GovCompass

EU AI Act timeline 2025–2028: all deadlines after the omnibus agreement

By GovCompass.ai· Last updated August 2026· Aligned with the consolidated EU AI Act, including the 2026 Omnibus amendments.

The EU AI Act phases in between 2025 and 2028: the Art. 5 prohibitions and Art. 4 AI literacy applied from 2 February 2025, the Art. 50 transparency obligations from 2 August 2026, and the full high-risk obligations for Annex III systems from 2 December 2027 following the Omnibus amendments.

Part of the wider governance context. This article covers the EU AI Act. How the law fits into AI governance as a whole, from the seven pillars of responsible AI to the controls that keep systems inside agreed boundaries, starts at What is AI governance.

Updated: June 2026, reflects AI Omnibus agreement of May 2026

Introduction: the omnibus changes everything

The EU AI ActEU AI ActRegulation (EU) 2024/1689, the European Union's law on artificial intelligence. It takes a risk-based approach: prohibited practices, requirements for high-risk AI systems, transparency obligations for specific uses, and a separate regime for general-purpose AI models. Obligations are divided between providers and deployers. See general-purpose AI, conformity assessment.Open full entry → entered into force on 1 August 2024 with a graduated implementation timeline. The May 2026 AI Omnibus agreement, a legislative amendment to the original regulation, significantly revised the deadlines for high-riskriskIn the EU AI Act's terms, the combination of the likelihood that a harm occurs and the severity of it if it does. The link between a principle (via the harm that would breach it) and a control (the measure that reduces it). Naming the harm and assessing its risk is required by Art. 9 before any mitigation measure is chosen. See harm, control, residual risk.Open full entry → AI obligationsAI obligationsThe duties the AI Act places on a party, which depend on its role in the value chain and the system's risk tier.Open full entry →, providing additional time for both providersproviderThe actor who develops an AI system (or has it developed) and places it on the market or into service under its own name. It carries manufacturer-style duties: design controls, documentation, conformity.Open full entry → and deployersdeployerAn organization using an AI system under its own authority in its activities. It carries the operator duties: use per instructions, oversight, input relevance, monitoring, notices.Open full entry → to achieve compliance.

This article presents the definitive post-Omnibus timeline for all EU AI Act obligations, with practical implications for Dutch organizations at each stage.

The complete timeline

2 February 2025 ✅, now in force

Prohibited AI practices (Art. 5): All eight prohibitions are in full force. Organizations using AI systemsAI systemA machine-based system that, for explicit or implicit objectives, infers from input how to generate outputs (predictions, content, recommendations or decisions) that can influence physical or virtual environments. The OECD-style definition followed by the EU AI Act.Open full entry → that fall within the prohibited categories must have decommissioned or modified those systems. Supervisors in several member states have opened investigations.

AI LiteracyAI literacySufficient understanding of AI's workings, capabilities and risks for one's role, an explicit expectation for provider and deployer staff under the EU AI Act.Open full entry → (Art. 4): The obligation to ensure sufficient AI literacy among staff dealing with AI systems is in force. Training programs should be operational.

2 August 2025 ✅, now in force

GPAI obligations (Art. 52–55): Obligations for providers of general-purpose AI modelsgeneral-purpose AI modelEU AI Act term for a model displaying significant generality and capable of many distinct tasks, typically integrated into downstream systems; carries its own obligation set, with extra duties for models posing systemic risk.Open full entry →, including transparencytransparencyOpenness about the fact that AI is used and how it operates in general: disclosures, documentation, notices. Pairs with explainability, which addresses individual outcomes.Open full entry → requirements, copyright policy, technical documentationtechnical documentationRecords a provider must compile and keep for a high-risk AI system to demonstrate conformity, covering its design, data, testing, risk management and monitoring.Open full entry →, and (for systemic risksystemic riskEU AI Act category for the most capable general-purpose models (presumed above a training-compute threshold), triggering extra duties: evaluations, adversarial testing, incident reporting, cybersecurity.Open full entry → models) adversarial testing, are in force.

2 August 2026 ⚠️, approaching (2 months away)

Transparency obligations (Art. 50): AI-generated content labeling, chatbot disclosure obligations, and deepfakedeepfakeAI-generated or manipulated audio, image or video that convincingly depicts real people or events that did not occur; subject to labeling duties under the EU AI Act's transparency tier.Open full entry → labeling requirements come into force.

Full applicability: the regulation's general provisions and the national governancegovernanceThe system through which an organization steers itself: corporate governance, risk management, compliance, lines of accountability, risk appetite, and the operating model. It exists across everything the organization does, before and beyond AI. AI governance is this same system extended for AI. See AI governance, governance design, execution level.Open full entry → structures apply from this date. Note: there is no separate, earlier high-risk deadline for the public sector. Standalone Annex IIIAnnex IIIThe EU AI Act's list of high-risk use-case areas: biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, justice.Open full entry → high-risk obligations (Art. 26, FRIAFRIAFundamental Rights Impact Assessment: required of public bodies and certain private deployers before using some high-risk AI systems under the EU AI Act.Open full entry → under Art. 27, registration) apply from 2 December 2027 for all sectors, public and private alike (see below).

