EU AI Act Deadlines After the Digital Omnibus: The Definitive 2026 Timeline
TL;DR
As of June 2026, the Digital Omnibus on AI is agreed but not yet law. It is a provisional political agreement (reached 7 May 2026) that the European Parliament confirmed at its plenary on 16 June 2026 (423 in favour, 57 against, 174 abstentions); Council formal adoption and Official Journal publication are still required before any new date takes effect. Until then, the original Regulation (EU) 2024/1689 dates remain the law in force, including 2 August 2026 for standalone high-risk (Annex III) obligations. The Omnibus would defer that to 2 December 2027, but it hasn't happened yet.
The dates that are live today: prohibited practices and AI literacy already apply (2 Feb 2025); GPAI model obligations apply (2 Aug 2025); on 2 Aug 2026, governance bodies and AI Office enforcement powers, Article 50 transparency duties, the GPAI penalty regime, and standalone high-risk (Annex III) obligations all currently apply. The Omnibus agreement, once in force, would move the Annex III date to 2 Dec 2027, the regulatory-sandbox obligation to 2 Aug 2027, and embedded high-risk (Annex I) to 2 Aug 2028, but those are pending, not done.
So if you read a blog post, a vendor checklist, or a law-firm alert telling you that high-risk obligations apply from 2 August 2026, as of today, that source is still right. The deferral has been agreed, not enacted. Anyone treating 2 Dec 2027 as the binding deadline today is jumping the gun.
This page is the dated reference: what is legally in force now, set against what the Omnibus would change once it clears the EP vote, Council adoption, and OJ publication. Bookmark it, cite it, and check the live Omnibus tracker for the moment the dates actually move.
What the Digital Omnibus changed
The EU AI Act, Regulation (EU) 2024/1689, entered into force on 1 August 2024 with a staged rollout. The original plan front-loaded the heaviest obligations on high-risk systems to 2 August 2026. Through 2025, regulators, industry, and member states all signalled the same problem: the harmonised standards, the technical guidance, and the conformity-assessment infrastructure simply would not be ready in time.
The Digital Omnibus on AI is the EU's response. On 7 May 2026, negotiators from the Council, the European Parliament, and the Commission reached a provisional political agreement to simplify and stagger the rollout. Coreper endorsed it on 13 May, and the IMCO and LIBE committees approved it on 2 June 2026 (93-4-15). The European Parliament gave its final plenary confirmation on 16 June 2026 (423 in favour, 57 against, 174 abstentions). Crucially, the co-legislators rejected the Commission's original "conditional trigger" idea (where deadlines would move only once standards were ready) in favour of fixed calendar dates, chosen specifically to give businesses clarity and predictability.
But "agreed" is not "in force." A provisional agreement does not change the law. The new dates take legal effect only after Council formal adoption and publication in the Official Journal (binding three days after publication). Until that happens, the original Regulation (EU) 2024/1689 schedule governs.
Here's what the Omnibus would change once it is enacted, agreed, but pending:
Note what does not change even on paper: Article 50 transparency obligations stay at 2 Aug 2026, and GPAI model obligations plus AI Office enforcement powers stay at 2 Aug 2026, the Omnibus does not move these to 2027. The prohibited practices live since February 2025 and the GPAI documentation duties live since August 2025 are likewise untouched. The Omnibus is targeted relief on the high-risk track, not a reset of the whole Act. And it adds new Article 5 prohibitions (AI-generated non-consensual intimate imagery, "nudifiers", and AI-generated child sexual abuse material), so the obligation surface is in some respects wider, not just later.
One caveat worth stating plainly, because it changes how you should plan right now: these changes are not yet law. They take legal effect only on formal adoption and publication in the Official Journal, and as of June 2026 that has not happened. The EP gave plenary approval on 16 June 2026 (423 in favour, 57 against, 174 abstentions); Council adoption and OJ publication still follow. Until OJ publication, the legally applicable date for standalone high-risk remains 2 August 2026. Plan against the current law, watch the deferral, and shift only when it actually lands.
Is your AI system high-risk?
