AI Governance Intelligence · Europe 2026
The EU AI Act's Toughest Deadline Was Due 2 August 2026 — It Was Postponed to December 2027 Six Days Earlier
Transparency obligations for chatbots, deepfakes and AI-generated content became enforceable on schedule. High-risk system rules for recruitment, credit scoring and biometric identification did not — the EU rewrote its own law's timeline days before that deadline arrived.
€35M or 7% turnover — maximum fine (Article 99)
2 August 2026 — Article 50 transparency applicable
2 December 2027 — high-risk deadline, postponed from 2 August 2026
Updated 13 August 2026
Maximum Penalty
€35M
or 7% of global turnover, whichever higher ·
Article 99
Entry Into Force
Aug 2024
Transparency Applicable
Aug 2026
High-Risk Deadline
Dec 2027
GPAI Code Signatories
8
Amazon, Anthropic, Google, IBM, Microsoft, OpenAI, Aleph Alpha, Mistral AI ·
EU AI Office
SME Fine Cap
Lower
SMEs pay the lower of the two amounts, not the higher ·
Article 99.6
The AI Act no longer applies on the schedule it was written with. Transparency duties for chatbots, deepfakes and AI-generated content are live as of 2 August 2026. The chapter covering human oversight and risk management for high-risk systems in hiring, credit scoring and biometric identification was pushed to 2 December 2027 — in a rewrite that entered into force on 27 July 2026, six days before the original deadline. Amazon, Anthropic, Google, IBM, Microsoft and OpenAI signed the EU's voluntary rulebook for how they train and document their models; Meta did not.
The EU AI Act Timeline — Ten Dates, 2024 to 2028
From entry into force to the final high-risk deadline
Compiled from the European Commission, artificialintelligenceact.eu, and law firm analysis of Regulation (EU) 2026/1744 (the "Digital Omnibus on AI"). The two dates marked Postponed were moved by the Omnibus; every other date on this list is unchanged from the original 2024 text.
1 August 2024
The AI Act enters into force
Published in the EU Official Journal on 12 July 2024; entered into force 20 days later. Source:
European Commission.
2 February 2025
Prohibited practices and AI literacy obligations apply
Article 5 bans on unacceptable-risk systems (e.g. social scoring, manipulative or subliminal techniques) and Article 4 AI literacy duties become applicable. Source:
artificialintelligenceact.eu.
2 August 2025
General-purpose AI (GPAI) obligations apply
Governance rules and provider obligations under Articles 53–55 become applicable. The voluntary GPAI Code of Practice, published 10 July 2025, enters application the same day. Source:
EU AI Office / Wikipedia.
19 November 2025
The European Commission proposes the Digital Omnibus on AI
Cites delays in the designation of national competent authorities and the finalisation of harmonised standards as the reason for proposing a postponement. Source:
Gibson Dunn.
16 June – 27 July 2026
The Omnibus is adopted and enters into force
European Parliament vote 16 June 2026, Council adoption 29 June 2026, signed 8 July 2026, published in the Official Journal 24 July 2026 as Regulation (EU) 2026/1744, in force 27 July 2026. Source:
Hunton.
2 August 2026 — now applicable
Article 50 transparency obligations become enforceable
Providers and deployers of chatbots, emotion-recognition systems and AI-generated or manipulated content (including deepfakes) must disclose AI involvement. The Omnibus left this date "largely unaffected." Source:
European Commission.
2 December 2026
Two transitional deadlines close
A four-month grace period for machine-readable watermarking of AI content on systems already on the market before 2 August 2026 ends. The Omnibus's new Article 5 prohibition on AI-generated non-consensual intimate imagery and child sexual abuse material also becomes fully enforceable. Source:
Gibson Dunn.
2 December 2027 — postponed
High-risk obligations apply to stand-alone Annex III systems
Recruitment, credit-scoring, law enforcement, education and border-control AI systems. Originally due 2 August 2026; postponed 16 months by the Digital Omnibus. Source:
Gibson Dunn.
2 August 2028 — postponed
High-risk obligations apply to Annex I product-embedded AI
AI safety components already regulated under other EU product law (e.g. machinery, toys, lifts). Originally due 2 August 2027; postponed 12 months by the Digital Omnibus. Source:
Gibson Dunn.
What €35 Million Actually Means — The Three-Tier Penalty Structure
Maximum administrative fines under Article 99 (€, log of severity)
Source:
EU AI Act — Article 99. Each tier is "whichever is higher" of the euro figure or the turnover percentage — except for SMEs, where Article 99.6 flips the rule to "whichever is lower."
Tier 1 — Prohibited AI practices (Article 5)€35M or 7%
The highest tier in the regulation — applies to systems the Act bans outright, such as social scoring or manipulative/subliminal techniques.
Tier 2 — Other obligations (incl. Article 50 transparency)€15M or 3%
Covers provider, importer, distributor and deployer duties (Articles 16, 22–26) and the Article 50 transparency obligations that took effect 2 August 2026.
Tier 3 — False or misleading information€7.5M or 1%
Applies to incorrect, incomplete or misleading information supplied to notified bodies or competent authorities.
Article 99.6 reverses the "whichever is higher" rule for SMEs, including start-ups. A small company faces the lower of the two amounts, not the higher — meaningful relief for the same violation that could cost a large enterprise the full 7% of turnover.
Four Risk Tiers, One Regulation
Prohibited
Unacceptable Risk — Banned Outright
Systems deploying subliminal, manipulative or deceptive techniques; social scoring; and, following the Digital Omnibus, AI-generated non-consensual intimate imagery and child sexual abuse material.
