- Since August 2, 2026 most of the AI Act applies: GPAI model rules, prohibitions, AI literacy, Article 50 transparency duties, and EU-level enforcement including fines for GPAI providers.
- The AI Omnibus (Regulation (EU) 2026/1744, in force July 27, 2026) moved high-risk rules to December 2, 2027 (Annex III) and August 2, 2028 (Annex I), and added new bans from December 2, 2026.
- The GPAI Code of Practice is the Commission-endorsed route to compliance; 22 companies have signed it in full and xAI has signed one chapter.
Contents
If you last read about the EU AI Act a year ago, some of your dates are now wrong. The European Commission says the Act "became applicable on 2 August 2026, with some exceptions." Since then, a July 2026 amending law, the "AI Omnibus", has pushed the high-risk rules back by more than a year. The rules on general-purpose AI (GPAI) models, the bans, the AI literacy duty and the new transparency obligations are already in force, and EU-level enforcement started on August 2, 2026. This explainer gives every date we could confirm on an official EU page as of October 8, 2026. For the latest developments, see our news coverage of the EU's AI content-marking rules. If you build on someone else's model, read what the AI Act means if you only use model APIs.
This article explains the law; it is not legal advice. If your product could fall into a high-risk category, talk to counsel.
The short version
Last verified: October 8, 2026
| Date | What applies | Status |
|---|---|---|
| August 1, 2024 | AI Act (Regulation (EU) 2024/1689) enters into force | Done |
| February 2, 2025 | Prohibited practices (Art. 5), AI literacy (Art. 4), definitions | Applies |
| August 2, 2025 | GPAI model obligations; governance (AI Office, AI Board, national authorities); penalty rules | Applies |
| August 2, 2026 | Most of the Act applies; Article 50 transparency rules; national and EU enforcement begins; AI Office can fine GPAI providers | Applies |
| December 2, 2026 | New bans on AI that generates non-consensual intimate imagery or child sexual abuse material; Article 50(2) marking deadline for generative systems already on the market before August 2, 2026 | Coming |
| August 2, 2027 | GPAI models placed on the market before August 2, 2025 must comply; each Member State must have at least one AI regulatory sandbox | Coming |
| December 2, 2027 | High-risk rules for Annex III use cases (biometrics, education, employment, essential services, migration, and others) | Moved from August 2, 2026 |
| August 2, 2028 | High-risk rules for AI in regulated products under Annex I (machinery, toys, medical devices, and others) | Moved from August 2, 2027 |
These dates come from the Commission's AI Act policy page and the AI Act Service Desk timeline. The Service Desk says its timeline already reflects the Omnibus.
What the AI Omnibus changed
On November 19, 2025, the Commission proposed the "Digital Omnibus on AI", part of a wider package of simplification proposals. Parliament and Council negotiators reached political agreement in early May 2026. The law was adopted as Regulation (EU) 2026/1744, dated July 8, 2026, and entered into force on July 27, 2026. That was six days before the original August 2, 2026 deadline for high-risk systems.
The main changes:
- High-risk deadlines moved. Obligations for Annex III systems, such as AI used in hiring, education, credit scoring or migration, now start on December 2, 2027. Obligations for AI built into products covered by EU product-safety law (Annex I) start on August 2, 2028.
- Two new prohibitions. From December 2, 2026, Article 5 bans AI systems that generate or manipulate realistic intimate images, video or audio of an identifiable person without their explicit consent (so-called "nudification" apps) and systems that generate child sexual abuse material. The amended text covers placing such a system on the market not only when that is its intended purpose but also when generating this material is "a reasonably foreseeable and reproducible outcome, without requiring significant technical modification," and it asks whether the system has "reasonable and adequate technical safety measures and other safeguards."
- A grace period for content marking. Generative AI systems placed on the market before August 2, 2026 have until December 2, 2026 to meet the machine-readable marking duty in Article 50(2). New systems have had to comply since August 2.
- A softer AI literacy duty. Article 4 originally required providers and deployers to ensure, "to their best extent", a sufficient level of AI literacy among their staff. It now requires them to "take measures to support" AI literacy, and the text says it does not require anyone to guarantee a specific level for any individual.
- More power for the AI Office. The Commission's AI Office now has exclusive oversight of AI systems built on a GPAI model when the same company provides both, such as a lab's own chatbot. It also covers AI systems that are, or are part of, very large online platforms or search engines under the Digital Services Act. It gained investigation and on-site inspection powers, can accept binding commitments, and can impose fines and periodic penalties. If you integrate someone else's model into your own product, your national authority still supervises you.
- Lighter paperwork for smaller firms. The Omnibus extends simplified technical documentation and quality-management rules to SMEs and "small mid-caps", and caps their fines at whichever is lower, the fixed amount or the percentage.
What did not change: the GPAI model obligations themselves, the original prohibitions, and the August 2, 2026 start date for the other Article 50 transparency duties.
The GPAI rules, which have applied since August 2, 2025
The GPAI rules cover models, not apps. They apply to companies that put a general-purpose model on the EU market, whether through an API, a download or a product.
The Commission's guidelines for GPAI providers, published July 18, 2025, set out who counts. According to summaries by WilmerHale and Slaughter and May, the guidelines treat a model trained with more than 10^23 FLOP that can generate text, images or video as an indicative general-purpose model. Models above 10^25 FLOP are presumed to have high-impact capabilities and so carry "systemic risk"; that threshold is set in the Act itself (Article 51(2)). If you modify someone else's model and the modification uses more than one-third of the original's training compute, you become a provider in your own right.
