The AI Act Implementation Timeline: What Changes Under the AI Omnibus?
The implementation timeline of the EU AI Act has been significantly modified through the recently adopted AI Omnibus, which pushes compliance with the obligations for high-risk AI systems to December 2027 (Annex III) and August 2028 (Annex I), from the initial date of 2 August 2026. Changes of the AI Act include, among others, the addition of new prohibited practices under Article 5, measures that further allow the processing of special categories of personal data for bias detection and correction in AI systems, and revises post-market monitoring requirements.
Since the AI Act’s entry into force in August 2024, several provisions have already begun to apply: the rules on prohibited AI practices and AI literacy, and the obligations for providers of general-purpose AI models. Others, especially the rules on high-risk AI systems, will take effect over the next several years.
In November 2025, the European Commission presented the AI Omnibus proposal, aiming to reduce administrative burden and provide additional time to comply with certain obligations. Following several months of negotiations, the European Parliament and the Council of the European Union reached a political agreement on the AI Omnibus in May 2026. One of their main priorities was to agree on the revised implementation timelines ahead of the AI Act’s next milestone, envisioned for 2 August 2026.
The European Parliament adopted the agreed text of the AI Omnibus on 16 June 2026, and the Council adopted it on 29 June 2026. The AI Omnibus was published in the Official Journal of the EU on 24 July 2026.
To reflect these developments, we have updated the AI Act Implementation Timeline and incorporated both the original AI Act milestones and the changes introduced by the AI Omnibus. This accompanying blog outlines several milestones already achieved under the AI Act, such as adopted guidelines and market surveillance authorities (MSAs) appointed thus far, and provides an overview of key changes introduced by the AI Omnibus. Key takeaways include:
- While several countries including Italy and Ireland have established MSAs and communicated their Single Points of Contact to the European Commission, several remaining Member States are yet to appoint national competent authorities for the supervision of certain AI systems;
- One of the driving factors of the AI Omnibus was the postponement of requirements for high-risk AI systems, most of which have been delayed to 2 December 2027;
- The AI Omnibus slightly amends the language of the AI literacy obligation in Article 4 AI Act, so that providers and deployers are no longer required to ensure a sufficient level of AI literacy, but rather have to support the development of AI literacy for staff and other individuals dealing with the operation and use of an AI system;
- A new prohibited AI practice is introduced covering AI systems that generate child sexual abuse material (CSAM) and non-consensual intimate material;
- The legal basis for processing special category data for bias detection and correction is expanded to providers and deployers of all AI systems and models, rather than applying only to high-risk AI;
- The AI Omnibus significantly expands the powers of the AI Office, which will now have exclusive competence over systems built on GPAI models not only when both the system and the model are developed by the same provider, but “also where they are developed by providers that form part of the same undertaking”;
- The AI Omnibus follows the competitiveness and innovation logic pursued by the European Commission by ensuring that certain exemptions, including for simplified technical documentation, will apply to SMCs in addition to SMEs and start-ups.
1. AI Act implementation has already begun: an overview of the milestones achieved so far
Although it entered into force as a whole, the application of the AI Act provisions follows a phased timeline, with different obligations becoming applicable at different points over the following years.
The first institutional deadline followed soon after the AI Act’s adoption when, by November 2024, Member States were required to identify the public authorities or bodies responsible for supervising or enforcing the EU law protecting fundamental rights, make the list publicly available, and notify it to the European Commission and other Member States. In practice, this was not a single designation event happening at the same time at EU level. National implementation proceeded at varying speeds, and the European Commission established a consolidated list of appointed fundamental rights agencies, to be updated as Member States provide or revise their information.
The next governance milestone came on 2 August 2025, when Member States were required to designate at least one MSA and at least one notifying authority. The designation and notification of these authorities did not occur simultaneously across the EU, with some Member States experiencing significant delays. The European Commission maintains a list of designated Single Points of Contact which is updated continuously as Member States submit or revise their notifications. At the time of writing, only a limited number of Member States had notified their designated Single Points of Contact. These include Cyprus, Ireland, Italy, Latvia and Lithuania, and notifications from Luxembourg, Slovenia and Spain are published subject to the final adoption of the national designation decision.
The first provisions of the AI Act became applicable on 2 February 2025. These referred to the scope and definitions, the rules on prohibited AI practices, and the AI literacy obligations. The European Commission published Guidelines soon after on prohibited AI practices under Article 5 AI Act (4 February 2025), and on the definition of an AI system (6 February 2025).
