EU AI Act Compliance
A dated EU AI Act compliance timeline and applicability map after Regulation (EU) 2026/1744, covering what changed in Article 113, Article 6 and Article 50 and why EUR-Lex, the Commission's AI Act tool and the most-cited third-party tracker still show the pre-amendment rules.
Key takeaways: EU AI Act compliance 5
The dates the July 2026 Omnibus changed, the two-track high-risk timeline it created and why the sources compliance teams check by default are already stale.
- The July 2026 amendment moved dates and substance Regulation (EU) 2026/1744 carries 43 amendment points across Article 1, rewriting duties and carve-outs in the AI Act rather than only shifting deadlines.
- High-risk compliance now has two dates, not one Annex III high-risk systems under Article 6(2) apply from 2 December 2027, while Annex I product-embedded systems under Article 6(1) apply from 2 August 2028, eight months later.
- The sources compliance teams check by default are stale EUR-Lex's consolidated AI Act, the Commission's AI Act Service Desk and the leading third-party implementation tracker all still show pre-amendment rules as of late July 2026.
- Entry into force is not application Article 4 set the amending act's entry into force at 27 July 2026, a date separate from the staggered application dates the amended Article 113 assigns to individual chapters.
- This is a program, not a single deadline Compliance runs on a sequence of dates through 2028 rather than one deadline, with separate workstreams needed for marking, classification, documentation and GPAI obligations.
In short: EU AI Act compliance now runs on the dates set by Regulation (EU) 2026/1744, which entered into force on 27 July 2026, moved high-risk application to 2 December 2027 and 2 August 2028, moved new Article 5 prohibitions to 2 December 2026 and made Articles 102 to 110 apply from that same day. The sources most compliance teams check by default (EUR-Lex, the Commission's AI Act Service Desk and the leading third-party tracker) still show the pre-amendment rules. A program built against the wrong date risks a deadline that no longer exists, or a gap where one does.
Two roles run through every date below: a provider develops an AI system or a general-purpose AI model and places it on the market or puts it into service under its own name, and a deployer puts an already-placed system to use under its own authority. Every date on this page also assumes the reader already sits inside the AI Act's scope. That scope is set by the Act's own scope provisions, not by this article, and a reader outside it is outside every date here.
What Regulation (EU) 2026/1744 changed in the AI Act
The Digital Omnibus on AI in one paragraph (43 amendment points, adopted 8 July 2026, published OJ L 2026/1744 on 24 July 2026)
The amending act's title, printed in the Official Journal, is "Regulation (EU) 2026/1744 of the European Parliament and of the Council of 8 July 2026 amending Regulations (EU) 2024/1689, (EU) 2018/1139 and (EU) 2023/1230 as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI)", signed at Strasbourg on 8 July 2026 and published as OJ L, 2026/1744, 24.7.2026. Article 1 carries 43 numbered points amending Regulation (EU) 2024/1689, the AI Act itself, while Articles 2 and 3 amend Regulation (EU) 2018/1139 and Regulation (EU) 2023/1230; most points rewrite what a duty requires, not only when it starts. For instance, point (8) of the amending act inserted new paragraphs 1a, 1b and 1c into Article 6, so systems intended solely for non-safety-related user assistance, performance optimization, service efficiency, automation, convenience or quality control no longer qualify as safety components, while systems whose failure would endanger health and safety still do.
Entry into force is not application - Article 4 sets the amending act in force on the third day after publication, not the standard twentieth
Confusing entry into force with application is the single most common error in how teams read this amendment. Article 4 of the amending act reads in full: "This Regulation shall enter into force on the third day following that of its publication in the Official Journal of the European Union." Publication landed on 24 July 2026, so the third day after is 27 July 2026, faster than the original AI Act's own Article 113, which set entry into force at "the twentieth day following that of its publication in the Official Journal of the European Union," the usual EU default.
Entry into force only means the amending act is now law, not that every duty inside it runs from that day. Application dates sit separately, mostly inside the amended Article 113 rather than Article 4, so reading 27 July 2026 as the start date for Article 6 or Article 50 duties is exactly the mistake this section corrects.
