Skip to content
TrustList
News

EU AI Act: in force for most businesses since 2 August 2026, with a new ban in December 2026 and high-risk rules from 2 December 2027

Editorial

By TrustList Editorial

The EU AI Act became applicable on 2 August 2026. After the AI Omnibus, high-risk rules for areas like employment and education apply from 2 December 2027, those in regulated products from 2 August 2028, and a ninth prohibition from December 2026.

About EU AI Act: in force for most businesses since 2 August 2026, with a new ban in December 2026 and high-risk rules from 2 December 2027

EU AI Act: in force for most businesses since 2 August 2026, with a new ban in December 2026 and high-risk rules from 2 December 2027

30 September 2026 — The European Commission's AI Act page sets out the dates that software companies selling or using AI in the EU now work to. The Act entered into force on 1 August 2024 and "became applicable on 2 August 2026", with exceptions. From that date the Commission's AI Office and national authorities are responsible for supervising and enforcing it. The AI Office holds enforcement powers over general-purpose AI models: it can request technical documentation, evaluate models, require corrective measures and issue fines.

The AI Omnibus moved the high-risk dates

The Commission's "AI Omnibus" was a legislative proposal to simplify the Act. It was adopted on 19 November 2025, reached political agreement on 7 May 2026 and entered into force on 27 July 2026. Its main effect for businesses is more time for high-risk systems:

  • High-risk use cases in sensitive areas (Annex III): biometrics, critical infrastructure, education, employment, migration, asylum and border control. These now apply from 2 December 2027. From that date such systems must meet strict obligations before they can be placed on the market.
  • High-risk AI embedded in regulated products (Annex I): products such as lifts or toys, with rules applying from 2 August 2028.

A new prohibition from December 2026

The Omnibus added a ninth prohibited practice: AI systems that generate non-consensual sexually explicit and intimate content, or child sexual abuse material, such as "nudification" apps. The Commission says it comes into effect in December 2026. Providers of image-generation tools should make sure their products cannot be used this way before then.

Transparency and general-purpose AI

  • Transparency: the rules apply from August 2026. On 20 July 2026 the Commission published guidelines on transparency obligations for providers and deployers of AI systems. There is also a voluntary Code of Practice on marking and labelling AI-generated content, with a set of icons publishers can use to disclose images, audio (deepfakes included) and text.
  • General-purpose AI models: the rules on transparency and copyright have applied since August 2025. Providers of models that may pose systemic risk must also assess and mitigate those risks. The GPAI Code of Practice is a voluntary way to show compliance.
  • Sandboxes: more innovators will gain access to regulatory sandboxes, including an EU-level sandbox, to test AI in real-world conditions.

Not yet independently verified. The Commission gives the new prohibition’s start only as “December 2026”, with no exact day. The publisher has not stated it yet; we will update the dates here as we hear from the publisher. We will update this when it can be confirmed, and remove this note.

What to do

  • Companies building or deploying AI for hiring, education, credit-style assessments or other Annex III areas have until 2 December 2027. Use the time for risk management, documentation and conformity work.
  • Vendors of generative tools should check their content labelling against the transparency guidelines now; those rules already apply.
  • Image-generation providers should close any route to the newly prohibited uses before December.
  • The Commission's AI Act Service Desk answers questions on applying the rules.

Sources

Categories & features