Guides · Updated August 2026
AI Act: every deadline, in order.
One entry per date: what starts, who it concerns, what to do. The dates are the ones written in the regulation and in the Italian rules attached to it; where the picture is still open, we say so.
The European calendar was rewritten by Regulation (EU) 2026/1744 of 8 July 2026 — the Digital Omnibus on AI — published in the Official Journal on 24 July and in force from the 27th. Anyone who read “the AI Act is delayed” and filed the matter away has moved the problem, not solved it: the postponement covers the high-risk obligations, not the rest.
All the dates sit in Article 113 of Regulation (EU) 2024/1689, whose third paragraph the Omnibus rewrote (Article 1, point 40). In the version now in force: the regulation applies from 2 August 2026 (second paragraph); Chapters I and II from 2 February 2025, except Article 5(1), first subparagraph, points (ba) and (bb) and Article 5(1a) and (1b), which apply from 2 December 2026 (point a); Chapter III, Section 4, Chapter V, Chapter VII, Chapter XII and Article 78 from 2 August 2025, with the exception of Article 101 (point b); Chapter III, Sections 1, 2 and 3, except Article 6(5), from 2 December 2027 for the high-risk systems under Article 6(2) and Annex III and from 2 August 2028 for those under Article 6(1) and Annex I (point c); and the newly added point (d), under which Articles 102 to 110 apply from 27 July 2026.
One date sits outside Article 113 and is widely missed: the new Article 111(4) gives providers of systems generating synthetic content placed on the market before 2 August 2026 until 2 December 2026 to comply with Article 50(2). It is a targeted transitional rule: it covers marking, not the other transparency duties.
This guide lines the dates up, including the Italian ones the AI Act does not contain but which arrive earlier. Every entry cites the rule it comes from and links to the operational notes behind it.
-
Prohibited practices and AI literacy
What starts
The bans on unacceptable practices — manipulation, social scoring, emotion recognition in the workplace — are in force, together with the AI literacy duty of art. 4 of Regulation (EU) 2024/1689, applicable under art. 113, third subparagraph, point (a). Regulation (EU) 2026/1744 rewrote art. 4 with effect from 27 July 2026: providers and deployers take measures to support the AI literacy of their own staff and of anyone else operating the systems on their behalf, and the rule states that they are not required to guarantee any specific level of AI literacy for anyone. The same regulation adds two new bans to art. 5, but those apply from 2 December 2026.
Who it concerns
Providers and deployers: every organisation that uses AI systems, not only those that build them.
What to do
A written policy, signed and communicated; a training register with materials, dates and attendance. After the Omnibus, art. 4 asks for measures rather than a result: what you need to have in hand does not change, because the measures still have to be evidenced. Art. 4 has no penalty band of its own in art. 99, but it is the evidence that turns out to be missing when a more serious incident comes under an authority’s scrutiny.
The notes behind it
-
Obligations on general-purpose models
What starts
The Chapter V obligations on general-purpose models formally enter into force: technical documentation and transparency for standard models (art. 53), reinforced assessment and mitigation duties for those with systemic risk (art. 55).
Who it concerns
Those who build general-purpose models and, downstream, anyone building a service on top of a third-party model.
What to do
List the models in use, direct and indirect. The window in which you could ask for the documentation without a deadline already on your back has closed: art. 101, which lets the Commission fine model providers directly, is the one provision carved out of the 2 August 2025 anticipation (art. 113, third paragraph, point b) and applies from 2 August 2026. What used to be a favour to ask is now a question with a deadline behind it.
The note behind it
-
Italy’s AI law enters into force
What starts
Law 132 of 23 September 2025 — the first comprehensive national AI law in Europe — sets the principles, designs national governance with AgID and ACN as the reference authorities, and lays down sector rules for healthcare, public administration, employment and justice. In healthcare the decision always stays with those practising the medical profession (art. 7(5)); in public administration responsibility for the decision stays with the person, not the system (art. 14(2)).
Who it concerns
Anyone using AI systems in contexts that touch people: patients, citizens, employees, candidates.
