AI Governance & Regulation: EU AI Act, NIST AI RMF and ISO/IEC 42001EU AI Act deep dive · Lesson 7 of 17
Timeline, enforcement and the 2026 Digital Omnibus
Video lecture
Timeline, enforcement and the 2026 Digital Omnibus
The narrated lecture is in production
Every chapter is scripted and ready. Browse the chapters and read the full transcript now — the video will appear here when it’s published.
Chapters
Transcript of the narration, chapter by chapter.
0:00 Timeline, enforcement, Omnibus
Dates in the EU AI Act have moved, and quoting the wrong one in a client proposal is an easy way to lose credibility. In this lesson you'll get the full timeline as of September twenty twenty-six, understand what the twenty twenty-six Digital Omnibus changed, see the penalty structure, and build a dated compliance calendar for your own organization. One reminder: always confirm dates against the consolidated legal text, because this area keeps moving.
0:32 Why dates matter
Why spend a whole lesson on dates? Because they drive budgets and priorities. If you think high-risk rules apply next month, you might spend heavily on the wrong controls. If you think nothing applies until twenty twenty-seven, you might ignore chatbot disclosure, which is already live. Clients also judge your expertise by precision. Quoting the correct post-Omnibus dates in a proposal signals that you're current. Quoting outdated ones signals the opposite.
1:03 Timeline, part 1
Let's walk it. The Act entered into force on the first of August twenty twenty-four. On the second of February twenty twenty-five, the prohibitions and AI literacy started. On the second of August twenty twenty-five, general-purpose model obligations and the governance structure kicked in. The second of August twenty twenty-six is the general date of application, including the transparency duties in Article fifty, and the Commission's power to fine model providers. Remember the difference between entry into force, when the law exists, and application, when duties actually bite.
1:41 Analogy: a phased building code
An analogy for staged application: think of a new building code that phases in. On day one, the most dangerous practices are banned immediately. A year later, rules for the biggest suppliers of materials apply. Later still, general rules for every building kick in. And for complex structures like hospitals, the deadline is pushed back because the official testing standards aren't finished yet. That's the AI Act: bans first, model providers next, general rules after, and high-risk systems last, once the standards exist.
2:17 Timeline, part 2 (after the Omnibus)
Then came the Digital Omnibus on AI, Regulation twenty twenty-six slash seventeen forty-four. It was proposed in November twenty twenty-five, politically agreed on the seventh of May twenty twenty-six, adopted by the Council at the end of June, and entered into force on the twenty-seventh of July twenty twenty-six. It moved the high-risk dates: Annex three systems to the second of December twenty twenty-seven, and Annex one product systems to the second of August twenty twenty-eight. It also set the second of December twenty twenty-six as the end of the marking grace period for existing generative systems and the start of the ban on nudification tools. And legacy general-purpose models must comply by August twenty twenty-seven.
3:07 Omnibus: the big picture
Beyond the dates, the Omnibus rewrote the AI literacy duty into a more flexible form, added support for smaller companies including SMEs and small mid-caps, expanded testing and sandbox opportunities, and clarified the AI Office's role. The headline message for businesses: the direction of travel hasn't changed. High-risk rules are deferred, not canceled. Transparency duties are live. And the ban list got longer, not shorter.
3:35 Penalty caps
Now penalties. Prohibited practices carry fines up to thirty-five million euros or seven percent of worldwide annual turnover, whichever is higher. Most other obligations, including transparency, go up to fifteen million or three percent. Giving authorities incorrect or misleading information goes up to seven and a half million or one percent. The Commission can fine model providers up to fifteen million or three percent. And here's a detail that matters for smaller firms: for SMEs and start-ups, each cap is the lower of the two amounts, not the higher.
4:14 Who enforces
Who enforces what? National market surveillance authorities handle AI systems, including high-risk and transparency. Each Member State chose its own, sometimes an existing digital or data protection regulator. The AI Office handles general-purpose models. Data protection authorities keep enforcing GDPR. And sector regulators, like financial or medical device authorities, stay in charge where AI sits inside their products. If you're outside the EU, your exposure runs through whichever authority covers the market where your AI or its output is used.