Find out in 2 minutes, free, no signup required.
Take the free assessmentEU AI Act deadlines, what's in force, and what the Omnibus would change
This is the centerpiece. The dates below are the law in force today under Regulation (EU) 2024/1689. Where the Digital Omnibus has agreed a different date, it's flagged, but remember those agreed dates are pending Council adoption and OJ publication (the EP approved it on 16 June 2026). They are not yet binding. For the always-current version, see the live EU AI Act Omnibus tracker and the AI Act deadline tracker.
What the Omnibus would change, once in force (pending, not yet law):
Note: Legalithm's staged AI Act timeline guide narrates the current statutory phasing. The Omnibus deferral dates above govern only after OJ publication; until then, 2 Aug 2026 / 2 Aug 2027 for high-risk remain the operative dates.
What this means for providers
If you build an AI system, the Omnibus would buy you time on the high-risk track, but only if you're actually in scope, only on the standalone path, and only once the deferral is enacted. Concretely:
- Annex III high-risk providers (e.g. AI in recruitment, credit scoring, education, critical infrastructure): your legal deadline today is still 2 August 2026 (Art 6-27, 49). The Omnibus has agreed to move it to 2 December 2027, but that only binds after OJ publication, expected after Council adoption (the EP approved it on 16 June 2026). Plan to the 2 Aug 2026 date until the deferral is law; treat the extra runway for risk management (Art 9), data governance (Art 10), technical documentation (Art 11), and conformity assessment as likely-but-not-yet-guaranteed.
- GPAI providers: nothing changed for you. Your obligations have been live since 2 August 2025, and the Omnibus does not touch them, including the GPAI enforcement and penalty powers that apply from 2 Aug 2026. Documentation, copyright policy, and training-data summaries are due now.
- Generative / synthetic-media providers: Article 50 transparency duties apply from 2 Aug 2026 (unchanged). The Omnibus would add a marking grace to 2 December 2026 for systems already on the market before 2 Aug 2026, and bring the new Art 5 bans on the same date, but those are pending enactment. Machine-readable marking of AI-generated output is not optional.
Not sure whether your system is even high-risk? Run the EU AI Act applicability checker before you spend a euro on compliance you may not owe.
What this means for deployers
If you use AI rather than build it, the picture is more nuanced. Deployer obligations for Annex III high-risk systems, including human oversight under Art 26 and the Fundamental Rights Impact Assessment (FRIA) under Art 27, currently apply from 2 August 2026. The Omnibus would move that to 2 December 2027, but the deferral is not yet law (pending Council adoption and OJ publication; the EP approved it on 16 June 2026), so plan to August 2026 until it lands.
But two deployer-facing duties are not deferred:
- AI literacy (Art 4) has applied since 2 February 2025. If your staff use AI in their work, you owe them a baseline of training and competence today.
- Prohibited practices (Art 5) bind you regardless of role. You cannot deploy a banned system and point at the vendor.
What this means for GPAI model providers
The GPAI track is the part of the Act most people underestimate because it's already live. Since 2 August 2025, providers of general-purpose AI models have owed technical documentation, a copyright policy, and a public summary of training content (Art 53). Providers of models with systemic risk (Art 55) owe additional model evaluation, adversarial testing, and serious-incident reporting. The Omnibus did not touch any of this. If you've been waiting for "the AI Act to kick in", for GPAI, it already did, ten months ago.
What this means for SMEs and small mid-caps
This is where the Omnibus quietly does the most for European startups. Beyond the timeline shift, it introduces proportionality relief: reduced documentation, conformity-assessment, and post-market-monitoring burdens for smaller players, with the small-mid-cap threshold set around under 750 employees and €150M turnover. It also explicitly permits processing personal data for bias detection in high-risk systems, a practical fix that previously sat in a legal grey zone.
For a startup-stage company, the message is: the heaviest high-risk obligations are legally due 2 August 2026 today, with a deferral to December 2027 agreed but not yet enacted; the burden is lighter than the headline text implies; and the prohibited-practices and literacy duties you already owe are cheap to meet. The risk cuts both ways, don't over-comply, but don't bet your compliance plan on a deferral that hasn't cleared the EP vote, Council adoption, and OJ publication yet. Build to the 2 Aug 2026 date and relax it only when the Omnibus is law.