What to do
Formalise human responsibility with names, not job functions; prepare the notices where AI is in use. The first package of implementing decrees had its preliminary reading by the Council of Ministers on 10 June 2026 and was approved on final reading by Council of Ministers no. 185 on 4 August 2026, under the delegation in art. 24: two legislative decrees, one on the use of AI in policing and on civil and criminal liability (Government Act 418), one on the powers of the national authorities and AI in training (Government Act 421). As of 12 August 2026 neither is yet in the Official Gazette: they appear in none of the tables of contents of the General Series from no. 179 of 4 August to no. 185 of 11 August, nor in the two ordinary supplements to no. 181, nor in ordinary supplement no. 30/L to no. 185, and no Gazette had been issued on 12 August. The cross-check is in the numbering: the most recent legislative decree published is no. 149 of 7 August 2026, issued on 11 August in ordinary supplement no. 30/L together with nos. 147 and 148, all three on tax matters, and the numbering of acts has reached no. 150 with the Prime Ministerial decree of 12 June 2026 carried in Gazette no. 185. Until they are published they are not in force. The designation of the AI Act authorities, however, does not wait for that decree: it is already in this law, at art. 20(2), in force since 10 October 2025, which names the digital agency AgID as the notifying authority and the cybersecurity agency ACN as market surveillance authority and single point of contact under art. 70 of the regulation, leaving the Bank of Italy, CONSOB and IVASS their market surveillance role under art. 74(6). The draft serves to give those authorities procedures, inspection powers and a penalty regime, and to add the data protection authority for art. 74(8): until it reaches the Official Gazette what is missing is the operating powers, not the designation. The delegations in arts. 16 and 24 expire on 10 October 2026, but the extension is not the same for all of them: sixty days for art. 16(2) and for the criminal-law delegation of art. 24(4), and three months for the one in art. 24(1), which follows the procedure of art. 31 of law 234/2012. Neither is automatic: it is triggered only if the deadline for the parliamentary opinion falls in the thirty days before the delegation expires, or later. Art. 24 has meanwhile been touched: decree-law 107 of 26 June 2026, in force since 27 June, inserted a new para. 5-bis — up to €100 million drawn on the “PN scuola 2021-2027” programme for the AI-literacy criterion of art. 24(2)(e) — and aligned para. 6. The delegation deadlines were not changed. Until then, what was announced is not in force.
The note behind it
-
Transparency, penalties and enforcement powers
What starts
The transparency duties of art. 50 start — anyone interacting with an AI system must know it, synthetic content must be marked in a machine-readable format, deep fakes must be disclosed. The national penalties of art. 99 have applied since 2 August 2025: what lands on this date is the last piece, art. 101, which lets the Commission fine general-purpose model providers directly up to 3% of total worldwide annual turnover or 15 million euro, whichever is higher. For generative systems placed on the market before 2 August 2026, the marking required by art. 50(2) is due from 2 December 2026. The Commission guidelines of 20 July 2026 (C(2026) 5054 final) clarify at paragraph 153 that compliance is owed “regardless of their date of placement on the market or putting into service”, and that systems which are partly interactive and partly generative benefit from the deferral only for the marking obligation. On 31 July 2026, with a day to spare, the Commission published the first list of signatories to the code of practice on transparency of AI-generated content — about 190 organisations — and announced that from 2 August the AI Office, together with national authorities, starts enforcing the regulation.
Who it concerns
Every organisation exposing AI to customers or citizens, and anyone adopting a general-purpose model.
What to do
Labels on generated content, chatbot disclosure, updated notices: weeks of work, not months — and the four extra months apply only to marking on generative systems already on the market. From model providers, ask in writing for technical documentation, information for downstream integrators, the copyright policy, the training-content summary and adherence to the code of practice — and archive the answers. The date falls on a Sunday: the first working day is Monday 3 August. Italy does have a supervisory authority, and not since today: art. 20(2) of Law 132/2025, in force since 10 October 2025, designates AgID as the notifying authority and the cybersecurity agency ACN as market surveillance authority and single point of contact under art. 70 of the AI Act, and the Commission lists ACN among the notified points of contact — without an asterisk, that is, as a designation no longer pending adoption. What is missing is the legislative decree giving those authorities procedures, inspection powers and a penalty regime, and designating the data protection authority for the systems covered by art. 74(8) — biometrics used for law enforcement, borders and justice: the draft, Government Act 421, was approved on final reading by the Council of Ministers on 4 August 2026 and as of 12 August is still awaiting publication in the Official Gazette. That same decree carries the national penalty rules that art. 99 requires of every Member State, graduated with ceilings below those of the regulation: those too exist on paper and not yet in the Gazette. None of these gaps moves the obligation: it applies regardless, and it bears on those who must comply, not on those who will supervise.
