The EU AI Act timeline
The AI Act does not switch on all at once. Some of it already binds you; the rest arrives on set dates to 2028. This is the plain-English time-map — what applies, from when, to whom, and what each duty actually requires, with examples. Written for the people who have to act on it.
Regulation (EU) 2024/1689 · current as at 30-06-2026 · Digital Omnibus adopted by the Council 29-06-2026
The short version.
Parts of the AI Act already apply to you — today. The heavier duties arrive in steps through 2028. One recent change, the Digital Omnibus, pushed the biggest deadline back to December 2027 — and, in the same breath, added new bans that land sooner. Below is the whole map, and where it touches your organisation.
What applies, from when, and to whom.
Read it as a calendar of duties. For each date: who it binds, what it requires, and an example you will recognise.
- 2 Feb 2025 Applies todayWhoEvery organisation that uses AI at work — any sector, any size.WhatTwo duties. The banned uses of AI are off-limits. And the AI-literacy duty: the people who use AI on your behalf must understand what it does and where it fails.For exampleYou may not run emotion-recognition on staff, or rank people through “social scoring”. And an HR team using a CV-screening tool must be trained to read its output critically — not treat it as a verdict.
- 2 Aug 2025 Applies todayWhoTwo audiences: the makers of the big AI models — and, through the penalties, you.WhatThe large “foundation” models behind tools like ChatGPT or Claude carry transparency and documentation duties. And the enforcement machinery — including the fines — is switched on.For exampleThe model-maker must publish a summary of its training data. For you, the headline is simpler: the penalty regime is now switched on.
- 2 Dec 2026 Coming — new, via the OmnibusWhoAnyone who builds or uses generative AI — plus a new ban that binds everyone.WhatA new prohibition on AI that creates non-consensual intimate imagery or child sexual abuse material (the “nudifier” apps). And a short window for generative-AI tools already in use to start labelling their AI-generated output.For exampleA tool that fabricates fake nude images of real people is banned outright. And a content-generation tool your team already uses must mark what it produces as AI-made.
- 2 Dec 2027 Coming — the big one for most employersWhoProviders and deployers of “high-risk” AI: recruitment, performance management, access to credit, education and essential services.WhatThe heavy obligations. If you deploy such a system: keep a competent human in control, run a fundamental-rights impact assessment (a documented check of who the system could unfairly affect), keep logs, and use it only as intended. Providers — those who build, brand or substantially change the system — add formal conformity checks (a CE-style sign-off) and registration in an EU database.For exampleIf you use AI to screen, rank or score job candidates, this is the date your governance has to be in place. The catch: the system you deploy today is the one you will have to prove compliant then.
- 2 Aug 2028 ComingWhoMakers of regulated products with AI inside — machinery, medical devices, toys, lifts and the like.WhatThe same high-risk obligations, for AI built into products already regulated under other EU law.For exampleA scanner that uses AI to flag tumours: the maker must meet the high-risk rules before the device can ship.
Two questions decide how hard the high-risk row hits you: is your system actually high-risk, and are you its provider or its deployer? Both are easier to get wrong than you would think — see deployer or provider? and the AI Act, explained.
The Digital Omnibus, in one idea.
You will see the Digital Omnibus referred to above. It is not a new law. It is a bundle of amendments to the AI Act — a set of edits the EU packaged together and adopted (the Council gave its final sign-off on 29 June 2026). Two kinds of edit matter to you.
It pushed some deadlines back.
More time to put the same governance in place — not less governance to build.
And it added new duties.
The same package created obligations that did not exist before: a new ban on AI “nudifier” / CSAM tools from December 2026, and a new labelling window for generative-AI systems already in use. So the Omnibus is not simply relief — it both postpones and expands.
These are obligations, not guidance.
The duties on this page are legal obligations, and they carry fines — set as a share of worldwide annual turnover. The penalty regime has been live since August 2025; each fine bites once the duty it backs is in force.
They run alongside the GDPR (which reaches 4%), not instead of it. But for most employers the sharper cost is commercial — the contract that stalls, the client question you cannot answer — long before any fine lands.
Primary sources: Regulation (EU) 2024/1689, esp. Article 113; the Digital Omnibus (adopted by the Council, 29-06-2026); the European Commission (digital-strategy.ec.europa.eu) and the Council of the EU. Current as at 30-06-2026.
A date on a calendar is not a compliance plan.
Knowing the map is step one. The work is turning it into a plan for your systems — and having the evidence to show for it. Three questions decide what actually lands on you:
Is any of your AI high-risk? Start with the AI Act, explained.
Are you a provider or a deployer? It flips more easily than you think — deployer or provider?
You sit in HR — what does this mean for hiring and people decisions? See AI for HR.
That is exactly what we facilitate: we map your systems against this calendar, tell you what you must do and by when, and help you build the evidence — so the deadline is a plan, not a worry.
Which of these dates already has your name on it?
Bring the AI systems you are weighing up. We’ll tell you, plainly, which dates have your name on them.
Book Kramer Consulting →Related guides
The EU AI Act, explained
Heard of it, hazy on the detail? Grasp it through two laws you may already know — GDPR and product-safety regulation.
Read the guide Provider or deployerDeployer or provider?
Most companies using AI are “deployers”, with manageable duties. But configure, rebrand or repurpose that AI and the Act can treat you as its “provider” — with a manufacturer’s full obligations. The line, and how not to cross it by accident.
Read the guide