Also in February of the same year, the AI Office launched a living repository of AI literacy practices. Important to note is that the repository does not create a presumption of compliance, but rather gives an indication of how the European Commission expects organizations to approach the obligation in practice. The AI Omnibus also introduces some significant changes to the AI literacy obligation, including by foreseeing an increased role of the European Commission and Member States, as further explored in Section 2.2 below.
The next milestone came on 2 August 2025, when the rules on general-purpose AI (GPAI) models, the governance framework, confidentiality obligations, and the provisions on penalties became applicable. The implementation of the GPAI framework extended beyond the envisaged application date. Article 56(9) required that the GPAI Code of Practice be ready by 2 May 2025. Although this deadline was not met, the European Commission published the GPAI Code of Practice on 10 July 2025. Soon after, the Commission also published the Guidelines on the scope of obligations for providers of GPAI models.
On 26 September 2025, the European Commission launched a public consultation on draft guidance and a reporting template on serious AI incidents under Article 73, later than the original deadline established for August 2025. The final guidance has not yet been published and the Commission published a reporting template for serious incidents involving GPAI models with systemic risk on 4 November 2025.
On 22 May 2026, the European Commission published its first review under Article 112(1), assessing whether the lists of prohibited AI practices and high-risk AI systems should be amended. It concluded that no immediate changes to Annex III were necessary and that it was still too early to assess the operation of the prohibited AI practices due to the limited implementation time. However, it identified a potential regulatory gap for AI systems generating child sexual abuse material and non-consensual intimate content, which was later addressed by the AI Omnibus through the introduction of a new prohibited AI practice (see Section 2.1 below).
The Guidelines on Transparency of AI-generated content under Article 50 were published on 20 July 2026. While Article 50 becomes generally applicable on 2 August 2026, the AI Omnibus postpones Article 50(2) (transparency obligations for GPAI models generating synthetic content) to 2 December 2026. These are complemented by a Code of Practice on Transparency of AI-generated content. The European Commission also published draft Guidelines on the classification of high-risk AI systems on 19 May 2026, with stakeholder consultations being open until 23 July 2026.
The implementation of the AI Act also revealed some of the challenges associated with this Regulation. Delays in the development of harmonized European standards and the need for additional implementation guidance became central during the legislative process and negotiations on the AI Omnibus. These developments ultimately shaped the decision to postpone the application of certain obligations for high-risk AI systems.
2. The AI Omnibus changes the timelines initially envisaged in the AI Act beyond high-risk AI
Before diving into the specifics of the changes to the AI Act timeline, it is useful to understand what the AI Omnibus is and why it was adopted. It was originally proposed by the European Commission in November 2025 as part of its broader Digital Omnibus package, aiming to reduce certain administrative burdens and facilitate the implementation of the AI Act, as part of the broader competitiveness push of the European Commission. The current text of the AI Omnibus is the result of the compromise between the European Parliament and the Council of the European Union in the legislative process, reached in May 2026. The agreed text was adopted by the European Parliament on 16 June and by the Council on 29 June.
The AI Omnibus provides for more than the postponement of implementation deadlines. It introduces a number of amendments that apply upon its entry into force, including new provisions on the supervisory and enforcement powers of the AI Office. It amends Article 113 of the AI Act (which regards the entry into force and application) to postpone the application of certain provisions, such as those concerning the requirements for high-risk AI systems, and leaves others subject to the AI Act’s existing application timeline.
The key highlights of the timeline as proposed by the AI Omnibus are the following:
- 2 August 2026: the AI Act becomes generally applicable.
- 2 December 2026: the new prohibited AI practice introduced by the AI Omnibus and the transitional transparency obligation for certain existing AI systems under Article 50(2) become applicable.
- 2 August 2027: providers of GPAI models placed on the market before 2 August 2025 must comply with the AI Act. Member States must ensure that their competent authorities establish at least one AI regulatory sandbox, operational by this date. The European Commission must also publish guidelines on the classification of high-risk AI systems under Article 6 and guidance on the implementation of Articles 8(2), 9(10), and 17(3). The Commission must also adopt delegated acts specifying the high-risk AI systems concerned, the applicable requirements or obligations, the conditions of any limitation, and its scope.
- 2 December 2027: Chapter III, Sections 1-3 (rules on the classification of high-risk AI systems, the requirements applicable to those systems, and the obligations of providers and other operators) become applicable to high-risk AI systems referred to in Article 6(2) and Annex III (AI systems classified as high-risk under Article 6(2), such as AI systems used in employment, education, law enforcement, migration, access to essential services, and the administration of justice, as listed in Annex III).