Point (32) inserts four new enforcement articles, not one
The Omnibus does not add a single enforcement article, it adds four. Point (32) of the amending act opens "the following articles are inserted" and inserts Article 75a (Supervisory and enforcement powers of the AI Office), Article 75b (Commitments), Article 75c (Non-compliance, fines and periodic penalty payments) and Article 75d (Safeguards and further specification). Article 75a gives the AI Office full market-surveillance powers, including remote or on-site inspections, plus the right to "fully reclaim from the relevant operator the totality of the costs of its supervision and enforcement activities with respect to instances of non-compliance, including costs for human and technical resources." Article 75c(5) lets the AI Office impose periodic penalty payments that "shall not exceed 5 % of the average daily income or worldwide annual turnover in the preceding financial year per day."
The full EU AI Act compliance timeline, dated
Seven dates fixed by Article 113 govern when the EU AI Act's chapters apply: three unchanged from Regulation (EU) 2024/1689, four new or moved by the July 2026 amendment.
Three further deadlines sit outside Article 113 and bind specific duties rather than whole chapters. Providers of general-purpose AI models placed on the market before 2 August 2025 still face Article 111(3)'s own deadline of 2 August 2027, a live date the Omnibus left untouched. Our GPAI model obligations article develops it. The Commission was required by Article 6(5) to publish classification guidelines no later than 2 February 2026, a deadline that has passed with no guidelines out, covered in AI Act high risk classification. A third deadline comes from the Code of Practice that operationalizes Article 50(2): it sets its own interoperability-solution date of 2 February 2027 for detection mechanisms, covered in AI Act Article 50.
2 February 2025 - prohibited practices and AI literacy (unchanged)
Chapters I and II, prohibited practices and the AI literacy obligation, applied from 2 February 2025 and still do. The amended Article 113, third paragraph, point (a) keeps that date and adds one carve-out: "Chapters I and II shall apply from 2 February 2025, with the exception of Article 5(1), first subparagraph, points (ba) and (bb), and Article 5(1a) and (1b) which shall apply from 2 December 2026." Only the two new prohibitions get a later start.
2 August 2025 - governance, notified bodies and the GPAI chapter (unchanged)
Governance, notified bodies and the general-purpose AI model chapter applied from 2 August 2025, untouched by the amendment. Article 113, third paragraph, point (b) reads: "Chapter III Section 4, Chapter V, Chapter VII and Chapter XII and Article 78 shall apply from 2 August 2025, with the exception of Article 101." The Omnibus does not touch point (b) at all.
27 July 2026 - Regulation (EU) 2026/1744 in force; Articles 102 to 110 apply
27 July 2026 does double duty: the Omnibus entered into force under Article 4 that day, and also set an application date inside the AI Act it amends. The amended Article 113, third paragraph adds an entirely new point: "the following point is added: '(d) Articles 102 to 110 shall apply from 27 July 2026.'" Those articles had no prior start date.
Articles 102 to 110 sit inside the Act's own Final Provisions, and none of them writes a new AI duty. Eight of the nine, Articles 102 to 109, amend separate pieces of sectoral product legislation: aviation security, agricultural and forestry vehicles, two- and three-wheel vehicles, marine equipment, rail interoperability, motor vehicle approval and general vehicle safety, plus civil aviation and EASA. Every one repeats the same formula, represented in Article 103's addition to Regulation (EU) No 167/2013: when adopting delegated acts on AI systems that are safety components within the meaning of the AI Act, "the requirements set out in Chapter III, Section 2, of that Regulation shall be taken into account." Article 110 carries the direct business effect: it adds the AI Act as a new point in Annex I to Directive (EU) 2020/1828, the Representative Actions Directive, bringing AI Act infringements within the scope of consumer collective-redress actions.
2 August 2026 - general application, including the Article 50(2) marking duty
The AI Act's default application date, covering everything not scheduled separately, is unchanged. The original Article 113, second paragraph states: "It shall apply from 2 August 2026." Article 50's transparency duties, including the Article 50(2) marking obligation, fall under this general date because Article 113 does not schedule them separately. Systems already on the market before that date get a different deadline under the amended Article 111, covered next.
