AI Governance, Risk & Red Teaming
Aware · M8 · lesson 8 of 18 · queued
Preview — browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll →
EU AI Act Compliance Timeline (Post-Omnibus VII)
📖
now learning

EU AI Act Compliance Timeline (Post-Omnibus VII)

15 min

In one paragraph, on one page, in a meeting with the CFO who has thirty seconds and a budget knife: what changed under Omnibus VII, what did not change, and what should we be doing about each in the next 90 days? This is the lesson that turns the 250-page EU AI Act timeline into the one-slide Gantt chart your AI Governance Committee actually approves. The May 7, 2026 political agreement re-baselined four key dates, but it did not eliminate the work. The bills come due on six distinct dates between Feb 2, 2025 (already past) and Aug 2, 2028. Knowing each one, what triggers, and which one is binding regardless of Omnibus regulation publication, is the difference between a compliance program that ships on time and one that finds itself answering a regulator's letter from a date it didn't know was on the calendar.

The Omnibus VII Summary - What Changed, in Two Paragraphs

On May 7, 2026 the Council of the EU and the European Parliament reached a provisional political agreement on the Digital Omnibus on AI (commonly called "Omnibus VII" or the "AI Act Omnibus"). The deal had been in negotiation since late 2025 in response to industry concerns, notified-body capacity constraints, and the practical bottleneck of producing the Annex IV technical files and Article 17 quality-management systems on the original timeline. The political agreement does four things: it delays stand-alone Annex III high-risk obligations from Aug 2, 2026 to Dec 2, 2027; it delays Annex I embedded-product obligations from Aug 2, 2027 to Aug 2, 2028; it cuts the Article 50(2) machine-readable marking grace period and brings synthetic-content marking obligations forward to Dec 2, 2026; and it leaves GPAI enforcement powers on the original Aug 2, 2026 track.

What did Omnibus VII not change? The Article 5 prohibitions (in force Feb 2, 2025), Article 4 AI literacy (in force Feb 2, 2025), Article 53 GPAI obligations (in force Aug 2, 2025), Article 99 penalty framework (in force Aug 2, 2025), Article 73 serious-incident reporting infrastructure (operational on the Aug 2, 2026 track), and Article 27 FRIA capability for public-body and credit/insurance §5(b)/§5(c) deployers (operational on the Aug 2, 2026 track). And, critical for every program reading this lesson, Omnibus VII is a political agreement, not yet a published regulation. It must still go through formal legal review, formal adoption by the Council and the Parliament, and publication in the Official Journal of the European Union before the new dates legally apply. Until publication, the prudent program runs against both timelines and budgets accordingly.

The Six Dates Every Program Must Know

The Gantt chart has six bars. Each bar is anchored to a specific calendar date and to a specific set of articles. Walk each one slowly.

Date 1 - Feb 2, 2025 (Already Past)

The first activation date for the EU AI Act, six months after the Regulation entered into force (Aug 1, 2024). Two binding obligation sets activated on this date and continue to apply to every in-scope organization in 2026:

  • Article 5 - Prohibited AI practices. The eight categories (subliminal manipulation, vulnerability exploitation, social scoring, predictive policing, untargeted facial scraping, workplace/education emotion recognition, biometric categorization to deduce protected attributes, real-time remote biometric ID for law enforcement except in narrowly enumerated cases). Article 99(2) penalty exposure of up to €35M or 7% of global turnover applies to violations from this date forward. If your organization has not run a negative-assurance review across the AI inventory by May 2026, it is overdue.
  • Article 4 - AI literacy. Providers and deployers must ensure sufficient AI literacy among staff and other persons dealing with the operation and use of the AI system. This is a horizontal obligation that applies to every in-scope tier, minimal-risk included. The Commission's living repository of AI literacy practices (published in late 2024 and updated quarterly) is the operational reference. A literacy curriculum, role-based training modules, completion tracking, and refresh cadence are the audit-defensible evidence.

For the May 2026 program, both obligations are operational. The audit-committee question is not "are these in scope?". They are. The audit-committee question is "is our evidence current?"

