AI Act: all 2025–2028 deadlines on one timeline [July 2026]

Digital Omnibus deferred some duties — and half the market decided the topic can wait until 2027. The problem is they deferred the wrong rules. Here is the full calendar: what already applies, what lands on 2 August 2026, and what can actually wait.

In short
  • Already in force (since 2 Feb 2025): prohibited AI practices (Art. 5) and the AI competence duty — AI literacy (Art. 4). For all firms, no size threshold.
  • In 14 days (2 Aug 2026): transparency duties (Art. 50 — chatbots and AI-generated content), national supervision and the fine framework.
  • Deferred (Digital Omnibus): high-risk system duties — Annex III to 2 Dec 2027, Annex I to 2 Aug 2028. That is the only thing that moved.

If in recent weeks you heard “the AI Act was postponed, we have calm until 2027” — this article exists to disarm that sentence before a supervisor or your client’s lawyer does. One category of duties was deferred. Two others have applied for a year and a half, and a third — with a real enforcement mechanism — lands on 2 August 2026.

Timeline

Five AI Act phases — where we are today

  • 1 Aug 2024

    Regulation enters into force

    The AI Act formally exists. No duties bind yet — but the clock for every later deadline starts here.

  • 2 Feb 2025 · Phase 1

    Bans (Art. 5) and AI literacy (Art. 4)

    Ban on eight AI practices (incl. subliminal manipulation, social scoring) and the duty to ensure a “sufficient level of AI competence” for staff. Covers everyone — providers and deployers, corporates and micro-firms. In force for 17 months.

  • 2 Aug 2025 · Phase 2

    General-purpose models (GPAI)

    Duties for GPAI model providers: documentation, copyright policy, and for systemic-risk models — evaluations and reporting. If you do not train your own models, this phase hits you indirectly — through your vendors.

  • in 14 days
    2 Aug 2026 · Phase 3

    Transparency, national supervision, fines

    Three things at once: Art. 50 transparency duties (chatbots disclose they are AI; synthetic content is labelled; deepfakes revealed), national supervisory authorities go live — from that day they can inspect and enforce, including Phase 1–2 arrears — and the fine framework applies. This is when the AI Act stops being literature and becomes procedure.

  • 2 Dec 2026 to verify

    Synthetic content watermarking + PLD

    After Digital Omnibus, technical machine-marking requirements (watermarking) apply from 2 Dec 2026. A week later, 9 Dec 2026, the new PLD directive applies: software — including AI systems — becomes a “product” under civil liability.

  • 2 Dec 2027 · Phase 4

    High-risk systems — Annex III

    Full duties for Annex III systems (incl. recruitment, credit scoring, education): risk management system, technical documentation, human oversight, registration. Originally: August 2026 — that date was moved.

  • 2 Aug 2028 · Phase 5

    High-risk systems — Annex I

    Duties for AI that is a component of products already regulated sectorally (machinery, medical devices, toys, etc.).

Download

This timeline as a one-page PDF — printable

A desk-and-board version: all dates, all phases, marked “already in force / imminent / deferred”.

Download timeline (PDF)
Straight talk

Myth vs fact: what Digital Omnibus really changed

The Digital Omnibus package (agreed spring 2026) triggered a wave of “AI Act postponed” headlines. Here is what is true:

MythFact
“The AI Act was postponed.”Only high-risk system duties moved (Annex III → Dec 2027, Annex I → Aug 2028). Transparency, supervision and fines arrive on schedule on 2 Aug 2026.
“It only hits big tech.”Art. 4 and Art. 5 bind anyone who develops or uses AI in business — including a 20-person firm with a website chatbot.
“SMEs are exempt.”SMEs get fine proportionality and regulatory sandboxes — not an exemption from duties. Art. 4 and 5 bind since 2 Feb 2025.
“We’ll wait for the Polish act.”The AI Act is a regulation — it applies directly, no transposition. The Polish act will clarify the authority and procedures; its absence does not suspend your duties. act status — to verify
“Fines only from 2027 anyway.”The fine framework applies from 2 Aug 2026 (for GPAI providers — at Commission level already from Aug 2025). From August the authority can also demand documentation for prior periods.
Checklist

What you must have on 2 August 2026

A minimal, sensible set — no certificates, no consulting overhead:

  1. AI literacy evidence (Art. 4): role-fitted training programme + participant register. “We ran a webinar” with no documentation does not exist to a regulator. We unpack this next →
  2. Art. 50 labelling at every AI–human touchpoint: chatbot, generated content, deepfake. Covered on Wednesday →
  3. AI system inventory — including “unofficial” shadow AI. You cannot evidence compliance for something you have not counted.
  4. AI policy — even one page: what is allowed, what is not, in which tools, who decides.
  5. Named ownership: one person who “has” the AI Act topic. Without an owner the previous four points dissolve across the organisation.
Why now

Until 2 August supervisors lacked tools — duties hung in a vacuum and the market got used to ignoring them. From 2 August the vacuum disappears. We do not assume a wave of inspections on day one; we assume something more practical — the first requests to show compliance will come not from the regulator but from your corporate clients, who are updating vendor questionnaires right now.

FAQ

Common questions

When did the AI Act start applying?

It entered into force on 1 Aug 2024; duties phase in: bans and AI literacy from 2 Feb 2025, GPAI from 2 Aug 2025, transparency and supervision from 2 Aug 2026, high-risk systems from Dec 2027 (Annex III) and Aug 2028 (Annex I).

Was the AI Act postponed?

Only the high-risk systems part. Transparency duties, national supervision and the fine framework arrive on the original plan — 2 August 2026.

Who does this hit in 2026?

Practically every firm using AI: competence (Art. 4) and bans (Art. 5) bind everyone since February 2025, and from August 2026 transparency (Art. 50) joins them.

What fines apply?

Up to EUR 35m / 7% turnover (prohibited practices), up to EUR 15m / 3% (other breaches), up to EUR 7.5m / 1% (misleading authorities). For SMEs — the lower of the amounts. Full table and who really pays — Thursday.

“2 August” series · 5 articles this week

You do not have to track these dates alone

All week we unpack Phase 3: tomorrow Art. 4 (AI literacy), Wednesday Art. 50 (content labelling), Thursday fines, Friday — a ready training programme with full documentation. Sign up and we will send the timeline PDF and the full article set.

Get the PDF and join the series

This article is informational and is not legal advice. Dates and duty scopes are based on Regulation 2024/1689 and the Digital Omnibus package status as of July 2026 — verify the legal state or consult a lawyer before business decisions.

RW

Rafał Wiatrowski — for 25 years has built and deployed technology: from code, through CTO roles, to GenAI strategy for large organisations. Designs production AI systems (agents, RAG, MCP) and helps companies move from pilots to accountable deployments. Executive MBA (Carlson School of Management).

Jeden artykuł tygodniowo. Zero lania wody.

Subskrybuj →