
Artificial Intelligence
AI Act Timeline: What Applies Today (and What Waiting Could Cost You)
AI Act Timeline: What Applies Today (and What Waiting Could Cost You)


Faced with an AI Act implementation timeline stretching over several years, the temptation is obvious: wait for the dates to settle before acting.
That's a misreading. This regulatory calendar isn't just a checklist of deadlines. It's a progressive stress test of each organization's AI governance maturity, one milestone at a time.
This post helps you separate what's already in force from what's still subject to change, and what this time should be used to build, so you learn to apply this calendar to your own systems portfolio rather than simply endure it.
In a nutshell
The Digital Omnibus, formally adopted in June 2026, reshuffled part of the AI Act's timeline
The definitive prohibitions and the GPAI obligations are already in force, with no room for negotiation
August 2, 2026 remains the key date for the transparency obligations (Article 50), regardless of the high-risk deadline extension
High-risk systems now have until December 2, 2027 (Annex III) or August 2, 2028 (Annex I) to reach compliance
This extension does not excuse you from identifying the systems concerned within your IT estate right now
The right posture isn't to follow the calendar, but to build a governance model capable of absorbing it

Reminder: what is the AI Act?
Regulation (EU) 2024/1689, better known as the AI Act, pursues a clear goal: protecting fundamental rights and people's safety without limiting Europe's capacity to innovate. It governs the development, market placement, and use of AI systems in Europe, and its provisions apply progressively, in successive waves. Much as GDPR once did for personal data, the AI Act imposes a new discipline - this time for AI systems.

