For about a year, anyone working on AI in Europe was focused on 2 August 2026. That was when the big requirements, risk files, conformity checks, and audits for high-risk systems, were set to begin. But in May, the EU changed the date.
Not all parts of the law are affected, just the section that worried companies most. Here’s a quick update for mid-2026: the bans are real and strict, rules for model builders started last summer, and most paperwork is now due at the end of 2027.
One law, four buckets
The EU AI Act, officially Regulation (EU) 2024/1689, was approved on 13 June 2024 and took effect that August. It’s the first broad AI law, setting one set of rules for all sectors. Instead of separate rules for medical, hiring, or credit AI, Brussels uses a single framework and sorts systems by how much harm they might cause.
Four tiers:
- An unacceptable risk: these systems are completely banned.
- High risk: allowed, but only if they meet requirements similar to product safety rules.
- Transparency risk: you only need to disclose it.
- Very low risk: these are standard tools, like spam filters, game AI, and most software your team builds.

Article 3 defines an AI system broadly. It’s any machine-based system that can work with different levels of autonomy, adapt after deployment, and use its inputs to decide how to generate outputs like predictions, content, recommendations, or decisions. The Commission’s guidelines from February 2025 break this into seven parts.
The rule works much like the GDPR: if your system’s output is used in the EU, you’re covered, no matter where your servers are. Providers have the most responsibility. Deployers have less, unless they rebrand, change, or use the system for high-risk purposes; then they become responsible. Research, personal use, and open source are excluded, except when open source models are banned, high risk, or pose systemic risk.

The bans have been live since February 2025
Article 5 lists what you can’t build or sell in Europe, in force since 2 February 2025:
- manipulation or deception causing significant harm
- exploiting age, disability, or social situation
- social scoring
- predicting individual criminality from profiling or personality traits alone
- scraping the web or CCTV footage to bulk-build facial recognition databases
- emotion recognition at work or in schools (medical and safety uses excepted)
- biometric categorisation inferring race, sexuality, or political views
- real-time remote biometric ID in public spaces for law enforcement, with narrow exceptions

The guidance released with the law includes about 140 pages of examples. The rules on scraping are similar to the Clearview case, which seems intentional. A ninth ban is being discussed. It would cover AI that creates non-consensual intimate images or child sexual abuse material, making providers liable if this is a foreseeable result of releasing the technology without proper safeguards. This is not law yet.
If you ship a model, your deadline was last August
The rules for general-purpose AI models started on 2 August 2025. GPAI means models that are truly general, can handle many tasks, and are designed for use in other applications. The Commission suggests that if your model for language, images, or video uses more than 10²³ FLOP in training, it likely counts as GPAI, though this is just a guideline since different types are judged differently. If your model uses more than 10²⁵ FLOP, it’s seen as a systemic risk and you must notify the AI Office within two weeks. Every provider in that bracket owes four things: to provide regulators with technical documentation, to supply downstream developers with documentation, to establish a copyright policy that respects text-and-data-mining opt-outs, and to publish a public summary of their training data using the Commission’s mandatory template, which has been available since 24 July 2025. In addition, those who are involved in systemic risk must also carry out adversarial evaluation, implement risk mitigation measures, report any incidents, and ensure cybersecurity. Models which were on the market before August 2025 have until 2 August 2027 to comply, with no mandatory retraining being required where such retraining is impossible or would be disproportionate, as long as the gaps are made public.