Date 2 - Aug 2, 2025 (Already Past)

The second activation date, twelve months after entry into force. Three binding obligation sets activated:

  • Article 53 - GPAI provider obligations. Every GPAI provider, designated under Article 51 or not, owes the four obligations from Aug 2, 2025: Annex XI technical documentation (53(1)(a)), Annex XII downstream-deployer information (53(1)(b)), copyright policy aligned with the Copyright Directive TDM opt-out (53(1)(c)), public training-content summary per AI Office template (53(1)(d)).
  • Article 55 - GPAI-with-systemic-risk obligations. Designated GPAI providers under Article 51 additionally owe the four pillars: state-of-the-art evaluation including adversarial testing (55(1)(a)), Union-level systemic-risk assessment and mitigation (55(1)(b)), serious-incident tracking and reporting to the AI Office (55(1)(c)), cybersecurity protection of the model and physical infrastructure (55(1)(d)).
  • Article 99 - Penalty framework. The financial-penalty regime activates: up to €35M / 7% for Article 5 prohibitions, up to €15M / 3% for most provider failures including Article 16 obligations, up to €15M / 3% under 99(4) for operator and notified-body specific obligations not in 99(3)/99(5), up to €7.5M / 1% under 99(5) for incorrect/incomplete/misleading information.

For programs deploying foundation models in 2026, the Aug 2, 2025 date matters because it created the obligation set the GPAI provider already owes. The deployer should already be receiving Annex XII documentation from every commercial foundation-model vendor by May 2026.

Date 3 - Aug 2, 2026 (Unchanged by Omnibus VII)

This is the date Omnibus VII did not move and is the single most important 2026 date for every program. Twenty-four months after entry into force. The obligation sets that activate or become operationally critical:

  • GPAI enforcement powers go live. Until this date, the AI Office and the Commission have authority to monitor GPAI compliance but cannot fine, recall, or compel mitigation. From Aug 2, 2026 forward, they can. The first enforcement actions are expected in the following 12 months. Article 99(3) penalty exposure of €15M / 3% becomes a real, not theoretical, exposure for GPAI providers.
  • Article 73 serious-incident reporting infrastructure operational. The deployer-side reporting machinery, the contact for the national market surveillance authority, the internal incident-classification process, the runbook for the 10-day / 2-day / 15-day clocks (death / widespread fundamental-rights infringement or critical-infrastructure disruption / other serious incidents per the Commission draft template), the legal-counsel routing, must be operational. Even though stand-alone Annex III obligations moved to Dec 2, 2027, the reporting infrastructure remains on the original timeline because Article 73 applies to providers of any in-scope system that has been placed on the market regardless of high-risk tier carve-outs.
  • Article 27 FRIA capability operational for public-body deployers, private operators providing public services, and Annex III §5(b) creditworthiness and §5(c) life/health insurance deployers. The stand-alone Annex III date slipped to Dec 2, 2027 under Omnibus VII, but the FRIA obligation for these specific deployer categories does not wait. It is triggered by their underlying status as public bodies, providers of public services, or credit/insurance deployers, not by the Annex III stand-alone applicability date.
  • National competent authority designation deadline. Each Member State must designate the national competent authority by this date. By May 2026, most Member States had already done so or were on the verge of doing so. The designated authority is the regulator your program engages with for incidents, complaints, and registrations.
  • Notified body designation regime fully operational under Article 31. The notified-body capacity available for Annex III conformity assessments expands toward this date. The Annex III stand-alone date shifted to Dec 2, 2027, which will reshape the notified-body engagement scheduling but does not eliminate the capacity-readiness expectation.

The audit committee should be informed in detail about Aug 2, 2026 readiness no later than the Q2 2026 board meeting. The risk of operating without Article 73 reporting infrastructure or without GPAI enforcement readiness is concrete and quantified through Article 99.

Date 4, Dec 2, 2026 (Article 50(2) Watermarking, Accelerated by Omnibus VII)

Omnibus VII cut the grace period for Article 50(2). Under the original AI Act timeline, Article 50(2) machine-readable marking of synthetic content had a grace period extending into mid-2027. Under Omnibus VII, that grace period was cut, and Article 50(2) obligations now apply from Dec 2, 2026, earlier than originally planned.

