The EU AI Act’s compliance calendar split this summer. Transparency rules landed on schedule. The heavier obligations moved to 2027 and 2028. Here’s what that means for your organization, phase by phase.
The timeline you were tracking probably changed
If you marked 2 August 2026 as the EU AI Act’s big compliance date, you were right and wrong at the same time. The date arrived. It carried far less than planned.
The Digital Omnibus on AI, Regulation (EU) 2026/1744, published 24 July 2026 and in force since 27 July, split the calendar in two. Rules about telling people they are dealing with AI landed on schedule. The rules for high-risk AI, meaning recruitment tools, credit scoring, and medical devices, were moved back by more than a year.
Some people read “AI Act delayed” and assumed everything moved. It did not. If your organization runs any AI that talks to customers, generates content, or reads emotions, you have obligations right now. If you use AI for hiring or credit decisions, you have time to prepare, and the clock is running.
The EU AI Act, Regulation (EU) 2024/1689, entered into force on 1 August 2024 and phases in across three windows (Official Journal of the European Union, 2024).

What has been in force since February 2025
Since 2 February 2025, the most dangerous uses of AI are banned outright, and everyone working with AI needs basic training (European Commission).
The banned practices under Article 5 cover the uses the EU considers unacceptable (European Commission AI Act Service Desk). The ones that matter most for enterprises:
- AI that manipulates people through hidden techniques they cannot detect
- AI that targets people’s vulnerabilities, such as age, disability, or financial situation, to change their behavior
- Social scoring: rating people on their social behavior or personal traits
- Scraping the internet or CCTV footage to build facial recognition databases
- Reading employees’ emotions at work, except for medical or safety reasons
If any AI tool in your organization does something on this list, turn it off. These rules have run for over a year, and the fines are the Act’s highest: up to 35 million euros or 7% of global annual turnover.
Article 4 adds a second duty: anyone who works with an AI system must understand what it does and where it falls short. It covers employees and contractors alike. The Omnibus softened the wording, but the obligation to take measures remains. You do not need a certification program. You do need documented training matched to the role: a support agent using an AI assistant needs something different from the team that configured it.
So before you look at anything newer, confirm two things. Nothing in use falls into a banned category, and the training is written down.
What took effect on 2 August 2026
This is the phase that needs attention now. The transparency rules under Article 50 are live, and they apply to organizations that use AI, not only to the companies that built it. In practice:
- Disclose the AI. Any chatbot, virtual assistant, or agent that someone could mistake for a human must say it is AI, at first contact.
- Mark generated content. Audio, images, video, or text made by AI must carry a machine-readable watermark. Systems already in use before 2 August have until 2 December 2026 to add it, new systems need it from day one.
- Flag emotion and biometric systems. People have the right to know when these are running.
- Label what you publish. Marketing materials, social posts, and any public content created or altered by AI.
The Commission’s guidelines on Article 50, published 20 July 2026, are clear on the point most organizations miss: you cannot pass this to your vendor (European Commission, 2026). Even where the tool you bought has disclosure features built in, you are responsible for checking they work in your setup.
These rules reach any company whose AI outputs land in front of people in the EU, wherever the company sits. Fines run up to 15 million euros or 3% of global annual turnover, and the AI Office and national authorities began enforcing on 2 August 2026.
The near-term work is a mapping exercise: which systems interact with people, which generate content, and which read emotions or biometric data.
What is coming in 2027 and 2028
The high-risk rules were supposed to hit on 2 August 2026, however, he Digital Omnibus pushed them back:
- Starting 2 December 2027: AI used for recruitment, HR decisions, credit scoring, insurance pricing, education assessments, law enforcement, border control, and critical infrastructure
- Starting 2 August 2028: AI built into regulated products such as medical devices, machinery, and vehicles
When those dates arrive, organizations using high-risk AI will need risk management and data governance, technical documentation, human oversight, accuracy and security testing, registration in the EU’s public database, and a process for reporting serious incidents.
Sixteen months is shorter than it sounds, and the hard part is not the paperwork. It is finding every AI system in the organization and working out which ones count as high-risk. A recruitment screening tool, a credit risk model, and an insurance pricing algorithm all qualify, as does AI embedded in medical devices or industrial machinery.
Treat the delay as schedule, not permission. Building risk frameworks, writing documentation, and setting up oversight takes months. Start now and you get time to test. Start in late 2027 and you will be scrambling.
What to do first
The starting point is the same for all three phases: know what AI your organization has, build an inventory of every system in use, who it interacts with, what it does, and how it would classify under the Act. That tells you whether you have banned uses to shut down, transparency duties to meet today, or high-risk systems to prepare for.
Note: this is not legal advice. It is the operational map that sits alongside your counsel’s reading of the Act.
