AI Act timeline: what actually entered into force in 2026
Within the legal infrastructure of the European Union, the year 2026 represents the pivotal turning point for the regulation of artificial intelligence. Those who wish to review the fundamental architecture of the regulation can consult the article on the EU AI Act explained which sets out the basic framework in detail. In this overview, we focus on the concrete legal reality of 2026: what fully took effect on August 2, 2026, which provisions were shifted due to recent interventions by European lawmakers, and which obligations organizations must comply with immediately to prevent fines and enforcement actions.
The phased rollout of Regulation (EU) 2024/1689 was designed to gradually adapt the market to the new requirements. However, following interventions in the European legislative process in the summer of 2026, the implementation timeline was adjusted in crucial areas. To immediately determine which legal risk category a specific AI system falls under, organizations can consult the EU AI Act category checker to quickly map out applicable obligations. All date and status claims in this analysis were meticulously verified on 2026-08-07.
The official EC timeline: an updated overview
The introduction of the AI Act follows a statutory roadmap that rolls out over a four-year period. According to the updated guidelines from the EC AI Act Service Desk, verified on 2026-08-07, the regulation's official phasing is structured as follows:
- August 01, 2024 — Entry into force: The regulation officially entered into force twenty days after publication in the Official Journal of the European Union. This marked the start of the statutory transition periods.
- February 02, 2025 — General provisions and prohibited AI practices: The general definitions from Chapter I and the absolute prohibitions on unacceptable AI risks under Article 5 (such as social credit scoring, subliminal manipulation, and untargeted scraping of facial images) became directly applicable. Enforcement regarding these prohibitions commenced on the same date.
- August 02, 2025 — GPAI rules and governance structure: The rules for General-Purpose AI (GPAI) models, the obligations for model providers presenting systemic risks, the establishment of the European AI Office, and the appointment of the Scientific Panel of independent experts became operational.
- 02 August 2026 — Main body of the Regulation and launch of general enforcement: The general application of the AI Act entered into force. This includes mandatory AI literacy for organizations (Article 4), expanded transparency obligations (Article 50), and the formalization of national supervisory and enforcement powers.
- 02 December 2026 — New prohibitions and watermarking transition period: Entry into force of the ninth prohibition under Article 5 (targeting AI systems for non-consensual intimate imagery and CSAM), as well as the expiration of the specific transition period for watermark integration under Article 50(2).
- 02 August 2027 — Mandatory regulatory sandboxes across Member States: Every EU Member State must have at least one operational national regulatory sandbox by this date to support innovation in trustworthy AI.
- 02 December 2027 — Application to Annex III high-risk systems: Entry into force of the stringent conformity and quality requirements for stand-alone high-risk AI systems (such as AI in recruitment and selection, credit scoring, administration of justice, and biometrics), as postponed via the Digital Omnibus.
- 02 August 2028 — Application to Annex I products: Application of obligations to AI systems serving as safety components in already regulated physical products (such as medical devices, aviation, lifts, and machinery).
What changed since the original timeline
The original 2024 roadmap assumed that all obligations regarding high-risk AI systems under Annex III would take effect exactly 24 months after entry into force — on 2 August 2026. However, preparatory phases during the first half of 2026 revealed that both the market and European standardisation bodies needed more time. The lack of fully finalized harmonized European standards (CEN/CENELEC) threatened to cause legal uncertainty and deadlocks in conformity assessments.
To prevent a regulatory vacuum, European legislators intervened during the 2026 summer recess with targeted legislation. This created a clear distinction between what actually became mandatory as of August 2026 and what has been deferred to subsequent years. All amendments relative to the original Regulation were formally finalized and enacted on 2026-08-07.
The Digital Omnibus on AI and revised deadlines
The primary legislative correction in 2026 was achieved through the adoption of the Digital Omnibus on AI (Regulation (EU) 2026/1744). This legislative act was formally adopted by the Council and the European Parliament on 8 July 2026, published in the Official Journal of the EU on 24 July 2026, and entered into force on 27 July 2026 — just in time to adjust the 2 August 2026 deadline.
