Updated for the June 2026 Omnibus

EU AI Act deadlines

Two obligations moved. The rest became enforceable on 2 August 2026 — including the ones most chatbot and generative products actually have.

Last updated 7 August 2026 · Regulation (EU) 2024/1689 as amended by the June 2026 Omnibus · Self-assessment, not legal advice

Most deadline tables you'll find are wrong. The June 2026 Omnibus moved two of these dates and left the rest alone. Published guidance written before June 2026 — which is still the majority of it — tells high-risk providers they are already late, and tells chatbot builders they have another eighteen months. Both are the opposite of true.

Here is every EU AI Act date that matters, as it stands after the Omnibus. Live obligations first, because those are the ones that can cost you something this quarter.

Enforceable now

ObligationApplied fromEnforceableWho
Article 5 — prohibited practices2 Feb 20252 Aug 2026Everyone
Article 4 — AI literacy2 Feb 20252 Aug 2026Providers & deployers
Article 50 — transparency2 Aug 20262 Aug 2026Chatbots, generative systems, deepfakes
Article 53 — GPAI providers2 Aug 20252 Aug 2026General-purpose model providers
Governance & penalties framework2 Aug 20252 Aug 2026National authorities

Notice the pattern in that table. Four separate obligation sets applied at different points across 2025, and every one of them became enforceable on the same day: 2 August 2026. That's the date regulators gained fining powers. Before it, these were duties without teeth. After it, they are duties with teeth.

What Article 5 actually prohibits

Real-time remote biometric identification in publicly accessible spaces for law enforcement, subject to narrow exceptions. Social scoring by or on behalf of public authorities. Emotion recognition in the workplace and in education. Untargeted scraping of facial images to build recognition databases. Exploitative manipulation of vulnerable groups. Predictive policing based solely on profiling.

These are bans, not obligations. There is no documentation that makes them permissible.

What Article 50 actually requires

If you ship a chatbot, this is your deadline and it has passed. The fix is usually one line of copy in the greeting. It is the cheapest obligation in the entire regulation to satisfy and the most common one to have missed, because it was never presented as a deadline — it arrived as part of a package everyone was told had been delayed.

Deferred by the Omnibus

ObligationWasNowWho
Annex III high-risk — Articles 9–15, 17, 43, 49, 732 Aug 20262 Dec 2027Employment, credit, education, essential services, law enforcement, migration, justice, biometrics, critical infrastructure
Annex I high-risk — AI in regulated products2 Aug 2027Aug 2028Medical devices, machinery, vehicles, toys and other CE-marked products

This is the part that got reported as "the EU delayed the AI Act". It is real and it is significant — but it applies only to these two rows.

Deferred is not the same as distant. A conformity assessment, a full Annex IV technical file and a functioning risk-management system take twelve to eighteen months for a small team, and a notified body's queue is not something you can compress with budget. December 2027 means scoping in 2026 and starting work in the first half of 2027. Teams that treat the deferral as eighteen months of silence will spend it discovering that the assessor is booked.

What high-risk providers owe, and when

If you land in Annex III as a provider, this is the full set. All of it lands on 2 December 2027.

ArticleObligationRealistic lead time
Art 9Risk management system, continuous and documented across the lifecycle3–6 months
Art 10Data governance — training and test sets examined for bias2–4 months, longer with an external audit
Art 11Technical documentation (Annex IV)2–4 months
Art 12Automatic logging, complete and retainedWeeks, if logging already exists
Art 13Instructions for use for your deployers2–4 weeks
Art 14Human oversight by design — a person must be able to understand and overrideProduct work, budget a quarter
Art 15Accuracy, robustness and cybersecurity, documented2–3 months
Art 17Quality management system3–6 months
Art 43Conformity assessment and CE markingDepends on the notified body's queue
Art 49Registration in the EU databaseDays, once the rest exists
Art 73Serious-incident reporting procedure1–2 weeks

Add those up honestly and December 2027 stops looking generous. Article 13 is worth pulling forward regardless of the deadline: your business customers are deployers with their own Article 26 duties, and they cannot meet them without documentation from you. Producing it early converts an obligation into a sales asset.

Deployer duties — Article 26

If you use someone else's high-risk system rather than supply one, your set is much smaller and also lands on 2 December 2027:

No conformity assessment. No CE marking. No EU database registration. If you have been quoted for those as a deployer, check your role again.

Penalties, and the figure everyone gets backwards

BreachCeiling for large companies
Prohibited practices (Art 5)€35M or 7% of worldwide annual turnover, whichever is higher
Most other obligations€15M or 3%, whichever is higher
Supplying incorrect information to authorities€7.5M or 1%, whichever is higher

Article 99(6) inverts this for SMEs and start-ups: the fine is the lower of the two figures, not the higher. For a company with €1.4M turnover, a Tier-2 breach ceiling is roughly €42,000, not €15M. Nearly every article you will read quotes the large-company number at small companies, which produces a mix of panic and disengagement — neither of which produces compliance.

The realistic near-term cost for a small company was never the fine. It is the enterprise procurement questionnaire you cannot answer, and the deal that stalls in the buyer's legal team. That happens years before a regulator has heard your name, and it happens constantly.

Dates worth putting in your calendar

Which of these apply to you?

Six questions, instant result. Or run the full 32-question assessment for a personalised gap report with your obligations and deadlines, per Article.

Start the free scan

No card, no account. Full gap report from €59. See a real report first.

Self-assessment, not legal advice. This page and the Reglynn report are a structured self-assessment based on the EU AI Act (Regulation 2024/1689, as amended by the June 2026 Omnibus). They indicate where you likely stand and what to verify with a qualified advisor. Reglynn is not a notified body and issues no certification.

How this was made. Reglynn reports are generated by an AI system and reviewed before delivery. Reglynn is a Limited Risk AI system under Article 50; we disclose AI involvement wherever it occurs, including in our chat assistant. Our own self-assessment.