EU AI Act: deadlines and review topics at a glance
Which application dates matter and why concrete triggers, market roles and legal bases need to be assessed separately.
5 min read
Published 17 July 2026 / Updated 18 July 2026
Regulation (EU) 2024/1689 becomes applicable in stages. Three types of date need to be distinguished: its entry into force, the application of individual provisions and later transitional deadlines for specific systems or market roles.
The Digital Omnibus PE-CONS 30/26 has been signed. As at the reviewed legal status of 18 July 2026, it has not yet been published in the Official Journal and is therefore not in force.
The amendments it envisages are explicitly distinguished below from the law currently in force.
Relevant application and transition dates
2 February 2025: prohibitions and AI literacy. Chapters I and II of the original AI Act have applied since this date.
Article 4 requires providers and deployers to take measures for a sufficient level of AI literacy. The obligation does not arise for importers or distributors solely from those market roles.
Each prohibition in Article 5 has its own conditions and, in some cases, exceptions. A broad industry classification is therefore insufficient.
2 August 2025: GPAI provider obligations and governance. Chapter V, which sets out duties for providers of general-purpose AI models, has generally applied since this date.
Separate transition rules apply to models placed on the market earlier and to other situations. Merely using a third-party GPAI model does not automatically make an organisation a GPAI provider.
2 August 2026: general application and Article 50. Under the original text, which remains binding, most of the Regulation applies from this date, including Article 50.
Article 50 distinguishes duties for providers and deployers. These concern human-AI interaction, machine-readable marking, emotion recognition, biometric categorisation, deepfakes and specified public-interest text.
2 December 2026: envisaged new prohibitions and transition rules. The signed Digital Omnibus adds provisions concerning non-consensual intimate synthetic content and synthetic representations of child sexual abuse.
It also provides a transition rule for certain existing systems that detect and mark synthetic content. These amendments are not yet in force at the reviewed legal status.
2 December 2027: envisaged application date for Annex III. The signed Digital Omnibus provides this date for requirements applying to systems under Article 6(2) together with Annex III.
Until publication in the Official Journal, the original AI Act remains binding.
2 August 2028: envisaged application date for Annex I. The signed Digital Omnibus provides this date for systems under Article 6(1) together with Annex I.
Such a trigger requires the AI system to be a covered product or its safety component and the relevant sectoral law to require third-party conformity assessment.
Machinery and other product sectors need to be assessed separately under the sectoral rules applicable at the relevant time.
Why concrete triggers and market roles matter
Requirements cannot be derived from an industry label or broad risk category alone. Scope, the AI-system definition, the specific activity and the market role need to be assessed first.
An organisation may hold several roles at once, including provider, deployer, importer, distributor or product manufacturer. Different obligations and potentially a role change under Article 25 follow from that assessment.
The technical assessment cannot be reduced to a distinction between learning and rule-based systems.
Logic-based, knowledge-based, search, optimisation and expert-system methods may also be covered. Basic data processing under fully specified human rules may be assessed differently.
The concrete system must still be examined in every case.
Assess Annex I, Annex III and the Article 6(3) exception separately
Article 6(3) concerns only systems potentially covered by Article 6(2) together with Annex III. The exception does not apply to a trigger under Article 6(1) and Annex I.
For an Annex III case, the exception can be considered only if the system does not pose a significant risk to health, safety or fundamental rights and at least one statutory ground is met.
The exception does not apply if the system materially influences a decision or performs profiling of natural persons.
Providers must document the assessment before placing the system on the market or putting it into service. Registration requirements may also continue to apply.
Technical trigger screener
Our EU AI Act risk checker considers multiple possible market roles, concrete Annex I and III triggers, Article 50 content types and the relationship to GPAI models.
The result identifies potential triggers, relevant legal bases, unresolved questions and the requirements and dates that need further review.
The technical assessment provides initial orientation and is non-binding. It does not replace legal advice, a legally binding classification or a conformity assessment.
A result of “no specific trigger identified” is not evidence of compliance.
Sources and reviewed legal status
Legal status and latest internal source review: 18 July 2026.
- Regulation (EU) 2024/1689, binding Official Journal text
- Digital Omnibus PE-CONS 30/26, signed text, not yet in force
- Procedure status 2025/0359(COD), publication status
- Commission guidelines on the AI-system definition, non-binding interpretive aid
- Commission guidelines on prohibited practices, non-binding interpretive aid
- Commission guidelines for GPAI providers, non-binding interpretive aid
- Commission guidelines on high-risk systems, preliminary draft and non-binding
Conclusion
Sound preparation begins by assessing concrete triggers, market roles and technical evidence. The relevant legal bases and application dates can then be derived from that assessment.
Until publication in the Official Journal, the Digital Omnibus remains a signed text that is not yet in force.
Related topics
The larger context.
AI Readiness and Governance
Assess existing capabilities and establish practical rules for data, tool access, approvals and technical responsibility.
View topicRelated services
How we support you.
Audits and assessments
For decisions, disputes and formal review situations that require an independent and traceable written technical assessment.
View serviceConsulting
For decisions on AI, architecture and tooling that need to fit existing systems, teams and operational conditions.
View serviceDoes your question go beyond the article?
Tell us what you are dealing with. You receive a technical answer, not a newsletter or sales call.