The AI Act in 2026: timeline, obligations and when enforcement really begins
2 August 2026 marks the decisive milestone of the European AI Regulation. From that date, the majority of AI Act obligations move from "preparation" to "effective enforcement." If you haven't yet done an inventory of your organization's AI systems, this is the last reasonable quarter to start.
Updated 11 August 2026: the Digital Omnibus (Regulation (EU) 2026/1744, published in the EU Official Journal on 24 July 2026, in force since 27 July) postponed the Annex III high-risk obligations from 2 August 2026 to 2 December 2027, and the Annex I ones to 2 August 2028. 2 August 2026 remains a real date, but only for Art. 50 transparency — not for the bulk of the Regulation described below. National regulatory sandboxes, also originally due 2 August 2026, were postponed too — to 2 August 2027. And the Digital Omnibus added two new Article 5 prohibitions — AI-generated non-consensual intimate imagery and CSAM — in force from 2 December 2026. Source: EUR-Lex, Regulation (EU) 2026/1744.
What exactly changes on 2 August 2026
The AI Act entered into force on 1 August 2024, but its application has been phased. Some blocks have been in force since 2025 (prohibitions, AI literacy, general-purpose AI model obligations). What changes on 2 August 2026 is the transparency obligations of Article 50 and the activation of national enforcement powers. The full regime for high-risk systems under Annex III — originally due the same day — no longer applies on this date: the Digital Omnibus pushed it to 2 December 2027, and national regulatory sandboxes to 2 August 2027 (see below).
The European Commission and the AI Act Service Desk make it clear: 2026 is still a real enforcement milestone, just a narrower one than originally planned. The accurate phrase now is that "August 2026 is when transparency and enforcement powers become effective; the heaviest obligations, for high-risk systems, now land in December 2027."
Definitive AI Act timeline
These are the key dates you need to know and communicate internally:
| Date | What comes into force |
|---|---|
| 2 Feb 2025 | Prohibitions under Art. 5 (unacceptable risk AI systems) + AI literacy obligations under Art. 4. |
| 2 Aug 2025 | Obligations for GPAI model providers (Chapter V), institutional governance (AI Office operational), and enforcement regime at Member State level. |
| 2 Aug 2026 | Art. 50 transparency and full enforcement powers. Annex III high-risk and national sandboxes, which were due here, no longer apply on this date — postponed by the Digital Omnibus. |
| 2 Dec 2026 (new) | Two new Art. 5 prohibitions added by the Digital Omnibus: AI-generated non-consensual intimate imagery and CSAM. The extended Art. 50.2 deadline (synthetic content marking) also lands here. |
| 2 Aug 2027 (previously: 2 Aug 2026) | Each Member State must have at least one national regulatory sandbox operational. Postponed by the Digital Omnibus. |
| 2 Dec 2027 | Full application of Annex III high-risk obligations (Arts. 8–15) — new date after the Digital Omnibus (Regulation (EU) 2026/1744), 16 months after the original. |
| 2 Aug 2028 | Application to high-risk systems embedded in products regulated by EU harmonised legislation (Annex I) — new date after the Digital Omnibus. |
The four risk categories, in one phrase each
The Regulation organises AI systems into four risk levels, and everything else hangs off them:
- Unacceptable risk: directly prohibited. Subliminal manipulation, government social scoring, real-time biometric identification in public spaces (with limited exceptions), among others — applicable since February 2025. The Digital Omnibus added two more prohibitions, in force from 2 December 2026: AI-generated non-consensual intimate imagery and CSAM.
- High risk: systems that may affect fundamental rights or safety. Education, employment, essential services, justice, border control, critical infrastructure. This is where the bulk of compliance sits: Arts. 8 to 15 and the full system lifecycle (risk management, data governance, technical documentation, automatic logging, transparency, human oversight, robustness and accuracy).
- Limited risk: transparency obligations under Art. 50. Chatbots and deepfakes must inform users that they are interacting with AI or that content has been generated/manipulated.
- Minimal risk: no specific obligations, though voluntary adoption of codes of conduct is encouraged.
GPAI: the special case
General-purpose AI models (GPAI) have their own calendar. Their obligations (Chapter V) came into force in August 2025, but the Commission's enforcement powers over GPAI providers do not activate until 2 August 2026. That is: during this first year, providers of models like GPT, Claude, Gemini or Llama have been obligated, but the Commission could not fine them; from August, it can.