How to Ensure Compliance with the AI Act
Download the guide
Which obligations are already in force?
Definitive prohibitions and the AI literacy obligation
Since February 2, 2025, a series of practices classified as "unacceptable risk" have been purely and simply banned across the European Union:
Social scoring by public authorities
Subliminal manipulation
Exploitation of cognitive vulnerabilities
Real-time biometric identification in public spaces
For most companies, this category doesn't directly touch their portfolio. It's still worth checking, though, as certain behavioral profiling or internal monitoring systems can come closer to this line than they first appear to.
That same date also brought the AI literacy obligation into force, and it's already producing effects. Every organization must ensure its staff have a sufficient level of understanding of the systems they use or deploy. In practical terms, for an IT department, this means having verified that no prohibited system is still active, and having launched at least a minimal training effort for teams.
Obligations for general-purpose AI model providers
Since August 2, 2025, providers of general-purpose AI (GPAI) models have been subject to strengthened transparency and governance obligations.
This date also shaped the regulation's institutional governance, with each member state designating the competent national authorities responsible for oversight.
For a deployer, this AI Act compliance deadline isn't an abstract check. It means making sure the model providers used within the organization (whether built in natively or consumed through a third-party API) meet these obligations, and formalizing that in contracts.
A trap to avoid: delegating your compliance
An IT department often holds several regulatory roles at once:
Provider, when it develops and markets its own AI tools
Deployer, when it integrates third-party solutions
Importer, when it redistributes internally models developed outside the EU
This overlap has a direct consequence: compliance cannot be delegated to your suppliers. Even when a solution is bought off the shelf, the organization remains responsible for how it's used - from risk classification to human oversight to documentation.
What does the August 2, 2026 deadline really change?
The Article 50 transparency obligations
From August 2, 2026, any user interacting with an AI system must be informed of it. In practice, this transparency obligation applies to every AI system: a customer service chatbot, an internal virtual assistant, a business conversational interface…
All of them must clearly communicate their artificial nature and identify themselves as AI, with no ambiguity for the end user. This is one of the pillars of the Commission's stated goal: trustworthy artificial intelligence.
August 2, 2026 is also the reference date for most of the regulation's general obligations - the date most organizations have flagged as the one to remember.
Why this date shouldn't be confused with the high-risk extension
This is where the most common confusion arises. The extension that's been widely discussed since spring 2026 concerns exclusively the obligations relating to high-risk systems - not the Article 50 transparency obligations, which remain due on August 2, 2026, with no additional grace period.
An organization deploying chatbots or AI assistants therefore cannot rely on the high-risk extension to delay compliance on this specific point.
"The AI Act's timeline gives the illusion that you can follow it passively. In reality, every deadline does nothing more than reveal whether the groundwork (knowing precisely what's running in your IT estate) has been done or not."
- Fouzia Mahieddine, Smoteo co-founder
Why was the high-risk deadline pushed back?
Delayed harmonized standards behind the extension
The extension isn't a political retreat by the legislature: it's a technical consequence.
The obligations for high-risk systems rest on harmonized standards (risk management, data quality, documentation, human oversight) that the European standardization bodies (CEN and CENELEC) weren't able to deliver within the originally planned timeframe.
Without these standards, companies would not have known concretely what to do, nor how to demonstrate compliance to supervisory authorities. Entry into force on August 2, 2026 would therefore have created major legal uncertainty rather than a workable framework.
The definitive deadlines
The Digital Omnibus, formally adopted in June 2026, now sets two dates depending on the type of system:
December 2, 2027 for standalone high-risk systems (Annex III) - such as biometrics, critical infrastructure, education, employment, essential services, migration
August 2, 2028 for high-risk systems embedded in products already subject to other regulations (Annex I) - such as medical devices, machinery, lifts
The obligations that will apply on these dates remain the same as those already in force for other systems since August 2026: technical documentation, risk management, CE marking, registration in the European database, human oversight throughout the system's lifecycle. Only the calendar has changed, not the level of requirement.
"An extended deadline doesn't erase a governance shortfall. It only moves the moment when that shortfall becomes visible."
- Fouzia Mahieddine, Smoteo co-founder
Want a complete view of every AI Act deadline, obligation, and risk level, along with a detailed action plan? Download the full compliance guide.
Which systems in your portfolio fall under high risk?
The eight areas identified in Annex III
Annex III of the regulation lists eight areas in which certain AI uses are automatically classified as high risk. It isn't the technology itself that's targeted, but the context and purpose of its use:
Biometrics (identification and categorization of individuals)
Critical infrastructure (energy, water, transport, digital)
Education and vocational training
Employment, worker management, and access to self-employment
Access to essential public and private services (credit, insurance, social benefits)
Law enforcement
Migration, asylum, and border management
Administration of justice and democratic processes
The most common cases for your IT department
For an IT department, the most frequent cases are:
Automated resume screening, candidate scoring, and performance evaluation (HR and recruitment)
Bank or insurance credit scoring
AI-assisted medical diagnosis
School assessment involving AI components
Safety of critical infrastructure (energy, water, transport)
Border control and identity verification
The same system can be classified as high risk in one organization and not in another: it all depends on the deployment context and the activity it actually influences. An HR recommendation tool, for instance, can shift from one category to another depending on how it's used.
A trap to avoid: classifying the software rather than the use case
Many organizations make the same mistake the first time around: they try to classify a tool, when it's actually the use that needs to be classified.
The same system can therefore generate different classifications depending on the contexts in which it's deployed. If your ERP, ATS, or CRM includes scoring or decision-recommendation features, you are a deployer of those features and subject to the corresponding obligations, whether you're aware of it or not. Documenting why a system was classified in a given category, and by whom, is worth as much as the classification itself.
How to turn this timeline into an action plan
The real risk isn't the date - it's the lack of visibility onto your IT ecosystem
Every AI Governance Act deadline assumes a silent prerequisite: knowing exactly which IT systems and AI agents operate within your organization, on what data, with what level of autonomy, and under whose responsibility. Without this visibility, no date can be anticipated - it can only be endured.
This is precisely what the timeline reveals, deadline after deadline: it's less a question of legal compliance than one of governance. Organizations that start now build this visibility progressively. Those that wait for the next deadline will have to reconstruct it under time pressure, in a rush. And this can't be improvised.
Why a one-off audit isn't enough to hold up over time
Even a rigorous AI audit produces a snapshot at a single point in time. Yet the AI Act's timeline stretches over several years, with systems that evolve, new uses that emerge, and teams that deploy tools without always reporting back to the IT department.
A registry frozen in a spreadsheet, or an audit carried out six months earlier, no longer reflects the reality of your IT estate. The visibility needed to navigate this calendar isn't therefore a state you reach once, but a capability you maintain continuously - something most traditional governance tools, designed for one-off checkpoints, simply don't allow.
What does that look like with Smoteo?
This is exactly the gap Smoteo closes:
The usage registry continuously centralizes every active AI system and initiative by department, along with their application context, owners, and qualified risk level. It's updated in real time rather than reconstructed at each deadline.
The AI Value Stream Map visually maps where these agents operate across your business and IT ecosystem: which domains they cover, which data they consume, which business capabilities they touch.
You end up with a documentation base that's directly usable against AI Act requirements, and that remains valid no matter how the calendar evolves next. Organizations that use Smoteo to structure themselves this way cut their pre-production non-compliance risk by 30%.
Take the lead on the AI Act timeline rather than just following it
The AI Act's timeline will likely keep evolving: new clarifications will come, standards will be published, some dates may still shift.
An organization that has built visibility into its IT estate rides out these adjustments without disruption. The question, then, isn't knowing the next date. It's knowing whether your organization would be ready, whatever date is set.
To go further, download the full AI Act compliance guide, with the details of every deadline, the four risk levels, and a seven-step action plan.

