This article accompanies Hour 3: EU AI Act Scope, Obligations & Governance in our full-day CPD programme on XpertAcademy. Completion of the full one-hour session, including the related learning materials, contributes to the one-hour CPD certificate issued for that session. Access CPD Event B: Full-Day AI, Technical Privacy & Emerging Technology Training.

The EU AI Act is often described through a single date: 2 August 2026. That is no longer a useful way to manage it.

Some duties have applied since February or August 2025. Transparency obligations began applying in August 2026. New prohibitions arrive in December 2026. The principal high-risk requirements have been moved to December 2027 and August 2028 by the AI Omnibus, which entered into force on 27 July 2026.

For DPOs, privacy operations teams, compliance leaders and accountable system owners, the practical question is not whether the AI Act is "in force". It is which rule applies to which system, in which organisational role, from which date, and what evidence should exist now.

This guide sets out the current timetable following Regulation (EU) 2026/1744, the AI Omnibus.

The timetable at a glance

Date What applies Practical significance
1 August 2024 AI Act entered into force The staged application timetable began.
2 February 2025 Chapters I and II, including scope, definitions, original prohibited practices and AI literacy Prohibited-practice screening and proportionate AI-literacy measures are already required.
2 August 2025 Governance provisions and obligations for providers of GPAI models placed on the market from this date GPAI providers need technical documentation, downstream information, copyright compliance measures and training-content summaries, with additional duties for systemic-risk models.
2 August 2026 General application date; Article 50 transparency duties; Commission GPAI enforcement powers; wider penalty and enforcement framework This is a major live deadline, but not the date on which every high-risk duty begins.
2 December 2026 New Omnibus-added prohibited practices; limited Article 50(2) transition ends for relevant systems placed on the market before 2 August 2026 Organisations must screen the additional prohibited uses and confirm whether the narrow synthetic-content marking transition applies.
2 August 2027 Pre-2 August 2025 GPAI models reach their compliance deadline Providers of older GPAI models must complete the relevant provider obligations.
2 December 2027 High-risk requirements for Article 6(2) and Annex III systems Relevant recruitment, employment, education, essential-services and other listed use cases move into the full high-risk regime.
2 August 2028 High-risk requirements for Article 6(1) and Annex I product-related systems High-risk AI used as a safety component, or itself a product, under listed product-safety legislation enters the regime.
2 August 2030 Transition for certain high-risk systems used by public authorities Relevant public-authority systems must meet the conditions in the Act by this long-stop date.

The dates do not remove the need to read the scope and transition provisions for a particular system. They are a planning map, not a substitute for classification.

What has applied since February 2025?

The AI Act's scope and definitions, the original prohibited practices and Article 4 AI-literacy obligation have applied since 2 February 2025.

Prohibited practices include defined forms of manipulative or deceptive AI, exploitation of vulnerability, social scoring, certain predictive-policing uses, untargeted scraping to build facial-recognition databases, certain emotion recognition in workplaces and education, sensitive biometric categorisation and some real-time remote biometric identification in public spaces.

Each prohibition has specific elements and exceptions. A short label is not enough for classification. Organisations should record the use case, affected people, data, system behaviour and purpose, then explain why a prohibition does or does not apply.

AI literacy also remains an obligation after the Omnibus amendments. Providers and deployers must take measures to support the development of AI literacy among staff and others operating or using AI systems on their behalf, taking account of their knowledge, experience, education, training and the context of use. The revised Article 4 does not require the organisation to guarantee a particular level for every individual.

The Omnibus simplified AI literacy; it did not make organisational inaction compliant.

Practical measures can include general awareness, system-specific guidance, training for decision-makers and human overseers, acceptable-use rules, escalation routes and supplier-supported instruction. There is no mandatory certificate or one-size-fits-all course. Keep a proportionate record of what was provided, to whom and why it matched the use and risk.

What has applied to general-purpose AI since August 2025?

Obligations for providers of general-purpose AI (GPAI) models began applying on 2 August 2025 for models placed on the market from that date. These include maintaining technical documentation, providing information to downstream providers, putting in place a policy to comply with EU copyright law and publishing a sufficiently detailed summary of training content.