2 December 2026 - the new Article 5 prohibitions added by the Omnibus
Two new prohibited practices take effect on 2 December 2026, inserted into Article 5 by point (7) of the amending act. New point (ba) bars an AI system that "generates or manipulates realistic images, videos, audio or similar material of an identifiable natural person's intimate parts, or of an identifiable natural person engaged in sexually explicit activities, without that person's freely-given, specific, informed, unambiguous and explicit consent." New point (bb) bars a system that generates or manipulates "material or performance within the meaning of Article 2, points (c) and (e), of Directive 2011/93/EU, except where a 'without right' defence applies under national law." The same date closes the amended Article 111 grace period: legacy synthetic-content generators already on the market by 2 August 2026 must meet Article 50(2) by then.
2 December 2027 - high-risk systems under Article 6(2) and Annex III
The amended Article 113, third paragraph, point (c) splits the old single high-risk date in two, the first reading: "2 December 2027 as regards AI systems classified as high-risk pursuant to Article 6(2) and Annex III." Chapter III, Sections 1 to 3, apart from Article 6(5), apply to this category from that date.
2 August 2028 - high-risk systems under Article 6(1) and Annex I
Most tools still show the pre-amendment default, making the second high-risk date the easiest to misquote. The original Article 113, third paragraph, point (c) set a single date: "Article 6(1) and the corresponding obligations in this Regulation shall apply from 2 August 2027." The amended point (c) replaces that with "2 August 2028 as regards AI systems classified as high-risk pursuant to Article 6(1) and Annex I." The move is from 2 August 2027 to 2 August 2028, one year later, not from 2 August 2026.
Applicability map
| Obligation | Legal basis | Date | Who it binds |
|---|---|---|---|
| Prohibited practices under Article 5, plus AI literacy | Article 113, third paragraph, point (a) | 2 February 2025 | Providers and deployers within Chapters I and II |
| Governance, notified bodies, GPAI chapter (Article 101 excepted) | Article 113, third paragraph, point (b) | 2 August 2025 | Notified bodies, market surveillance authorities, GPAI model providers |
| Articles 102 to 110 | Article 113, third paragraph, point (d), new | 27 July 2026 | Entities within the scope of Articles 102 to 110 |
| General application, including Article 50(2) marking | Article 113, second paragraph | 2 August 2026 | Providers and deployers not otherwise scheduled |
| New Article 5 prohibitions inserted by the Omnibus | Article 113 point (a) as amended; Article 5(1) points (ba)-(bb), 5(1a)-(1b) | 2 December 2026 | Providers and deployers generating the material in Article 5(1), points (ba) and (bb) |
| Legacy content-marking compliance deadline | Article 111(4), added by point (39) | 2 December 2026 | Providers of synthetic-content generators on the market before 2 August 2026 |
| High-risk AI systems under Article 6(2) | Article 113 point (c)(i) as amended | 2 December 2027 | Providers and deployers of Annex III high-risk systems |
| High-risk AI systems under Article 6(1) | Article 113 point (c)(ii) as amended | 2 August 2028 | Providers and deployers of Annex I high-risk systems |
What point (40) actually rewrote in Article 113
Article 113 has three paragraphs, and the Omnibus touches only the third. Point (40) states its own scope precisely: "in Article 113, the third paragraph is amended as follows." Only the 2 August 2025 date under point (b) and the first two paragraphs of Article 113 remain untouched. A pre-Omnibus search shows a single high-risk date, no Article 5 exception yet, and no mention of Articles 102 to 110, all three traceable to point (40) alone.
Why EUR-Lex and the Commission's own tools still show the old rules
Three default sources still show the pre-27 July 2026 AI Act, each stale for a different reason.
The EUR-Lex consolidated text is stamped 12/07/2024, no amendments folded in
EUR-Lex carries exactly one consolidated version of Regulation (EU) 2024/1689, and its own interface says so. The "Hide consolidated versions" panel on the AI Act's EUR-Lex page lists a single entry, dated "12/07/2024," carrying the ELI http://data.europa.eu/eli/reg/2024/1689/2024-07-12, the AI Act's original publication date rather than a re-consolidation date. No re-consolidation has happened since, so the text folds in no amendment; for anything the Omnibus changed, only the amending act is authoritative.
