EU AI Act Timeline 2026–2028: What Was Delayed and What Still Applies
Article 50 transparency rules, the December 2026 transition, and the revised deadlines for high-risk AI systems.

The EU AI Act was not postponed as a whole. Article 50 transparency obligations apply from 2 August 2026. A limited transition for providers of certain existing synthetic-content systems ends on 2 December 2026. The main rules for Annex III high-risk AI systems now apply from 2 December 2027, while the rules for high-risk AI embedded in regulated products under Annex I apply from 2 August 2028. These dates reflect Regulation (EU) 2026/1744, which amended the original timetable. This guide explains who is affected by each deadline and what organisations should do next.
By Dzhamal Statsenko, lawyer and AI governance consultant based in the Netherlands | Last reviewed: 29 July 2026
The most common mistake is to assume that the entire AI Act was postponed. It was not. The organisations receiving the most additional time are providers and deployers of high-risk AI systems. Ordinary businesses using chatbots or publishing synthetic content may still face transparency duties from 2 August 2026.
This article gives a practical EU AI Act timeline for companies, deployers, providers, professional users of AI tools, publishers, NGOs, media organisations and other organisations operating in or affecting the EU market.
Table of Contents:
▫️ EU AI Act Deadlines at a Glance
▫️ What Regulation (EU) 2026/1744 Delayed—and What It Did Not
▫️ What Applies in 2026
▫️ What Applies in 2027
▫️ What Applies in 2028
▫️ Which Deadline Applies to Your Organisation?
▫️ Rules Already Applicable|
▫️ Special Transition Rules for Existing Systems
▫️ Practical Takeaway
▫️ Frequently Asked Questions
▫️ Official Sources and Disclaimer
🟩 EU AI Act Deadlines at a Glance
2 August 2026: Article 50 transparency obligations and most remaining AI Act provisions apply.
2 December 2026: the limited Article 50(2) transition ends for certain existing synthetic-content systems, and additional prohibited practices apply.
2 August 2027: providers of older GPAI models must complete compliance with applicable GPAI obligations; Member States must have AI regulatory sandboxes operational.
2 December 2027: principal requirements for high-risk AI systems classified under Article 6(2) and Annex III apply.
2 August 2028: principal requirements for high-risk AI systems classified under Article 6(1) and Annex I apply.
🟩 What Regulation (EU) 2026/1744 Delayed—and What It Did Not
Article 50 transparency duties generally: not generally delayed. They apply from 2 August 2026, including transparency requirements for certain AI interactions, emotion-recognition and biometric-categorisation systems, deepfakes, and certain AI-generated public-interest texts.
The applicable obligation depends on the organisation’s role. Providers are responsible for designing interactive AI systems to inform users and for implementing machine-readable marking of synthetic outputs. Deployers are responsible for disclosures concerning emotion recognition, biometric categorisation, deepfakes and certain public-interest text publications.
Article 50(2) limited grace period: Providers of synthetic-content systems placed on the market before 2 August 2026 have until 2 December 2026 to comply with the machine-readable marking and detection obligation.
Annex III high-risk AI: the main requirements now apply from 2 December 2027.
Annex I high-risk AI in regulated products: the main requirements now apply from 2 August 2028.
Regulatory sandboxes: Member States must have AI regulatory sandboxes operational by 2 August 2027.
New prohibitions: additional prohibited AI practices concerning non-consensual intimate material and child sexual abuse material apply from 2 December 2026.

Regulation (EU) 2026/1744 was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. It amended the original AI Act timetable rather than replacing the AI Act as a whole.
🟩 What Applies in 2026
🗓 2 August 2026: Transparency Rules Still Apply
For many organisations, 2 August 2026 remains the most important practical compliance date. The AI Act did not move all transparency obligations to 2027 or 2028.
Article 50 applies to specific transparency situations. These include informing people when they interact with an AI system, disclosing certain emotion-recognition and biometric-categorisation systems, labelling deepfakes, and disclosing certain AI-generated or AI-manipulated public-interest texts. The European Commission explains the provider and deployer distinction in its Article 50 transparency FAQ.
Article 50 does not mean that every AI-assisted email, design, illustration or internal draft needs a visible label. The question is what the system does, what content is produced, whether the content could falsely appear authentic or truthful, and whether the organisation is acting as provider or deployer.
