New timeline
The AI Act came into force on 1 August 2024, and its various provisions are being implemented in phases. The first rules have applied since 2 February 2025. The AI Omnibus Regulation has further postponed the original timeline. The provisions for high-risk AI systems have been postponed until 2 December 2027 (for high-risk AI systems listed in Annex III of the AI Act) and 2 August 2028 (for products containing high-risk AI systems listed in Annex I of the AI Act), respectively. Only once the final part has come into force will the AI Act be fully in force. The current timeline for the entry into force of all provisions is therefore as follows:
- 2 February 2025: provisions on prohibited AI systems come into force
- 2 August 2025: provisions for providers of general-purpose AI models come into force
- 2 August 2026: transparency obligations
- 2 December 2027: provisions for high-risk AI systems (new deadline)
- 2 August 2028: provisions for products incorporating high-risk AI systems come into force (new deadline)
- 2 August 2030: provisions for high-risk AI systems in the public sector
Transparency obligations that came into force on 2 August 2026
The transparency obligations set out in Article 50 of the AI Act are intended to prevent deception and to enable individuals to make informed decisions. The obligations apply to all AI systems falling under the four situations described in Article 50, regardless of whether they are classified as high-risk. This means that even organisations without high-risk AI may have significant obligations, for example when using a customer service chatbot or publishing AI-generated text. The transparency obligations apply to the following AI systems:
- Direct interaction with natural persons
Where AI systems are intended to interact directly with natural persons (such as chatbots, avatars, voice assistants, etc.), providers must design them in such a way that it is immediately clear to the natural persons that they are communicating with an AI system. - AI systems that generate synthetic content
The synthetic content generated by AI systems (text, images, audio or video) must be marked by providers in a recognisable and machine-readable manner as having been artificially generated or manipulated (e.g. a digital ‘watermark’ or label). Furthermore, this marking must be detectable. - AI systems for emotion recognition or biometric categorisation
Where natural persons are exposed to AI systems designed for emotion recognition or biometric categorisation, they must be informed of this by the deployer. - AI systems that generate or alter deepfakes, or publish texts to inform the public about matters of public interest
Deployers must disclose when image, audio or video content is a deepfake, and when text published on matters of public interest has been artificially generated or edited.
Code of Practice
The European Commission provides guidance on compliance with the transparency obligations under the AI Act through a Code of Practice and guidelines. The Code of Practice sets out practical measures that providers and deployers of AI systems can take to meet these obligations and to demonstrate compliance by signing the Code. The guidelines, on the other hand, are intended to clarify the scope of the transparency obligations. Together, they provide both a practical and a legal framework for compliance.
Impact of the Omnibus Regulation
In addition to the deferral of provisions for high-risk AI systems, the Omnibus Regulation, which came into force on 27 July 2026, introduces two new prohibited AI practices by amending Article 5 of the AI Act:
- Non-consensual intimate images. AI systems capable of generating realistic intimate images without the consent of the person depicted are prohibited.
- Child sexual abuse material. AI systems that enable the generation of child sexual abuse material are prohibited.
The ban on placing on the market or putting into service applies if: generation or manipulation is the intended purpose of the system, or the system enables this as a reasonably foreseeable and reproducible result without adequate technical safeguards. Furthermore, the ban on use applies only if the deployer actively deploys the system for that purpose. Providers and deployers have until 2 December 2026 to bring their AI systems into compliance with the new prohibitions.
Enforcement and sanctions
Enforcement of the transparency obligations rests primarily with the national market surveillance authorities. The European Commission’s AI Office has a limited role in relation to AI systems built on general-purpose AI models. Failure to comply with Article 50 may result in fines of up to 15 million euros or 3% of global annual turnover, taking into account proportionality for SMEs and small mid-cap companies.
Next steps
Organisations that offer or deploy AI systems would be well advised to take action now: determine whether they are a provider or a deployer, carry out an inventory of AI systems falling under Article 50, and implement the required transparency measures. For AI systems placed on the market before 2 August 2026, there is a transition period until 2 December 2026 for the mandatory machine-readable label. Further guidance and enforcement practices will continue to take shape in the coming months.