Article 50(2) requires providers of AI systems generating synthetic audio, image, video, or text content to ensure that the outputs are marked in a machine-readable format and detectable as artificially generated or manipulated. Compatible technical standards include C2PA (Coalition for Content Provenance and Authenticity), SynthID (Google DeepMind's watermarking standard), and IPTC photo metadata. The Commission's draft Article 50 guidelines, published in early 2026, name these technical standards as compatible and provide guidance on labelling conditions and the limited exceptions for artistic, satirical, fictional, or law-enforcement contexts.

For a 2026 program, this affects every generative-content tool in the stack: generative-image marketing tools (Adobe Firefly, Midjourney, DALL-E), generative-video tools (Sora, Runway, Pika), generative-audio tools (ElevenLabs, Suno), generative-text tools where the output may be distributed externally. Procurement contracts for these vendors should include C2PA / SynthID / IPTC marking commitments, technical-integration delivery dates, and SLA on marking-failure incident handling. The Dec 2, 2026 date is not a polite request. It is a regulatory ceiling that the Omnibus VII deal explicitly accelerated.

Article 50(4) deepfake disclosure obligations also apply on this date for deployers of AI systems generating or manipulating image, audio, or video content constituting a "deep fake." Carve-outs apply for artistic, satirical, fictional works; additional disclosure is required for AI-generated text intended to inform the public on matters of public interest.

Date 5, Dec 2, 2027 (Stand-Alone Annex III, Moved by Omnibus VII)

The biggest Omnibus VII change. Under the original AI Act timeline, stand-alone Annex III high-risk obligations applied from Aug 2, 2026, twenty-four months after entry into force. Under Omnibus VII, this date moved to Dec 2, 2027, sixteen months later. The activating obligation set is the full high-risk machinery:

  • Article 9 risk management system: Established, implemented, documented, and maintained throughout the entire lifecycle of the high-risk AI system. Iterative process. Aligned to the state of the art.
  • Article 10 data governance: Training, validation, and testing data sets subject to data-management practices appropriate to the intended purpose; examination of biases; identification of data gaps; provisions for special categories under 10(5).
  • Article 11 + Annex IV technical documentation: The nine-section Annex IV file: (1) general description and intended purpose; (2) elements of the AI system and development process; (3) monitoring, functioning, and control; (4) appropriateness of performance metrics; (5) risk management system (Article 9); (6) changes through the lifecycle; (7) harmonized standards applied; (8) EU declaration of conformity; (9) post-market monitoring plan.
  • Article 13 transparency and information to deployers: Instructions for use, characteristics of the system, expected lifetime, human oversight measures, computational and hardware requirements.
  • Article 14 human oversight, Effective oversight of the high-risk AI system; measures appropriate to the risks and intended use.
  • Article 15 accuracy, robustness, cybersecurity: Achievement of appropriate levels of accuracy, robustness, and cybersecurity. Mitigation of risks of feedback loops in continuously learning systems.
  • Article 16 obligations of providers of high-risk AI systems, Compliance with all Chapter III Section 2 requirements; quality management system; technical documentation; record-keeping; declaration of conformity; CE marking; registration in the EU database; corrective action.
  • Article 17 quality management system, Strategy for regulatory compliance; design controls; quality control and assurance procedures; data management procedures; risk management system; post-market monitoring; communication procedures with authorities; record-keeping; resource management.
  • Article 26 obligations of deployers of high-risk AI systems. Use according to instructions; monitor; report serious incidents to the provider and to the market surveillance authority where in scope; ensure human oversight; assign sufficiently competent operators; cooperate with authorities.
  • Article 43 conformity assessment procedures, Internal control under Annex VI for most Annex III systems; notified-body assessment under Annex VII for biometric ID systems under Annex III §1.
  • Article 47 EU declaration of conformity, Signed declaration by an authorized person on behalf of the provider; identification of the system; identification of the provider; conformity statement; harmonized standards applied; notified body involvement if any.
  • Article 71 EU database registration, Registration of the high-risk AI system in the central EU database before placing on the market or putting into service.
  • Article 72 post-market monitoring, Establishment and documentation of a post-market monitoring system proportionate to the nature of the AI technologies and the risks.