- 2 August 2028: The same Chapter III rules become applicable to high-risk AI systems referred to in Article 6(1) and Annex I (AI systems classified as high-risk under Article 6(1) because they are safety components of products, or are themselves products, covered by the Union harmonization legislation listed in Annex I).
Indeed, perhaps the most impactful change introduced by the AI Omnibus is the postponement of Chapter III, Sections 1-3 AI Act, which set out the rules on the classification of high-risk AI systems, the requirements applicable to those systems, and the obligations of providers and other operators. For the high-risk AI systems referred to in Article 6(2) and Annex III, the Chapter III requirements will apply from 2 December 2027 rather than 2 August 2026. For high-risk AI systems referred to in Article 6(1) and Annex I, the same provisions will apply from 2 August 2028 rather than 2 August 2027.
The AI Omnibus also brings some changes on substance to the AI Act. While not significant changes, they further shape AI law in the EU and are a first concrete expression of the European Commission’s push for “simplification” of regulation as part of its competitiveness agenda. Below, the blog explores some of the key changes in substance:
2.1. New prohibited AI practice focused on AI-generated CSAM and non-consensual intimate material
The AI Omnibus expands the list of prohibited AI practices under Article 5 AI Act by introducing a new prohibition covering AI systems that generate child sexual abuse material (CSAM) and non-consensual intimate material. Unlike the original Article 5 prohibitions, which have applied since 2 February 2025, this new prohibition applies from 2 December 2026. This gives providers and deployers falling within its scope approximately four months from the entry into force of the AI Omnibus to comply with the prohibition.
Given that Article 96 AI Act continues to require the European Commission to develop guidelines on the prohibited AI practices referred to in Article 5, the Guidelines on prohibited AI practices published in February 2025 will likely be updated to reflect the new prohibition introduced by the AI Omnibus. To better understand the prohibited AI practices, FPF’s “Red Lines under the AI Act” blog series breaks down each prohibition, as well as their interplay with existing EU law such as the GDPR and the Digital Services Act, and is available here.
2.2. Changes to the AI literacy obligation
Article 4 AI Act originally stated that “providers and deployers of AI systems shall take measures to ensure, to their best extent, a sufficient level of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf” (emphasis added). The new Article 4(1) of the AI Omnibus has changed slightly the wording of this provision so that providers and deployers of AI systems “shall take measures to support the development of AI literacy…” (emphasis added). The same Article 4(1) also introduces a new sentence explaining that this obligation “does not require providers or deployers to guarantee any specific level of AI literacy of any individual.” In this way, the AI literacy requirement is seemingly presented less as a strict obligation through which providers or deployers shall ensure a sufficient, measurable level of AI literacy, and more as an obligation through which some level of AI literacy should be achieved.
Coupled with the new Article 4(2) of the AI Omnibus, which introduces a role for the Commission and Member States in issuing guidance and practical examples on how the AI literacy obligation should be fulfilled, it remains to be seen how the AI literacy requirement will be implemented in practice.
2.3. Processing of special categories of personal data for bias detection and correction
The AI Omnibus introduces a new Article 4a, which allows providers of high-risk AI systems to exceptionally process special categories of personal data where this is strictly necessary to detect and correct bias. The bias detection provision originally foreseen for high-risk AI systems in Article 10(5)(a) – (f) AI Act remains unchanged by the new Article 4a of the AI Omnibus.
Where a change can be seen is in the expansion of this provision to AI systems not classified as high-risk. Indeed Article 4a introduces a new point (2) allowing “providers and deployers of other AI systems and models” (emphasis added) to exceptionally process special category data “to the extent that such processing is strictly necessary to ensure bias detection and correction in view of possible biases that are likely to affect the health and safety of persons, have a negative impact on fundamental rights or lead to discrimination” (new Article 4a (2)(a) AI Omnibus). While the applicable safeguards for this processing remain the same as those for high-risk AI systems, the legal basis for processing special category data is expanded to providers and deployers of all AI systems and models, including general-purpose AI models.
Interestingly, the new Article 4a of the AI Omnibus also adds a new sentence which clarifies that “This paragraph does not create any obligation to conduct such bias detection and correction”, leaving bias detection to the discretion of providers and deployers. The new Article 4a applies upon the entry into force of the AI Omnibus, and must continue to be applied alongside the GDPR and other applicable data protection rules.
