Skip to content
Cloud Security DeskSearch
Menu

Technical guideAI systems

Track EU AI Act deadlines after the Digital Omnibus delay

The Digital Omnibus moved high-risk AI duties to December 2027 and August 2028, but prohibitions, AI literacy and Article 50 transparency already apply. See which dates moved and what cloud teams should build now.

Published
Sources checked
Next review
Reading time
14 minutes
Coverage
European Union · European Commission
A dark calendar rail with five milestone flags. Three green flags stay planted on the left; two amber flags have been lifted from empty sockets and carried further right along the rail by curved blue arrows.
Conceptual illustration: the Digital Omnibus left early AI Act dates in place and moved the high-risk dates later.

A timeline guide for compliance leads and AI platform owners that compares the AI Act's original application dates with those set by Regulation (EU) 2026/1744, using the Official Journal texts reviewed in October 2026. It explains provider and deployer roles and turns deployer duties into logging, oversight and documentation work, with a dated preparation plan.

At a glance

Key findings

  • Prohibited practices and AI literacy (since February 2, 2025), general-purpose model duties (since August 2, 2025) and Article 50 transparency (since August 2, 2026) already apply. [1][4]
  • Regulation (EU) 2026/1744 was published on July 24, 2026 and entered into force on July 27, 2026; it moved Annex III high-risk duties to December 2, 2027 and Annex I duties to August 2, 2028. [2]
  • The omnibus added prohibitions on non-consensual intimate imagery and child sexual abuse material, and a marking deadline for generators already on the market, both from December 2, 2026. [2]
  • Deployer duties in Article 26, including keeping logs under their control for at least six months, are unchanged in substance and start with the Annex III date. [1][2]
  • A team that builds a system on a hosted model and uses it under its own name is that system's provider, and repurposing a system into an Annex III use makes it a provider under Article 25. [1]

What already applies

On October 8, 2026, three groups of AI Act obligations are already in application. The prohibited practices and the AI literacy duty have applied since February 2, 2025. Obligations for providers of general-purpose AI models, together with the governance chapter and penalties, have applied since August 2, 2025. The general application date of August 2, 2026 then brought in the Article 50 transparency rules and the Commission's power to fine model providers. [1][4][5] What has not started is the high-risk regime in Chapter III, Sections 1 to 3: classification, requirements, and the obligations of providers and deployers of high-risk systems. The Digital Omnibus on AI moved that to December 2, 2027 for the stand-alone uses listed in Annex III and to August 2, 2028 for AI built into products covered by Annex I. [2]

For a cloud team, the live obligations are concrete. A provider of a chat interface must design it so people know they are talking to an AI system, unless that is obvious. A provider of a system that generates synthetic audio, images, video or text must mark outputs in a machine-readable format so they are detectable as artificially generated. A deployer that uses AI to generate or manipulate deepfake image, audio or video content must disclose that it is artificial, and a deployer that publishes AI-generated text to inform the public on matters of public interest must disclose that too, unless the text went through human review or editorial control under someone's editorial responsibility. Deployers of emotion recognition or biometric categorisation systems must tell the people exposed to them. [1]

AI literacy also still applies to every provider and deployer, not only to high-risk use. Since July 27, 2026 the amended Article 4 asks them to take measures to support the AI literacy of staff and others operating AI systems on their behalf, and says this does not require guaranteeing any specific level of literacy for any individual. The earlier text asked for measures to ensure, to their best extent, a sufficient level. [1][2] A dated training record for the people who configure, approve and operate AI features is the obvious evidence.

This guide reads the Official Journal texts and turns them into engineering work. It is not legal advice, and whether a particular system is high-risk, or whether your organisation is its provider, needs a qualified legal opinion. The timeline below lists the dates that matter for cloud teams, with the provision that sets each one.

Figure 01

Which AI Act dates have passed and which moved

Prohibitions, AI literacy, model duties and Article 50 already apply; high-risk duties start December 2, 2027 or August 2, 2028. [1][2]

Timeline of ten AI Act milestones from entry into force on August 1, 2024 to August 2, 2030, including the omnibus entry into force on July 27, 2026, the December 2, 2026 prohibitions and marking date, the December 2, 2027 Annex III date and the August 2, 2028 Annex I date.

Source. Regulation (EU) 2024/1689 and Regulation (EU) 2026/1744 as published in the Official Journal; Commission GPAI guidelines page. [1][2][5]

Method. Dates transcribed from the cited articles of the published texts. Ordinal layout; spacing does not represent elapsed time.