Providers of GPAI models with systemic risk have additional evaluation, risk-assessment, incident-reporting and cybersecurity duties.

From 2 August 2026, the Commission can enforce these GPAI obligations, including through fines. Providers of models placed on the market before 2 August 2025 have until 2 August 2027 to comply.

Most organisations using an external model will be deployers rather than GPAI-model providers. However, fine-tuning, repackaging, integrating or placing a model or system on the market can affect role allocation. The answer should be established per product and use case, using contractual and technical facts. See our guide to AI Act provider and deployer obligations.

What changed on 2 August 2026?

The Act's general application date brought a large part of the remaining framework into use, including Article 50 transparency obligations and wider national supervision and penalties. It also activated the Commission's enforcement powers for GPAI-provider obligations. Our European privacy and AI governance map explains which EU and national bodies perform the different coordination, advisory and enforcement roles.

Article 50 is especially relevant to ordinary organisational use. Depending on role and system, it requires:

  • providers to design relevant interactive systems so people are informed that they are interacting with AI;
  • providers of systems generating synthetic audio, image, video or text to support machine-readable marking and detection;
  • deployers of emotion-recognition or biometric-categorisation systems to inform exposed individuals;
  • deployers to disclose deepfake audio, image or video; and
  • deployers to disclose certain AI-generated or manipulated text published to inform the public on matters of public interest, unless it has undergone human review or editorial control and responsibility is held for publication.

The rules contain exceptions and detailed conditions. Organisations should use the Commission's Article 50 guidelines to test each use, rather than applying a generic "made with AI" notice everywhere.

There is one narrow transition: providers of relevant synthetic-content-generating systems placed on the market before 2 August 2026 have until 2 December 2026 to comply with Article 50(2) marking and detection. That does not postpone the rest of Article 50. Content generated before 2 August 2026 does not need to be labelled retroactively.

What arrives on 2 December 2026?

The Omnibus added prohibited practices addressing AI systems that generate certain non-consensual intimate or sexually explicit material and child sexual abuse material. Those additions apply from 2 December 2026.

This date also ends the limited Article 50(2) transition described above. Providers relying on it should identify the affected systems, confirm the original market date and retain an implementation plan. Deployers should obtain supplier confirmation rather than assuming a system is technically compliant.

The new prohibitions require careful reading, including definitions and exceptions. Organisations hosting, procuring or enabling generative image, video, audio or text capabilities should update prohibited-use policies, monitoring, reporting and escalation before December.

What moved to December 2027?

The full high-risk requirements for systems classified under Article 6(2) and Annex III now apply from 2 December 2027. Annex III includes defined uses in areas such as biometrics, critical infrastructure, education, employment, access to essential services, law enforcement, migration and the administration of justice or democratic processes.

Being used in one of those sectors does not automatically make every AI tool high risk. The intended purpose, decision context, effect and exemptions must be assessed. Providers and deployers also have different obligations.

For relevant providers, preparation may include risk management, data and data-governance controls, technical documentation, logging, transparency to deployers, human-oversight design, accuracy, robustness, cybersecurity, quality management, registration, conformity assessment and post-market monitoring.

Deployers may need to follow instructions, assign competent human oversight, monitor operation, preserve logs, complete a fundamental-rights impact assessment in specified cases, carry out a DPIA where required, provide notices and cooperate with authorities.

A later compliance date is useful implementation time. It is not evidence that the system is low risk today.

Our guide to AI governance registers and technical documentation sets out the evidence that takes time to build, including human-oversight, escalation and decision records.

What moved to August 2028?

High-risk requirements for Article 6(1) and Annex I systems apply from 2 August 2028. These are AI systems used as safety components of products, or which are themselves products, covered by specified EU product-safety legislation and requiring third-party conformity assessment.

Examples can arise in machinery, medical devices, toys, lifts and other regulated products, but the legislation and conformity route must be checked. These systems need coordinated ownership across product, engineering, quality, safety, legal, cybersecurity, privacy and market-access functions. Treating the AI Act as a DPO-only programme would be particularly ineffective here.