2.4. New powers for the AI Office
The AI Office sees its supervisory role significantly expanded under the AI Omnibus. Recital 31 of the AI Omnibus states that clarifying the role of the AI Office is necessary in order to strengthen the governance of AI systems, and that it should have exclusive competence over systems built on GPAI models not only when both the system and the model are developed by the same provider, but “also where they are developed by providers that form part of the same undertaking” (emphasis added). The AI Omnibus amends Article 75 AI Act to this effect.
The AI Office will also act as the MSA for AI systems constituting or embedded in Very Large Online Platforms and Very Large Online Services as designated under the Digital Services Act (DSA) (see Recital 32 of the AI Omnibus). The same Recital also explicitly includes the requirement of regulatory cooperation between the AI Office and the European Commission unit responsible for DSA enforcement.
The AI Omnibus also introduces several new Commission guidance obligations. By 1 August 2027, the Commission must publish guidelines on the classification of high-risk AI systems under Article 6 and guidance on the practical implementation of Articles 8(2) (requirements for high-risk AI systems), 9(10) (risk management system) and 17(3) (quality management system). In addition, by 2 September 2027, the Commission must publish guidance on the post-market monitoring plan for high-risk AI systems. The extended timelines provide the Commission with significantly more time to publish and adopt interpretative guidelines to support the implementation of the AI act.
2.5. Sandboxes and other “competitiveness” markers
In view of the European Commission’s overall competitiveness agenda, the AI Omnibus similarly aims to address and facilitate innovation. A core part of this goal is the extension of certain simplified requirements from applying only to SMEs to include small mid-cap enterprises (SMCs). The Commission defines SMCs as having fewer than 750 employees and an annual turnover not exceeding EUR 150 million (see Commission Recommendation 2025/1099 of May 2025). The introduction of a new SMC category and definition is aimed at supporting the transition of enterprises from SME to SMC, recognizing that the latter may continue to face similar regulatory burdens as the former and should therefore continue to benefit from simplified requirements.
In this context, certain AI Act exemptions applicable to SMEs will also apply to SMCs, namely:
- Technical documentation for high-risk AI systems – SMCs may also use the simplified template for providing technical documentation under Annex IV AI Act (amended Article 11(1) AI Act);
- Quality management systems – SMCs can also benefit from the proportionality requirement in Article 17 AI Act, by which the implementation of quality management systems should be proportionate to the size of the provider’s organization;
- Priority to AI regulation sandboxes – alongside startups and SMEs (Recital 24 AI Omnibus, and amendments made to Article 57).
In addition to the role expansion foreseen for the AI Office, as explored above, the AI Omnibus also introduces a requirement for it to establish an AI regulatory sandbox at the Union level for systems based on GPAI models. The reasoning behind this change is a recognition that sandboxes act as regulatory tools to foster clarity and consistency in the governance of AI systems, and to foster innovation (see Recitals 24-26 AI Omnibus).
3. Concluding reflections
The simplification and competitiveness agenda of the European Commission has been so far translated for the AI Act into more generous timelines for compliance, support for sandboxes, easing of compliance bureaucracy for medium-sized enterprises and easing of the AI literacy obligations. It is notable that the amendment of the AI Act was swift – it took only about nine months for the EU legislative machine to convert the proposal into law. On the other hand, the amendments are a targeted intervention, given that the core obligations and legislative philosophy of the AI Act were not touched.
One visible structural shift achieved by the AI Omnibus was the enhancement of supervisory powers of the AI Office, which aligns with the European Commission’s inclination to centralize under its authority supervisory powers within the digital acquis. The supervisory structure of the DSA for VLOPS and VLOSES, as well as that of the Digital Markets Act follow the same trend.
The AI Omnibus does not change the AI Act’s phased implementation, but it provides a larger window for compliance readiness to providers of high-risk AI systems, addressing some of the AI Act’s deadlines and milestones. Beyond the rules for high-risk AI, prohibited practices under Article 5 are already in force and applicable, as are transparency requirements for GPAI model providers (Article 53) and systemic risk rules (Article 51).
As the implementation of the AI Act continues, keeping track of the changes provided by the AI Omnibus and the new guidance will be essential. For requirements regarding AI literacy in particular, ensuing Commission and Member States’ guidance will determine how the obligation will apply in practice.
The updated FPF AI Act Implementation Timeline provides an overview of the revised implementation timeline, key AI Omnibus amendments, and the remaining AI Act provisions that continue to apply.