Accessible table and figure data
Figure 1 accessible table
DateWhat appliesLegal basis
August 1, 2024AI Act enters into forceRegulation 2024/1689, Article 113
February 2, 2025Prohibited practices and AI literacyArticle 113(a)
August 2, 2025General-purpose AI model duties, governance, penaltiesArticle 113(b)
July 27, 2026Digital Omnibus on AI enters into forceRegulation 2026/1744, Article 4
August 2, 2026General application, including Article 50 and model finesArticle 113, second paragraph
December 2, 2026New Article 5 prohibitions; marking for older generatorsAmended Articles 113(a) and 111(4)
August 2, 2027Older general-purpose models comply; national sandboxes runArticles 111(3) and 57(1)
December 2, 2027Annex III high-risk duties, including deployersAmended Article 113(c)(i)
August 2, 2028Annex I product high-risk dutiesAmended Article 113(c)(ii)
August 2, 2030High-risk systems used by public authoritiesArticle 111(2)
Figure 1 accessible table
DateWhat appliesLegal basis
August 1, 2024AI Act enters into forceRegulation 2024/1689, Article 113
February 2, 2025Prohibited practices and AI literacyArticle 113(a)
August 2, 2025General-purpose AI model duties, governance, penaltiesArticle 113(b)
July 27, 2026Digital Omnibus on AI enters into forceRegulation 2026/1744, Article 4
August 2, 2026General application, including Article 50 and model finesArticle 113, second paragraph
December 2, 2026New Article 5 prohibitions; marking for older generatorsAmended Articles 113(a) and 111(4)
August 2, 2027Older general-purpose models comply; national sandboxes runArticles 111(3) and 57(1)
December 2, 2027Annex III high-risk duties, including deployersAmended Article 113(c)(i)
August 2, 2028Annex I product high-risk dutiesAmended Article 113(c)(ii)
August 2, 2030High-risk systems used by public authoritiesArticle 111(2)

What the omnibus changed

The amending act is Regulation (EU) 2026/1744 of July 8, 2026, the Digital Omnibus on AI. It was published in the L series of the Official Journal on July 24, 2026, and its Article 4 says it enters into force on the third day following publication, which is July 27, 2026. Recital 46 gives the reason for the short gap: the AI Act's general application date of August 2, 2026 was days away. [2] Summaries written before publication sometimes describe proposal-stage mechanisms or a different entry-into-force rule, so check any date you rely on against the published text.

The European Parliament's legislative record gives the path. The Commission proposed the omnibus as COM(2025) 836 on November 19, 2025, linking the start of the high-risk rules to the availability of standards and other compliance tools. The provisional agreement of May 7, 2026 replaced that link with fixed dates. Parliament approved the text on June 16, 2026 by 423 votes to 57 with 174 abstentions, and the Council adopted it on June 29, 2026. [3] The Commission's AI Act page, last updated August 3, 2026, now shows the new high-risk dates. [4]

The central change is a replacement point (c) in the third paragraph of Article 113. Chapter III, Sections 1, 2 and 3, except Article 6(5), now apply from December 2, 2027 for systems that are high-risk under Article 6(2) and Annex III, and from August 2, 2028 for systems that are high-risk under Article 6(1) and Annex I. Under the original text, Annex III systems fell under the general date of August 2, 2026, and Article 6(1) with its corresponding obligations applied from August 2, 2027. [1][2] Recital 40 explains the move by the late arrival of harmonised standards, common specifications and guidance, and by national authorities that were not yet in place. [2]

Four further date changes sit outside Article 113(c), as the table shows. One extends the time to mark generated content for generators already on the market. One adds two new prohibitions with their own start date. One gives Member States another year to run a national sandbox. One brings Articles 102 to 110, which amend other Union acts, into application on July 27, 2026. [2]

Dates changed by Regulation (EU) 2026/1744, compared with Regulation (EU) 2024/1689 as published in 2024. Reviewed October 8, 2026. [1][2]
ProvisionOriginal textAs amended
Annex III high-risk obligations, Article 113(c)August 2, 2026 (general date)December 2, 2027
Annex I high-risk obligations, Article 113(c)August 2, 2027August 2, 2028
Article 50(2) marking for generators placed on the market before August 2, 2026, Article 111(4)No separate date (August 2, 2026)December 2, 2026
Prohibitions on non-consensual intimate imagery and child sexual abuse material, Article 5(1)(ba) and (bb)Not in the original textDecember 2, 2026
National AI regulatory sandbox operational, Article 57(1)August 2, 2026August 2, 2027
High-risk systems already in use, Article 111(2) cutoffPlaced on the market before August 2, 2026Placed on the market before the Chapter III date
Figure 02

How far the omnibus pushed each date

Annex III duties moved from 24 to 40 months after entry into force; earlier obligations did not move. [1][2]

Grouped bar chart of whole months from the AI Act's entry into force on August 1, 2024 to each application date. Prohibitions and AI literacy 6 and 6; general-purpose model duties 12 and 12; Article 50 transparency 24 and 24; Article 50(2) marking for older generators 24 and 28; Annex III high-risk duties 24 and 40; Annex I high-risk duties 36 and 48.