Practical Guide
How to Ensure Compliance with the AI Act
Deadline schedule, risk levels, and a comprehensive checklist to keep your project on track
Faced with an AI Act implementation timeline stretching over several years, the temptation is obvious: wait for the dates to settle before acting.
That's a misreading. This regulatory calendar isn't just a checklist of deadlines. It's a progressive stress test of each organization's AI governance maturity, one milestone at a time.
This post helps you separate what's already in force from what's still subject to change, and what this time should be used to build, so you learn to apply this calendar to your own systems portfolio rather than simply endure it.
In a nutshell
The Digital Omnibus, formally adopted in June 2026, reshuffled part of the AI Act's timeline
The definitive prohibitions and the GPAI obligations are already in force, with no room for negotiation
August 2, 2026 remains the key date for the transparency obligations (Article 50), regardless of the high-risk deadline extension
High-risk systems now have until December 2, 2027 (Annex III) or August 2, 2028 (Annex I) to reach compliance
This extension does not excuse you from identifying the systems concerned within your IT estate right now
The right posture isn't to follow the calendar, but to build a governance model capable of absorbing it

Reminder: what is the AI Act?
Regulation (EU) 2024/1689, better known as the AI Act, pursues a clear goal: protecting fundamental rights and people's safety without limiting Europe's capacity to innovate. It governs the development, market placement, and use of AI systems in Europe, and its provisions apply progressively, in successive waves. Much as GDPR once did for personal data, the AI Act imposes a new discipline - this time for AI systems.