The Omnibus VII slip from Aug 2, 2026 to Dec 2, 2027 gives organizations sixteen additional months to build the Annex IV technical file, stand up the Article 17 QMS, complete the Article 27 FRIA (where applicable on the deployer-side), engage notified bodies under Article 31, and complete the Article 71 registration. This is not "permission to pause", the work has compressed against a single date, and notified-body capacity will become a binding constraint as the deadline approaches. Programs that defer all 2026 work will hit a wall in late 2027. Prudent programs use 2026-2027 to clear documentation backlogs, run the FRIA process, and engage early with notified bodies.

Date 6, Aug 2, 2028 (Annex I Embedded Products, Moved by Omnibus VII)

The final activation date under the Omnibus VII timeline. Annex I embedded-product high-risk obligations: for AI systems that are safety components of, or are themselves, products covered by the harmonized Union legislation listed in Annex I (medical devices, IVDs, machinery, lifts, radio equipment, pressure equipment, etc.): applied originally from Aug 2, 2027 and moved to Aug 2, 2028. The activating obligation set is the same as the Annex III stand-alone obligation set (Article 9, 10, 11, Annex IV, etc.), integrated into the existing harmonized-product conformity machinery.

The Aug 2, 2028 date is particularly important for medical-device, in-vitro diagnostic, and industrial-equipment manufacturers. The IVDR transition has been complex and ongoing; the AI Act overlay on IVDR conformity assessment adds another year to product-readiness planning. Companies in these industries should not interpret the Omnibus VII slip as relief, the integrated CE-marking workflow under MDR / IVDR / Machinery Directive plus AI Act is more complex than either alone, and the additional year is partial compensation for the integration complexity.

The Legacy-System Carve-Out

The AI Act includes carve-outs for legacy systems that were placed on the market or put into service before the applicability dates and that are not substantially modified afterward. The Omnibus VII deal preserved (and clarified) these legacy carve-outs:

  • Legacy high-risk Annex III systems placed on the market before Aug 2, 2026 (or before Dec 2, 2027 post-Omnibus VII for stand-alone applications) that are not substantially modified are subject to a more limited obligation set. The Aug 2, 2030 legacy backstop, when the legacy carve-out narrows further for systems that remain in service, was preserved under Omnibus VII.
  • Legacy Annex I embedded products placed on the market before the Aug 2, 2028 applicability date are subject to the harmonized-product legislation's transition rules, with the AI Act overlay applying only to substantial modifications going forward.
  • Legacy GPAI models placed on the market before Aug 2, 2025 (the GPAI in-force date) have a longer transition window, most legacy obligations apply from Aug 2, 2027, but the Aug 2, 2026 enforcement date applies to all GPAI providers regardless of legacy status.

The "substantial modification" question controls the legacy carve-out's durability. Article 3(23) defines substantial modification, and Article 43(4) lays out the change-control mechanics. Programs running legacy systems should establish a change-control gate that flags any change that potentially qualifies as substantial modification: prompt updates, retraining, foundation-model swap, scope expansion, new data sources, language additions, threshold adjustments. The legacy carve-out is a real benefit but is fragile.

Omnibus VII Publication Risk - The Two-Timeline Hedge

Until Omnibus VII is formally adopted and published in the Official Journal of the European Union, the new dates do not legally apply. The original AI Act dates remain operative law. Publication is expected before Aug 2, 2026 to give the new timeline effect before the original Annex III date arrives, but adoption timelines have slipped before, and prudent programs do not assume publication on the optimistic schedule.

The two-timeline hedge: organize the 2026 Gantt chart with both the "post-Omnibus" date and the "legal date as of May 2026" for each obligation, with the conservative date (the earlier one) as the planning anchor. For example, the Annex III stand-alone date should be tracked as "Dec 2, 2027 if Omnibus VII published; Aug 2, 2026 if not." The cost of running against the conservative date is the cost of compressing 2026 spend on Annex IV technical files and Article 17 QMS work. The cost of running against the optimistic date and missing publication is missing the original Aug 2, 2026 statutory deadline. The hedge favors the conservative date for high-value, hard-to-reverse work (Annex IV file, FRIA, notified-body engagement) while allowing the post-Omnibus date for budget planning and notified-body scheduling.

