Skip to content
NLEN
Illustration: AI Act timeline: what took effect in 2026

AI Act timeline: what actually entered into force in 2026

By Ivo Donker — compiled with AI assistance (Claude & Gemini)

Within the legal infrastructure of the European Union, the year 2026 represents the pivotal turning point for the regulation of artificial intelligence. Those who wish to review the fundamental architecture of the regulation can consult the article on the EU AI Act explained which sets out the basic framework in detail. In this overview, we focus on the concrete legal reality of 2026: what fully took effect on August 2, 2026, which provisions were shifted due to recent interventions by European lawmakers, and which obligations organizations must comply with immediately to prevent fines and enforcement actions.

The phased rollout of Regulation (EU) 2024/1689 was designed to gradually adapt the market to the new requirements. However, following interventions in the European legislative process in the summer of 2026, the implementation timeline was adjusted in crucial areas. To immediately determine which legal risk category a specific AI system falls under, organizations can consult the EU AI Act category checker to quickly map out applicable obligations. All date and status claims in this analysis were meticulously verified on 2026-08-07.

Verification date and status: All legal milestones, statutory articles, and supervisory frameworks in this article were verified on 2026-08-07 against the Official Journal of the European Union, official reports from the EC AI Act Service Desk, and consultation documents from the Dutch Central Government.

The official EC timeline: an updated overview

The introduction of the AI Act follows a statutory roadmap that rolls out over a four-year period. According to the updated guidelines from the EC AI Act Service Desk, verified on 2026-08-07, the regulation's official phasing is structured as follows:

What changed since the original timeline

The original 2024 roadmap assumed that all obligations regarding high-risk AI systems under Annex III would take effect exactly 24 months after entry into force — on 2 August 2026. However, preparatory phases during the first half of 2026 revealed that both the market and European standardisation bodies needed more time. The lack of fully finalized harmonized European standards (CEN/CENELEC) threatened to cause legal uncertainty and deadlocks in conformity assessments.

To prevent a regulatory vacuum, European legislators intervened during the 2026 summer recess with targeted legislation. This created a clear distinction between what actually became mandatory as of August 2026 and what has been deferred to subsequent years. All amendments relative to the original Regulation were formally finalized and enacted on 2026-08-07.

The Digital Omnibus on AI and revised deadlines

The primary legislative correction in 2026 was achieved through the adoption of the Digital Omnibus on AI (Regulation (EU) 2026/1744). This legislative act was formally adopted by the Council and the European Parliament on 8 July 2026, published in the Official Journal of the EU on 24 July 2026, and entered into force on 27 July 2026 — just in time to adjust the 2 August 2026 deadline.

The Digital Omnibus has postponed the effective date for high-risk AI systems under Annex III by sixteen months, moving it from 2 August 2026 to 2 December 2027. For AI systems embedded in safety products under Annex I, the deadline has been set for 2 August 2028. This shift provides manufacturers, developers, and notified bodies with the necessary breathing room to carefully set up audits and CE marking procedures based on harmonised standards.

What DID come into force on 2 August 2026

It is a widespread misconception that the Digital Omnibus has delayed the AI Act in its entirety. On 2 August 2026, the bulk of the general regulation took effect in full force. Organisations developing, importing, or deploying AI systems within the EU must comply with a range of mandatory legal obligations from this date forward.

First and foremost, the transparency requirements under Article 50 of the AI Act are now fully enforceable. This entails that organisations are required to make it clear to natural persons when they are interacting with an AI system (such as automated customer service chatbots). Additionally, synthetic audio, video, text, and image files generated or manipulated by AI must be equipped with machine-readable watermarks and technical metadata indicating their AI origin.

Secondly, Article 4 of the AI Act has been activated. This article obliges providers and deployers of AI systems to ensure an adequate level of AI literacy among their staff and other persons dealing with the operation of AI systems on their behalf. Employers must demonstrate that their employees possess the necessary knowledge to understand the functioning, risks, and societal impact of the AI applications they use.

Thirdly, on 2 August 2026, the complete enforcement framework for General-Purpose AI (GPAI) models became operational. The European AI Office is now actively overseeing compliance with documentation requirements, copyright transparency, and systemic risk management. To compare European requirements with regulatory frameworks in other global markets, you can consult the background article on AI legislation outside the EU for an international perspective.