How to Ensure Compliance with the AI Act
Download the guide
Which obligations are already in force?
Definitive prohibitions and the AI literacy obligation
Since February 2, 2025, a series of practices classified as "unacceptable risk" have been purely and simply banned across the European Union:
Social scoring by public authorities
Subliminal manipulation
Exploitation of cognitive vulnerabilities
Real-time biometric identification in public spaces
For most companies, this category doesn't directly touch their portfolio. It's still worth checking, though, as certain behavioral profiling or internal monitoring systems can come closer to this line than they first appear to.
That same date also brought the AI literacy obligation into force, and it's already producing effects. Every organization must ensure its staff have a sufficient level of understanding of the systems they use or deploy. In practical terms, for an IT department, this means having verified that no prohibited system is still active, and having launched at least a minimal training effort for teams.
Obligations for general-purpose AI model providers
Since August 2, 2025, providers of general-purpose AI (GPAI) models have been subject to strengthened transparency and governance obligations.
This date also shaped the regulation's institutional governance, with each member state designating the competent national authorities responsible for oversight.
For a deployer, this AI Act compliance deadline isn't an abstract check. It means making sure the model providers used within the organization (whether built in natively or consumed through a third-party API) meet these obligations, and formalizing that in contracts.
A trap to avoid: delegating your compliance
An IT department often holds several regulatory roles at once:
Provider, when it develops and markets its own AI tools
Deployer, when it integrates third-party solutions
Importer, when it redistributes internally models developed outside the EU
This overlap has a direct consequence: compliance cannot be delegated to your suppliers. Even when a solution is bought off the shelf, the organization remains responsible for how it's used - from risk classification to human oversight to documentation.
What does the August 2, 2026 deadline really change?
The Article 50 transparency obligations
From August 2, 2026, any user interacting with an AI system must be informed of it. In practice, this transparency obligation applies to every AI system: a customer service chatbot, an internal virtual assistant, a business conversational interface…
All of them must clearly communicate their artificial nature and identify themselves as AI, with no ambiguity for the end user. This is one of the pillars of the Commission's stated goal: trustworthy artificial intelligence.
August 2, 2026 is also the reference date for most of the regulation's general obligations - the date most organizations have flagged as the one to remember.
Why this date shouldn't be confused with the high-risk extension
This is where the most common confusion arises. The extension that's been widely discussed since spring 2026 concerns exclusively the obligations relating to high-risk systems - not the Article 50 transparency obligations, which remain due on August 2, 2026, with no additional grace period.
An organization deploying chatbots or AI assistants therefore cannot rely on the high-risk extension to delay compliance on this specific point.
"The AI Act's timeline gives the illusion that you can follow it passively. In reality, every deadline does nothing more than reveal whether the groundwork (knowing precisely what's running in your IT estate) has been done or not."
- Fouzia Mahieddine, Smoteo co-founder
Why was the high-risk deadline pushed back?
Delayed harmonized standards behind the extension
The extension isn't a political retreat by the legislature: it's a technical consequence.
The obligations for high-risk systems rest on harmonized standards (risk management, data quality, documentation, human oversight) that the European standardization bodies (CEN and CENELEC) weren't able to deliver within the originally planned timeframe.
Without these standards, companies would not have known concretely what to do, nor how to demonstrate compliance to supervisory authorities. Entry into force on August 2, 2026 would therefore have created major legal uncertainty rather than a workable framework.
The definitive deadlines
The Digital Omnibus, formally adopted in June 2026, now sets two dates depending on the type of system:
December 2, 2027 for standalone high-risk systems (Annex III) - such as biometrics, critical infrastructure, education, employment, essential services, migration
August 2, 2028 for high-risk systems embedded in products already subject to other regulations (Annex I) - such as medical devices, machinery, lifts
The obligations that will apply on these dates remain the same as those already in force for other systems since August 2026: technical documentation, risk management, CE marking, registration in the European database, human oversight throughout the system's lifecycle. Only the calendar has changed, not the level of requirement.
"An extended deadline doesn't erase a governance shortfall. It only moves the moment when that shortfall becomes visible."
- Fouzia Mahieddine, Smoteo co-founder
Want a complete view of every AI Act deadline, obligation, and risk level, along with a detailed action plan? Download the full compliance guide.
Which systems in your portfolio fall under high risk?
The eight areas identified in Annex III
Annex III of the regulation lists eight areas in which certain AI uses are automatically classified as high risk. It isn't the technology itself that's targeted, but the context and purpose of its use:
Biometrics (identification and categorization of individuals)
Critical infrastructure (energy, water, transport, digital)
Education and vocational training
Employment, worker management, and access to self-employment
Access to essential public and private services (credit, insurance, social benefits)
Law enforcement
Migration, asylum, and border management
Administration of justice and democratic processes
The most common cases for your IT department
For an IT department, the most frequent cases are:
Automated resume screening, candidate scoring, and performance evaluation (HR and recruitment)
Bank or insurance credit scoring
AI-assisted medical diagnosis
School assessment involving AI components
Safety of critical infrastructure (energy, water, transport)
Border control and identity verification
The same system can be classified as high risk in one organization and not in another: it all depends on the deployment context and the activity it actually influences. An HR recommendation tool, for instance, can shift from one category to another depending on how it's used.
A trap to avoid: classifying the software rather than the use case
Many organizations make the same mistake the first time around: they try to classify a tool, when it's actually the use that needs to be classified.
The same system can therefore generate different classifications depending on the contexts in which it's deployed. If your ERP, ATS, or CRM includes scoring or decision-recommendation features, you are a deployer of those features and subject to the corresponding obligations, whether you're aware of it or not. Documenting why a system was classified in a given category, and by whom, is worth as much as the classification itself.
How to turn this timeline into an action plan
The real risk isn't the date - it's the lack of visibility onto your IT ecosystem
Every AI Governance Act deadline assumes a silent prerequisite: knowing exactly which IT systems and AI agents operate within your organization, on what data, with what level of autonomy, and under whose responsibility. Without this visibility, no date can be anticipated - it can only be endured.
This is precisely what the timeline reveals, deadline after deadline: it's less a question of legal compliance than one of governance. Organizations that start now build this visibility progressively. Those that wait for the next deadline will have to reconstruct it under time pressure, in a rush. And this can't be improvised.
Why a one-off audit isn't enough to hold up over time
Even a rigorous AI audit produces a snapshot at a single point in time. Yet the AI Act's timeline stretches over several years, with systems that evolve, new uses that emerge, and teams that deploy tools without always reporting back to the IT department.
A registry frozen in a spreadsheet, or an audit carried out six months earlier, no longer reflects the reality of your IT estate. The visibility needed to navigate this calendar isn't therefore a state you reach once, but a capability you maintain continuously - something most traditional governance tools, designed for one-off checkpoints, simply don't allow.
What does that look like with Smoteo?
This is exactly the gap Smoteo closes:
The usage registry continuously centralizes every active AI system and initiative by department, along with their application context, owners, and qualified risk level. It's updated in real time rather than reconstructed at each deadline.
The AI Value Stream Map visually maps where these agents operate across your business and IT ecosystem: which domains they cover, which data they consume, which business capabilities they touch.
You end up with a documentation base that's directly usable against AI Act requirements, and that remains valid no matter how the calendar evolves next. Organizations that use Smoteo to structure themselves this way cut their pre-production non-compliance risk by 30%.
Take the lead on the AI Act timeline rather than just following it
The AI Act's timeline will likely keep evolving: new clarifications will come, standards will be published, some dates may still shift.
An organization that has built visibility into its IT estate rides out these adjustments without disruption. The question, then, isn't knowing the next date. It's knowing whether your organization would be ready, whatever date is set.
To go further, download the full AI Act compliance guide, with the details of every deadline, the four risk levels, and a seven-step action plan.

Practical Guide
How to Ensure Compliance with the AI Act

About the Author

About the Author
Focus on What Matters
Everyone Drives Change, Smoteo Connects the Dots
Whatever your role - CIO, Architect, PMO, or Product Owner - we've got your back
Everyone Drives Change, Smoteo Connects the Dots
Whatever your role - CIO, Architect, PMO, or Product Owner - we've got your back