The EU AI Act timeline after the omnibus
The dates changed on 27 July 2026. High-risk obligations were deferred, not cancelled.
Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force on 27 July 2026 and amended Regulation (EU) 2024/1689. Much online guidance still shows the earlier timetable and is now out of date. The central correction is that the Annex III and Annex I high-risk obligations moved to later dates, while the duties already in force remained live.
For a UK organisation with EU exposure, the timetable should be read in two bands. The first contains duties that can require attention now under Articles 4, 5 and 50 and Chapter V. The second contains high-risk obligations deferred under Regulation (EU) 2026/1744, but the delay does not remove the relevant categories or the need to understand whether a system falls within them.
| Date and status | What applies |
|---|---|
| Already in force | |
| 2 February 2025In force | Prohibited AI practices and AI literacyArticles 5 and 4 |
| 2 August 2025In force | General-purpose AI model obligationsChapter V |
| 2 August 2026In force | Transparency obligationsArticle 50 |
| Deferred by the omnibus | |
| 2 December 2027Deferred | Annex III stand-alone high-risk obligationsRegulation (EU) 2026/1744 |
| 2 August 2028Deferred | Annex I product-embedded high-risk obligationsRegulation (EU) 2026/1744 |
What has applied since February 2025?
Two parts of the Act have applied since 2 February 2025. Article 5 prohibits the specified AI practices, which include manipulative or deceptive techniques causing significant harm, exploitation of listed vulnerabilities, defined forms of social scoring, predictive policing based solely on profiling, untargeted scraping of facial images, and certain biometric or emotion-related uses. The list is specific, so an organisation should test its actual use case against Article 5 rather than treating every higher-risk use as prohibited.
Article 4 has applied from the same date. It requires providers and deployers to ensure that staff dealing with AI have a sufficient level of AI literacy. This is a current duty, not part of the high-risk deferral. The AI literacy guide explains how to approach it without turning a short legal duty into an invented compliance checklist.
What changed in August 2025 and August 2026?
General-purpose AI model obligations under Chapter V have applied since 2 August 2025. The role matters here: the Act distinguishes providers from deployers and defines other roles including importers, distributors and product manufacturers, while allowing one company to hold more than one role (Article 3).
Transparency obligations under Article 50 have applied since 2 August 2026. They cover notice when a person interacts with an AI system unless that interaction is obvious, machine-readable marking by providers of systems generating synthetic content, information for people exposed to emotion recognition or biometric categorisation, and disclosure of deepfakes. The practical implications are covered in our Article 50 transparency guide.
What moves to December 2027?
Annex III stand-alone high-risk obligations are deferred to 2 December 2027 under Regulation (EU) 2026/1744. The areas listed in the facts sheet are biometrics, critical infrastructure, education and vocational training, employment and worker management, access to essential private and public services, law enforcement, migration and border control, and the administration of justice and democratic processes.
For an ordinary UK organisation with EU exposure, employment systems can be particularly easy to recognise in this list because it expressly covers recruitment, screening, promotion, termination, task allocation and monitoring. Creditworthiness, insurance risk assessment and pricing, emergency dispatch and benefits are among the listed essential-service uses. The relevant date is later, but the category test is still worth making now so that the organisation knows which systems sit on the deferred track.
What moves to August 2028?
Annex I product-embedded high-risk obligations are deferred to 2 August 2028 under Regulation (EU) 2026/1744. This band concerns AI used as a safety component of products subject to EU harmonisation law, including machinery, medical devices, toys, lifts, radio equipment and in-vitro diagnostics.
The distinction between Annex I and Annex III matters because the dates differ. A software system used for a listed stand-alone function should not be placed on the product-embedded timetable without checking why it belongs there. Start with scope, role and system use; our guide on whether the Act applies to a UK organisation covers that first decision (Articles 2 and 3).
Checked against Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744. Last reviewed 11 August 2026.