Codes of practicecodes of practiceVoluntary guidance under the AI Act, notably for general-purpose AI, that helps providers show compliance until harmonized standards exist.Open full entry →: GPAI providers must comply with the EU AI OfficeAI OfficeThe European Commission body that coordinates implementation of the EU AI Act and supervises general-purpose AI models. National market surveillance authorities enforce the Act for most AI systems; the AI Office is the central point for the general-purpose AI layer. See general-purpose AI, EU AI Act.Open full entry →'s approved codes of practice.

2 December 2027 🔜, NEW omnibus deadline

Stand-alone high-risk AI (Annex III): The original deadline was 2 August 2026. The Omnibus agreement extended this to 2 December 2027 for all sectors, public and private alike, there is no separate, earlier date for public authorities. This is the deadline for standalone Annex III high-risk systems, covering AI in HR, credit, healthcare, and similar contexts. The Omnibus is a provisional political agreement (May 2026); formal adoption and publication are expected in July 2026, and 2 December 2027 is the planning anchor pending that final adoption.

What this means for deployers: you have until December 2027 to achieve full Art. 26 compliance for Annex III systems. However, the preparatory work, inventory, classification, FRIA, DPIADPIAData Protection Impact Assessment: required before likely-high-risk processing (systematic profiling with significant effects, large-scale special categories, public monitoring); AI development triggers it constantly.Open full entry →, supplier documentation, governance setup, should begin now. 18 months sounds long. It is not, for organizations with complex AI estates.

2 August 2028 🔜, NEW omnibus deadline

High-risk AI in regulated products (Annex I): AI systems embedded in machinery, medical devices, vehicles, and other regulated products face this extended deadline (original: 2 August 2027).

What has NOT changed

The Omnibus changes affected timing, not substance. The full compliance obligations remain. Notably:

  • Art. 5 prohibitions: unchanged, in force since February 2025
  • Art. 4 literacy: unchanged, in force since February 2025
  • The risk classification framework: unchanged
  • The Art. 26 deployer obligation set: unchanged in content, extended in deadline

Enforcement outlook

No Dutch market surveillance authoritymarket surveillance authorityThe national body that enforces the AI Act in a member state, with powers to investigate, order corrective action and apply penalties.Open full entry → has been formally designated yet. The draft Uitvoeringswet AI-verordening (UAIV), in public consultation until 1 June 2026, proposes the AP and RDI as coordinating supervisors, the AP as market surveillance authority for prohibited practicesprohibited practicesAI uses banned outright under the AI Act, such as social scoring, manipulative techniques and untargeted scraping of facial images.Open full entry → (Art. 5), transparency (Art. 50) and much of Annex III, and the AFM and DNB for financial institutions. Until the UAIV enters into force the Regulation applies directly. The Omnibus deadline extensions do not affect the AP's supervisory powers over Art. 5 violations and AI literacy requirements.

Compliance checklist

  1. Are you compliant with Art. 5 (prohibited practices)? This is non-negotiable, it has been in force since February 2025.
  2. Is your Art. 4 AI literacy program operational?
  3. If you use GPAI models: are you monitoring your providers' Art. 52–55 compliance?
  4. For Art. 50 (August 2026): are AI-generated content labeling and chatbot disclosures in place?
  5. For Annex III high-risk AI: is your compliance roadmap targeting December 2027?
  6. Is your AI governance framework in place to manage the transition through all deadlines?

Teams preparing for these deadlines increasingly formalize the skill with the AIGP.

Continue withAccountability
Share Share on LinkedIn

More on Accountability

Agentic AI and governance: why autonomy sharpens the control question

Analysis

Agentic AI does not need a new kind of governance. Autonomy widens the gap between what a system does and who is accountable for it, which makes the existing governance chain, control tracing to risk and forward to evidence, more important, not less. The actions are real and sometimes irreversible, so the stakes on each control rise.

Agentic AI risk assessment: from architecture decisions to control objectives

Analysis

Assessing the risk of an AI agent does not need a separate method. The steps stay the same: recognize the risk, assess how likely and how severe it is for your system, and control it. What changes is the input. An agent runs the process through recorded architecture decisions, about the model, the instruction, retrieved knowledge, tools, orchestration, memory, and autonomy, and each of those decisions, alone or in combination, creates the possibility of harm. The output of the assessment is a set of risk scenarios with a control objective for each.

AI certification: what exists and what it proves

Analysis

AI certification is not one category. Three different objects are assessed, each by a different kind of assessor: a person, an organization's AI management system, and an AI system placed on the EU market. The first two can be certified. The third is subject to a legal conformity assessment, which produces a certificate on one of its two routes and none on the other. Identifying which object a credential covers is the first step to judging what it is worth.

AI governance and enterprise risk management: where they meet

Analysis

AI governance is not a parallel structure that sits beside enterprise risk management. It belongs inside it. The seven pillars of responsible AI are the control structure the organization uses to govern each AI system; enterprise risk management is the machine that carries the residual risk those controls leave behind into the board's risk appetite, the risk register, and the assurance plan. The practical question is not whether to build AI governance or ERM, but how to slot the first into the second so that one accountable structure, not two competing ones, owns AI risk.