Sign up for free for our Privacy & Security event on 28 May

Timeline of the AI Act and the impact of the Digital Omnibus on AI

August 3, 2026
The European AI Act is gradually coming into force. What began as ambitious legislation is increasingly translating into concrete obligations for organisations. A significant recent development is the postponement of the obligations for high-risk AI systems. This follows from the Digital Omnibus on AI, through which the European legislator has amended the implementation of certain parts of the AI Act. This gives organisations more time to put the necessary measures in place, whilst the substantive obligations remain unchanged.

The implementation timeline for the AI Act

Although the AI Act officially entered into force on 1 August 2024, the European legislator has deliberately opted for a phased introduction, so that organisations, supervisory authorities and Member States can prepare for the new obligations step by step.

2 February 2025: first obligations come into force
From that date, the following, amongst other things, will apply:

  • The general provisions and definitions of the AI Act;
  • The obligation to promote AI literacy;
  • The prohibitions on certain AI applications posing an unacceptable risk.

For organisations, this marked the first concrete step towards AI governance and compliance.

2 August 2025: obligations for providers of general-purpose AI models
The obligations for providers of general-purpose AI models have been in force since 2 August 2025. These include obligations such as technical documentation, copyright policy and a transparent information package for the supply chain.

2 August 2026: transparency obligations for providers and deployers, and supervision in force
The following rules are in force since last Sunday:

  • The transparency obligations for providers and deployers of chatbots, systems for emotion recognition or biometric categorisation, and systems that generate deepfakes or content (Article 50 of the AI Act). A four-month transition period applies to generative AI systems already placed on the market before 2 August 2026;
  • Various measures to support innovation;
  • The enforcement of the rules currently in force by national and European supervisory authorities.

2 December 2026: new prohibited AI applications and end of the transition period for transparency obligations

  • New prohibitions on AI systems that generate non-consensual deepfakes and child sexual abuse material (CSAM) will come into force;
  • End of the transition period for transparency obligations relating to generative AI systems (Article 50(2) of the AI Act) that had already been placed on the market before 2 August 2026.

2 August 2027: AI regulatory sandbox

  • Each Member State must have established at least one operational AI regulatory sandbox. This is a controlled testing environment in which organisations can develop and test AI systems under the supervision of the supervisory authorities.

2 December 2027: obligations for AI systems with a high-risk use case (Annex III)

  • On this date, the rules for providers and deployers of AI systems used for a high-risk use case, as set out in Annex III of the AI Act, will come into force.

2 August 2028: obligations for high-risk AI integrated into regulated products (Annex I)

  • Finally, the rules for providers and deployers of products in which high-risk AI is integrated will come into force.

Postponement of obligations for high-risk AI

The most significant changes to the timeline stem from the Digital Omnibus on AI1, an amending act by the European legislator, which entered into force on 27 July 2026. The amendments to the AI Act aim to simplify certain parts of the Regulation and make them more practicable.

The most significant change to the timeline is the deadline for high-risk AI. Under the original AI Act, many of these obligations were due to come into force as early as 2 August 2026. The AI Omnibus package postpones the deadline for AI systems with high-risk use cases to 2 December 2027. Regulated products incorporating high-risk AI will need to comply with the obligations on 2 August 2028.

What does this mean for me as an organisation?

The postponement gives organisations extra time for implementation and greater legal clarity, but does not alter the substance of the obligations for high-risk AI. Furthermore, compliance with the obligations for high-risk AI systems requires an intensive implementation process. Among other things, organisations must gain an understanding of their AI landscape, carry out risk analyses, organise human oversight, establish appropriate governance and policy frameworks, and set up the required documentation processes.

For example, if you are already using an AI system to assess job applicants or are planning to deploy such a system, you should continue with your compliance activities. Make the most of this extra implementation time to build up your AI governance step by step and implement the necessary measures.

Do you have any questions about the AI Act and the obligations that may apply to your organisation? The legal advisers at Privacy Company will be happy to help. Please contact info@privacycompany.nl.

 

 
 

1 Regulation (EU) 2026/1744 of the European Parliament and of the Council of 8 July 2026 amending Regulations (EU) 2024/1689, (EU) 2018/1139 and (EU) 2023/1230 as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI).

Download
Ine
Consultant