The Digital Omnibus has postponed the effective date for high-risk AI systems under Annex III by sixteen months, moving it from 2 August 2026 to 2 December 2027. For AI systems embedded in safety products under Annex I, the deadline has been set for 2 August 2028. This shift provides manufacturers, developers, and notified bodies with the necessary breathing room to carefully set up audits and CE marking procedures based on harmonised standards.
What DID come into force on 2 August 2026
It is a widespread misconception that the Digital Omnibus has delayed the AI Act in its entirety. On 2 August 2026, the bulk of the general regulation took effect in full force. Organisations developing, importing, or deploying AI systems within the EU must comply with a range of mandatory legal obligations from this date forward.
First and foremost, the transparency requirements under Article 50 of the AI Act are now fully enforceable. This entails that organisations are required to make it clear to natural persons when they are interacting with an AI system (such as automated customer service chatbots). Additionally, synthetic audio, video, text, and image files generated or manipulated by AI must be equipped with machine-readable watermarks and technical metadata indicating their AI origin.
Secondly, Article 4 of the AI Act has been activated. This article obliges providers and deployers of AI systems to ensure an adequate level of AI literacy among their staff and other persons dealing with the operation of AI systems on their behalf. Employers must demonstrate that their employees possess the necessary knowledge to understand the functioning, risks, and societal impact of the AI applications they use.
Thirdly, on 2 August 2026, the complete enforcement framework for General-Purpose AI (GPAI) models became operational. The European AI Office is now actively overseeing compliance with documentation requirements, copyright transparency, and systemic risk management. To compare European requirements with regulatory frameworks in other global markets, you can consult the background article on AI legislation outside the EU for an international perspective.
New prohibitions and transitional rules for deepfakes
In addition to granting extensions for high-risk classifications, the Digital Omnibus also introduced supplementary enforcement mechanisms. A new legal prohibition has been added to Article 5 of the AI Act, specifically targeting the generation, dissemination, or facilitation of non-consensual intimate imagery (including so-called 'nudification' tools) and child sexual abuse material (CSAM).
This ninth prohibited practice formally takes effect on 2 December 2026. From that date onward, national supervisory authorities will have the power to take immediate action through periodic penalty payments and the takedown of infrastructures that make such software available within the European market.
Regarding transitional arrangements, pursuant to Article 50(2), existing generative systems are granted until 2 December 2026 to fully integrate advanced technical detectability and indelible watermarking into their software architecture. As of 2 December 2026, this grace period expires, and unencoded generative models may no longer be offered on the European market.
What this means for organizations: practical implications
For businesses, public sector bodies, and civil society organizations, the situation as of August 2026 demands immediate action, regardless of the postponement for high-risk systems. Organizations cannot afford to wait until 2027 to set up their AI governance.
The practical implications that apply immediately (verified on 2026-08-07) are:
- Mandatory AI inventory and audit: Organizations must map out precisely which AI systems are in use, which data sources are utilized, and whether any generative AI components fall under the transparency obligations.
- Establishing AI literacy programs: Employers must facilitate training for personnel working with AI. This encompasses not only technical training, but also awareness regarding ethics, data protection, and the limitations of automated decision-making.
- Adapting customer interfaces and disclosures: Every application in which an end user interacts with an AI system must feature clear and comprehensible notifications. When publishing AI-generated content, its origin must be explicitly disclosed.
- Application of the transitional rule of Article 113(2): For AI systems already placed on the market or put into service before 2 August 2026, the rules of the AI Act will only become applicable if a significant change is made to the system's design, intended purpose, or functionality after 2 August 2026. Merely performing maintenance or minor bug fixes does not qualify as a significant change, whereas restructuring the algorithm or modifying the training data does.
