AI Act: The European Timeline to Be Prepared by August 2026
As of January 15, 2026, the AI Act’s timeline has already entered its operational phase. The prohibitions and requirements related to general-purpose AI models are now in effect; for many high-risk systems, the next milestone remains August 2, 2026. While the Commission did propose on November 19, 2025, to modify this timeline, this proposal does not yet alter the current law. For a business leader, the right decision is therefore to prepare for the current legal deadline while monitoring the negotiations.
Updated September 10, 2026. Regulation (EU) 2026/1744 amending the AI Act was published in the Official Journal on July 24, 2026, and entered into force on July 27. The new deadlines for high-risk systems are now set for December 2, 2027 (Annex III) and August 2, 2028 (Annex I). Full details in our reference article.
The Essentials in 30 Seconds
- The AI Act took effect on August 1, 2024.
- Chapters I and II, which include, among other things, prohibited practices, have been in effect since February 2, 2025.
- The rules on governance and general-purpose AI models have been in effect since August 2, 2025.
- The regulation generally applies as of August 2, 2026; Article 6(1) follows a separate timeline ending on August 2, 2027.
- Proposal COM(2025) 836, submitted on November 19, 2025 under procedure 2025/0359(COD), remains a proposal.
What Has Happened
Regulation (EU) 2024/1689, known as the AI Act, does not impose a single deadline on all organizations. Article 113 provides for a phased implementation. It entered into force on August 1, 2024. Chapters I and II became applicable on February 2, 2025. This is the date from which prohibited practices fall under the applicable framework. On August 2, 2025, other sections took effect, including Section 4 of Chapter III, Chapter V on general-purpose models, Chapter VII, Chapter XII, and Section 78, subject to the provision specified for Section 101.
The text then sets August 2, 2026 as the date of general application. This date serves as the immediate reference for high-risk systems classified under Article 6(2) and Annex III. However, these systems must be distinguished from those falling under Article 6(1): for systems that are safety components or are themselves part of products covered by Union sector-specific legislation, Article 113 provides for application as of August 2, 2027. Confusing the two categories leads to incorrect planning.
On November 19, 2025, the Commission presented the “Digital Omnibus on AI,” a proposal identified as COM(2025) 836 final and 2025/0359(COD). It aims, in particular, to amend the timeline for the requirements of Chapter III. However, its very title is that of a proposal for a regulation of the European Parliament and of the Council: as of January 15, 2026, it had not replaced Article 113 of the current regulation.
Applicable Law and the Proposed Scenario
The timeline framework involves separating the applicable law, the legislative proposal, and internal measures. The applicable law specifies the preparation date. The proposal outlines a scenario to monitor, not an authorization to defer. In the Commission’s text, the application of the requirements of Chapter III to the systems listed in Annex III would be contingent upon a Commission decision confirming the availability of adequate supporting measures, including harmonized standards, common specifications, and guidelines. Following this decision, the proposed deadline would be six months.
The proposal also sets end dates: December 2, 2027 for systems under Article 6(2) and Annex III, and August 2, 2028 for systems under Article 6(1) and Annex I. These deadlines are important for scenario analysis. As of January, they are not dates that the company can cite to challenge a currently applicable obligation. A responsible roadmap therefore treats August 2, 2026 as a target date for the Annex III scope, while providing for a decision point should the legislature adopt a different timeline.
This distinction has budgetary implications. The work that is useful in both scenarios is not wasted: inventory of use cases, definition of system functions, collection of evidence, allocation of responsibilities, mechanisms for human oversight, and preparation of documentation. These are the most time-consuming tasks, because they span procurement, business units, security, data, and legal functions. A potential delay does not make them any less necessary.
Planning by System Portfolio
The first mistake is to treat “AI” as a single, monolithic entity. The portfolio must be broken down by system, by organizational role, and by intended use. A tool purchased from a vendor, an in-house developed system, a feature integrated into a product, and a service outsourced to a provider do not require the same level of scrutiny. Qualification is not limited to the commercial label: one must consider the actual purpose, the deployment context, and the organization’s place in the value chain.
For cases potentially covered by Annex III, the goal is to reach a traceable decision: out of scope, to be confirmed, or to be treated as high risk. The “to be confirmed” category must have an owner and a closure date. Without these, it becomes a holding area that compromises documentation and controls. For security products and components, the roadmap must include the specific milestone of August 2, 2027 and coordinate with the teams already responsible for sector-specific regulations.
Finally, preparations must not suspend obligations that are already in effect. General-purpose models and governance rules have had their own timeline since August 2, 2025. A credible roadmap therefore links these initiatives: it does not distort the debate on high-risk systems by ignoring requirements that are already in effect.
What Needs to Be Done Now
- Map — establish a registry of systems, their purpose, their providers, and their qualification status.
- Distinguish between deadlines — separate Annex III, systems under Article 6(1), general-purpose models, and obligations that are already in effect.
- Prepare the evidence — define who produces, maintains, and updates the documentation, as well as who is responsible for oversight and monitoring.
- Follow the procedure — treat COM(2025) 836 as a regulatory scenario, with formalized monitoring.
- Prioritize — assign personnel and resources to priority cases without waiting for negotiations to conclude.
Sources
- AI Act Service Desk, Article 113 and implementation timeline: ai-act-service-desk.ec.europa.eu
- European Commission, Digital Omnibus on AI proposal, COM(2025) 836 final: europarl.europa.eu
- EUR-Lex, Regulation (EU) 2024/1689: eur-lex.europa.eu
GPAI Code: When Voluntary Initiatives Shape Compliance (2026-02-12) →