Every GPAI provider must:
- keep technical documentation for the AI Office and national authorities;
- give downstream companies that build on the model enough documentation to meet their own obligations (Article 53(1)(b));
- have a policy to comply with EU copyright law, including machine-readable opt-outs from text and data mining;
- publish a summary of the content used for training, using the Commission's template, published July 24, 2025 and last updated March 26, 2026.
Providers of models with systemic risk must also evaluate and mitigate those risks, report serious incidents, and keep adequate cybersecurity.
Models released under a free and open-source license get a partial exemption from the documentation duties, but only if they are not monetized and do not pass the systemic-risk threshold. Whether a given license qualifies is not obvious; we look at the main license texts in our comparison of open-weight licenses.
The deadlines that matter for GPAI
- August 2, 2025: the obligations applied to new models.
- August 2, 2026: the Commission's enforcement powers, including fines, took effect. Under Article 101, fines for GPAI providers can reach €15 million or 3% of worldwide annual turnover, whichever is higher. Under the new Article 75c, inserted by the Omnibus, the AI Office can impose periodic penalty payments of up to 5% of average daily income or worldwide annual turnover in the preceding financial year, per day.
- August 2, 2027: models placed on the market before August 2, 2025, such as most 2024 and early-2025 frontier and open-weight models, must comply.
The GPAI Code of Practice
The General-Purpose AI Code of Practice, published July 10, 2025, is a voluntary way to show compliance. It has three chapters. Transparency, with a Model Documentation Form, and Copyright apply to all GPAI providers. Safety and Security applies only to providers of systemic-risk models. The Commission and the AI Board have confirmed it as an "adequate voluntary tool", and the Commission says signatories can expect less administrative burden and more legal certainty.
As of the page's October 7, 2026 update (re-checked October 9, 2026), 22 organizations had signed the full code: AI Studio Delta, Aleph Alpha, Almawave, Amazon, Anthropic, Black Forest Labs, Bria AI, Cohere, Domyn, Dweve, Fastweb, Google, IBM, LINAGORA, Microsoft, Mistral AI, Open Hippo, OpenAI, Pleias, Reflection AI, ServiceNow and WRITER. xAI, listed under that name although the company now publishes as SpaceXAI, signed only the Safety and Security chapter, so it must show compliance with the transparency and copyright duties some other way.
Meta is not on the list. In July 2025 the company said it would not sign, calling the code an overreach. Not signing does not exempt a provider from the law; it only means the provider must show compliance by other means.
Transparency rules, which have applied since August 2, 2026
Article 50 is the part of the Act most consumers will notice:
- Chatbots and other interactive AI must tell people they are dealing with an AI system unless that is obvious. This is a duty on the provider.
- Generative AI outputs (text, images, audio, video) must carry a machine-readable mark. This is also a provider duty, with the December 2, 2026 grace period for systems already on the market.
- Deepfakes and AI-written text on matters of public interest must be labelled by the deployer that publishes them. Text is exempt if it went through human editorial review and someone holds editorial responsibility.
The Commission published a Code of Practice on marking and labelling AI-generated content on June 10, 2026. It published guidelines on Article 50 on July 20, 2026. Our news story on how labs are rolling out text marking covers how companies are implementing these duties in practice.
Penalties
Under Article 99, fines reach €35 million or 7% of worldwide turnover for prohibited practices, €15 million or 3% for most other breaches, and €7.5 million or 1% for supplying misleading information to authorities. In each case the higher figure applies, except for SMEs and, after the Omnibus, small mid-caps, where the lower figure applies. National penalty regimes had to be in place by August 2, 2025.
What's confirmed and what's uncertain
Confirmed (official EU pages): all the dates in the table above; the Omnibus's entry into force on July 27, 2026; the GPAI Code of Practice signatory list as of October 7, 2026 (unchanged when re-checked on October 9); the wording of the new Article 5 prohibitions, Article 75c and the small mid-cap fine rule (Article 99(6a)) in the Omnibus text.
Less certain:
- The 10^23 FLOP and one-third figures come from the Commission's guidelines as summarized by two law firms (the 10^25 FLOP presumption is in Article 51(2) of the Act). They are indicative criteria, and the Commission can classify models case by case.
- How strictly the AI Office will use its new powers is still an open question. Its enforcement powers over GPAI providers have only existed since August 2, 2026.
- The political agreement on the Omnibus is dated May 7, 2026 on the Commission's page and May 6 in some law-firm accounts of the overnight negotiations. The adopted text and the dates it sets are not in dispute.
What to do next
- If you train or fine-tune models: check whether your fine-tuning compute crosses the one-third threshold. If you ship in the EU, prepare documentation and a training-data summary, and decide whether to sign the Code of Practice.
- If you build products on someone else's model: your main live duties are Article 50 transparency, AI literacy and the prohibitions. Our explainer for API-only teams walks through them.
- If you're comparing self-hosting with APIs: the open-source exemption and the license terms both matter. See frontier APIs vs open models: what they really cost.
- If you are in a high-risk area (hiring, credit, education, critical infrastructure): the Omnibus gives you until December 2, 2027. The requirements themselves have not been removed.
About this storyBased on the sources linked below. Editorial standards