The extended date reflects the need for standards, guidance and conformity infrastructure. Product organisations should use the time to integrate AI requirements into existing quality and product-safety systems rather than create a disconnected compliance layer in 2028.

What should organisations do now?

The practical programme can be organised into ten actions.

  1. Build a usable AI inventory. Record the system, model, version, supplier, purpose, business owner, users, affected people, data, integrations, jurisdictions and current status.
  2. Map the organisation's role. Determine whether it is acting as provider, deployer, importer, distributor, product manufacturer or GPAI-model provider for each use case.
  3. Screen prohibited practices. Recheck existing systems now and include the December 2026 additions in procurement, acceptable-use and escalation controls.
  4. Maintain proportionate AI literacy. Tailor awareness, guidance and training to the people, systems, decisions and risks involved; retain simple evidence.
  5. Complete an Article 50 review. Examine chatbots, assistants, synthetic media, public-interest content, emotion recognition and biometric categorisation, including supplier capabilities.
  6. Identify potential high-risk systems early. Record the classification rationale, likely date, provider/deployer split and the evidence gap. Do not wait for 2027 or 2028 to discover that logs or data provenance were never retained.
  7. Connect assessments. Align AI assessment, DPIA, fundamental-rights assessment, security review and sectoral assurance while preserving each legal test. See our comparison of AI impact assessments, DPIAs and FRIAs.
  8. Strengthen supplier evidence. Obtain role allocation, model and system documentation, training-data or copyright information where relevant, Article 50 support, logs, incident duties, change notices and subprocessor details.
  9. Set monitoring and incident ownership. Define who receives model or feature changes, who monitors outputs and drift, and who decides on suspension, notification or corrective action.
  10. Report a dated implementation position. Senior management should see systems by category, live duties, upcoming deadlines, material gaps, accountable owners and decisions needed.

The inventory is the connecting control. Without it, legal analysis remains generic, training cannot be targeted, supplier evidence cannot be matched to use and management reporting becomes a collection of percentages with no reliable denominator.

Three weak approaches should be avoided as the programme develops.

The first is treating the high-risk delay as permission to wait. GDPR, equality, employment, consumer, safety, contractual and sectoral duties continue, while several AI Act requirements already apply.

The second is giving every AI system the same governance package. Proportionate governance depends on role, use, people affected, data, autonomy and consequence. A low-impact drafting assistant and an employment-screening system should not be managed identically.

The third is documenting a classification without preserving its factual basis. Supplier features, models, intended purposes and organisational use change. Classification needs versioning and review triggers.

The XpertDPO view

The amended timetable is more workable, but it has not made the AI Act simple. It has made sequencing more important.

Organisations should deal first with live obligations and the controls that support everything else: inventory, role mapping, prohibited-practice screening, AI literacy, transparency, supplier evidence and clear ownership. Potential high-risk systems should then move through a planned evidence programme aligned to the appropriate 2027 or 2028 date.

Privacy teams have a central contribution because personal data, transparency, rights, impact assessment and accountability run through many AI uses. They should not be left to own product safety, technical conformity or enterprise AI risk alone.

XpertDPO's AI governance and DPIA lifecycle support helps organisations classify use cases, connect assessments, challenge supplier evidence and build a practical implementation record that senior teams can review.

The objective is not a perfect AI policy. It is being able to show which systems exist, which rules apply, who is responsible, what evidence supports the position and what must happen before the next date arrives.

What This Means for CPD

For Event B Hour 3, learners should be able to identify the organisation's AI Act role, distinguish duties that already apply from later high-risk requirements, and turn the staged timetable into a dated implementation plan. The practical output is a position supported by system, role, risk, evidence, owner and review-date records.

This article is intended to support the learning covered in Hour 3 of our XpertAcademy CPD programme. The relevant CPD certificate is issued for completion of the full one-hour session on XpertAcademy, rather than for reading this article on its own. Return to CPD Event B: Full-Day AI, Technical Privacy & Emerging Technology Training.

Sources