The notes behind it
- The AI Act's Delay Has a Catch: What Still Applies from 2 August 2026
- General-purpose AI models: from 2 August, you can demand more from your vendor
- AI-generated content: has your vendor signed the EU code on marking?
- AI transparency: the EU guidelines say who is on the hook from 2 August
- Article 50 of the AI Act: what to do on Monday 3 August if you are not ready
- The EU’s list of AI sandboxes was due yesterday. We could not find it
-
New bans, and marking for systems already on the market
What starts
Two deadlines on the same date, both introduced by Regulation (EU) 2026/1744. The two bans added to art. 5 of the AI Act start to apply, and they catch placing on the market, putting into service and use: systems that generate or manipulate realistic images, video and audio, or similar material, of the intimate parts of a recognisable person, or that show them taking part in sexually explicit acts, without their freely given, specific, informed and unambiguous consent; and systems that generate or manipulate child sexual abuse material or pornographic performances within the meaning of art. 2(c) and (e) of Directive 2011/93/EU. And the four-month transitional period ends for providers of systems generating synthetic audio, image, video or text content, placed on the market before 2 August 2026, to comply with the marking of art. 50(2).
Who it concerns
Anyone providing generative AI systems that were already in production before August, and anyone offering tools that generate or edit images, video, audio and text.
What to do
If a generative service was already on the market on 1 August 2026, the four months end here: machine-readable marking on the outputs, through a technical solution that is effective, interoperable and robust. On the bans, the perimeter is narrower than the headline suggests: placing on the market or putting into service is prohibited only where that generation is the system’s intended purpose, or where it is a reasonably foreseeable and reproducible outcome without significant technical modification and reasonable, adequate technical safeguards to prevent it are missing; for the deployer the ban bites only if the system is used precisely to generate that material. Anyone exposing a third-party model to their own users should get in writing which safeguards the provider has put in place, and archive the answer: the art. 5 penalty band is the highest in the regulation.
The notes behind it
- The AI Act's Delay Has a Catch: What Still Applies from 2 August 2026
- General-purpose AI models: from 2 August, you can demand more from your vendor
- AI-generated content: has your vendor signed the EU code on marking?
- The supervisor is not challenging satire: it is challenging how the notice was designed
-
Product liability: software and AI inside the perimeter
What starts
Directive (EU) 2024/2853 applies to products placed on the market or put into service after 8 December 2026 — that is art. 2(1) as it reads after the corrigendum published in Official Journal L 2026/90364 of 7 May 2026, which replaced “after 9 December 2026”, so products placed on the market on 9 December itself are covered too, where the original wording left them out — and member states must have transposed it by 9 December 2026 (art. 22(1)). For products placed on the market before that date, Directive 85/374/EEC — repealed with effect from the same day — stays in force: the line is drawn by the date of placing on the market, not by the date of the damage. The definition of “product” now includes software and artificial intelligence systems, whatever the distribution channel.
Who it concerns
Anyone placing on the market, or integrating, software and AI systems in a product or service under their own brand.
What to do
Strengthen technical documentation and decision logs: they are the first defence against the presumption of defectiveness for failure to disclose. In Italy the delegation sits in law 36 of 17 March 2026, Annex A, point 4, and has to be exercised by 9 August 2026 under art. 31(1) of law 234/2012. The Council of Ministers approved the draft on a preliminary reading on 4 August 2026, and transmission to Parliament arrived in time: it is Government Act no. 434, assigned on 7 August 2026 to the II Justice Committee with the opinion due by 16 September 2026 — exactly forty days from transmission, as art. 31(3) of law 234/2012 requires. Because that date falls after 9 August, the three-month extension has been triggered: the delegation must now be exercised by 9 November 2026. The European deadline remains 9 December 2026, and does not depend on the Italian one.
