EU AI Omnibus in force: the compliance calendar | TLY

AI Regulation Tracker  /  Effective-Date Activation

The EU AI Omnibus is binding law. Here is the calendar it locks in

Regulation (EU) 2026/1744 entered into force on 27 July 2026. The amended AI Act obligations do not apply that day. They apply on dates in December 2026, December 2027 and August 2028, and those dates are now statutory rather than proposed.

What actually happened on 27 July?

A proposal became law. That is the whole event, and it is a bigger one than it sounds.

The Regulation was published in the Official Journal on 24 July 2026. Its final article does the ordinary thing: "This Regulation shall enter into force on the third day following that of its publication in the Official Journal of the European Union. This Regulation shall be binding in its entirety and directly applicable in all Member States." The European Commission newsroom recorded it the same day: "On 27 July 2026, the AI Omnibus enters into force across the EU, bringing extended timelines to administrative simplification."

Since the Commission put the Omnibus forward on 19 November 2025, every plan built around the amended deadlines rested on the assumption that the amendments would survive the legislative process roughly intact. That assumption is now retired. The dates in the calendar below are the dates in the statute.

Why "in force" is not "applies"

This is the sentence that gets written wrong in half the coverage of any EU regulation, so it is worth being slow about it. Entry into force is the moment an instrument exists as binding law. Application is the moment an obligation inside it starts to bite on a particular person. EU regulations routinely separate the two, and the Omnibus separates them deliberately, because the point of the amendments was to move application dates.

So on 27 July 2026 the Regulation became binding. On the same day, no amended AI obligation became newly applicable to a provider or deployer. The Regulation assigns the later dates itself, including 2 December 2026, 2 December 2027 and 2 August 2028. If a memo circulating inside a company says the amended high-risk regime is live, that memo is wrong.

One related trap is worth naming. The AI Act's Article 50 transparency obligations apply from 2 August 2026. That date belongs to the AI Act's own original calendar. It was not created by the Omnibus and should not be attributed to it. The two events sit six days apart and are unrelated in origin.

What does the Omnibus change?

The Commission frames the instrument as targeted simplification that preserves the AI Act's safeguards, and its newsroom summary describes extended timelines plus administrative simplification. That is the Commission's characterisation. The dated substance is easier to hold onto.

On timing, high-risk AI systems listed in Annex III apply from 2 December 2027, and high-risk AI embedded in physical products covered by Annex I, meaning machinery, toys and lifts, applies from 2 August 2028.

On substance, it is not purely a deferral instrument. It prohibits AI systems generating non-consensual sexually explicit and intimate content or child sexual abuse material. It permits processing of special categories of personal data to detect and correct bias, which resolves a real tension between the AI Act's testing expectations and data protection law. It extends to small mid-cap companies measures previously reserved for SMEs. It widens sandbox access and introduces an EU-level regulatory sandbox. It simplifies the company-level AI literacy requirement, with the Commission and Member States taking a stronger role instead, and it simplifies registration of exempted systems in the EU database and conformity assessment procedures. The AI Office gains extended oversight of certain AI systems, including those built on general-purpose models and those embedded in very large online platforms and search engines.

Which dates does a firm with EU exposure now hold?

The fourth column matters as much as the first, because the origin of a date tells you whether it moved and whether it can move again.

Operative AI compliance calendar after Regulation (EU) 2026/1744
DateWhat happensWho it lands onOrigin, and what changed
27 July 2026Regulation (EU) 2026/1744 enters into force, binding in its entirety and directly applicable in all Member StatesEveryone in scope of the AI Act, plus national competent authoritiesThe Omnibus. Status change only. The amended calendar stops being a proposal
2 August 2026AI Act Article 50 transparency obligations applyProviders and deployers of systems within Article 50The AI Act's own calendar. Not created or moved by the Omnibus
2 December 2026Compliance required with the prohibition on AI systems generating non-consensual sexually explicit and intimate content or child sexual abuse materialProviders of image and video generation systems, and deployers offering that capabilityThe Omnibus. A new prohibition, not a deferral. Not enforceable on 27 July
2 December 2027High-risk obligations apply to AI systems listed in Annex IIIProviders, deployers, importers and distributors of Annex III systemsThe Omnibus. Extended relative to the AI Act as originally adopted
2 August 2028High-risk obligations apply to AI embedded in physical products under Annex IManufacturers in machinery, toys and lifts, and their notified bodiesThe Omnibus. Extended relative to the AI Act as originally adopted

Note what the table does not contain: any obligation that became applicable on 27 July. There is none.

What should a US company do in each interval?

Take the deferral at face value and it looks like eighteen months of quiet. It is not, and the reason is capacity rather than law. Annex III high-risk landing on 2 December 2027 and Annex I embedded high-risk on 2 August 2028 points a very large number of organisations at two dates. Conformity assessment does not scale on demand. Notified body capacity, documentation review and testing all queue. Start classification work in mid-2027 and you enter that queue behind everyone else who read the deferral as breathing room.

Between now and 2 December 2026, the work is narrow. Any organisation whose systems can generate images or video should establish whether they can produce non-consensual sexually explicit or intimate content, and what controls sit in front of that. It is a defined prohibition with a defined date, and the nearest item on the calendar that is new rather than deferred. Through 2028, the equivalent work belongs to product engineering: embedded high-risk AI in machinery, toys and lifts touches existing product safety conformity routes, which have lead times measured in quarters.

Through 2027, the work is classification, then documentation. Whether a system falls in Annex III is a judgement call needing legal input and honest engineering input. Over-classify and you buy a conformity assessment you did not need. Under-classify and you are exposed on a date you cannot move. Small mid-caps should also check whether the extended SME relief now reaches them.

One structural point. The EU gives you a dated statutory calendar you can put in a tracker and defend to a board. The US position for the same company arrives largely through state law on unsynchronised dates, which is harder to plan against even where each obligation is lighter.

How this differs from the earlier Omnibus coverage

The tracker has followed this instrument through three stages. The political agreement and the shape of the high-risk delay are covered in the high-risk delay and penalties entry, and the deferral itself in the deadlines deferral entry. Both remain accurate for those stages.

This entry covers a different event on the same instrument: entry into force. What changed is not the content of the deferral but its legal character. The separate 2 August 2026 transparency date is covered in the Article 50 transparency entry.

Frequently asked questions

Do the amended AI Act obligations apply now that the Omnibus is in force?

No. Entry into force on 27 July 2026 makes Regulation (EU) 2026/1744 binding and directly applicable in all Member States, but the obligations it amends carry their own later dates: 2 December 2026, 2 December 2027 and 2 August 2028.

Did the Omnibus create the 2 August 2026 transparency deadline?

No. The Article 50 transparency obligations apply from 2 August 2026 under the AI Act's own calendar, set before the Omnibus existed. The two land days apart, which is why they are conflated, but that date is not attributable to Regulation (EU) 2026/1744.

When do the high-risk obligations apply under the amended timetable?

High-risk AI systems listed in Annex III apply from 2 December 2027. High-risk AI embedded in physical products regulated under Annex I, such as machinery, toys and lifts, applies from 2 August 2028. The European Commission describes these as extended timelines.

What does the Omnibus add rather than defer?

It prohibits AI systems generating non-consensual sexually explicit and intimate content or child sexual abuse material, with compliance required by 2 December 2026. It also permits processing of special categories of personal data to detect and correct bias, extends SME relief to small mid-caps, and introduces an EU-level regulatory sandbox.

Last verified: July 28, 2026