For a deeper treatment of labels, deepfakes, watermarking and fines, see my detailed guide to EU AI Act Article 50 transparency rules.
🗓 2 December 2026: Limited Article 50 Transition and New Prohibitions
The 2 December 2026 date is often misunderstood. It is not a general postponement of Article 50 and it does not move every transparency duty to December.
Providers of synthetic-content systems placed on the market before 2 August 2026 must comply with the machine-readable marking and detection obligation under Article 50(2) by 2 December 2026. This limited transition is different from deployer disclosure duties for deepfakes and other transparency obligations that apply from 2 August 2026.
Regulation (EU) 2026/1744 also introduces additional prohibited AI practices concerning non-consensual intimate material and child sexual abuse material that start to apply from 2 December 2026.
🟩 What Applies in 2027
🗓 2 August 2027: Older GPAI Models and Regulatory Sandboxes
Providers of general-purpose AI models placed on the market before 2 August 2025 must comply with applicable GPAI obligations by 2 August 2027 under Article 111 transitional rules.
This date matters mainly for providers of GPAI models, not for ordinary companies that simply use AI tools. Businesses using GPAI-powered services should still ask vendors how they are handling documentation, transparency, copyright-policy and systemic-risk obligations where relevant.
Member States also have until 2 August 2027 to ensure that national AI regulatory sandboxes are operational under Article 57 on AI regulatory sandboxes.
🗓 2 December 2027: Annex III High-Risk AI
The main requirements for high-risk AI systems classified under Article 6(2) and Annex III now apply from 2 December 2027 under the amended Article 113 application timetable.
This category can affect AI systems used in areas such as employment, worker management, education, creditworthiness, access to essential services, law enforcement, migration, border control, administration of justice and democratic processes.
For employers, banks, schools, public authorities and HR technology providers, the extra time should not be treated as a reason to wait. Annex III systems require classification, risk management, data governance, technical documentation, logging, transparency, human oversight, accuracy, robustness and cybersecurity.
🟩 What Applies in 2028
The main requirements for high-risk AI systems classified under Article 6(1) and Annex I now apply from 2 August 2028 under the amended Article 113 application timetable.
This concerns certain high-risk AI systems embedded in regulated products or performing safety functions, including certain medical devices, in-vitro diagnostic devices, lifts, toys and radio equipment covered by the Union product-safety legislation listed in Annex I.
Separate sector-specific arrangements may apply to machinery, aviation and motor vehicles.
The later date recognises that these systems interact with sector-specific conformity assessment and product-safety regimes. Manufacturers should still map AI components early because product development and certification cycles can be long.
🟩 Which Deadline Applies to Your Organisation?

🟢 Small businesses, creators and marketing teams
Main practical date: 2 August 2026. A small business may be directly affected if it provides an interactive AI system under its own name or trademark, or acts as a professional deployer using emotion recognition, biometric categorisation, deepfake content or unreviewed AI-generated public-interest texts. Merely using an off-the-shelf AI tool does not automatically make the business responsible for every Article 50 obligation.
It is still sensible to check whether a chatbot installed on a company website informs users that they are interacting with AI, and whether the vendor has designed the system to support the provider-side obligations.
Ordinary AI-assisted advertising copy or clearly fictional illustrations do not automatically require an AI label.
For nonprofit organisations, the same role-based analysis matters; see my separate guide to AI compliance for NGOs.
🟢 Providers of existing generative AI systems
Main date: 2 December 2026. This concerns providers of systems placed on the market before 2 August 2026 that generate synthetic audio, images, video or text. They receive a limited transition period for the technical marking and detection obligation under Article 50(2).
🟢 Providers of older GPAI models
Main date: 2 August 2027. Providers of general-purpose AI models placed on the market before 2 August 2025 must complete compliance with the applicable GPAI obligations.
🟢 Employers, banks, schools and public authorities
Main date: 2 December 2027. This may apply when AI influences recruitment, employment, education, creditworthiness, insurance, public benefits, migration, law enforcement or justice.
🟢 Manufacturers of regulated products
Main date: 2 August 2028. This concerns certain high-risk AI systems embedded in medical devices and other regulated products or performing a safety function.
🟩 Rules Already Applicable
The EU AI Act entered into force on 1 August 2024. Its obligations apply progressively.
Since 2 February 2025, prohibited AI practices and AI literacy requirements have applied. Under the amended Article 4 on AI literacy, providers and deployers must take measures to support the development of AI literacy among staff and other persons operating or using AI systems on their behalf, taking account of their knowledge, experience and the context of use.
