For two years, 2 August 2026 was circled in every AI compliance calendar as the EU AI Act's big-bang date - the day the high-risk regime and most of the rest of the Regulation would apply in full. That is no longer what the date delivers. The Digital Omnibus on AI, adopted in June 2026, moved the heavy high-risk obligations to December 2027 and August 2028, while leaving the rest of the 2 August 2026 wave intact: transparency duties for chatbots and AI-generated content, the Commission's enforcement powers over general-purpose AI providers, and the full market-surveillance and penalty machinery. This pillar guide sets out the corrected timeline, wave by wave, with what each date means in practice.
This article is legal information, not legal advice. Obligations under the AI Act depend on your systems, your role in the value chain, and your member state - consult a qualified lawyer in your jurisdiction before acting.
What actually applies on 2 August 2026?
Three things activate on or around 2 August 2026: the Article 50 transparency obligations (people must be told when they interact with an AI system, and deepfakes must be disclosed), the Commission's power to fine general-purpose AI model providers up to EUR 15 million or 3% of worldwide turnover, and full market surveillance by national authorities under the Act's three-tier penalty framework. The high-risk regime does not arrive with them - the Digital Omnibus deferred it to 2 December 2027 for Annex III systems.
That answer needs one procedural footnote. The Omnibus was signed on 8 July 2026 but enters into force only on the third day after publication in the Official Journal, which was still pending as this article went to press in mid-July 2026. Until publication, the original Regulation (EU) 2024/1689 dates remain the letter of the law - a gap that matters mainly to teams that stood down their high-risk programmes on the strength of a political agreement.
The waves already in force: February 2025 and August 2025
The AI Act entered into force on 1 August 2024 and has been applying in waves since. The first wave, on 2 February 2025, switched on the Act's general provisions, the Article 4 AI literacy duty, and the Article 5 prohibitions - eight practices banned outright, including social scoring, untargeted scraping of facial images, individual crime-risk prediction based solely on profiling, and emotion recognition in workplaces and educational institutions. The European Commission published guidelines on the prohibited practices in February 2025 to steer interpretation.
The second wave, on 2 August 2025, brought the obligations for providers of general-purpose AI (GPAI) models - technical documentation, information for downstream builders, a copyright policy, and a published training-content summary on the AI Office's mandatory template - plus the Act's governance architecture and the deadline for member states to designate national authorities. The voluntary GPAI Code of Practice, published on 10 July 2025, became the practical compliance route; signatories include OpenAI, Google, Microsoft, Anthropic, Amazon, IBM, and Mistral AI. Models already on the market before 2 August 2025 have until 2 August 2027 to comply.
The Digital Omnibus: what moved, what did not
The Commission proposed the Digital Omnibus on AI in November 2025, citing delayed harmonised standards and unready national authorities; Parliament adopted it on 16 June 2026 and the Council gave final approval on 29 June 2026.
Four dates moved. Stand-alone high-risk systems under Annex III - hiring tools, credit scoring, education, law enforcement, the administration-of-justice category relevant to legal AI - now face full compliance on 2 December 2027. High-risk AI embedded in regulated products (Annex I) moved to 2 August 2028. Machine-readable watermarking for generative systems already on the market before 2 August 2026 moved to 2 December 2026. And the deadline for national regulatory sandboxes slipped to 2 August 2027.
The package tightened as well as loosened. A new prohibition on AI systems that generate non-consensual intimate imagery or child sexual abuse material joins Article 5, with compliance required by 2 December 2026. The AI Office gained exclusive supervisory powers over AI systems built by a provider on its own general-purpose model and over AI embedded in designated very large online platforms. What did not move at all: the Article 5 prohibitions in force since February 2025, the GPAI obligations in force since August 2025, Article 50 transparency from 2 August 2026, and every penalty ceiling. Our companion piece on deployer obligations for law firms maps these dates to concrete duties.
The full corrected timeline
This is the wave-by-wave schedule as it stands in mid-July 2026, incorporating the Digital Omnibus deferrals.
| Date | What applies | Who it principally affects |
|---|---|---|
| 2 Feb 2025 | Article 5 prohibitions; Article 4 AI literacy | Every provider and deployer |
| 2 Aug 2025 | GPAI model obligations; governance bodies; national authority designation | Model providers; member states |
| 2 Aug 2026 | Article 50 transparency; Commission GPAI fining powers; full market surveillance and penalties | Providers and deployers of interactive and generative systems |
| 2 Dec 2026 | Watermarking for pre-existing generative systems; new intimate-imagery prohibition | Generative AI providers |
| 2 Aug 2027 | Legacy GPAI models compliant; national sandboxes operational | Model providers; member states |
| 2 Dec 2027 | Annex III high-risk regime, including deployer duties and fundamental rights impact assessments | Deployers and providers of hiring, credit, justice-facing systems |
| 2 Aug 2028 | Annex I embedded high-risk regime | Product manufacturers |
| 2 Aug 2030 | Legacy high-risk systems used by public authorities | Public-sector deployers |
Two habits keep a timeline like this honest. Treat every future date as provisional until the underlying act is in the Official Journal, and re-verify against the Commission's AI Act Service Desk before you rely on a date in advice or a board paper.
Penalties: the fining machinery switches on
The Act's penalty ceilings were set from the start, but 2 August 2026 is when the machinery to impose them is fully live: national market surveillance authorities gain their complete toolkit, and the Commission can fine GPAI providers directly. The tiers are unchanged by the Omnibus: up to EUR 35 million or 7% of worldwide annual turnover for prohibited practices, up to EUR 15 million or 3% for breaching most other obligations, and up to EUR 7.5 million or 1% for supplying incorrect or misleading information to authorities, in each case whichever is higher - with SMEs capped at the lower figure instead.
Context tempers the headline numbers. As of mid-July 2026 no fine under the Act had been publicly confirmed, and reporting through the spring suggested many member states had still not fully stood up their enforcement authorities. Uneven readiness is not a reason to relax: penalty exposure for prohibited practices has been accumulating since February 2025, and the first enforcement actions tend to land on the clearest breaches.
What legal teams should do with the extra time
The Omnibus bought time on the hardest tier; it did not change what most legal teams must do first. Start with an inventory of every AI tool in use, then a classification pass - our guide to classifying legal AI under the Act walks through the tiers, and most lawyer-facing research and drafting tools land outside the high-risk category. Check the two duties already in force: nothing in your stack touches a prohibited practice, and an AI literacy programme exists and is documented.
Then prepare for the August 2026 wave. If your organisation deploys client-facing chatbots or publishes AI-generated content, Article 50 disclosure and marking duties need an owner. If you advise clients on any of this, the corrected timeline is itself the advisory product - the reset dates change project plans, budgets, and contract negotiations across every client that deploys AI in the EU. Research tools with verifiable citations make that advisory work materially faster: AI legal research grounded in primary sources is how a team keeps pace with a regulation that has amended itself before fully applying. For the EU market context, see our Europe jurisdiction hub.
How Judicio approaches the AI Act
Judicio is built for the compliance posture the Act rewards regardless of tier: citation-grounded outputs a lawyer can verify against the source, human review designed into every workflow, role-based access with an activity trail, and client documents that are never used to train models. Our general explainer of the Act covers the risk-tier architecture in depth, and the security page and methodology page document the controls that vendor due-diligence teams ask about.
If you are building your firm's AI Act file now, start with the timeline above and the governance policy template from this series. You can also try Judicio free for 7 days - 500 credits, no card required - or talk to us about how the platform fits an AI Act-ready stack.