Source. Calculated from application dates in Article 113 of Regulation (EU) 2024/1689 and in Articles 1(39) and 1(40) of Regulation (EU) 2026/1744. [1][2]

Method. Calculated: whole calendar months from August 1, 2024 to each application date (every date falls on the 2nd, so each value omits one day). The original text has no separate Article 50(2) date for systems already on the market, so the general date of August 2, 2026 is used.

Accessible table and figure data
Figure 2 accessible table
ObligationOriginal textAs amended
Prohibitions and AI literacy66
General-purpose AI model duties1212
Article 50 transparency2424
Article 50(2) marking, generators already on the market2428
Annex III high-risk duties2440
Annex I high-risk duties3648
Figure 2 accessible table
ObligationOriginal textAs amended
Prohibitions and AI literacy66
General-purpose AI model duties1212
Article 50 transparency2424
Article 50(2) marking, generators already on the market2428
Annex III high-risk duties2440
Annex I high-risk duties3648

Systems already in service

Article 111(2) now ties the treatment of existing high-risk systems to the Chapter III date. High-risk systems placed on the market or put into service before that date are covered only if, from that date, they are subject to significant changes in their designs. Providers and deployers of high-risk systems intended for use by public authorities must comply by August 2, 2030 in any case. [2] Read literally, an Annex III system put into service before December 2, 2027 and left unchanged in design falls outside the high-risk obligations, while a significant design change afterwards brings it in.

That makes design change control a compliance input. Recital 177 of the AI Act says significant change should be understood as equivalent in substance to substantial modification, which Article 3(23) defines as an unplanned change after release that affects compliance with the Chapter III, Section 2 requirements or modifies the assessed intended purpose. [1] Record design changes to any system that might be Annex III, such as a new model family, a new decision output or a new input category, with dates and the reasoning behind each, and ask counsel how your organisation reads the rule before you plan a release around it. Public bodies and contractors serving them should plan to the 2030 date regardless.

Provider or deployer

Most of the AI Act's work follows from which role you hold. A provider develops an AI system or general-purpose AI model, or has one developed, and places it on the market or puts it into service under its own name or trademark, whether for payment or free. A deployer is anyone using an AI system under its authority, except for personal non-professional use. Putting into service includes supplying a system for your own use in the Union. [1] The role attaches to each system, not to the company. One platform team can be the deployer of a vendor's recruitment screening tool and the provider of an internal assistant it built on a hosted model.

The company whose model API you call is, for that model, a provider of a general-purpose AI model with the Chapter V duties that have applied since August 2025. [1][5] It is not usually the provider of the system you assemble around that model. If your team wraps the model with prompts, retrieval and an interface, and puts the result into service under your name, including for staff only, your organisation is the provider of that AI system. Where the model runs, in which region and under which contract, does not change that analysis; it matters for data protection and contracts, not for the role.

Article 25 turns deployers and others into providers of a high-risk system in three cases: they put their name or trademark on a high-risk system already on the market, they make a substantial modification to one, or they change the intended purpose of a system that was not high-risk, including a general-purpose AI system, so that it becomes high-risk. [1] As a hypothetical, a team that configures a general chat assistant to filter job applications has moved it into Annex III point 4(a), recruitment and selection, and holds the provider obligations for that use.

The omnibus strengthened the supply chain side. Under the amended Article 25(2), the initial provider must give a new provider technical documentation sufficient to assess compliance, information on known limitations and failure modes, and targeted technical access for testing and validation, unless it clearly specified that its system was not to be changed into a high-risk system. The amended Article 25(4) requires a written agreement between the provider of a high-risk system and any third party supplying an AI system, model, tool, service, component or process used in it, specifying the information, capabilities, technical access and assistance needed to comply. [2] For a cloud team that buys models and managed AI services, that is a procurement checklist with a legal basis.

