Most deadline tables you'll find are wrong. The June 2026 Omnibus moved two of these dates and left the rest alone. Published guidance written before June 2026 — which is still the majority of it — tells high-risk providers they are already late, and tells chatbot builders they have another eighteen months. Both are the opposite of true.
Here is every EU AI Act date that matters, as it stands after the Omnibus. Live obligations first, because those are the ones that can cost you something this quarter.
Enforceable now
| Obligation | Applied from | Enforceable | Who |
|---|---|---|---|
| Article 5 — prohibited practices | 2 Feb 2025 | 2 Aug 2026 | Everyone |
| Article 4 — AI literacy | 2 Feb 2025 | 2 Aug 2026 | Providers & deployers |
| Article 50 — transparency | 2 Aug 2026 | 2 Aug 2026 | Chatbots, generative systems, deepfakes |
| Article 53 — GPAI providers | 2 Aug 2025 | 2 Aug 2026 | General-purpose model providers |
| Governance & penalties framework | 2 Aug 2025 | 2 Aug 2026 | National authorities |
Notice the pattern in that table. Four separate obligation sets applied at different points across 2025, and every one of them became enforceable on the same day: 2 August 2026. That's the date regulators gained fining powers. Before it, these were duties without teeth. After it, they are duties with teeth.
What Article 5 actually prohibits
Real-time remote biometric identification in publicly accessible spaces for law enforcement, subject to narrow exceptions. Social scoring by or on behalf of public authorities. Emotion recognition in the workplace and in education. Untargeted scraping of facial images to build recognition databases. Exploitative manipulation of vulnerable groups. Predictive policing based solely on profiling.
These are bans, not obligations. There is no documentation that makes them permissible.
What Article 50 actually requires
- 50(1) — systems interacting directly with people must disclose they are AI, at or before the first interaction, unless it is obvious to a reasonably observant person.
- 50(2) — providers of generative systems must mark synthetic output as artificially generated in a machine-readable format. This duty sits with the provider of the generative system, not with everyone who uses one.
- 50(4) — deployers must disclose deepfakes, and must disclose AI-generated text published to inform the public on matters of public interest — unless the content underwent human review and a person holds editorial responsibility for its publication.
If you ship a chatbot, this is your deadline and it has passed. The fix is usually one line of copy in the greeting. It is the cheapest obligation in the entire regulation to satisfy and the most common one to have missed, because it was never presented as a deadline — it arrived as part of a package everyone was told had been delayed.
Deferred by the Omnibus
| Obligation | Was | Now | Who |
|---|---|---|---|
| Annex III high-risk — Articles 9–15, 17, 43, 49, 73 | 2 Aug 2026 | 2 Dec 2027 | Employment, credit, education, essential services, law enforcement, migration, justice, biometrics, critical infrastructure |
| Annex I high-risk — AI in regulated products | 2 Aug 2027 | Aug 2028 | Medical devices, machinery, vehicles, toys and other CE-marked products |
This is the part that got reported as "the EU delayed the AI Act". It is real and it is significant — but it applies only to these two rows.
Deferred is not the same as distant. A conformity assessment, a full Annex IV technical file and a functioning risk-management system take twelve to eighteen months for a small team, and a notified body's queue is not something you can compress with budget. December 2027 means scoping in 2026 and starting work in the first half of 2027. Teams that treat the deferral as eighteen months of silence will spend it discovering that the assessor is booked.
What high-risk providers owe, and when
If you land in Annex III as a provider, this is the full set. All of it lands on 2 December 2027.
| Article | Obligation | Realistic lead time |
|---|---|---|
| Art 9 | Risk management system, continuous and documented across the lifecycle | 3–6 months |
| Art 10 | Data governance — training and test sets examined for bias | 2–4 months, longer with an external audit |
| Art 11 | Technical documentation (Annex IV) | 2–4 months |
| Art 12 | Automatic logging, complete and retained | Weeks, if logging already exists |
| Art 13 | Instructions for use for your deployers | 2–4 weeks |
| Art 14 | Human oversight by design — a person must be able to understand and override | Product work, budget a quarter |
| Art 15 | Accuracy, robustness and cybersecurity, documented | 2–3 months |
| Art 17 | Quality management system | 3–6 months |
| Art 43 | Conformity assessment and CE marking | Depends on the notified body's queue |
| Art 49 | Registration in the EU database | Days, once the rest exists |
| Art 73 | Serious-incident reporting procedure | 1–2 weeks |
Add those up honestly and December 2027 stops looking generous. Article 13 is worth pulling forward regardless of the deadline: your business customers are deployers with their own Article 26 duties, and they cannot meet them without documentation from you. Producing it early converts an obligation into a sales asset.
Deployer duties — Article 26
If you use someone else's high-risk system rather than supply one, your set is much smaller and also lands on 2 December 2027:
- Use the system in accordance with the provider's instructions
- Assign human oversight to someone competent, with the authority to override
- Ensure input data is relevant for the intended purpose
- Monitor operation and report serious incidents
- Retain logs where you control them
- Inform workers and affected individuals
- Where you are a public body or provide public services, complete a fundamental-rights impact assessment under Article 27
No conformity assessment. No CE marking. No EU database registration. If you have been quoted for those as a deployer, check your role again.
Penalties, and the figure everyone gets backwards
| Breach | Ceiling for large companies |
|---|---|
| Prohibited practices (Art 5) | €35M or 7% of worldwide annual turnover, whichever is higher |
| Most other obligations | €15M or 3%, whichever is higher |
| Supplying incorrect information to authorities | €7.5M or 1%, whichever is higher |
Article 99(6) inverts this for SMEs and start-ups: the fine is the lower of the two figures, not the higher. For a company with €1.4M turnover, a Tier-2 breach ceiling is roughly €42,000, not €15M. Nearly every article you will read quotes the large-company number at small companies, which produces a mix of panic and disengagement — neither of which produces compliance.
The realistic near-term cost for a small company was never the fine. It is the enterprise procurement questionnaire you cannot answer, and the deal that stalls in the buyer's legal team. That happens years before a regulator has heard your name, and it happens constantly.
Dates worth putting in your calendar
- Now — Articles 4, 5, 50 and 53 are enforceable. If you have a chatbot or generate content, this is a this-week job, not a 2027 one.
- Q1 2027 — if you are high-risk, get a fixed quote and a lead time from a notified body. Not to buy, to know.
- Q2 2027 — last comfortable moment to start conformity work for a December 2027 date.
- 2 December 2027 — Annex III high-risk obligations apply.
- August 2028 — Annex I high-risk obligations apply.
Which of these apply to you?
Six questions, instant result. Or run the full 32-question assessment for a personalised gap report with your obligations and deadlines, per Article.
Start the free scanNo card, no account. Full gap report from €59. See a real report first.
Self-assessment, not legal advice. This page and the Reglynn report are a structured self-assessment based on the EU AI Act (Regulation 2024/1689, as amended by the June 2026 Omnibus). They indicate where you likely stand and what to verify with a qualified advisor. Reglynn is not a notified body and issues no certification.
How this was made. Reglynn reports are generated by an AI system and reviewed before delivery. Reglynn is a Limited Risk AI system under Article 50; we disclose AI involvement wherever it occurs, including in our chat assistant. Our own self-assessment.