The English CELEX page currently renders French-language text
EUR-Lex also publishes a machine-addressable consolidated-version address for the AI Act, CELEX:02024R1689-20240712, and its English rendering returns French: the page opens "Article premier" and "Objet," continuing into a section headed "ANNEXE," French for "Article 1," "Subject matter" and "Annex." A second, differently dated address, CELEX:02024R1689-20260727, returns no legal text at all.
The Commission's AI Act tool still shows Article 6, Article 50 and Article 113 unamended
The Commission's own AI Act Service Desk, built for reading the Act article by article, flags its own gap on two of the three provisions this article covers. Both its Article 6 page and its Article 50 page carry the same disclaimer, observed on 28 July 2026: "This provision has been amended by the Digital Omnibus on AI. The text displayed on this page has not yet been updated to reflect those amendments." Its Article 113 page carries no such disclaimer and still renders the pre-amendment text outright, including "It shall apply from 2 August 2026" and "(c) Article 6(1) and the corresponding obligations in this Regulation shall apply from 2 August 2027," so trusting that page alone would place Article 6(1) obligations a year early.
The leading third-party timeline has not moved since 1 August 2024
Outside government sources, the implementation timeline at artificialintelligenceact.eu, observed on 28 July 2026, carries a last-updated stamp of 1 August 2024 and has not moved since. Against 2 August 2026 it still lists "Application: The remainder of the AI Act starts to apply, except Article 6(1)." Against 2 August 2027 it still lists "Article 6(1) and the corresponding obligations in the Regulation start to apply." The string "2 December 2027" does not appear anywhere on the page, and it carries no note that an amendment exists. Naming it is not a judgment on the operator, only evidence that a two-year-old snapshot still circulates as current.
A 24-month compliance sequencing checklist
Every date above is a legal deadline, not a project plan, so build the sequence backward from each one rather than treating 2028 as far away.
- Before 2 August 2026: confirm whether any system you ship generates synthetic content, and whether Article 50(2) marking is built into the pipeline, not added as a label afterward.
- Between 2 August 2026 and 2 December 2026: close out Article 111(4) compliance for any legacy generator, and screen every system against the new Article 5(1) points (ba) and (bb).
- Through 2027, ahead of 2 December 2027: run Article 6(2) and Annex III classification against the full system inventory covering both providers and deployers, and start conformity work early since Annex III obligations apply first.
- By 2 August 2028: repeat the exercise for Article 6(1) and Annex I, usually a different team since it overlays an existing product-safety process.
- Continuously: re-check every deadline against the amended Article 113 text, never a cached summary.
The four duty areas this cluster covers
Each duty above gets its own deep-dive elsewhere in this cluster: Article 50 marking, Article 6 classification, Annex IV documentation and the GPAI chapter each carry enough mechanics to fill an article on their own.
- AI Act Article 50 covers the transparency and marking duty in full, including the 2 August 2026 general date, the Article 50(2) marking mechanics and the 2 December 2026 legacy grace period under Article 111(4).
- AI Act high risk classification works through Article 6 and Annexes I and III, including how the split between 2 December 2027 and 2 August 2028 changes sequencing.
- Providers turn to AI Act technical documentation for what to produce and maintain once a system is classified as high-risk under either Annex.
- GPAI model obligations covers the general-purpose AI model chapter and what the Omnibus changes.
How Pharos Production supports EU AI Act compliance builds
Our AI governance practice builds the classification and documentation controls the later dates require. Our compliance and regtech solutions team works with legal counsel once a date on this list needs an owner, whichever one comes next for your system.
Sources: Regulation (EU) 2026/1744 of 8 July 2026 (the Digital Omnibus on AI), OJ L, 2026/1744, 24.7.2026, ELI data.europa.eu/eli/reg/2026/1744/oj; Regulation (EU) 2024/1689 (the EU AI Act), consolidated text stamped 12 July 2024, via EUR-Lex; the amending act via EUR-Lex; the European Commission's AI Act regulatory framework page and its AI Act Service Desk; and the artificialintelligenceact.eu implementation timeline, all observed 28 July 2026. This article is engineering guidance, not legal advice. Confirm every date against the Official Journal text with qualified counsel before you rely on it.
FAQ
Quick answers to common questions about custom software development, pricing, process and technology.