Whether a system is high-risk under Annex III depends on its intended use, not its technology. The listed areas are biometrics, safety components in critical infrastructure, education and vocational training, employment and worker management, access to essential services including credit scoring and life and health insurance pricing, law enforcement, migration and border control, and the administration of justice and democratic processes. Article 6(3) lets a provider conclude that an Annex III system is not high-risk when it performs a narrow procedural task, improves a completed human activity, detects patterns without replacing human assessment, or performs a preparatory task, but never when it profiles natural persons. A provider relying on that exception must document the assessment before release and register the system under Article 49(2); the omnibus kept that registration duty but simplified the information it requires. [1][2]

Figure 03

Find your role for each AI system

Building a system on a hosted model and using it under your name makes you its provider, even for internal use. [1]

Decision tree with four questions: whether you develop a system and put it into service under your own name, whether you put your name on someone else's high-risk system, whether you substantially modify a high-risk system or repurpose a system into a high-risk use, and whether you use the system under your authority professionally, leading to provider, provider under Article 25, deployer or outside the deployer definition.

Source. Conceptual decision aid based on Article 3(3), 3(4), 3(11) and Article 25(1) of Regulation (EU) 2024/1689. [1]

Method. Conceptual ordering of the role definitions. It does not cover importers, distributors, authorised representatives or providers of general-purpose AI models, and it is not a legal determination.

Accessible table and figure data
Figure 3 accessible table
QuestionYes, thenNo, then
Do you develop the system, or have it built, and use or supply it under your own name?you are its providerask about branding
Do you put your name or trademark on a high-risk system built by someone else?you become provider under Article 25(1)(a)ask about changes
Did you substantially modify a high-risk system, or repurpose a system into a high-risk use?you become provider under Article 25(1)(b) or (c)ask about use
Do you use the system under your authority for professional purposes?you are its deployeryou are outside the deployer definition
Figure 3 accessible table
QuestionYes, thenNo, then
Do you develop the system, or have it built, and use or supply it under your own name?you are its providerask about branding
Do you put your name or trademark on a high-risk system built by someone else?you become provider under Article 25(1)(a)ask about changes
Did you substantially modify a high-risk system, or repurpose a system into a high-risk use?you become provider under Article 25(1)(b) or (c)ask about use
Do you use the system under your authority for professional purposes?you are its deployeryou are outside the deployer definition

Obligations that become engineering work

Article 26 lists what a deployer of a high-risk system must do. Its text is unchanged by the omnibus, and from December 2, 2027 it applies to Annex III systems. [1][2] Each duty becomes a control a platform team can build and show:

  • Use the system in line with the provider's instructions for use (Article 26(1)). Pin the instructions-for-use version in the deployment configuration and treat a new version as a change that needs review.
  • Assign human oversight to people with the necessary competence, training, authority and support (Article 26(2)). Keep a named roster, link it to training records, and make sure the role can actually override or stop the system.
  • Where you control input data, make sure it is relevant and sufficiently representative for the intended purpose (Article 26(4)). Version the input schema and record the checks run before each data source is added.
  • Monitor operation against the instructions, inform the provider, and suspend use if the system may present a risk. On a serious incident, inform the provider first, then the importer or distributor and the market surveillance authority (Article 26(5)). Write the suspension path as a runbook with a feature flag or routing switch.
  • Keep the automatically generated logs that are under your control for at least six months (Article 26(6)). The next section covers this.
  • Before using a high-risk system at work, inform workers' representatives and affected workers (Article 26(7)). For Annex III systems that make or help make decisions about people, inform those people (Article 26(11)). [1]
Figure 04

Who does what for a high-risk system

Providers build the capability; deployers operate it and keep the proof. [1][2]

Matrix of six duties for high-risk systems: logs, use and oversight, input data, monitoring and incidents, affected people, and impact assessment and registration. For each it lists the provider's duty, the deployer's duty, and evidence a cloud team can keep.

Source. Conceptual mapping of Articles 10, 12, 13, 19, 26, 27, 49, 50, 72 and 73 of Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744. [1][2]

Method. Conceptual. Provider and deployer cells paraphrase the cited articles; the evidence column is an editorial suggestion, not a legal requirement.