What to do now
The agreed deferral is a probable planning gift, not a reason to stand down today. A sane sequence:
- Confirm scope. Are you a provider, deployer, or GPAI provider, and is any system high-risk? Use the applicability checker.
- Close the obligations that are already live. AI literacy (Art 4) and prohibited-practice screening (Art 5) are due today. Article 50 transparency duties apply from 2 Aug 2026 regardless of the Omnibus.
- Size the exposure. Run the penalty calculator, fines reach up to €35M or 7% of global turnover, and that ceiling did not move.
- Build the high-risk file to the date in force, 2 August 2026. Do not pause your conformity-assessment work on the assumption that 2 Dec 2027 is locked; it isn't law until OJ publication. If the deferral lands, you gain runway. If it slips, you're still covered.
- Track the Omnibus status. Watch the Omnibus tracker for Council adoption and OJ publication (the EP approved it on 16 June 2026), that is the moment the dates actually move.
- Get a baseline. The free AI Act assessment maps your obligations against the dates in force in minutes.
Frequently asked questions
When do high-risk AI obligations apply now?
As of June 2026, the law in force says 2 August 2026 for standalone Annex III high-risk systems (Art 6-27, 49), and 2 August 2027 for high-risk AI embedded in regulated products under Annex I (medical devices, machinery, vehicles). The Digital Omnibus has agreed to defer these to 2 December 2027 and 2 August 2028 respectively, but that deferral is not yet law. It is pending Council adoption and Official Journal publication (the European Parliament approved it on 16 June 2026). Until OJ publication, plan to the 2 August 2026 date.
Is the "comply by August 2026" advice still correct?
For now, yes. The 2 August 2026 high-risk deadline is still the legally applicable date. The Omnibus deal of 7 May 2026 agreed to move it to 2 December 2027, but that agreement has not yet been adopted into law, so as of today, sources telling you to comply by August 2026 are still correct. Anyone presenting 2 December 2027 as the binding deadline today is ahead of the law.
Did the Digital Omnibus delay the whole AI Act?
No, and it has not legally delayed anything yet, since it isn't in force. Even on paper, prohibited practices (Art 5, since 2 February 2025), GPAI model obligations (Art 53/55, since 2 August 2025), Article 50 transparency duties (2 Aug 2026), and GPAI/AI Office enforcement powers (2 Aug 2026) are untouched. The Omnibus is targeted relief on the high-risk track plus proportionality measures for smaller companies, once enacted. It also adds new Art 5 prohibitions (nudifiers, AI CSAM).
When are the AI watermarking / content-marking rules in force?
Article 50 transparency and marking obligations apply from 2 August 2026 under the current law, the Omnibus does not move this date. What the Omnibus would add (pending enactment) is a marking grace period extended to 2 December 2026 for systems already on the market before 2 Aug 2026, alongside the new transitional bans on AI-generated non-consensual intimate imagery and AI-generated child sexual abuse material (also to 2 Dec 2026).
Are these new dates legally binding yet?
No. As of June 2026 the Digital Omnibus is a provisional political agreement, not law. The European Parliament approved it on 16 June 2026 (423 in favour, 57 against, 174 abstentions); Council formal adoption and publication in the EU Official Journal must follow before the new dates take effect (binding three days after publication). Until then, the legally applicable date remains 2 August 2026 for standalone high-risk. Track the status on the live Omnibus tracker.
The deadlines are agreed to move but haven't moved yet, the obligations didn't disappear, and the €35M / 7% penalty ceiling is exactly where it was. The companies that win the next 18 months are the ones who keep building to the 2 August 2026 date in force, watch the Omnibus clear its final hurdles, and bank the deferral as runway if and when it becomes law, not the ones who pause on a deadline that isn't binding yet.
Get your current obligation map, against the dates in force today, in minutes with the free Legalithm AI Act assessment.