For GPAI models placed on the market before 2 August 2025, the deadline extends to 2 August 2027. This is the clause giving leeway to adapt pre-existing models.
Fines are deterrent: up to €35 million or 7% of global annual turnover (whichever is higher) for serious breaches of the prohibitions regime. For breaches of provider or deployer obligations, up to €15 million or 3% of global annual turnover.
Who enforces the Regulation in Spain
Enforcement is two-tiered. At European level, the Commission acts through the AI Office, fully operational since August 2025, with exclusive competences over GPAI. At national level, each Member State designates one or more market authorities. Spain was a pioneer: in 2024 it created the Spanish Agency for the Supervision of Artificial Intelligence (AESIA), based in A Coruña.
The AEPD retains its role as data protection authority and, by extension, over any AI system that processes personal data. In July 2025 it published guidance clarifying that it can already act against prohibited AI systems that process personal data, even before full AI Act application. In practice, for many cases in Spain you will not have one authority but two, and both must be coordinated in your compliance plan.
What to do now if you haven't prepared yet
The Digital Omnibus bought most organisations 16 extra months — full high-risk compliance is now due 2 December 2027, not August 2026. That's real breathing room, not a reason to wait: the four tasks below take months to do properly, and December 2027 arrives sooner than it looks.
1. Complete inventory of AI systems
Exhaustive list of all systems with an AI component that your organisation develops, deploys or uses. Include not just in-house models: also count SaaS platforms with embedded AI (CRM, HR, marketing, customer service). A typical company discovers twice as many systems as it thought when doing this inventory.
2. Risk classification
Each system in the inventory is mapped against the four categories. Annex III of the Regulation is the reference: eight areas that automatically classify a system as high-risk (biometrics, critical infrastructure, education, employment, essential private/public services, law enforcement, borders, justice and democratic processes).
3. AI literacy programme
Mandatory since February 2025 (Art. 4), though the Digital Omnibus softened its wording: it no longer requires you to "ensure" an outcome, only to "take measures" to promote it — an obligation of effort, not of result, but still binding on every deployer. There is no defined measure of "sufficient", but the European Commission — and, in Spain, also the AEPD — consider simply sending a PDF insufficient: documented, role-adapted and registrable training is expected. National supervision of this obligation starts 3 August 2026. If you operate in another country, check your own authority's criteria, though the underlying requirement is the same across the EU.
4. Internal governance
Designate clear responsibilities. In small organisations, this often falls to the DPO expanding their role or an ad hoc committee. In medium and large organisations, a reasonable approach is an AI Governance Officer or a multidisciplinary committee (legal + IT + business + security). If you are pursuing ISO 42001 certification, this governance is the foundation on which the entire AIMS is built.
What comes after August 2026
Transparency and enforcement powers landing in August 2026 already trigger some market moves: (a) the first national enforcement proceedings, likely on Art. 50 transparency since it's easier to detect than high-risk compliance gaps; (b) a cascade of contractual updates in the AI supply chain (each client will demand formal compliance guarantees from their providers) as the December 2027 high-risk deadline approaches; and (c) the consolidation of ISO/IEC 42001 as the "ISO 27001 for AI", with audits already available under BS ISO/IEC 42006:2025.
The AI Act is not perfect and there will still be clarifications in its practical application during 2026 and 2027. But the direction is clear: in Europe, doing AI without thinking about governance is no longer an option.
Frequently asked questions
What exactly changes on 2 August 2026?
Governance obligations for general-purpose AI (GPAI) models and the penalties tied to the Art. 5 prohibitions enter into application, among other milestones on the AI Act calendar.
What are the four AI Act risk categories?
Unacceptable risk (prohibited), high risk (strict obligations), limited risk (transparency), and minimal risk (no specific obligations) — every AI system is classified into one of these four categories.
What is a GPAI model and why is it a special case?
A GPAI (general-purpose AI) model is one like those powering generative AI assistants. It has its own set of obligations (Arts. 51-56), separate from high-risk AI systems, with an additional tier for models with systemic risk.
Which authority enforces the AI Act in Spain?
AESIA (the Spanish AI Supervision Agency) is Spain's reference authority for AI Act market surveillance — other EU Member States designate their own equivalent national authority.
What should a company do if it hasn't prepared for the AI Act yet?
At minimum: inventory the AI systems in use, run a preliminary risk classification, and designate someone responsible for AI governance — before the full application deadlines arrive.
Discover your AI Act exposure
Free assessment with your priority gaps, plus the risk classifier and savings calculator on the AI Governance path.