Accessible table and figure data
Figure 4 accessible table
DutyProviderDeployerEvidence to keep
LogsBuild automatic event logging; keep own logs six months minimumKeep logs it controls six months minimumRetention setting, storage location, access list
Use and oversightInstructions for use, including how to read logsFollow instructions; assign trained overseersPinned instructions version, overseer roster
Input dataData governance for training and testing dataKeep controlled inputs relevant and representativeInput schema version, check results
Monitoring and incidentsPost-market monitoring; report serious incidentsMonitor, tell provider first, suspend on riskAlert route, suspension runbook, incident record
Affected peopleDesign chat systems to disclose AITell workers and decision subjectsNotice text, date shown, audience
Assessment and registrationRegister Annex III systems in EU databasePublic bodies register use; FRIA where requiredFRIA linked to DPIA, registration reference
Figure 4 accessible table
DutyProviderDeployerEvidence to keep
LogsBuild automatic event logging; keep own logs six months minimumKeep logs it controls six months minimumRetention setting, storage location, access list
Use and oversightInstructions for use, including how to read logsFollow instructions; assign trained overseersPinned instructions version, overseer roster
Input dataData governance for training and testing dataKeep controlled inputs relevant and representativeInput schema version, check results
Monitoring and incidentsPost-market monitoring; report serious incidentsMonitor, tell provider first, suspend on riskAlert route, suspension runbook, incident record
Affected peopleDesign chat systems to disclose AITell workers and decision subjectsNotice text, date shown, audience
Assessment and registrationRegister Annex III systems in EU databasePublic bodies register use; FRIA where requiredFRIA linked to DPIA, registration reference

Impact assessments, transparency and penalties

A fundamental rights impact assessment under Article 27 is required before deploying an Annex III system, except those in critical infrastructure, when the deployer is a body governed by public law or a private entity providing public services, and for any deployer of credit scoring or life and health insurance pricing systems. The assessment covers the processes in which the system is used, the period and frequency of use, the people and groups affected, specific risks of harm, human oversight measures and the response if risks materialise. [1] The omnibus lets a deployer cross-refer to, or reuse parts of, a data protection impact assessment under the GDPR where that already meets an obligation, and asks the AI Office to provide a questionnaire template, including through an automated tool. [2] Keep the two assessments linked by identifier so that a change to one prompts review of the other.

Transparency is the area where engineering work is due now rather than in 2027. The Commission published the final Code of Practice on transparency of AI-generated content on June 10, 2026. It covers Article 50(2), (4) and (5), with one section for providers on marking and detection and one for deployers on labelling deepfakes and AI-generated text. Adherence is voluntary, and the Commission and the AI Board have confirmed the code as an adequate voluntary tool for demonstrating compliance. [6] Providers of generators placed on the market before August 2, 2026 have until December 2, 2026 for the Article 50(2) marking duty. [2] From the same date, the amended Article 5 prohibits placing on the market, putting into service or using AI systems to generate non-consensual intimate imagery of identifiable people or child sexual abuse material. For providers, the ban covers systems whose intended purpose is that output, or that can foreseeably produce it without reasonable safeguards to prevent it. [2] Teams that run image or video generation should check their safeguards against that wording before December.

Penalties already apply. Under Article 99, breaches of the Article 5 prohibitions can reach EUR 35 million or 7 percent of worldwide annual turnover, whichever is higher. Breaches of deployer obligations under Article 26 or transparency obligations under Article 50 can reach EUR 15 million or 3 percent, whichever is higher. For SMEs the lower of the two figures applies, and the omnibus extended that lower cap to small mid-cap enterprises except for fines for prohibited practices. [1][2]

Logging and retention

Logging is shared between provider and deployer. Article 12 requires a high-risk system to technically allow automatic recording of events over its lifetime, so that events relevant to three purposes are captured: identifying situations that may present a risk or amount to a substantial modification, supporting the provider's post-market monitoring, and supporting the deployer's monitoring under Article 26(5). For remote biometric identification systems, Article 12(3) sets minimum fields: the period of each use, the reference database, the input data that led to a match, and the people who verified the results. The provider's instructions for use must, where relevant, describe how deployers can collect, store and interpret the logs. [1]

Retention has a floor and a ceiling. Article 19 for providers and Article 26(6) for deployers require keeping the automatically generated logs under their control for a period appropriate to the intended purpose, of at least six months, unless Union or national law, in particular data protection law, provides otherwise. Financial institutions keep them as part of the documentation required by financial services law. [1] The GDPR sets the other bound: personal data must be adequate, relevant and limited to what is necessary, and kept in identifiable form no longer than necessary for the purpose. [7] In practice, keep an event record that supports monitoring and incident reconstruction for at least six months, and decide separately, with a written reason, whether full inputs and outputs belong in it.