4:49 SME roadmap
So what should a small business do right now? By the end of twenty twenty-six, have your inventory and classification done, your ban screen complete, AI literacy running, Article fifty disclosures live, a synthetic asset register, and vendor documentation on file. During twenty twenty-seven, mature your policy and management system, and test your incident process. And if you deploy any Annex three system, like an HR tool, be ready for deployer duties by the second of December twenty twenty-seven. The lesson text has a dated calendar template you can copy.
5:28 Example 2: fixing a proposal
A simple example of getting dates right. An agency in Dubai wrote in a September proposal that its client's AI recruitment screening would need to comply from August twenty twenty-six. After the Omnibus, that's wrong: Annex three high-risk duties now apply from the second of December twenty twenty-seven. The corrected proposal says so, adds that the client should still plan now because contracts and processes signed today will be running then, and notes that transparency duties for any candidate-facing chatbot already apply. Precise dates build credibility with clients.
6:06 Common mistakes
Three mistakes to avoid. Quoting the original high-risk date after the Omnibus changed it. Assuming postponed means canceled, when the obligations are exactly the same, just later. And confusing entry into force with application. The Act entered into force in twenty twenty-four, but most duties applied later. When a client asks is the AI Act in force, the precise answer is yes, and here's which parts apply to you, and from when.
6:37 Watch me do it: compliance calendar
Watch me do it. I open a tab called Compliance calendar with five columns: Date, Obligation, Owner, Status, Evidence link. I start with what already applies. Second of February twenty twenty-five: Article five screen of the inventory, owner AI lead, status done, evidence links to the screen column. Same date: AI literacy plan version one, done. Second of August twenty twenty-six: chatbot and voice agent disclosures live, owner marketing ops, done, evidence is the monthly disclosure test. Same date: deepfake labeling rule in the content procedure, done. Now the future dates. Second of December twenty twenty-six: confirm our generative tool vendors mark outputs, status in progress. Thirtieth of June twenty twenty-seven: readiness review for the HR screening tool. Second of December twenty twenty-seven: Annex three deployer duties apply, owner HR director. Then I export the three nearest dates to the team calendar, with reminders two months ahead. Finally, I add a note at the top: dates as of September twenty twenty-six, confirm against the consolidated text each quarter.
7:50 Recap and next step
Recap. Know the difference between entry into force and application. The key dates are February twenty twenty-five for bans and literacy, August twenty twenty-five for model rules, August twenty twenty-six for general application and transparency, December twenty twenty-six for marking and the new ban, and December twenty twenty-seven and August twenty twenty-eight for high-risk systems. Penalties scale with severity, and SMEs get the lower cap. Your next step: copy the calendar template, fill in owners and evidence links, and put the next three dates in your team calendar.
Why dates matter
The AI Act applies in stages, and the 2026 Digital Omnibus on AI changed several of them. Getting the dates wrong leads either to panic (spending on controls not yet needed) or complacency (missing duties already in force). Always confirm against the consolidated text on EUR-Lex and Commission guidance; this lesson reflects the position as of September 2026.
The consolidated timeline
| Date | What applies |
|---|---|
| 1 August 2024 | AI Act (Regulation (EU) 2024/1689) enters into force |
| 2 February 2025 | Prohibited practices (Article 5); AI literacy (Article 4); general provisions and definitions |
| 2 August 2025 | GPAI model obligations; governance structures (AI Office, AI Board); national authorities to be designated; penalties framework; notified-body rules |
| 2 August 2026 | General date of application: Article 50 transparency duties; Commission enforcement powers over GPAI providers; most remaining provisions |
| 27 July 2026 | Digital Omnibus on AI (Regulation (EU) 2026/1744) enters into force, amending the Act |
| 2 December 2026 | End of Article 50(2) marking grace period for generative systems placed on the market before 2 August 2026; new prohibition on AI nudification/CSAM systems applies |
| 2 August 2027 | GPAI models placed on the market before 2 August 2025 must comply |
| 2 December 2027 | High-risk obligations for Annex III systems (after the Omnibus) |
| 2 August 2028 | High-risk obligations for Annex I product-embedded systems (after the Omnibus) |
What the Digital Omnibus on AI changed (headline level)
The European Commission proposed the "Digital Omnibus" simplification package in November 2025. Parliament and Council reached political agreement on the AI part on 7 May 2026; Parliament approved it in June, the Council adopted it on 29 June 2026, it was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. Headline changes include:
- Postponed high-risk deadlines (Annex III to 2 December 2027; Annex I to 2 August 2028), mainly because harmonized standards were not ready.