Type to filter questions and answers. Use Topic to narrow the list.
Showing all 7
No matches
Try a different keyword, change the topic or clear filters
-
High-risk classification applies on two different dates depending on which route a system takes. Systems classified as high-risk under Article 6(2) and Annex III apply from 2 December 2027, while systems under Article 6(1) and Annex I apply from 2 August 2028, eight months later.
Both dates come from the amended Article 113, third paragraph, point (c), rewritten by point (40) of Regulation (EU) 2026/1744. Before the amendment both routes shared a single 2 August 2027 date, so a plan built against the old date needs updating either way.
-
The Digital Omnibus, Regulation (EU) 2026/1744, carries 43 amendment points in its Article 1, and most of them rewrite what a duty requires rather than only when it starts. Confirmed changes include the new Article 6(1a) to (1c) high-risk carve-outs, the Article 50(7) shift in which body encourages the codes of practice, four new enforcement articles inserted at Article 75a to 75d and a new Article 111(4) transitional period for content marking.
Each duty area gets its own dedicated article in this cluster, covering content marking, high-risk classification, technical documentation and GPAI model obligations. The GPAI chapter itself was left untouched by this amendment.
-
No, Regulation (EU) 2026/1744 is the amending act, not the AI Act itself. The AI Act is Regulation (EU) 2024/1689, published in 2024, and the 2026 regulation only amends specific articles and annexes inside it, mostly through the 43 numbered points in its Article 1.
Reading the two together is necessary because EUR-Lex has not folded the amendment into a new consolidated version of the AI Act, so the original text and the amending act currently sit in two separate documents.
-
EUR-Lex still shows the pre-amendment AI Act because its single consolidated version of Regulation (EU) 2024/1689 carries a stamp of 12 July 2024, the original publication date, with no re-consolidation since. Because no re-consolidation has taken place, none of the July 2026 changes are folded into that page, and only the separate amending act, Regulation (EU) 2026/1744, reflects them.
The English-language address for that consolidated version currently renders French text instead, compounding the problem for an English-reading team checking the source directly.
-
The two new prohibited practices the Omnibus inserted into Article 5, covering non-consensual intimate deepfakes and certain child-sexual-abuse material, take effect on 2 December 2026. That is 22 months after the original AI Act prohibitions, which have applied since 2 February 2025 under Article 113, third paragraph, point (a).
The two prohibition sets share Article 5 but not a start date, so a compliance calendar needs both entries recorded separately.
-
Entry into force is when a law becomes legally valid, while application is when its duties actually start binding providers and deployers. Article 4 of Regulation (EU) 2026/1744 set entry into force for the amending act at 27 July 2026, the third day after its 24 July 2026 publication, faster than the original twentieth-day default the AI Act itself used.
That in-force date does not by itself start any AI Act duty. The staggered application dates instead sit inside the amended Article 113, running from 2 February 2025 through 2 August 2028 depending on the chapter.
-
The official text of Regulation (EU) 2026/1744 is published at its ELI address, data.europa.eu/eli/reg/2026/1744/oj, and on EUR-Lex under CELEX number 32026R1744. No amended English-language consolidated version of the AI Act exists yet that folds those changes into Regulation (EU) 2024/1689, so reading the original AI Act and the amending act side by side is currently the only way to see the full picture in English.
I work with startup founders who need a dedicated software development team but don’t want to gamble on hiring, random outsourcing, or opaque delivery.
Most founders face the same problem sooner or later.
Early technical and team decisions lock the product into tech debt, slow delivery, missed milestones and constant re-hiring. By the time this becomes visible, fixing it is already expensive.As a CTO and software architect, I help founders design, build and run dedicated development teams that work as a true extension of the startup. Not as a black-box vendor.
My focus is on complex products where mistakes are costly:
- Web3 and blockchain platforms
- FinTech and regulated products
- High-load startup systems
- MVP → scale transitions
We don’t do body-shopping.
We don’t sell generic outsourcing.Instead, we help founders:
- build the right team structure from day one
- keep technical ownership and transparency
- scale delivery without losing control
- avoid vendor lock-in and hidden risks
Teams are aligned with the product roadmap, business goals and long-term architecture. Not just short-term velocity.