EU AI Act: the deadlines that actually apply now — as of July 2026

The Digital Omnibus pushed the high-risk deadlines to 2027/2028 — but transparency duties and penalties arrive on 2 August 2026. What matters now for AI projects.

If you research the EU AI Act right now, you’ll find plenty of outdated material: many vendors still advertise 2 August 2026 as the hard deadline for high-risk AI. That is no longer accurate. The Digital Omnibus — formally endorsed by the European Parliament on 16 June and by the Council on 29 June 2026 — pushes exactly those obligations well into the future. What does arrive on 2 August 2026, meanwhile, tends to get lost in the deadline panic.

The deadlines at a glance (as of 2 July 2026)

Obligation Applies from Status
Prohibited AI practices (Art. 5) 2 February 2025 in force
AI-literacy duty for deployers (Art. 4) 2 February 2025 in force
GPAI model obligations (new models) 2 August 2025 in force
Transparency duties (Art. 50): labelling chatbots, AI content, deepfakes 2 August 2026 arriving now
Enforcement & penalty regime (incl. Commission oversight of GPAI) 2 August 2026 arriving now
Stand-alone high-risk systems (Annex III) 2 December 2027 postponed via Omnibus
High-risk AI embedded in products (Annex I) 2 August 2028 postponed via Omnibus

The reason for the postponement is unspectacular: harmonised standards, notified bodies and national supervisory structures simply aren’t ready. The delay is preparation time, not an all-clear — the obligations themselves remain.

What actually counts from 2 August 2026

For most business applications the relevant part is not high-risk but Art. 50: if you run a chatbot, it must be identifiable as an AI system. If you publish AI-generated content, it must be labelled. On top of that, the penalty regime becomes enforceable — up to €35 million or 7 % of global annual turnover for prohibited practices.

In Germany the supervisory structure is taking shape in parallel: the implementation act adopted in February 2026 (KI-MIG) makes the Bundesnetzagentur the central AI market-surveillance authority. For the first time there is an authority that is responsible — and that can ask questions.

And the GDPR?

It continues to apply unchanged, and in practice it is the more common stumbling block: data minimisation, purpose limitation, a deletion concept, processing agreements — and the question of which data an AI system needs to see at all. Compliance and good architecture pull in the same direction here: clear boundaries, verifiable decisions, no data sprawl.

What this means for your AI project

  • Determine the risk class early. Most mid-market applications are not high-risk — knowing (and documenting) that takes pressure off and saves retrofit costs.
  • Do an Art. 50 check. Chatbot in customer contact? AI-generated content on your website? Then labelling is due by 2 August 2026 — a manageable, clearly scoped step.
  • Use the extended runway. If you’re planning a high-risk system for late 2027, you now have time for proper preparation: AI inventory, risk classification, governance — instead of a scramble at the last minute.
  • Don’t forget the GDPR behind the AI Act. The two frameworks interlock; the data-protection question often decides architecture and model choice (EU hosting, on-premise).

For a first read on where your project stands, try our AI self-check — six questions, no registration. How we build AI applications GDPR- and AI-Act-compliant is on our AI & LLM applications page.

We clarify the risk class before the first line of code, keep the human in the decision, and host fully in the EU on request. That turns “compliant” from an afterthought patch into part of the design.

Sources: Council of the EU, press release on the 7 May 2026 agreement · Gibson Dunn: EU AI Act Omnibus Agreement. Not legal advice — consult your legal counsel for a binding assessment of your case.

← All articles