36 practical checks covering every EU AI Act obligation that binds today, plus the deadlines still ahead. Updated for the Digital Omnibus amendments that took effect in July 2026, which most published checklists do not yet reflect.
Verified against the Official Journal text on 17 August 2026
Two new prohibitions begin to apply, and providers of synthetic-content systems that were already on the market before 2 August 2026 must meet the machine-readable marking duty by the same date. It is the nearest binding date, and it is missing from most timelines published before the Omnibus.
What binds, and when
Date
What applies
Status
2 Feb 2025
Prohibited practices and AI literacy duties
In force
2 Aug 2025
General-purpose AI model obligations, governance bodies, penalties
In force
27 Jul 2026
The Digital Omnibus amendments take effect
In force
2 Aug 2026
General application: transparency, registration, and the new enforcement powers
In force
2 Dec 2026
Two new prohibitions, and machine-readable marking for pre-existing synthetic-content systems
Upcoming
2 Aug 2027
Legacy GPAI models compliant; national regulatory sandboxes operational
Upcoming
2 Dec 2027
High-risk obligations for stand-alone Annex III systems
Upcoming
2 Aug 2028
High-risk obligations for AI in Annex I regulated products
Upcoming
2 Aug 2030
Backstop for legacy high-risk systems used by public authorities
Upcoming
The deferral of the high-risk obligations carries no standards-readiness trigger and no automatic extension, so the 2027 and 2028 dates bind whether or not harmonised standards are ready. For the full picture, read our EU AI Act compliance timeline.
The checklist: 36 items across 8 sections
0 of 36 complete
Progress is saved in this browser only. Nothing is uploaded.
1. Scope and inventory
0/5
Applies to every organisation. Nothing else in this list can be answered until this is done.
2. Prohibited practices
0/7
Binding since 2 February 2025. Two new prohibitions apply from 2 December 2026. Breach carries the highest penalty tier, up to 35 million euro or 7 percent of worldwide annual turnover.
3. AI literacy
0/2
Article 4. Binding on every provider and deployer at every risk tier, including minimal risk. In force since 2 February 2025 and softened, not removed, in July 2026.
4. Transparency duties
0/5
Article 50. Live since 2 August 2026 with no grace period, other than the one marking deadline noted below. This is the tranche most organisations wrongly believe was delayed.
5. General-purpose AI models
0/4
Chapter V. Binding since 2 August 2025 on providers of GPAI models. Skip this section if you only use models built by others.
6. High-risk classification
0/3
The obligations are deferred to 2 December 2027 (Annex III) and 2 August 2028 (Annex I), but the Commission's classification guidance was carved out of that deferral and applies from 2 August 2026. Classify now.
7. High-risk obligations
0/6
Chapter III. The build programme behind the 2027 and 2028 dates. Conformity work realistically takes longer than the time remaining.
8. Registration, governance and enforcement
0/4
The new enforcement architecture went live on 2 August 2026, not with the deferred high-risk tranche.
Frequently asked questions
Was the EU AI Act delayed?
Only partly. Regulation (EU) 2026/1744, the Digital Omnibus on AI, deferred the high-risk obligations in Chapter III to 2 December 2027 for stand-alone Annex III systems and 2 August 2028 for AI embedded in regulated products. Everything else kept its original date. The prohibited practices have bound since February 2025, general-purpose AI obligations since August 2025, and the transparency duties, registration and the new enforcement powers went live on 2 August 2026.
What happens on 2 December 2026?
Two new prohibitions in Article 5 begin to apply, covering AI that generates or manipulates non-consensual intimate imagery of an identifiable person and AI that generates child sexual abuse material. The same date is the deadline for providers of synthetic-content systems that were already on the market before 2 August 2026 to meet the machine-readable marking duty.
Does the AI Act apply to companies outside the EU?
Yes. It reaches providers and deployers established outside the Union where the output produced by the AI system is used in the EU, and non-EU providers of high-risk systems must appoint an authorised representative established in the Union.
Can using someone else's AI system make us a provider?
Yes, and this is the most commonly missed exposure. Under Article 25 you become a provider, inheriting the full high-risk obligation set, if you put your own name or trademark on a high-risk system already on the market, make a substantial modification to it, or change its intended purpose so that a system becomes high-risk. The name and trademark limb applies without prejudice to any contract allocating those obligations differently. Separately, the 2026 amendments put the original provider's duty to cooperate with that new provider, and to hand over documentation and technical access, into the penalty tier of up to 15 million euro or 3 percent of worldwide turnover, so that new exposure sits with the upstream supplier rather than the party that rebranded.
What are the penalties under the EU AI Act?
Breaching the prohibited practices carries fines of up to 35 million euro or 7 percent of total worldwide annual turnover, whichever is higher. Most other operator obligations carry up to 15 million euro or 3 percent, and supplying incorrect or misleading information to authorities up to 7.5 million euro or 1 percent. Since August 2026 the AI Office can also impose periodic penalty payments of up to 5 percent of average daily worldwide turnover per day within its area of exclusive competence.
Does AI literacy still apply after the 2026 amendments?
Yes. Article 4 was rewritten but not removed. Providers and deployers must still take measures to support the development of AI literacy among staff and others operating AI on their behalf. The current wording expressly does not require you to guarantee any particular level of competence in any individual, so the evidence of compliance is the programme you run and document.
About this checklist
Prepared from Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744, read in the Official Journal. Note that the EUR-Lex HTML rendering of the amending regulation is truncated, and that several widely used reference sites still serve the unamended 2024 text, so dates found elsewhere may be out of date.
This is general information, not legal advice, and it does not create a lawyer-client relationship. Obligations depend on your specific systems, role and sector. Take advice from qualified counsel before relying on any point here, and confirm against the Official Journal text.
Track the AI Act against your own systems
TimeLaw monitors the EU AI Act and every amendment to it, mapped to the systems and sectors you actually operate in, and alerts you before each deadline lands.