2026 | Marking of AI-generated content, for systems already on the market before August 2026 | Article 50(2) |
| 2 December 2027 | Standalone high-risk systems (Annex III): conformity, CE marking, registration | Article 6(2), Annex III |
| 2 August 2028 | High-risk systems embedded in already-regulated products (Annex I) | Article 6(1), Annex I |
The last two rows are the ones that changed with the Digital Omnibus. They originally fell in 2026 and 2027.
Three blocks of obligations are already in force and affect most organizations, including SMEs and nonprofits.
Since 2 February 2025, AI practices deemed unacceptable are banned: general-purpose social scoring, subliminal manipulation, emotion recognition in the workplace in most cases. On the same date, the AI literacy duty under Article 4 requires any organization deploying or providing an AI system to ensure its staff has a sufficient level of understanding of these tools. This obligation is directly operational and often underestimated. We cover it in our dedicated article on Article 4 and mandatory AI training.
Since 2 August 2025, providers of general-purpose AI models, such as the large models behind conversational assistants, are subject to documentation and transparency obligations. Governance also came into place, with national supervisory authorities and the European AI Office.
To find out exactly whether your organization is covered and on what basis, read who is affected by the AI Act.
2 August 2026 activates the transparency obligations of Article 50, but be careful not to confuse two dates that sit close together. From that date, an AI system interacting with a person must inform them, and artificially generated content (text, image, audio, video) must be flagged as such. Authorities also gain their full enforcement powers.
The nuance many articles blur concerns the machine marking of generated content, set out in Article 50(2). The official AI Act service desk and the European Commission confirm that this marking obligation applies in principle from 2 August 2026, but that a grace period runs until 2 December 2026 for systems already on the market before August 2026. In other words, a generative AI tool launched after 2 August 2026 must mark its content immediately; an earlier tool gets four extra months to comply on this specific point.
This distinction is the one we most often see missed in timelines published online, which present 2 December 2026 as a general transparency deadline. It is not: it applies only to content marking for pre-existing systems.
The most significant delay concerns high-risk systems, whose compliance was the deadline companies feared most. The Digital Omnibus, adopted by the Council of the EU on 29 June 2026, shifted two major deadlines.
Standalone high-risk systems under Annex III (for example, automated candidate screening, credit scoring, certain uses in education) were due to be compliant by 2 August 2026. That date is now set at 2 December 2027. Affected companies gain roughly sixteen months to finalize their conformity assessment, obtain CE marking, and register their system in the European database.
High-risk systems embedded in products already regulated under Annex I (medical devices, machinery, toys, for instance) move from 2 August 2027 to 2 August 2028.
This delay is not a repeal. It shifts the compliance burden, it does not cancel it. The Digital Omnibus also introduced relief for smaller organizations, including a new category of "small mid-caps" (fewer than 750 employees and under 150 million euros in turnover) that benefit from simplified technical documentation. For SMEs and nonprofits, this means extra time, not a free pass.
Even with the delays, the penalty regime under Article 99 remains one of the heaviest in EU digital law. Three tiers exist: up to 35 million euros or 7% of worldwide annual turnover for using a prohibited practice, up to 15 million euros or 3% for breaching other obligations, and up to 7.5 million euros or 1% for supplying incorrect information to authorities.
For SMEs and startups, the regulation provides that the fine applied is the lower of the two amounts (percentage or fixed sum), not the higher. This proportionality does not remove the need to prepare: the first building block, immediate and low-cost, remains the staff training required by Article 4. We explain this in our analysis of AI Act penalties for untrained companies.
The right approach is not to wait until 2027, but to handle the obligations already in force and map your systems now. Three actions are justified without delay.
First, get AI literacy in order: it has been a live obligation since February 2025 and is simple to meet through a suitable training action. Second, inventory the AI systems you use and classify them by risk level, so you know which will fall under the high-risk regime in December 2027. Third, prepare content transparency if you produce text or visuals with AI. Our AI Act compliance checklist for SMEs walks through these steps one by one.
An initial AI audit lets you place your organization on this timeline in a single session and identify the deadlines that actually concern you.
Is the AI Act already applicable in 2026? Yes. Several obligations have been in force since February and August 2025 (prohibited practices, AI literacy, general-purpose models), and the transparency rules apply from 2 August 2026. Only the high-risk obligations were postponed.
Which date matters most for a typical SME? 2 February 2025 for AI literacy, already passed and often ignored. It is the most immediate obligation for an SME that uses AI tools without developing them.
Why is 2 August 2026 no longer the big high-risk deadline? Because the Digital Omnibus, adopted on 29 June 2026, postponed the obligations for standalone high-risk systems (Annex III) to 2 December 2027. 2 August 2026 remains the transparency date.
What is the difference between 2 August 2026 and 2 December 2026? 2 August 2026 marks the start of transparency obligations in general. 2 December 2026 is a grace period limited to marking content generated by systems already on the market before August 2026.
Does the Digital Omnibus delay also cover regulated products? Yes. High-risk systems embedded in Annex I products (medical devices, machinery, toys) move from 2 August 2027 to 2 August 2028.
What does a non-compliant company risk? Fines of up to 35 million euros or 7% of worldwide turnover for prohibited practices, with proportionate caps for SMEs. The detail is in Article 99 of the regulation.
Where can I find the official source for the timeline? The reference text is Regulation (EU) 2024/1689, supplemented by the Council of the EU decisions on the Digital Omnibus from June 2026 and the clarifications from the European Commission's official AI Act service desk.
At GrowthPerf, a Qualiopi-certified training provider, we help executives, HR teams, and nonprofit leaders turn this timeline into concrete actions. It rarely starts with a complex compliance audit: it starts with training teams, the most immediate AI Act obligation, then a simple mapping of your AI uses to anticipate the high-risk deadlines of 2027 and 2028.
If you want to know where your organization sits on this timeline, book a free 30-minute AI audit. We review your real deadlines and the first steps to take, without jargon. To stay on top of changes to the text, our compliance newsletter relays every timeline update verified at the source. And to go further on the full set of obligations, the AI Act compliance guide for SMEs remains your starting point. You can also explore our AI for business training.