Guides · Updated July 2026

AI Act: every deadline, in order.

One entry per date: what starts, who it concerns, what to do. The dates are the ones written in the regulation and in the Italian rules attached to it; where the picture is still open, we say so.

The European calendar was rewritten by Regulation (EU) 2026/1744 of 8 July 2026 — the Digital Omnibus on AI — published in the Official Journal on 24 July and in force from the 27th. Anyone who read “the AI Act is delayed” and filed the matter away has moved the problem, not solved it: the postponement covers the high-risk obligations, not the rest.

All the dates sit in Article 113 of Regulation (EU) 2024/1689, whose third paragraph the Omnibus rewrote (Article 1, point 40). In the version now in force: the regulation applies from 2 August 2026 (second paragraph); Chapters I and II from 2 February 2025, except Article 5(1), first subparagraph, points (ba) and (bb) and Article 5(1a) and (1b), which apply from 2 December 2026 (point a); Chapter XII from 2 August 2025, with the exception of Article 101 (point b); Chapter III, Sections 1, 2 and 3, except Article 6(5), from 2 December 2027 for the high-risk systems under Article 6(2) and Annex III and from 2 August 2028 for those under Article 6(1) and Annex I (point c); and the newly added point (d), under which Articles 102 to 110 apply from 27 July 2026.

One date sits outside Article 113 and is widely missed: the new Article 111(4) gives providers of systems generating synthetic content placed on the market before 2 August 2026 until 2 December 2026 to comply with Article 50(2). It is a targeted transitional rule: it covers marking, not the other transparency duties.

This guide lines the dates up, including the Italian ones the AI Act does not contain but which arrive earlier. Every entry cites the rule it comes from and links to the operational notes behind it.

  1. Already in force AI Act

    Prohibited practices and AI literacy

    What starts

    The bans on unacceptable practices — manipulation, social scoring, emotion recognition in the workplace — are in force, together with the AI literacy duty of art. 4 of Regulation (EU) 2024/1689, applicable under art. 113(a). Regulation (EU) 2026/1744 rewrote art. 4 with effect from 27 July 2026: providers and deployers take measures to support the AI literacy of those operating the systems on their behalf, and the rule states that they are not required to guarantee any particular level for anyone. The same regulation adds two new bans to art. 5, but those apply from 2 December 2026.

    Who it concerns

    Providers and deployers: every organisation that uses AI systems, not only those that build them.

    What to do

    A written policy, signed and communicated; a training register with materials, dates and attendance. After the Omnibus, art. 4 asks for measures rather than a result: what you need to have in hand does not change, because the measures still have to be evidenced. Art. 4 has no penalty band of its own in art. 99, but it is the evidence that turns out to be missing when a more serious incident comes under an authority’s scrutiny.

  2. Already in force AI Act

    Obligations on general-purpose models

    What starts

    The Chapter V obligations on general-purpose models formally enter into force: technical documentation and transparency for standard models (art. 53), reinforced assessment and mitigation duties for those with systemic risk (art. 55).

    Who it concerns

    Those who build general-purpose models and, downstream, anyone building a service on top of a third-party model.

    What to do

    List the models in use, direct and indirect. The Commission’s enforcement powers arrive a year later: that is the window in which to ask for the documentation without a deadline already on your back.

  3. Already in force Italy

    Italy’s AI law enters into force

    What starts

    Law 132 of 23 September 2025 — the first comprehensive national AI law in Europe — sets the principles, designs national governance with AgID and ACN as the reference authorities, and lays down sector rules for healthcare, public administration, employment and justice. In healthcare the decision always stays with those practising the medical profession (art. 7(5)); in public administration responsibility for the decision stays with the person, not the system (art. 14(2)).

    Who it concerns

    Anyone using AI systems in contexts that touch people: patients, citizens, employees, candidates.

    What to do

    Formalise human responsibility with names, not job functions; prepare the notices where AI is in use. The first package of implementing decrees only had a preliminary reading by the Council of Ministers on 10 June 2026: as of 28 July 2026 none has been published in the Official Gazette. The drafts sit with the parliamentary committees as Government Acts 418 — policing, criminal and civil liability, assigned on 26 June 2026 with a 25 August deadline — and 421 — powers of the national authorities and AI in training, assigned on 7 July with a 16 August deadline: both are recorded as still under examination. The delegations in arts. 16 and 24 expire on 10 October 2026, extendable by sixty days: until then, what was announced is not in force.

  4. Coming up AI Act

    Transparency, penalties and enforcement powers

    What starts

    The transparency duties of art. 50 start — anyone interacting with an AI system must know it, synthetic content must be marked in a machine-readable format, deep fakes must be disclosed. The national penalties of art. 99 have applied since 2 August 2025: what lands on this date is the last piece, art. 101, which lets the Commission fine general-purpose model providers directly up to 3% of total worldwide annual turnover or 15 million euro, whichever is higher. For generative systems placed on the market before 2 August 2026, the marking required by art. 50(2) is due from 2 December 2026. The Commission guidelines of 20 July 2026 (C(2026) 5054 final) clarify at paragraph 153 that compliance is owed “regardless of their date of placement on the market or putting into service”, and that systems which are partly interactive and partly generative benefit from the deferral only for the marking obligation.

    Who it concerns

    Every organisation exposing AI to customers or citizens, and anyone adopting a general-purpose model.

    What to do

    Labels on generated content, chatbot disclosure, updated notices: weeks of work, not months — and the four extra months apply only to marking on generative systems already on the market. From model providers, ask in writing for technical documentation, information for downstream integrators, the copyright policy, the training-content summary and adherence to the code of practice — and archive the answers.

