Recommended Free Tools
The EU AI Act is already in force; it did not begin in 2026. Its requirements are being phased in, with some applying since 2025 and the European Commission’s current implementation timeline extending to 2 August 2028. The Digital Omnibus on AI, which entered into force on 27 July 2026, amended parts of that rollout without replacing the Act’s risk-based framework. What applies to a particular system depends on its intended use, risk category, the actor’s role and the relevant deadline.
When will the AI Act be fully applicable?
The Act entered into force on 1 August 2024. “Fully applicable” can be misleading: provisions have different application dates, and the Commission’s timeline identifies 2 August 2028 as the end of the main rollout—not as the date the Act first takes effect. The schedule below reflects the Commission’s current timeline as of 8 October 2026; regulatory timelines can change. See the EU AI Act implementation timeline.
| Date | What applies or is due |
|---|---|
| 1 August 2024 | The AI Act entered into force. |
| 2 February 2025 | Definitions, AI literacy provisions and the initial prohibitions apply. The Commission overview says prohibitions 1–8 became effective on this date. |
| 2 August 2025 | Rules for general-purpose AI (GPAI) models and governance provisions apply. Member States were to designate national competent authorities and adopt national penalty laws; EU governance bodies were also to be set up. |
| 2 August 2026 | Article 50 transparency rules apply, and enforcement begins for applicable provisions. |
| 2 December 2026 | The additional prohibitions on generating non-consensual sexual deepfakes and child sexual abuse material apply. This is also the transition deadline listed for certain systems already on the market before 2 August 2026 to meet the Article 50(2) marking and detection obligation. |
| 2 August 2027 | Member States should have at least one AI regulatory sandbox operational. |
| 2 December 2027 | Rules for high-risk AI systems covered by Annex III apply. |
| 2 August 2028 | Rules for high-risk AI systems embedded in products covered by Annex I apply. |
What did the Digital Omnibus change?
The European Commission says the Digital Omnibus on AI was adopted on 19 November 2025, reached political agreement on 7 May 2026 and entered into force on 27 July 2026. It changed the implementation framework and specified obligations; it did not repeal the AI Act. The Commission describes the changes as including:
- Setting dates for the later high-risk obligations: 2 December 2027 for Annex III systems and 2 August 2028 for high-risk systems embedded in Annex I regulated products.
- Adding a prohibition, applying from 2 December 2026, on AI systems generating non-consensual sexually explicit or intimate content or child sexual abuse material.
- Reinforcing AI Office powers and centralising oversight in specified areas.
- Extending certain simplified requirements available to SMEs to small mid-cap companies, broadening access to regulatory sandboxes, and clarifying how the AI Act interacts with EU product safety law.
A Commission FAQ published during the proposal period estimated that extending certain benefits to small mid-cap companies could make implementation easier for an additional 8,250 companies in Europe. That is a proposal-era estimate, not a measured count of companies that have benefited. The Commission’s AI Act overview describes the enacted changes; the Service Desk’s Digital Omnibus FAQ also contains historical proposal-stage wording. For the current deadlines, use the implementation timeline above rather than treating proposed mechanisms or maximum delays in the FAQ as the final rule.
#1 Best Overall
Which AI systems are high-risk—and which are not?
The AI Act uses four risk levels: unacceptable risk, high risk, transparency risk, and minimal or no risk. It does not classify every AI application as high-risk. The Commission says minimal- or no-risk applications generally face no additional AI Act rules, though other laws may still apply. Classification depends on the system’s intended use and the Act’s criteria, not merely on whether it uses AI.
Prohibited practices
Prohibited practices include harmful manipulation or exploitation of vulnerabilities, social scoring, certain predictions of an individual’s criminal offending, specified scraping of facial images to build recognition databases, emotion recognition in workplaces and education, certain biometric categorisation, and specified real-time remote biometric identification for law enforcement. The additional prohibition concerning non-consensual sexually explicit or intimate content and child sexual abuse material applies from 2 December 2026. The Commission’s overview of the AI Act’s risk framework describes the categories and prohibitions.
Rank #2
High-risk uses
Commission examples include AI used in critical infrastructure, education decisions, product-safety components, recruitment and worker management, certain essential services such as credit scoring, biometrics, law enforcement, migration, asylum and border control, justice, and democratic processes. These are examples, not an exhaustive classification test. If a system is high-risk, the applicable date also depends on whether it falls under Annex III or is embedded in an Annex I regulated product.
For high-risk systems, the Commission lists requirements that include risk assessment and mitigation, high-quality datasets, activity logging, technical documentation, adequate information for deployers, human oversight, and robustness, cybersecurity and accuracy. The Commission’s timeline gives the later application dates for these two groups.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallOutdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWho has duties under the GPAI and transparency rules?
General-purpose AI model providers
GPAI model rules have applied since 2 August 2025. The Commission describes provider duties concerning transparency and copyright, with assessment and mitigation of systemic risks for models that may pose them. These are model-provider obligations; they should not be treated as identical to the obligations of every downstream provider or deployer using a model. The Commission explains the GPAI requirements in its AI Act overview.
Transparency under Article 50
Article 50 transparency requirements apply from 2 August 2026. They include disclosure in relevant interactions and identification or labelling for certain AI-generated content. For certain systems already placed on the market before that date, the Service Desk timeline lists a transition until 2 December 2026 for the Article 50(2) marking and detection obligation. That transition is specific; it is not a general extension of all transparency duties.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How to work out which deadline matters to you
Do not choose a date based only on the product’s launch year. First identify the system’s intended use and risk classification, then identify your role and the provision involved.
- Identify the use and risk category. Check whether the system falls within a prohibited practice, a high-risk use, a transparency obligation, or the minimal- or no-risk category. The Commission’s risk overview gives examples, but examples alone do not determine classification.
- Identify your role. Distinguish whether you are acting as a system provider, a deployer, or a provider of a GPAI model. A model provider’s duties do not automatically become every downstream user’s duties.
- Match the obligation to its date. Use the implementation timeline for the relevant provision; an obligation already applicable in 2025 or 2026 is not postponed just because some high-risk rules start later.
- If the system is high-risk, check which route applies. Annex III rules are scheduled for 2 December 2027; Annex I rules for high-risk AI embedded in regulated products are scheduled for 2 August 2028.
The Commission describes the purpose of the framework this way: “The AI Act ensures that Europeans can trust what AI has to offer.” In practice, the key change is a phased set of duties—not a single start date or a rule that treats every AI system alike.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