- Applicable since 2 February 2025 (Article 5)
- New prohibitions from the Omnibus apply fully from 2 December 2026
High-Risk
Annex III & Annex I Systems
Eight use-case categories (below) plus AI embedded in products already regulated under other EU law. Subject to risk management, data governance, technical documentation and human-oversight requirements.
- Stand-alone Annex III systems: 2 December 2027 (postponed)
- Annex I product-embedded systems: 2 August 2028 (postponed)
Limited Risk
Transparency Obligations — Article 50
Chatbots, emotion-recognition and biometric-categorisation systems, and AI-generated or manipulated content (deepfakes). Requires disclosure that the user is interacting with or viewing AI output.
- Applicable now — 2 August 2026
- Watermarking grace period for pre-existing systems ends 2 December 2026
Minimal Risk
Unregulated Applications
Spam filters, most current AI-enabled inventory, pricing and recommendation tools. No obligations under the Act, though the Commission encourages voluntary codes of conduct.
- The category most current EU-market AI still falls into
The Eight High-Risk Categories Under Annex III
Category 1
Biometrics
Remote biometric identification, biometric categorisation by sensitive attributes, and emotion-recognition systems.
Category 2
Critical Infrastructure
AI safety components managing digital infrastructure, road traffic, and utility supply systems.
Category 3
Education & Vocational Training
Systems for admission decisions, learning evaluation, assessment of educational level, and monitoring of student behaviour.
Category 4
Employment & Workers Management
Recruitment filtering and evaluation; systems affecting work terms, promotions, task allocation or performance monitoring.
Category 5
Essential Private & Public Services
Eligibility assessment for benefits and healthcare, creditworthiness evaluation, insurance risk assessment, and emergency-call triage.
Category 6
Law Enforcement
Risk assessment of re-offending or victimisation, polygraph tools, evidence-reliability evaluation, and criminal profiling.
Category 7
Migration, Asylum & Border Control
Security and health risk assessment, asylum-application evaluation, and person-detection systems (excluding travel-document verification).
Category 8
Justice & Democratic Processes
Judicial decision-support systems and AI intended to influence election outcomes or voting behaviour.
Why Meta Didn't Sign the EU AI Act?
The General-Purpose AI Code of Practice
Published by the EU AI Office 10 July 2025 under Article 56, to help GPAI model providers demonstrate compliance with Articles 53 (transparency) and 55 (systemic-risk safety) ahead of the 2 August 2025 obligation date. Signing is voluntary — non-signatories must still meet the underlying legal obligations by other means.
"The Code introduces legal uncertainties for model developers, as well as measures which go far beyond the scope of the AI Act."
— Joel Kaplan, Meta Chief Global Affairs Officer · Source:
The Register
Signed
Full Code — All Three Chapters
- Amazon
- Anthropic
- Google
- IBM
- Microsoft
- OpenAI
- Aleph Alpha (Germany)
- Mistral AI (France)
Partial Signatory
Safety & Security Chapter Only
Declined
Did Not Sign
- Meta
- Alibaba
- Baidu
- DeepSeek
Signatory status verified against the European Commission's registry on
5 July 2026 — signing is ongoing and the list can change. Check the
live registry before treating this as current.
What the Digital Omnibus Actually Changed
Provision
Original Deadline
Revised Deadline
High-risk stand-alone systems (Annex III)
2 August 2026
2 December 2027
High-risk product-embedded systems (Annex I)
2 August 2027
2 August 2028
Watermarking of AI content, pre-existing systems
2 August 2026
2 December 2026 (grace period)
Member-state regulatory sandboxes
2 August 2026
2 August 2027
Article 50 transparency obligations
Unchanged — 2 August 2026
Explicitly left "largely unaffected" by the Omnibus
Article 5 prohibited practices
Unchanged — 2 February 2025
Continues applying without interruption; new prohibitions added on top
Beyond the deadline changes, the Omnibus (Regulation (EU) 2026/1744): extends simplified technical-documentation rules to medium-sized companies, not only micro and small ones; broadens the EU AI Office's supervisory role over general-purpose AI models; reinstates a simplified registration requirement for certain AI systems; restores a stricter standard for processing special-category personal data for bias detection; and softens the Article 4 AI literacy obligation from guaranteeing specific staff literacy levels to supporting staff development.
Strategic Priorities — What Companies Should Track Now
Priority 2 · Watermarking
The watermarking grace period closes 2 December 2026
Systems already on the market before 2 August 2026 have a four-month extension for machine-readable AI content marking — but only for that specific requirement, not for the visible-disclosure duty itself.
Priority 3 · High-Risk Timeline
16 extra months does not mean 16 months of nothing
Companies running Annex III systems — recruitment tools, credit-scoring models, biometric identification — now have until 2 December 2027. Risk-management and documentation infrastructure for these systems typically takes longer to build than the delay itself.
Priority 4 · SME Status
Confirm SME classification before estimating exposure
Article 99.6 caps SME and start-up fines at the lower of the euro amount or the turnover percentage, reversing the standard "whichever is higher" rule for larger enterprises.
Priority 5 · Vendor Risk
GPAI Code adherence is now a vendor due-diligence question
Amazon, Anthropic, Google, IBM, Microsoft and OpenAI signed the voluntary Code of Practice; Meta did not. Companies building on third-party models may need to assess this position as part of vendor risk review.
Priority 6 · New Prohibitions
A new Article 5 ban takes full effect 2 December 2026
The Digital Omnibus added a prohibition on AI systems generating non-consensual intimate imagery and child sexual abuse material, with a transitional period to 2 December 2026.
About the Author
TrendsOnFire is a AI based market intelligence platform publishing analysis on retail, technology, supply chain, finance, compliance, education, people and transformation trends across Europe.
Created by Olga Bressers, a senior executive with experience in sales & digital operations, ecommerce, omni-channel retail, supply chain, programs management and business transformation.
Contact →