  5. Coming up AI Act

    New bans, and marking for systems already on the market

    What starts

    Two deadlines on the same date, both introduced by Regulation (EU) 2026/1744. The two bans added to art. 5 of the AI Act start to apply: systems that generate or manipulate realistic images, video or audio of the intimate parts of a recognisable person, or that depict them in sexually explicit acts, without their consent, and systems that generate child sexual abuse material. And the four-month transitional period ends for providers of generative AI systems placed on the market before 2 August 2026 to comply with the synthetic-content marking of art. 50(2).

    Who it concerns

    Anyone providing generative AI systems that were already in production before August, and anyone offering tools that generate or edit images, video and audio.

    What to do

    If a generative service was already on the market on 1 August 2026, the four months end here: machine-readable marking on the outputs, through a technical solution that is effective, interoperable and robust. On the bans, the perimeter is narrower than the headline suggests: placing on the market is prohibited where that generation is the system’s intended purpose, or where it is a reasonably foreseeable and reproducible outcome and adequate technical safeguards to prevent it are missing. Anyone exposing a third-party model to their own users should get in writing which safeguards the provider has put in place, and archive the answer: the art. 5 penalty band is the highest in the regulation.

  6. Coming up Related rule

    Product liability: software and AI inside the perimeter

    What starts

    Directive (EU) 2024/2853 applies to products placed on the market from that date, and member states must have transposed it by the same deadline. The definition of “product” now includes software and artificial intelligence systems, whatever the distribution channel.

    Who it concerns

    Anyone placing on the market, or integrating, software and AI systems in a product or service under their own brand.

    What to do

    Strengthen technical documentation and decision logs: they are the first defence against the presumption of defectiveness for failure to disclose. In Italy the delegation sits in law 36 of 17 March 2026, Annex A, point 4, and has to be exercised by 9 August 2026 under art. 31(1) of law 234/2012: as of 28 July 2026 no draft decree has been transmitted to Parliament. The European deadline stands regardless.

  7. Coming up AI Act

    High-risk systems under Annex III

    What starts

    After the postponement decided by Regulation (EU) 2026/1744, the obligations on stand-alone high-risk systems under Annex III — recruitment, credit, education, critical infrastructure, justice — apply from 2 December 2027. What follows for those who adopt them moves with them, including the FRIA: the fundamental rights impact assessment required of certain deployers, public bodies and private operators providing essential services.

    Who it concerns

    Those who build and those who adopt systems falling under Annex III.

    What to do

    The postponement does not cancel the obligations, it moves them: banks, public bodies and large buyers are already writing AI Act requirements into their tender documents. The FRIA and the data protection impact assessment overlap to a large extent and are best produced from a single analysis: since 27 July 2026 art. 27(4), as rewritten by the Omnibus, expressly allows deployers to cross-refer to the relevant sections of the data protection impact assessment, or to incorporate parts of it into the FRIA. And the delay is not a pause: the art. 5 bans were never in the package that moved, and for HR systems the duty to inform workers about the logic, purposes and data categories of automated decision or monitoring systems has been Italian law since 2022 (art. 1-bis of Legislative Decree 152/1997).

  8. Coming up AI Act

    High-risk systems embedded in regulated products

    What starts

    For AI systems embedded in products already covered by sector legislation — Annex I: medical devices, machinery, automotive — the date is 2 August 2028.

    Who it concerns

    Manufacturers of regulated products that incorporate AI, and those who integrate them into larger installations.

    What to do

    From 27 July 2026 Regulation (EU) 2026/1744 moves Regulation (EU) 2023/1230 from Section A to Section B of Annex I to the AI Act. An AI system that is a safety component of machinery remains high risk under article 6(1), but its requirements no longer come from Chapter III of the AI Act: they enter Annex III to the Machinery Regulation, through delegated acts applying by 2 August 2028. One technical file, one conformity assessment route, the machinery notified body — which must also be designated under the AI Act: art. 43(3), as replaced by the Omnibus, gives bodies already notified under Annex I Section A until 28 January 2028 to apply. Ask yours whether it has.

What does not have a date yet.

  • AgID guidelines on AI development and procurement in public administration

    The public consultation closed on 11 April 2026; the two documents are awaiting the opinions of the Unified Conference and the data protection authority. The final version is expected in the second half of 2026 — expected, not fixed. They will bring an AI bill of materials, an exit strategy, a levelised cost of AI and conformity sheets into tender documents.

    The note behind it
  • Implementing decrees of Italian law 132/2025

    The first package had its preliminary reading by the Council of Ministers on 10 June 2026 and is not in the Official Gazette yet; penalties and operational detail arrive there. The delegations expire on 10 October 2026, extendable by sixty days: it is the only firm date in the Italian package.

    The note behind it
  • The Italian product liability decree

    The delegation sits in the 2025 European delegation law; the detailed legislative decree has not been published yet. The European deadline of 9 December 2026 does not depend on the Italian one.

    The note behind it

The work that is identical whatever the date.

An inventory of systems with role and risk class, a signed policy, a training register, traceability of AI-assisted decisions: the same work is needed whatever the final date. It is the path described under the AI governance solution; the deadlines that ask for documents sit in the other guide.

The first step

Operational from week one.

A real use case, on your data, in production. Then it grows, week after week.

30 minutes video call €150 free July promotion
Start an operational trial

It starts with a session with our engagement expert. Your data stays yours, always.