EU AI Act: Compliance Timeline Shifts
The EU AI Act's implementation timeline has been revised following the Digital Omnibus on AI, a package of amendments aimed at simplifying parts of the Act.

The EU AI Act's compliance deadlines have shifted following the Digital Omnibus on AI, a package of amendments aimed at simplifying parts of the Act.
The EU AI Act's high-risk regime was meant to switch on on 2 August 2026, but the Digital Omnibus has pushed back the deadlines. Standalone Annex III high-risk AI systems now apply from 2 December 2027, while high-risk AI embedded in products already subject to EU product safety legislation moves to 2 August 2028.
A new prohibition has been added to the Act, covering AI systems built to generate non-consensual intimate imagery and child sexual abuse material. This applies from 2 December 2026.
Transparency obligations under Article 50 of the Act now require anyone deploying chatbots, generating synthetic content, using emotion recognition or biometric categorisation systems, or building tools whose output could be mistaken for human interaction to meet disclosure requirements. There is no general grace period, and Article 50 applies from 2 August 2026.
The EU's AI Office and national market surveillance authorities are now responsible for implementing, supervising, and enforcing the Act. The AI Office holds investigative and sanctioning powers over GPAI model providers, and can issue requests for information, demand access to models and technical documentation, conduct evaluations, require corrective measures, and impose fines.
A Code of Practice on Transparency of AI-generated Content has been published, setting practical steps for providers and deployers of generative AI systems to meet Article 50 obligations. The Code remains open for signature, and adherence is not conclusive evidence of compliance, but signatories may rely on it to demonstrate compliance.
The Commission has also created standardised icons that deployers may use to label AI-generated or manipulated content.
The penalty framework has applied since 2 August 2025, with non-compliance with Article 5 prohibitions carrying fines of up to €35 million or 7% of total worldwide annual turnover, whichever is higher.
Compliance Timeline
| Deadline | Description |
|---|---|
| 2 December 2027 | Standalone Annex III high-risk AI systems |
| 2 August 2028 | High-risk AI embedded in products already subject to EU product safety legislation |
| 2 December 2026 | New prohibition on AI systems built to generate non-consensual intimate imagery and child sexual abuse material |
Transparency Obligations
Article 50 of the Act now requires anyone deploying chatbots, generating synthetic content, using emotion recognition or biometric categorisation systems, or building tools whose output could be mistaken for human interaction to meet disclosure requirements. There is no general grace period, and Article 50 applies from 2 August 2026.
Enforcement Authority
The EU's AI Office and national market surveillance authorities are now responsible for implementing, supervising, and enforcing the Act. The AI Office holds investigative and sanctioning powers over GPAI model providers.
Code of Practice
A Code of Practice on Transparency of AI-generated Content has been published, setting practical steps for providers and deployers of generative AI systems to meet Article 50 obligations. The Code remains open for signature, and adherence is not conclusive evidence of compliance, but signatories may rely on it to demonstrate compliance.
Penalties
The penalty framework has applied since 2 August 2025, with non-compliance with Article 5 prohibitions carrying fines of up to €35 million or 7% of total worldwide annual turnover, whichever is higher.