The note behind it
-
High-risk systems under Annex III
What starts
After the postponement decided by Regulation (EU) 2026/1744, the obligations on stand-alone high-risk systems under Annex III — recruitment, credit, education, critical infrastructure, justice — apply from 2 December 2027. What follows for those who adopt them moves with them, including the FRIA: the fundamental rights impact assessment required of certain deployers, public bodies and private operators providing essential services.
Who it concerns
Those who build and those who adopt systems falling under Annex III.
What to do
The postponement does not cancel the obligations, it moves them: banks, public bodies and large buyers are already writing AI Act requirements into their tender documents. The FRIA and the data protection impact assessment overlap to a large extent and are best produced from a single analysis: since 27 July 2026 art. 27(4), as rewritten by the Omnibus, expressly allows deployers to cross-refer to the relevant sections of the data protection impact assessment, or to incorporate parts of it into the FRIA. And the delay is not a pause: the art. 5 bans were never in the package that moved, and for HR systems the duty to inform workers about the logic, purposes and data categories of automated decision or monitoring systems has been Italian law since 2022 (art. 1-bis of Legislative Decree 152/1997).
The notes behind it
-
High-risk systems embedded in regulated products
What starts
For AI systems embedded in products already covered by sector legislation — Annex I: medical devices, machinery, automotive — the date is 2 August 2028.
Who it concerns
Manufacturers of regulated products that incorporate AI, and those who integrate them into larger installations.
What to do
From 27 July 2026 Regulation (EU) 2026/1744 moves Regulation (EU) 2023/1230 from Section A to Section B of Annex I to the AI Act. An AI system that is a safety component of machinery remains high risk under article 6(1), but its requirements no longer come from Chapter III of the AI Act: they enter Annex III to the Machinery Regulation, through delegated acts applying by 2 August 2028. One technical file, one conformity assessment route, the machinery notified body — which must also be designated under the AI Act: art. 43(3), as replaced by the Omnibus, gives bodies already notified under Annex I Section A until 28 January 2028 to apply. Ask yours whether it has.
The notes behind it
What does not have a date yet.
-
AgID guidelines on AI development and procurement in public administration
The public consultation closed on 11 April 2026; the two documents are awaiting the opinions of the Unified Conference and the data protection authority. The final version is expected in the second half of 2026 — expected, not fixed. They will bring an AI bill of materials, an exit strategy, a levelised cost of AI and conformity sheets into tender documents.
The note behind it -
Implementing decrees of Italian law 132/2025
The first package had its preliminary reading by the Council of Ministers on 10 June 2026, was approved on final reading on 4 August 2026 and, as of 12 August, is not in the Official Gazette yet; penalties and operational detail arrive there. The delegations expire on 10 October 2026, but the extension is not one and the same: three months for the one in art. 24(1), which follows the procedure of art. 31 of law 234/2012, sixty days for art. 16(2) and for the criminal-law delegation of art. 24(4). It is the only firm date in the Italian package.
The note behind it -
The Italian product liability decree
The delegation sits in the 2025 European delegation law; the detailed legislative decree has not been published yet, but the draft has been before Parliament since 7 August 2026 as Government Act no. 434, with the opinion due by 16 September 2026. The delegation, extended by three months, expires on 9 November 2026. The European deadline of 9 December 2026 does not depend on the Italian one.
The note behind it
The work that is identical whatever the date.
An inventory of systems with role and risk class, a signed policy, a training register, traceability of AI-assisted decisions: the same work is needed whatever the final date. It is the path described under the AI governance solution; the deadlines that ask for documents sit in the other guide.
Governance of AI systems The deadlines that ask for documents, not statements
The first step
Operational from week one.
A real use case, on your data, in production. Then it grows, week after week.
It starts with a session with our engagement expert. Your data stays yours, always.