Back to InsightsAI Governance

The AI Compliance Deadlines That Actually Matter for Your Business

The EU AI Act has been live for nearly two years. Some deadlines have already passed. Others are closer than most businesses realise. Here's where you actually stand.

Updated after the May 2026 Omnibus. On 7 May 2026, the EU agreed an amendment package that shifted several key deadlines. If you've read guidance written before that date, some dates you've seen are now out of date.

The EU's AI Act Omnibus agreement, finalised in May 2026, extended some deadlines, simplified certain requirements for smaller businesses, and added a few new obligations. It's the most substantive amendment package to the Act since it entered into force, and it shifts the full compliance deadline for high-risk AI systems to 2 December 2027.

That sounds like good news, and in some ways it is. But it doesn't mean you can wait.

The full compliance timeline

August 2024In force

EU AI Act entered into force

The Act became law. The clock started for all businesses operating in or selling to the EU.

February 2025Passed

Prohibited AI practices banned + AI literacy requirements

Social scoring, subliminal manipulation, and certain biometric surveillance banned. AI literacy (Article 4) now legally required — businesses must document that staff using AI tools have sufficient understanding to do so appropriately.

August 2025Passed

General-Purpose AI (GPAI) obligations

Providers of models like GPT-4, Claude, and Gemini must comply with transparency and data governance requirements. As a deployer, this reinforces why using enterprise-grade, paid versions of these tools matters.

2 August 2026Passed

Transparency obligations (Article 50)

Chatbot disclosure required — customers must be told they're interacting with an AI. AI-generated content must be labelled. Emotion recognition and deepfake obligations apply. Not deferred by the Omnibus — this deadline stands. Fines up to €15m or 3% of worldwide turnover.

2 December 2026New from Omnibus

New prohibitions + deferred synthetic-content marking

Two new prohibited practices take effect: AI systems that generate or manipulate non-consensual intimate imagery or CSAM are banned. Separately, for AI systems generating synthetic content that were placed on the EU market before 2 August 2026, the provider's obligation to mark outputs in a machine-readable format — deferred four months by the Omnibus — now applies.

2 December 2027Extended by Omnibus

High-risk AI system compliance (Annex III)

Extended 16 months from the original 2 August 2026 date. Covers AI used in recruitment, credit scoring, education, healthcare, and critical infrastructure. Documentation, monitoring, and human oversight must be in place. Compliance programmes should be substantially advanced now.

2 August 2028Extended by Omnibus

Regulated-product safety components (Annex I)

High-risk AI embedded in regulated products (medical devices, vehicles, lifts) — deferred one year from the original 2 August 2027 date. Documentation requirements apply throughout.

The August 2026 transparency deadline has now passed

If you have any customer-facing AI interactions and you haven't addressed transparency obligations yet, that's the immediate priority. By Q1 2026, EU member states had already issued 50 fines totalling €250 million — enforcement isn't theoretical.

What about UK businesses specifically?

The EU AI Act applies to you if you have EU customers, EU staff, or your AI systems affect people in the EU. Prohibitions have been enforceable since February 2025. The full weight of high-risk AI obligations applies from 2 December 2027.

For businesses operating purely within the UK, there is currently no single binding UK AI law with hard compliance dates. UK regulators — the ICO, FCA, CMA — are each developing AI guidance within their sectors, and a government-backed UK AI bill is expected but not yet confirmed.

Aligning with the EU framework now is the sensible approach for any UK business, regardless of whether you currently trade in Europe. When UK legislation does arrive, it will almost certainly follow a similar risk-based architecture.

One genuinely useful update from the Omnibus

The SME simplification now extends to companies with up to 750 employees and €150 million revenue. Previously, simplified requirements — reduced technical documentation, streamlined conformity assessments, sandbox access — only applied to micro and small businesses. That threshold change is significant, and it means more UK mid-market businesses qualify for a lighter compliance pathway than they would have under the original Act.

Where you need to act

Immediate
  • Audit any customer-facing AI interactions — chatbots, automated responses, AI-generated content
  • Implement chatbot disclosure notices before 2 August 2026
  • Label any AI-generated content published externally
If not already done
  • Implement AI literacy training and document it — this was required from February 2025
  • Build an AI system register listing every tool in use, its risk level, and data handling status
In progress by end of 2026
  • Complete risk classification for all AI systems — especially anything touching HR, recruitment, or credit
  • Document your impact assessment process for new AI deployments
  • Establish board-level accountability for AI governance

The honest summary

Treat 2026 as the preparation year, not the compliance year. The businesses that are scrambling to get compliant by the deadlines are the ones that left it too late.

The ones building their framework now — AI system register, impact assessment process, governance structure, staff training records — will find each subsequent deadline straightforward rather than stressful.

The August 2026 transparency deadline is the most urgent for most SMEs. Start there.

Need help understanding where your business stands against the AI Act deadlines?

We value your privacy

We use cookies to keep the site working, understand how it's used, and show you relevant Magnetic AI content. You can choose what you're happy with at any time. Read our Privacy Policy.