The 90-Day Tactical Plan - May 15, 2026 Forward

For an AI Officer reading this lesson in May 2026, the 90-day tactical plan looks like this:

  1. Days 1-15, Refresh the AI inventory and tiering memo with the post-Omnibus-VII applicability columns. Identify the Annex III §5(b)/§5(c) deployers (credit, insurance) and public-body deployers; their FRIA work is on the Aug 2, 2026 track regardless of Omnibus VII. Confirm Article 5 negative-assurance review status across the inventory.
  2. Days 15-30, Refresh the GPAI exposure map. Confirm Annex XII receivable status from every foundation-model vendor. Engage non-signatory vendors on Annex XI / XII / copyright / public training-data summary delivery. Prepare for Aug 2, 2026 GPAI enforcement readiness.
  3. Days 30-45, Stand up Article 73 serious-incident reporting infrastructure. Identify the contact at the national market surveillance authority. Build the incident-classification decision tree. Test the 10/2/15-day reporting runbook with a tabletop exercise.
  4. Days 45-60, Engage with C2PA / SynthID / IPTC for the Article 50(2) Dec 2, 2026 watermarking obligation. Refresh procurement contracts for generative-content vendors. Test marking-failure incident handling.
  5. Days 60-75, Brief the AI Governance Committee on the post-Omnibus-VII roadmap. Re-baseline the FY26 and FY27 budgets. Reset the notified-body engagement schedule against the Dec 2, 2027 stand-alone Annex III deadline.
  6. Days 75-90: Brief the audit committee on the dual-timeline planning posture, the Aug 2, 2026 readiness state, the Dec 2, 2027 Annex III runway, the GPAI exposure-map status, and the Article 99 worst-case penalty exposure across the portfolio.

This is the plan you ship to the AI Officer. Each step has an owner, a deadline, a deliverable, and a place on the Gantt chart. The audit committee can read it in five minutes. The CFO can see the budget implications in two columns. The regulator-engagement playbook for Aug 2, 2026 readiness is concrete and shippable.

Key Takeaways

  • Omnibus VII is a political agreement, not yet a published regulation. The May 7, 2026 deal must still go through formal legal review, adoption, and publication in the Official Journal. Prudent programs run against both timelines.
  • Six dates anchor the post-Omnibus timeline. Feb 2, 2025 (Article 5 prohibitions + Article 4 literacy, past); Aug 2, 2025 (Article 53 GPAI + Article 55 systemic-risk + Article 99 penalties, past); Aug 2, 2026 (GPAI enforcement, Article 73 reporting, FRIA capability for public/credit/insurance, unchanged); Dec 2, 2026 (Article 50(2) watermarking, accelerated); Dec 2, 2027 (stand-alone Annex III, moved); Aug 2, 2028 (Annex I embedded products, moved).
  • Aug 2, 2026 did NOT move. GPAI enforcement powers, Article 73 reporting infrastructure, FRIA capability for specific deployer categories, national competent authority designation, and notified-body capacity ramp all stay on the original timeline.
  • Dec 2, 2026 accelerated. Article 50(2) machine-readable marking grace period was cut. C2PA / SynthID / IPTC procurement commitments should be in contracts now.
  • Annex III stand-alone moved to Dec 2, 2027. The full high-risk machinery, Article 9 RMS, Article 10 data governance, Article 11 + Annex IV technical file, Article 13/14/15, Article 17 QMS, Article 26 deployer, Article 43 conformity assessment, Article 47 declaration, Article 71 registration, Article 72 post-market monitoring, comes due here.
  • Annex I embedded products moved to Aug 2, 2028. Particularly material for medical devices, IVDs, machinery, and industrial-equipment manufacturers with integrated CE-marking workflows.
  • Legacy carve-outs are preserved but fragile. Article 3(23) substantial modification and Article 43(4) change control determine durability. A robust change-control gate keeps the carve-out alive.
  • Notified-body capacity is the long-pole constraint. Compressed deadline + limited supply = scheduling pressure starting now. Engage early.
  • Article 99 penalty exposure activated Aug 2, 2025. The penalty framework is real, not theoretical. €35M / 7% (Article 5), €15M / 3% (most provider failures), €7.5M / 1% (misleading info).
  • The 90-day tactical plan turns the timeline into a Gantt chart. Inventory refresh, GPAI exposure-map refresh, Article 73 infrastructure standup, Article 50(2) watermarking integration, governance-committee brief, audit-committee brief. Each step has an owner and a deadline.