AI literacy also matters for workplace governance. Employees cannot follow an AI policy they do not understand; for workplace AI risks, see my article on shadow AI and employee use of ChatGPT.
Since 2 August 2025, GPAI obligations have applied for providers of general-purpose AI models placed on the market from that date, with transitional rules for older models.
🟩 Special Transition Rules for Existing Systems
Existing high-risk AI systems: High-risk AI systems placed on the market or put into service before the relevant Chapter III application date are generally subject to the high-risk requirements only if they undergo significant changes in their design from that date.
High-risk AI for public authorities: Providers and deployers of high-risk AI systems intended to be used by public authorities must comply by 2 August 2030.
Large-scale EU IT systems: Certain AI components of the large-scale information systems listed in Annex X that were placed on the market or put into service before 2 August 2027 must comply by 31 December 2030.
Older GPAI models: GPAI models placed on the market before 2 August 2025 must comply with the applicable GPAI obligations by 2 August 2027.
These special transition rules are set out in Article 111.
🟩 Practical Takeaway
The EU AI Act timeline is now more nuanced than a simple August 2026 deadline. Transparency duties still matter in 2026. Older GPAI models and national sandboxes matter in 2027. Annex III high-risk AI systems now move to December 2027. High-risk AI in regulated products moves to August 2028.
The best next step is to build an AI inventory and classify each AI system by role, risk category, function, deployment context and deadline. For a broader implementation roadmap, use the practical EU AI Act checklist for companies.
Not sure which EU AI Act deadline applies to your organisation? I help companies, NGOs, media teams and professionals map their AI use, identify their legal role and build practical AI governance rules before the relevant deadline.
💬 Frequently Asked Questions
❔Did the EU AI Act start on 2 August 2026
No. The EU AI Act entered into force on 1 August 2024. Most of its remaining applicable provisions begin to apply from 2 August 2026, subject to specific transitional periods.
❔Was the EU AI Act delayed
Only partially. Article 50 transparency rules remain applicable from 2 August 2026. The principal requirements for Annex III high-risk systems were moved to 2 December 2027, while the rules for high-risk AI embedded in regulated products were moved to 2 August 2028.
❔What changes on 2 December 2026
A limited transition for providers of certain existing synthetic-content systems ends, and new prohibited AI practices concerning non-consensual intimate content and child sexual abuse material begin to apply.
❔Who has until 2 December 2027
Providers and deployers of Annex III high-risk AI systems, including certain systems used in employment, education, credit assessment, public services, migration, law enforcement and justice.
❔Do small businesses need to comply from 2 August 2026
Potentially, yes, but the answer depends on role and use case. A small business may be directly affected if it provides an interactive AI system under its own name or trademark, or acts as a professional deployer using emotion recognition, biometric categorisation, deepfake content or unreviewed AI-generated public-interest texts. Merely using an off-the-shelf AI tool does not automatically make the business responsible for every Article 50 obligation.
❔Must every AI-generated image be labelled
No. The AI Act does not impose a universal visible-label requirement on every AI-generated image. However, providers of generative AI systems may have to embed machine-readable markings under Article 50(2). Businesses and other deployers must provide a human-visible disclosure principally where the content qualifies as a deepfake and could falsely appear authentic or truthful.
❔When do high-risk AI rules apply
High-risk AI systems classified under Article 6(2) and Annex III apply from 2 December 2027. High-risk AI systems classified under Article 6(1) and Annex I apply from 2 August 2028.
🟩 Official Sources and Disclaimer
Regulation (EU) 2024/1689 — the original EU AI Act.
Regulation (EU) 2026/1744 — the Digital Omnibus on AI amendments.
Article 111 transitional rules for existing systems and GPAI models.
This timeline is based on Regulation (EU) 2024/1689, Regulation (EU) 2026/1744, the European Commission’s AI Act Service Desk and the Commission’s Article 50 guidance. It was last reviewed on 29 July 2026.
This article provides general information and does not constitute legal advice. The classification of an AI system and the applicable deadline depend on its intended purpose, functionality, deployment context and the role of the organisation involved.
Subscribe to Lawyer Against The Machine for practical analysis of AI regulation, compliance and digital risk in Europe.
I will continue writing about this in plain language
See you in the next piece
Cheers,


