Regulation
What applies when under the EU AI Act
The EU AI Act has been in force since 1 August 2024 and applies in stages. The prohibitions applied from 2 February 2025, the general-purpose AI model obligations from 2 August 2025, and the Regulation applies generally from 2 August 2026. The Digital Omnibus on AI, Regulation (EU) 2026/1744, has since amended it and added further prohibitions that apply from 2 December 2026. The high-risk requirements follow in December 2027 and August 2028.
EU AI Act application dates
The Digital Omnibus on AI, Regulation (EU) 2026/1744, is adopted law and is in force. It amended the AI Act rather than simply postponing it, and it added prohibitions that apply from 2 December 2026. The dates below are read from the consolidated text as it now stands.
The Regulation enters into force, the twentieth day after publication in the Official Journal.
Date of effect: 01/08/2024; Entry into force Date pub. +20 See Art 113
Chapter I, including the AI-literacy duty, and Chapter II, the prohibited practices, begin to apply.
(a) Chapters I and II shall apply from 2 February 2025, with the exception of Article 5(1), first subparagraph, points (ba) and (bb), and Article 5(1a) and (1b) which shall apply from 2 December 2026;
The general-purpose AI model obligations begin to apply, with governance, penalties and notified-body provisions.
(b) Chapter III Section 4, Chapter V, Chapter VII and Chapter XII and Article 78 shall apply from 2 August 2025, with the exception of Article 101;
Deadline for the Commission to issue guidelines on the practical implementation of the high-risk classification rules.
The Commission shall, after consulting the European Artificial Intelligence Board (the 'Board'), and no later than 2 February 2026, provide guidelines specifying the practical implementation of this Article in line with Article 96 together with a comprehensive list of practical examples of use cases of AI systems that are high-risk and not high-risk.
The amendments the AI Act makes to other Union acts begin to apply.
(d) Articles 102 to 110 shall apply from 27 July 2026.
General application date. Everything not carved out by the staggered points applies, including the transparency obligations.
It shall apply from 2 August 2026.
- next to apply
The prohibitions ADDED by the Digital Omnibus begin to apply. These are new obligations, not postponed ones.
(a) Chapters I and II shall apply from 2 February 2025, with the exception of Article 5(1), first subparagraph, points (ba) and (bb), and Article 5(1a) and (1b) which shall apply from 2 December 2026;
Providers of systems generating synthetic audio, image, video or text placed on the market before 2 August 2026 must comply with the marking obligation.
Providers of AI systems, including general-purpose AI systems, generating synthetic audio, image, video or text content, that have been placed on the market before 2 August 2026 shall take the necessary steps in order to comply with Article 50(2) by 2 December 2026.
Providers of general-purpose AI models placed on the market before 2 August 2025 must have brought them into compliance.
Providers of general-purpose AI models that have been placed on the market before 2 August 2025 shall take the necessary steps in order to comply with the obligations laid down in this Regulation by 2 August 2027.
The high-risk requirements begin to apply to systems classified as high-risk under Annex III.
(c) Chapter III, Sections 1, 2, and 3, with the exception of Article 6(5), shall apply from: (i) 2 December 2027 as regards AI systems classified as high-risk pursuant to Article 6(2) and Annex III; and
The high-risk requirements begin to apply to systems that are safety components of products regulated under Annex I.
(ii) 2 August 2028 as regards AI systems classified as high-risk pursuant to Article 6(1) and Annex I;
Systems that are components of the large-scale EU IT systems listed in Annex X, placed on the market before 2 August 2027, must be brought into compliance.
AI systems which are components of the large-scale IT systems established by the legal acts listed in Annex X that have been placed on the market or put into service before 2 August 2027 shall be brought into compliance with this Regulation by 31 December 2030.
Reference frameworks, voluntary
These are dated publications, not obligations. Nothing below carries a legal deadline.
NIST released the AI Risk Management Framework 1.0, a voluntary framework. It imposes no legal obligation.
Released on January 26, 2023, the Framework was developed through a consensus-driven, open, transparent, and collaborative process
NIST released the Generative AI Profile, a voluntary companion to the AI RMF. It imposes no legal obligation.
NIST AI 600-1, Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile
