EU AI Act Explained: What Applies Now and Every Deadline to 2028
Enforcement started in August and the AI Omnibus moved the high-risk deadlines. Here is what the EU AI Act requires today, what comes next, and how big the fines are.

The EU AI Act has been fully enforceable since August 2, 2026, when the European Commission’s AI Office and national regulators began supervising it and new transparency rules for chatbots, deepfakes and AI-generated content took effect. The biggest remaining piece, the obligations for high-risk AI systems, was pushed back by the AI Omnibus to December 2, 2027 for sensitive uses such as hiring and credit scoring, and to August 2, 2028 for AI built into regulated products.
Key facts
- In force since: August 1, 2024; generally applicable since August 2, 2026
- Already applying: bans on eight AI practices and AI literacy duties (February 2025), general-purpose AI model rules (August 2025), transparency rules and enforcement (August 2026)
- Next deadlines: December 2, 2026, for machine-readable marking on generative AI systems already on the market; a new ban on AI “nudification” apps also takes effect in December 2026
- High-risk rules: December 2, 2027 (Annex III uses) and August 2, 2028 (AI in regulated products)
- Maximum fines: €35 million or 7% of global annual turnover for prohibited practices
What is the EU AI Act?
The AI Act, formally Regulation (EU) 2024/1689, is the European Union’s horizontal law on artificial intelligence. It sets rules for providers and deployers of AI systems in the EU market, including the big international AI labs. Rather than regulating the technology as a whole, it sorts uses of AI by the risk they pose and sets rules for each level.
The European Commission’s official overview of the AI Act describes four levels:
| Risk level | What it covers | What the law requires |
|---|---|---|
| Unacceptable risk | Practices seen as a clear threat to safety, livelihoods and rights, such as social scoring | Banned outright |
| High risk | Uses that can seriously affect health, safety or fundamental rights, such as CV sorting or credit scoring | Strict obligations before the system can be sold or used |
| Transparency risk | Chatbots, generative AI, deepfakes, emotion recognition | Disclosure and labelling duties |
| Minimal or no risk | Most AI in use today, such as spam filters and AI in video games | No new rules |
On top of this sits a separate set of rules for general-purpose AI (GPAI) models, the large foundation models behind services like ChatGPT, Claude and Gemini, which we compared in our guide to every ChatGPT, Claude and Gemini plan.
EU AI Act timeline: what applies when
The law was designed to phase in over several years, and the AI Omnibus amendments adopted this summer moved some of the later dates. This is the timeline as it stands in late September 2026, based on the Commission’s published application dates:
| Date | What happens | Status |
|---|---|---|
| August 1, 2024 | AI Act enters into force | Done |
| February 2, 2025 | Eight prohibited practices banned; AI literacy obligations apply | In effect |
| August 2, 2025 | Governance rules and obligations for general-purpose AI models apply | In effect |
| July 27, 2026 | AI Omnibus amendments enter into force | In effect |
| August 2, 2026 | Act becomes generally applicable; Article 50 transparency rules apply; AI Office and national authorities start enforcing | In effect |
| December 2, 2026 | Marking and detection duty for generative AI systems placed on the market before August 2, 2026 | Upcoming |
| December 2026 | Ninth prohibition (AI that generates non-consensual intimate content or CSAM, such as nudification apps) takes effect | Upcoming |
| December 2, 2027 | High-risk rules for Annex III uses (biometrics, critical infrastructure, education, employment, migration and more) | Upcoming |
| August 2, 2028 | High-risk rules for AI in products covered by Annex I, such as lifts and toys | Upcoming |
What changed on August 2, 2026?
Two things switched on at once. First, enforcement began. In a press release on the start of AI Act enforcement, the Commission said that from August 2 its AI Office, together with national authorities, would begin enforcing the law. The AI Office holds the enforcement powers over general-purpose AI models: it can request technical documentation, evaluate models, require corrective measures and issue fines.
Second, the transparency obligations in Article 50 started to apply. In the Commission’s words, “chatbots and other interactive AI systems will have to tell users they are dealing with AI, not a human. Deepfakes (images, videos, or audio that have been edited or generated using AI) will have to be labelled. AI-generated or altered content will also have to carry machine-readable marks so it can be detected more easily.”
The transparency rules explained
Article 50 is the part of the AI Act most people will actually notice. The Commission’s FAQ on Article 50 transparency obligations breaks it into several duties:
Chatbots must say they are AI
Providers of AI systems that interact directly with people must make clear that the person is dealing with AI, unless that is already obvious to a reasonably well-informed, observant person. The Commission says the “obvious” exception should be read restrictively.
Generated content must be machine-readable
Providers of systems that generate synthetic audio, images, video or text must mark outputs in a machine-readable format so they can be detected as AI-generated. Some outputs fall outside this, including source code, short strings of numbers or letters, machine-to-machine outputs never shown to people, and standard editing assistance.
Deepfakes must be visibly labelled
Deployers who publish deepfakes must disclose them clearly at the latest on first exposure, using labels people can see or hear; a hidden watermark alone does not satisfy the duty. For evidently artistic, satirical or fictional work, the disclosure can be lighter so it does not spoil the work.
AI-written public-interest text must be labelled
Text generated or manipulated by AI and published to inform the public on matters of public interest, such as politics, public health or the economy, must be labelled. The exception is text that has gone through genuine human review or editorial control by someone who carries editorial responsibility. The Commission is explicit that spell-checking or grammar fixes do not count.
Emotion recognition must be disclosed
Deployers of emotion recognition or biometric categorisation systems must inform the people exposed to them.
There is a limited grace period. Generative AI systems placed on the market before August 2, 2026 have until December 2, 2026 to meet the machine-readable marking requirement, and content created before August 2 does not need to be labelled retroactively. To help companies comply, the Commission backed a voluntary Code of Practice on transparency of AI-generated content, which includes a set of disclosure icons; the Commission said more than 180 organisations were on the first list of signatories.
What is the AI Omnibus, and what did it delay?
The AI Omnibus is an amending regulation that the Commission proposed on November 19, 2025 as part of its digital simplification package. Parliament and Council reached a political agreement on the AI Omnibus on May 7, 2026, and the final text, published as Regulation (EU) 2026/1744, entered into force on July 27, 2026, days before the original August 2026 high-risk deadline.
Its headline change is timing. The Commission says the high-risk rules now apply from December 2, 2027 for systems used in sensitive areas and from August 2, 2028 for systems built into products, so that “technical standards and other support tools are in place before the rules start to apply.” The Omnibus also:
- adds a ninth prohibited practice, banning AI systems that generate non-consensual sexually explicit or intimate content or child sexual abuse material, such as “nudification” apps, effective in December 2026;
- strengthens the AI Office and centralises oversight of AI systems built on general-purpose AI models;
- extends some simplified requirements, including lighter technical documentation, from SMEs to small mid-cap companies;
- opens regulatory sandboxes to more innovators, including an EU-level sandbox;
- clarifies how the AI Act interacts with EU product safety laws such as the Machinery Regulation.
What it did not do is delay the transparency rules. Article 50 still applied from August 2, 2026, and the December 2, 2026 marking deadline for existing generative systems stands.
What AI is banned in the EU?
According to the Commission, the AI Act now prohibits nine practices:
- Harmful AI-based manipulation and deception
- Harmful AI-based exploitation of vulnerabilities
- Social scoring
- Individual criminal offence risk assessment or prediction
- Untargeted scraping of the internet or CCTV footage to build or expand facial recognition databases
- Emotion recognition in workplaces and education institutions
- Biometric categorisation to deduce certain protected characteristics
- Real-time remote biometric identification for law enforcement in publicly accessible spaces
- AI systems that generate non-consensual sexually explicit and intimate content or child sexual abuse material, such as nudification apps
The first eight have applied since February 2025. The ninth was added by the Omnibus and takes effect in December 2026.
What do the high-risk rules require?
High-risk uses listed by the Commission include AI in critical infrastructure, education and exam scoring, CV sorting and worker management, credit scoring and access to essential services, remote biometric identification, law enforcement, migration and border control, and the administration of justice. From December 2, 2027, such systems must meet strict obligations before they can be put on the market:
- adequate risk assessment and mitigation systems;
- high-quality training datasets to minimise discriminatory outcomes;
- activity logging so results can be traced;
- detailed documentation for authorities to assess compliance;
- clear information for the organisations deploying them;
- appropriate human oversight;
- a high level of robustness, cybersecurity and accuracy.
Once on the market, providers must run post-market monitoring, deployers must ensure human oversight, and both must report serious incidents and malfunctions.
What about ChatGPT, Gemini and other general-purpose models?
Providers of general-purpose AI models have had obligations since August 2025, covering transparency and copyright, with extra duties to assess and mitigate risks for models that may pose systemic risks. The Commission published three tools to support this in July 2025: guidelines on the scope of GPAI obligations, the voluntary General-Purpose AI Code of Practice covering transparency, copyright, and safety and security, and a template for a public summary of the content used to train each model. Since August 2026, the AI Office can enforce those obligations directly.
Who enforces the AI Act, and what are the fines?
Enforcement is split. National market surveillance authorities handle most AI systems. The AI Office handles general-purpose AI models, and for transparency duties it is also competent for AI systems built on a general-purpose model by the same provider, or integrated into a very large online platform or search engine under the Digital Services Act. The European Data Protection Supervisor covers AI used by EU institutions. The Commission has also launched an AI Act complaints tool and a whistleblower tool.
The penalty tiers are set out in Article 99 of the AI Act:
| Violation | Maximum fine (whichever is higher) |
|---|---|
| Using a prohibited AI practice | €35 million or 7% of worldwide annual turnover |
| Breaching other operator obligations, including Article 50 transparency | €15 million or 3% of worldwide annual turnover |
| Supplying incorrect, incomplete or misleading information to authorities | €7.5 million or 1% of worldwide annual turnover |
The Commission notes that proportionality can be taken into account for SMEs and small mid-caps.
What the AI Act means for you
- If you use AI tools in the EU: expect chatbots and AI voice agents to tell you they are not human, deepfakes to carry visible labels, and more AI-generated images and video to carry hidden machine-readable marks.
- If you publish AI-generated content: label deepfakes, and label AI-written text on matters of public interest unless it has genuinely been through human editorial review.
- If you build or sell AI products: check whether any use falls into Annex III. You now have until December 2, 2027 rather than August 2026, but conformity work takes time, and the transparency and GPAI rules already apply.
- If you only use minimal-risk AI: no new product rules, although the AI literacy obligations that have applied since February 2025 still matter for organisations using AI.
The Commission’s AI Act Service Desk and single information platform are the official places to check how a specific use case is classified.
What happens next
The next hard date is December 2, 2026, when older generative AI systems must support machine-readable marking; the nudification ban takes effect the same month. After that, attention shifts to the harmonised technical standards that high-risk providers will rely on before December 2027. For anyone building AI for the European market, the practical message of the Omnibus is that the deadlines moved, but the obligations themselves did not go away.
Frequently asked questions
Is the EU AI Act in force now?
Yes. It entered into force on August 1, 2024 and became generally applicable on August 2, 2026, when the Commission's AI Office and national authorities began enforcing it. Some high-risk rules apply later, in December 2027 and August 2028.
Did the EU delay the AI Act?
Partly. The AI Omnibus, in force since July 27, 2026, moved high-risk obligations for Annex III uses to December 2, 2027 and for AI in regulated products to August 2, 2028. Transparency rules and general-purpose AI rules were not delayed.
Do chatbots have to say they are AI in the EU?
Yes. Since August 2, 2026, Article 50 requires AI systems that interact directly with people to disclose that users are dealing with AI, unless that is already obvious.
What are the fines under the EU AI Act?
Up to 35 million euros or 7% of worldwide annual turnover for prohibited practices, up to 15 million euros or 3% for most other breaches including transparency duties, and up to 7.5 million euros or 1% for supplying misleading information to authorities.
Does AI-generated content have to be watermarked in the EU?
Providers of generative AI must mark outputs in a machine-readable format so they can be detected. Systems placed on the market before August 2, 2026 have until December 2, 2026 to comply, and deepfakes also need a visible label.
Are nudification apps banned in the EU?
Yes. The AI Omnibus added a ninth prohibited practice covering AI systems that generate non-consensual sexually explicit content or child sexual abuse material, such as nudification apps, which takes effect in December 2026.
Sources
- European Commission: AI Act regulatory frameworkdigital-strategy.ec.europa.eu
- European Commission: Transparency obligations under Article 50 FAQdigital-strategy.ec.europa.eu
- European Commission: Enforcement and transparency rules start on 2 Augustdigital-strategy.ec.europa.eu
- European Commission: Political agreement on the AI Omnibusdigital-strategy.ec.europa.eu
- AI Act Service Desk: Article 99 Penaltiesai-act-service-desk.ec.europa.eu
Theo Park runs the AI desk at Pandromeda. He follows model launches from the frontier labs and the open-weight community, tracks the assistants and developer tools built on them, and explains what each release changes on pricing, capability and safety. His reporting leans on primary sources: model cards, technical reports, API documentation and the companies' own announcements.


