AI Act calendar: obligations and deadlines in 2026
A practical AI Act calendar for businesses: what already applies, what starts in August 2026 and the next transparency, GPAI and high-risk deadlines.
AI ACT · IMPLEMENTATION CALENDAR
The AI Act does not have one single application date. For an SME, the difference between an obligation that is already active, a rule starting in August 2026 and a deadline for high-risk systems can completely change the order of internal projects.
Why there are so many different dates
The Regulation entered into force in 2024, but its application was spread across several stages. Definitions, prohibited practices, AI literacy, general-purpose models, transparency and high-risk systems did not start at the same time. Commission guidelines, voluntary codes and amendments adopted in 2026 were then added to that calendar, making it risky to rely on an older article as the only source. [EU-REG] [EU-NAV]
A useful calendar must first answer the question “what role and system do we have?”. An SME using an assistant for documents does not track the same deadlines as a GPAI model provider. An application recommending stock levels must not be confused with a system embedded in a regulated product or used in an Annex III area. [EU-NAV] [EU-RISK]
2 February 2025: definitions, prohibitions and AI literacy
The first rules have applied since February 2025: the AI-system definition, a limited set of prohibited practices and the AI-literacy obligation. For most SMEs, staff literacy is the obligation with the broadest practical reach. It concerns people who operate or use AI systems on behalf of the organisation, not only the technical team. [EU-LIT] [EU-NAV]
The amendment entering into force in July 2026 retained the obligation to take measures but removed the idea that every person must reach one single legally prescribed level. There is no universal certificate that automatically resolves Article 4. The company should adapt information and preparation to knowledge, experience, role and context and be able to document the measures taken. [EU-LIT]
2 August 2025: obligations for GPAI models
Rules for providers of general-purpose AI models became applicable on 2 August 2025. They include documentation and information for downstream actors, a copyright-compliance policy and a public summary of training content; models with systemic risk face additional evaluation, safety and reporting requirements. [EU-GPAI-G] [EU-REG]
These obligations do not automatically transfer in full to an SME merely because it uses an API. The company must determine whether it provides a GPAI model, provides a system built on such a model or is only a deployer. A downstream product provider nevertheless needs relevant documents and information from the model provider for its own assessment. [EU-GPAI-G] [EU-A50]
2–3 August 2026: transparency and effective supervision
The transparency obligations in Article 50 start on 2 August 2026. In the situations defined by the Regulation, they cover informing people that they are interacting with an AI system, marking certain synthetic outputs in a detectable format and disclosing deepfake content or certain texts published to inform the public. [EU-A50] [EU-A50-G]
For AI literacy, the Commission’s updated material states that supervision and enforcement rules apply from 3 August 2026. This does not mean a company should rush the same course to everyone. It means it needs an explainable process: who uses AI, what they need to know, which risks are relevant and what evidence shows that the measure was implemented. [EU-LIT]
2 December 2026: a narrow transition, not a general delay
The Commission describes a limited transition for the technical marking obligation concerning generated or manipulated content for certain systems placed on the market before 2 August 2026. Those systems must comply with Article 50(2) from 2 December 2026. [EU-A50]
The transition does not postpone every transparency obligation and does not justify ignoring user information or disclosures that fall on the deployer. Content created before 2 August 2026 does not have to be labelled retroactively under this rule, although the Commission encourages voluntary labelling where possible and useful. [EU-A50]
2027 and 2028: existing GPAI and high-risk systems
From 2 August 2026, the Commission exercises its enforcement powers for obligations applying to providers of new GPAI models. Providers of models placed on the market before 2 August 2025 have until 2 August 2027 to comply with the relevant obligations. [EU-GPAI-G]
Under the current calendar presented by the Commission, rules for certain high-risk systems in areas such as biometrics, critical infrastructure, education, employment, migration and border control apply from 2 December 2027. For AI systems embedded in products such as robots, machinery or other products covered by harmonised legislation, the stated date is 2 August 2028. [EU-RISK] [EU-NAV]
What should be done now, not at the next deadline
An SME using AI should not begin by interpreting every annex. Start with an inventory of real uses, establish roles, identify workflows reaching customers or influencing people, verify interface transparency and prepare teams. For unclear situations, the official Compliance Checker and AI Act Service Desk provide a better orientation point than an unverified summary. [EU-DESK]
- Now: inventory, roles, AI literacy and screening for prohibited practices.
- By 2 August 2026: transparency for interactions and content according to role and use case.
- Before every launch: reassess purpose, data, vendor and affected people.
- For high-risk: follow the final guidance and the calendar applicable to the concrete use.
Official sources and verification date
- Regulation (EU) 2024/1689 — Artificial Intelligence Act
- European Commission — Navigating the AI Act
- European Commission — AI Literacy Questions & Answers
- European Commission — transparency obligations under Article 50
- European Commission — guidelines on transparency obligations
- European Commission — guidelines for general-purpose AI model providers
- European Commission — high-risk AI system classification
- European Commission — AI Act Service Desk and Compliance Checker