New prohibitions and transitional rules for deepfakes

In addition to granting extensions for high-risk classifications, the Digital Omnibus also introduced supplementary enforcement mechanisms. A new legal prohibition has been added to Article 5 of the AI Act, specifically targeting the generation, dissemination, or facilitation of non-consensual intimate imagery (including so-called 'nudification' tools) and child sexual abuse material (CSAM).

This ninth prohibited practice formally takes effect on 2 December 2026. From that date onward, national supervisory authorities will have the power to take immediate action through periodic penalty payments and the takedown of infrastructures that make such software available within the European market.

Regarding transitional arrangements, pursuant to Article 50(2), existing generative systems are granted until 2 December 2026 to fully integrate advanced technical detectability and indelible watermarking into their software architecture. As of 2 December 2026, this grace period expires, and unencoded generative models may no longer be offered on the European market.

What this means for organizations: practical implications

For businesses, public sector bodies, and civil society organizations, the situation as of August 2026 demands immediate action, regardless of the postponement for high-risk systems. Organizations cannot afford to wait until 2027 to set up their AI governance.

The practical implications that apply immediately (verified on 2026-08-07) are:

The Dutch context and the AI Regulation Implementation Act (Uitvoeringswet AI-verordening)

In the Netherlands, the European regulation is being further anchored through the national AI Regulation Implementation Act (Uitvoeringswet AI-verordening). Its preparation is in a decisive phase. Between 20 April 2026 and 1 June 2026, the Ministry of Economic Affairs and Climate Policy submitted the draft implementation act for public online consultation.

The consultation documents indicate that the Dutch Cabinet has opted for a decentralized, hybrid supervisory model. Rather than establishing a single new, central AI authority, supervisory duties will be distributed across ten existing market surveillance authorities. These include, among others, the Dutch Authority for the Financial Markets (AFM), De Nederlandsche Bank (DNB), the Netherlands Food and Consumer Product Safety Authority (NVWA), the Dutch Healthcare Authority (NZa), the Health and Youth Care Inspectorate (IGJ), and the Netherlands Labour Authority (Nederlandse Arbeidsinspectie).

Within this structure, two authorities play a central, coordinating role:

As of the reference date of 7 August 2026, the AI Regulation Implementation Act has not yet been definitively adopted by the House of Representatives and the Senate; following the processing of the consultation responses, the bill is currently in the phase of editorial revision and advisory review by the Council of State. For a comprehensive overview of the division of powers and roles among the various supervisory authorities, see the dossier on AI supervision in the Netherlands in which the ten supervisory authorities are covered individually.

Standardization and technical standards: EN 18286

An essential pillar underpinning the implementation of the AI Act is the development of harmonized European standards by CEN/CENELEC, the European standardization organizations. These standards provide concrete technical specifications that systems must meet to benefit from the legal 'presumption of conformity'.

On 22 July 2026, CEN/CENELEC reached a major milestone with the official publication of the harmonized standard EN 18286 (Quality Management System for AI applications). This standard specifies the requirements for establishing, implementing, and maintaining a quality management system for AI development and AI applications.

EN 18286 serves as a practical framework aligned with existing ISO/IEC standards (such as ISO/IEC 42001), but contains specific additions that directly operationalize the requirements of the European AI Act regarding risk management, data governance, transparency, and human oversight. Although the statutory obligations for high-risk systems have been postponed to 2027, the use of EN 18286 is strongly recommended by the EC AI Act Service Desk as the best practice for organizations looking to bring their governance in order immediately.

For further depth on the interplay between European harmonized standards and international standards, see the overview of AI standards and standardization in which the relevant ISO and CEN frameworks are thoroughly analyzed.

Conclusion and strategic outlook

The status of the EU AI Act as of August 2026 presents a twofold picture. On the one hand, the European legislator has demonstrated pragmatism by postponing the most stringent certification requirements for high-risk systems to December 2027 and August 2028 via the Digital Omnibus. This prevents market disruption and allows organizations time to prepare thoroughly using mature standards such as EN 18286.

On the other hand, the enforcement era has definitely arrived. Since 2 August 2026, the obligations regarding AI literacy, transparency in generative content, and oversight of general-purpose AI models have taken effect. With the upcoming expansions in December 2026 and the final adoption of the Dutch Implementation Act (Uitvoeringswet), organizations must formally establish their AI governance now. Compliance with the AI Act is no longer a future prospect, but a daily operational reality.