- Rewritten AI literacy duty (support the development of AI literacy, no guaranteed individual level) with support from the Commission and Member States, especially for SMEs.
- A four-month grace period for Article 50(2) marking for existing generative systems.
- A new prohibition targeting AI systems for creating non-consensual intimate imagery and CSAM, from 2 December 2026.
- Simplifications and support for smaller companies, including measures for SMEs and small mid-caps, expanded testing and sandbox opportunities, and clarifications on the AI Office's supervisory role.
The detail of each change matters for anyone near the lines. Read a reputable consolidated version, not a summary.
Penalties (Article 99 and 101)
| Infringement | Maximum fine |
|---|---|
| Prohibited practices | EUR 35 million or 7% of total worldwide annual turnover, whichever is higher |
| Most other obligations (operators, notified bodies, Article 50) | EUR 15 million or 3%, whichever is higher |
| Supplying incorrect, incomplete or misleading information to authorities | EUR 7.5 million or 1%, whichever is higher |
| GPAI model providers (imposed by the Commission) | EUR 15 million or 3%, whichever is higher |
For SMEs, including start-ups, each cap is the lower of the two amounts. Member States set the detailed rules for penalties on AI systems.
Who enforces what
- National market surveillance authorities: AI systems, including high-risk and Article 50 duties. Each Member State designates its own (for example, some chose existing digital, telecoms or data protection regulators).
- The AI Office: GPAI models, and systems built on GPAI models by the same provider in certain cases.
- Data protection authorities: GDPR and, in some Member States, certain AI Act areas involving biometrics or law enforcement.
- Sector regulators (financial, medical devices) where AI sits inside their products.
Planning with a roadmap
A sensible SME roadmap as of September 2026:
| Now (Q4 2026) | 2027 | By Q4 2027 |
|---|---|---|
| Inventory and classification complete; Article 5 screen; literacy program running; Article 50 disclosures live; asset register; vendor due diligence on GPAI documentation | Policy and management system maturing (ISO/IEC 42001-aligned); monitoring and incident process tested; FRIA/DPIA templates ready | Any Annex III system you deploy meets deployer duties from 2 December 2027; contracts updated; oversight staff trained |
Hands-on: a dated compliance calendar
date,obligation,owner,status,evidence_link
2025-02-02,Article 5 screen of inventory,AI lead,done,/gov/inventory-v3.xlsx
2025-02-02,AI literacy program v1,People ops,done,/gov/literacy/
2026-08-02,Chatbot and voice agent disclosures live,Marketing ops,done,/gov/tests/disclosure-aug26.pdf
2026-08-02,Deepfake labeling rule in content SOP,Head of content,done,/gov/sop/content-v5.pdf
2026-12-02,Confirm vendors mark generative outputs (50(2)),AI lead,in progress,
2027-06-30,High-risk deployer readiness review (HR tool),HR director,planned,
2027-12-02,Annex III deployer duties apply,HR director,planned,Pitfalls
- Quoting the original 2 August 2026 high-risk date in client proposals after the Omnibus changed it.
- Assuming "postponed" means "canceled".
- Confusing entry into force (when a law exists) with application (when duties bite).
Key takeaways
- Key dates: 2 Feb 2025 (bans, literacy), 2 Aug 2025 (GPAI), 2 Aug 2026 (general application, Article 50), 2 Dec 2026 (marking grace ends, new ban), 2 Dec 2027 (Annex III), 2 Aug 2028 (Annex I).
- The Digital Omnibus on AI (Regulation (EU) 2026/1744) entered into force on 27 July 2026; it deferred, not canceled, high-risk duties.
- Fines reach EUR 35m/7% for bans, EUR 15m/3% for most duties, EUR 7.5m/1% for misleading information; SMEs face the lower cap.
- National authorities enforce AI system rules, the AI Office enforces GPAI rules, and GDPR enforcement continues in parallel.
Check your understanding
Quick questions to lock in the lesson. They don’t count towards your certificate.
Put it into practice
Copy the CSV compliance calendar, adapt the rows to your inventory, assign owners and evidence links, and add the next three dates to your team calendar.
Enrol for free to save your progress
Reading is always free. Enrol to keep your place, take the final assessment and earn a verifiable certificate.