The EU AI Act timeline after the omnibus
The dates changed on 27 July 2026. The high-risk duties moved out to 2027 and 2028, and they still arrive.
The Annex III and Annex I high-risk obligations moved to later dates, and the duties already in force stayed live.
Regulation (EU) 2026/1744, the Digital Omnibus on AI entered into force on 27 July 2026 and amended Regulation (EU) 2024/1689, so any timetable written before then is out of date.
For a UK organisation with EU exposure the timetable reads in two bands. Article 4, Article 5, Article 50 and Chapter V are in force now. The high-risk obligations deferred under Regulation (EU) 2026/1744 keep their categories, so it's still worth working out which of your systems sit on that track. If scope or role is unsettled, start with the EU AI Act overview.
- 2 February 2025Prohibited practices and AI literacyArticles 5 and 4in force
- 2 August 2025General-purpose AI model obligationsChapter Vin force
- 2 August 2026Transparency obligationsArticle 50in force
- 2 December 2027Annex III stand-alone high-risk obligationsRegulation (EU) 2026/1744deferred
- 2 August 2028Annex I product-embedded high-risk obligationsRegulation (EU) 2026/1744deferred
What has applied since February 2025?
Two parts of the Act have applied since 2 February 2025. Article 5 prohibits the specified AI practices, which include manipulative or deceptive techniques causing significant harm, exploitation of listed vulnerabilities, defined forms of social scoring, predictive policing based solely on profiling, untargeted scraping of facial images, and certain biometric or emotion-related uses. The list is specific, so test your own use case against it before you treat a higher-risk use as prohibited.
Article 4 applies from the same date and requires providers and deployers to make sure the staff dealing with AI have a sufficient level of AI literacy. The high-risk deferral doesn't touch it. The AI literacy guide covers what it asks of you.
What changed in August 2025 and August 2026?
General-purpose AI model obligations under Chapter V have applied since 2 August 2025, and which of them are yours depends on the role you hold: the Act separates providers from deployers and also names importers, distributors and product manufacturers, with one company able to hold more than one (Article 3).
Transparency obligations under Article 50 have applied since 2 August 2026. They cover notice when a person interacts with an AI system unless that interaction is obvious, machine-readable marking by providers of systems generating synthetic content, information for people exposed to emotion recognition or biometric categorisation, and disclosure of deepfakes. The Article 50 transparency guide works through what each of those asks for.
What moves to December 2027?
Annex III stand-alone high-risk obligations are deferred to 2 December 2027 under Regulation (EU) 2026/1744. The areas listed in Regulation (EU) 2024/1689 are biometrics, critical infrastructure, education and vocational training, employment and worker management, access to essential private and public services, law enforcement, migration and border control, and the administration of justice and democratic processes.
Employment systems are usually the ones a UK organisation recognises first, since the list expressly covers recruitment, screening, promotion, termination, task allocation and monitoring, and the essential-service entries include creditworthiness, insurance risk assessment and pricing, emergency dispatch and benefits. The date is later, so make the category test now and know which of your systems sit on the deferred track. The high-risk and Annex III guide covers the classification and the EU AI Act conformity assessment what it leads to.
What moves to August 2028?
Annex I product-embedded high-risk obligations are deferred to 2 August 2028 under Regulation (EU) 2026/1744. This band concerns AI used as a safety component of products subject to EU harmonisation law, including machinery, medical devices, toys, lifts, radio equipment and in-vitro diagnostics.
The line between Annex I and Annex III matters because their dates differ, so check why a software system used for a listed stand-alone function belongs on the product-embedded timetable before you put it there. Scope and role settle that first, and the guide on whether the Act applies to a UK organisation covers them (Articles 2 and 3). You can download this timeline as a one-page PDF to keep alongside your systems list.