There’s also the GPAI Code of Practice, a voluntary way to show compliance. It was published on 10 July 2025, two months late, and has three parts: transparency, copyright, and safety and security (the last part is only for systemic-risk models). Amazon, Anthropic, Google, IBM, Microsoft, OpenAI, and Mistral signed on, along with many others. Meta did not, citing ‘legal uncertainties’ and saying the measures go ‘far beyond the scope of the AI Act.’ xAI only signed the safety section. Not signing isn’t illegal, but it means you’ll have to answer more questions and show compliance in other ways.
The high-risk rules are the part that moved
Risk of a high degree occurs in two forms. Annex III includes standalone systems in eight areas: biometrics, critical infrastructure, education, the management of employment and workers, essential services such as credit and insurance, law enforcement, migration and borders, and justice and democratic processes. Embedded AI is covered in Annex I: it refers to safety features in regulated products such as medical devices, machinery, toys, cars and lifts.
Article 6(3) has a very narrow exception for some procedural or preparatory systems, but this is interpreted strictly. The exception ends if the system is used for profiling, and just recording and registering a claim in the EU database does not count. Draft guidelines from 19 May 2026 (consultation runs until 23 June) make it clear: your system’s purpose is judged by your instructions, marketing, and technical documents together, so you can’t avoid the rules with a terms-of-service clause. Automated CV ranking is clearly high risk, as shown in the examples.
The challenge was that in 2025, the support systems for these rules were missing. The harmonised standards from CEN-CENELEC expected towards the end of 2026. Guidance documents came just weeks before their deadlines, and by the end of last year, only about a third of member states had named their responsible authorities for August 2025.
The industry noticed. In July 2025, several European CEOs, from Airbus to Mistral, signed an open letter asking for a two-year ‘stop the clock’. Brussels responded clearly: “There is no stop the clock. There is no grace period. There is no pause.” The model rules took effect as planned.
Four months later, the Commission suggested a delay. On 19 November 2025, the Digital Omnibus on AI was introduced, tying the high-risk start date to a Commission decision about whether support tools were ready, with backup plans if not. The first trilogue talks broke down on 28 April 2026, but negotiators reached a provisional deal on 6 May, announced it the next day, and member states confirmed it on 13 May. Now, instead of a conditional trigger, there are fixed dates: 2 December 2027 for Annex III and 2 August 2028 for Annex I.

This is not binding law yet. As of early June 2026, it’s a political agreement and should be published in the Official Journal within a few weeks, before August. Until then, the old dates still apply.
Where the timeline stands
| Date | What | Status |
|---|---|---|
| 1 Aug 2024 | Act enters into force | Done |
| 2 Feb 2025 | Prohibitions and AI literacy duty | In force |
| 2 Aug 2025 | GPAI obligations, governance, penalties | In force |
| 2 Aug 2026 | Transparency duties; enforcement powers on | Weeks away |
| 2 Dec 2026 | Watermarking grace ends; NCII/CSAM ban | Agreed, pending |
| 2 Aug 2027 | Legacy GPAI models must comply | Planned |
| 2 Dec 2027 | Annex III high-risk obligations | Agreed, pending |
| 2 Aug 2028 | Annex I high-risk obligations | Agreed, pending |
Fines are real; the enforcement machine is still warming up
Penalties have applied since August 2025. Breaking a prohibition can mean a fine of €35 million or 7% of global turnover, whichever is higher. For most other breaches, including GPAI and transparency rules, the maximum is €15 million or 3%. If you mislead regulators, the penalty is €7.5 million or 1%. Smaller companies get the lower amount, and the Omnibus bill extends this relief to small mid-caps too.

It is a somewhat subtle, often causes confusion. While obligations start in August 2025, the Commission can’t fine GPAI providers until 2 August 2026. That’s also when national penalty systems begin. The AI Office handles general-purpose models, while national market surveillance authorities are in charge of other cases, though many have not been named yet.
What to do between now and August
Since February 2025, Article 4 has required anyone building or using your systems to have a ‘sufficient level’ of AI literacy. The wording is intentionally vague, and the Omnibus changes ‘ensure’ to ‘support the development of.’ Take real steps and document them.
Article 50’s transparency rule starts on 2 August 2026. Chatbots must label deepfakes and generated content, and synthetic outputs need machine-readable marks. Systems already on the market have until 2 December 2026 to add watermarks. Since the Code of Practice and guidelines are still drafts, follow the law itself for now.
Be honest in your classifications now. December 2027 may seem distant, but it will affect systems being designed this year. The delay gives you more time, but not an exemption.


