Timeline of the AI Act and the impact of the Digital Omnibus on AI

The implementation timeline for the AI Act
Although the AI Act officially entered into force on 1 August 2024, the European legislator has deliberately opted for a phased introduction, so that organisations, supervisory authorities and Member States can prepare for the new obligations step by step.
2 December 2026: new prohibited AI applications and end of the transition period for transparency obligations
- New prohibitions on AI systems that generate non-consensual deepfakes and child sexual abuse material (CSAM) will come into force;
- End of the transition period for transparency obligations relating to generative AI systems (Article 50(2) of the AI Act) that had already been placed on the market before 2 August 2026.
2 August 2027: AI regulatory sandbox
- Each Member State must have established at least one operational AI regulatory sandbox. This is a controlled testing environment in which organisations can develop and test AI systems under the supervision of the supervisory authorities.
2 December 2027: obligations for AI systems with a high-risk use case (Annex III)
- On this date, the rules for providers and deployers of AI systems used for a high-risk use case, as set out in Annex III of the AI Act, will come into force.
2 August 2028: obligations for high-risk AI integrated into regulated products (Annex I)
- Finally, the rules for providers and deployers of products in which high-risk AI is integrated will come into force.
Postponement of obligations for high-risk AI
The most significant changes to the timeline stem from the Digital Omnibus on AI1, an amending act by the European legislator, which entered into force on 27 July 2026. The amendments to the AI Act aim to simplify certain parts of the Regulation and make them more practicable.
The most significant change to the timeline is the deadline for high-risk AI. Under the original AI Act, many of these obligations were due to come into force as early as 2 August 2026. The AI Omnibus package postpones the deadline for AI systems with high-risk use cases to 2 December 2027. Regulated products incorporating high-risk AI will need to comply with the obligations on 2 August 2028.
What does this mean for me as an organisation?
The postponement gives organisations extra time for implementation and greater legal clarity, but does not alter the substance of the obligations for high-risk AI. Furthermore, compliance with the obligations for high-risk AI systems requires an intensive implementation process. Among other things, organisations must gain an understanding of their AI landscape, carry out risk analyses, organise human oversight, establish appropriate governance and policy frameworks, and set up the required documentation processes.
For example, if you are already using an AI system to assess job applicants or are planning to deploy such a system, you should continue with your compliance activities. Make the most of this extra implementation time to build up your AI governance step by step and implement the necessary measures.
Do you have any questions about the AI Act and the obligations that may apply to your organisation? The legal advisers at Privacy Company will be happy to help. Please contact info@privacycompany.nl.
1 Regulation (EU) 2026/1744 of the European Parliament and of the Council of 8 July 2026 amending Regulations (EU) 2024/1689, (EU) 2018/1139 and (EU) 2023/1230 as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI).