- Preparing for the 2027/2028 milestones: Providers of potential high-risk systems (such as AI used in recruitment and personnel selection, access to financial services, or critical infrastructure) must utilize the additional time to build their Quality Management System (QMS) and risk management processes.
The Dutch context and the AI Regulation Implementation Act (Uitvoeringswet AI-verordening)
In the Netherlands, the European regulation is being further anchored through the national AI Regulation Implementation Act (Uitvoeringswet AI-verordening). Its preparation is in a decisive phase. Between 20 April 2026 and 1 June 2026, the Ministry of Economic Affairs and Climate Policy submitted the draft implementation act for public online consultation.
The consultation documents indicate that the Dutch Cabinet has opted for a decentralized, hybrid supervisory model. Rather than establishing a single new, central AI authority, supervisory duties will be distributed across ten existing market surveillance authorities. These include, among others, the Dutch Authority for the Financial Markets (AFM), De Nederlandsche Bank (DNB), the Netherlands Food and Consumer Product Safety Authority (NVWA), the Dutch Healthcare Authority (NZa), the Health and Youth Care Inspectorate (IGJ), and the Netherlands Labour Authority (Nederlandse Arbeidsinspectie).
Within this structure, two authorities play a central, coordinating role:
- Dutch Data Protection Authority (AP): The AP acts as the coordinating supervisory authority for the protection of fundamental rights, algorithms, and the processing of personal data within AI systems. The AP also houses the Algorithm Supervision Directorate.
- Dutch Authority for Digital Infrastructure (RDI): The RDI has been designated as the statutory Single Point of Contact (SPOC) for the European Commission and other EU Member States. In addition, the RDI is responsible for the market surveillance role regarding general product safety, GPAI models, and technical conformity.
As of the reference date of 7 August 2026, the AI Regulation Implementation Act has not yet been definitively adopted by the House of Representatives and the Senate; following the processing of the consultation responses, the bill is currently in the phase of editorial revision and advisory review by the Council of State. For a comprehensive overview of the division of powers and roles among the various supervisory authorities, see the dossier on AI supervision in the Netherlands in which the ten supervisory authorities are covered individually.
Standardization and technical standards: EN 18286
An essential pillar underpinning the implementation of the AI Act is the development of harmonized European standards by CEN/CENELEC, the European standardization organizations. These standards provide concrete technical specifications that systems must meet to benefit from the legal 'presumption of conformity'.
On 22 July 2026, CEN/CENELEC reached a major milestone with the official publication of the harmonized standard EN 18286 (Quality Management System for AI applications). This standard specifies the requirements for establishing, implementing, and maintaining a quality management system for AI development and AI applications.
EN 18286 serves as a practical framework aligned with existing ISO/IEC standards (such as ISO/IEC 42001), but contains specific additions that directly operationalize the requirements of the European AI Act regarding risk management, data governance, transparency, and human oversight. Although the statutory obligations for high-risk systems have been postponed to 2027, the use of EN 18286 is strongly recommended by the EC AI Act Service Desk as the best practice for organizations looking to bring their governance in order immediately.
For further depth on the interplay between European harmonized standards and international standards, see the overview of AI standards and standardization in which the relevant ISO and CEN frameworks are thoroughly analyzed.
Conclusion and strategic outlook
The status of the EU AI Act as of August 2026 presents a twofold picture. On the one hand, the European legislator has demonstrated pragmatism by postponing the most stringent certification requirements for high-risk systems to December 2027 and August 2028 via the Digital Omnibus. This prevents market disruption and allows organizations time to prepare thoroughly using mature standards such as EN 18286.
On the other hand, the enforcement era has definitely arrived. Since 2 August 2026, the obligations regarding AI literacy, transparency in generative content, and oversight of general-purpose AI models have taken effect. With the upcoming expansions in December 2026 and the final adoption of the Dutch Implementation Act (Uitvoeringswet), organizations must formally establish their AI governance now. Compliance with the AI Act is no longer a future prospect, but a daily operational reality.