Under their control is the phrase to settle in contracts. When a vendor runs the system as a service, it holds most of the logs, and the deployer keeps what it can see or export. Ask each provider which events its system records, how a deployer can retrieve them, in what format and for how long, and record the answer next to the instructions-for-use version. For systems you provide yourself, all of the logs are under your control, along with every place they are copied: tracing back ends, analytics stores and support tickets.

The same records support incident handling. Providers must report a serious incident to market surveillance authorities no later than 15 days after becoming aware of it, no later than two days for a widespread infringement or serious disruption of critical infrastructure, and no later than 10 days after a death. A deployer that identifies a serious incident must inform the provider immediately. [1] A log that cannot connect an output to the system version, input reference and human action that followed will not support either deadline.

Example event record for a hypothetical deployer of a recruitment screening system. Field names are illustrative and not prescribed by the AI Act. The input is stored by reference, so the full application can follow a shorter, separately justified retention period.
{
  "eventTime": "2027-12-06T09:14:22Z",
  "aiSystemId": "example-cv-screening",
  "providerSystemVersion": "4.2.0",
  "instructionsForUseVersion": "2027-11",
  "requestId": "req-000000000000",
  "inputRef": "sha256:0000000000000000000000000000000000000000000000000000000000000000",
  "outputSummary": "ranked 12 of 140 applications",
  "oversight": {
    "reviewerRole": "recruiter-reviewer",
    "action": "overrode",
    "reasonCode": "R07"
  },
  "affectedPersonNoticeShown": true,
  "retentionClass": "deployer-logs-min-6-months"
}

A preparation plan by date

Work backwards from the dates that are fixed in the published text, and treat the guidance still to come as inputs rather than reasons to wait.

Review this plan when the Commission publishes delegated acts or guidelines under the amended Act, and whenever a system's intended purpose or design changes. The dates in this plan come from the Official Journal texts as of October 8, 2026, and any later amendment will appear there first.

  • Now: list every AI system you build or use, with its intended purpose, your role for it and whether it touches Annex III areas. Check chat interfaces, generated content and deepfake publication against Article 50, and keep AI literacy training records current.
  • By December 2, 2026: if you provide a generator that was on the market before August 2, 2026, have machine-readable marking in place. If you run image or video generation, test your safeguards against the new Article 5 prohibitions.
  • During 2027: watch for Commission guidance and templates, including post-market monitoring guidance with a voluntary template due by September 2, 2027, and the AI Office questionnaire for impact assessments. [2] Ask model vendors how they meet the August 2, 2027 deadline for general-purpose models placed on the market before August 2025. [1][5]
  • Before December 2, 2027: for each Annex III system you deploy, have the instructions-for-use pin, oversight roster, input data checks, suspension runbook, six-month log retention, worker and affected-person notices and, where required, the impact assessment in place. Providers need their full Chapter III file.
  • Before August 2, 2028: complete the same work for AI built into products covered by Annex I.
  • By August 2, 2030: bring high-risk systems already in use by public authorities into compliance.

Method and provenance

Source-led analysis of the Official Journal texts of Regulation (EU) 2024/1689 and Regulation (EU) 2026/1744, with European Commission and European Parliament pages for procedure and guidance. Sources were reviewed on October 8, 2026.

No organisation's AI systems or contracts were assessed. Dates and obligations are bounded to the cited texts as of the review date; delegated acts, guidelines and national implementing measures published later may change how obligations apply. This is not legal advice.

AI assistance. AI assisted research synthesis, drafting, diagram planning and visual production, with deterministic editorial checks. No personal compliance experience, independent human review or live test is claimed.

Published under the Cloud Security Desk organizational byline. Read the practitioner guide policy.

References

  1. Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act), OJ L, 12.7.2024 Official Journal of the European Union (EUR-Lex). Published . Accessed .
  2. Regulation (EU) 2026/1744 amending Regulations (EU) 2024/1689, (EU) 2018/1139 and (EU) 2023/1230 (Digital Omnibus on AI), OJ L, 24.7.2026 Official Journal of the European Union (EUR-Lex). Published . Accessed .
  3. Legislative Train Schedule: Digital Omnibus on AI European Parliament. Accessed .
  4. AI Act: regulatory framework for AI European Commission. Accessed .
  5. Guidelines for providers of general-purpose AI models European Commission. Accessed .
  6. Code of Practice on Transparency of AI-generated Content European Commission. Accessed .
  7. Regulation (EU) 2016/679 (General Data Protection Regulation), Article 5 Official Journal of the European Union (EUR-Lex). Published . Accessed .