Regulatory changelog
EU AI Act timeline: every date, and where it comes from
Telling a compliance officer the wrong applicability date is the worst error a product like this can make. So there is one source for these dates inside E-ARI, every surface reads from it, and this page shows you that source. If we are wrong, you can see that we are wrong.
- Dated entries
- 9
- Moved by the Omnibus
- 4
- Engines on the consolidated text
- 22 / 41
Digital Omnibus
What the Digital Omnibus changed
Regulation (EU) 2026/1744 (Digital Omnibus on AI), amending 2024/1689 came into force on 27 July 2026. It deferred the high-risk obligations and added two prohibitions. It did not move the Article 4 literacy duty or the Article 50 transparency duties, which is the part most summaries get wrong — those still apply on their original dates.
Two further prohibitions: non-consensual intimate imagery, and child sexual abuse material
Art.5Marking of synthetic content for systems already on the market before 2 August 2026 — providers only
Art.50(2)High-risk obligations for standalone Annex III systems
Art.6(2)Art.9–17Art.26Annex IIIHigh-risk obligations for AI embedded in regulated products
Art.6(1)Annex I
Application ledger
The full application timeline
Each entry is the date a part of the Act applies, the provisions it concerns and who it binds. Entries the Omnibus moved carry a stamp.
- applies now
Art.5Prohibited practices banned
- applies now
Art.4AI literacy duty — applies to every organisation using AI, not only high-risk
- applies now
Art.53Art.55General-purpose AI model obligations
Binds providers
- applies now
Art.50Transparency duties for AI that interacts with people or generates content
- 60 days away
Art.5Two further prohibitions: non-consensual intimate imagery, and child sexual abuse material
Moved by the Omnibus
- 60 days away
Art.50(2)Marking of synthetic content for systems already on the market before 2 August 2026 — providers only
Moved by the OmnibusBinds providers
- 425 days away
Art.6(2)Art.9–17Art.26Annex IIIHigh-risk obligations for standalone Annex III systems
Moved by the Omnibus
- 669 days away
Art.6(1)Annex IHigh-risk obligations for AI embedded in regulated products
Moved by the Omnibus
- 1399 days away
Art.111Legacy public-authority systems brought into scope
Provenance register
When each engine was last checked against the text
Regulatory content in this product cannot be added without recording what it was checked against. These are the modules that encode the law, what each one decides, and the date it was last verified.
| Module | Decides | Checked | Consolidated text |
|---|---|---|---|
| operator-role.ts | Three plain questions that suggest an operator role when a system is registered: provider (builds it, has it built, or offers it under its own name, Art.3(3); putting one’s name on, or substantially modifying, a high-risk system makes one its provider, Art.25(1)), deployer (uses it under its own authority, Art.3(4)), importer (places a third-country provider’s system on the Union market, Art.3(6)), distributor (otherwise makes it available, Art.3(7)), and provider and deployer at once for an organisation that builds a system and uses it itself (Art.3(3) with Art.3(11), and Art.3(4)), whose roles apply cumulatively (Recital 83). A suggestion the registrant confirms by the tile it selects; it decides no obligation. | 2026-10-02 | Pending re-verification |
| eu-act-terms.ts | The Act’s own vocabulary in five languages: the official title of every article the duty table cites, and the Article 3 defined terms, extracted from the Official Journal rather than translated. It encodes no rule — it is the wording the other engines and the translated surfaces are required to use, so that "deployer" is Betreiber in German and responsable del despliegue in Spanish because the Regulation says so, not because we chose. | 2026-09-02 | Pending re-verification |
| compliance/artefact-satisfaction.ts | Which obligations a finalised document discharges: a finalised FRIA answers Art.27, a finalised Annex IV technical file answers the Annex IV codes and Art.11, and an EU database reference answers Art.49 and the deployer duty at Art.49(3). Draft documents discharge nothing — an unfinalised FRIA is work in progress, and counting it would flatter the reader. | 2026-08-27 | Pending re-verification |
| controls-derive.ts | How an obligation is satisfied: by an uploaded document, or by the classification record. The Art.5 prohibitions are settled by the screening determination — a prohibition is not evidenced by a document saying you do not do the thing — and a system classified prohibited fails rather than passes. | 2026-08-18 | Pending re-verification |
| ai-act-timeline.ts | Application dates for each part of the Act, and which operator each date binds. Re-read against the consolidated text on 19 Aug 2026: Art.111(4) defers only Art.50(2) and binds providers, so it is not a deployer deadline; Art.113(3)(c) puts Annex III high-risk at 2 Dec 2027 and Annex I at 2 Aug 2028. | 2026-08-24 | Read |
| ai-act-scope.ts | Safety-component test, Art.6(1a) exclusions, Art.6(1c) carve-out, small mid-cap thresholds. Re-read against the consolidated text on 20 Aug 2026. Two corrections: the Art.6(1b) override was carrying Art.3(14)'s "or property" wording, which the override does not have, so systems 6(1a) excludes were being pulled back in; and Art.6(1c) was not encoded at all. | 2026-08-20 | Read |
| compliance/ai-act-obligations.ts | Obligation catalogue behind the gap radar and coverage matrix. Re-read against the consolidated text on 20 Aug 2026. It had been verified against artificialintelligenceact.eu, which publishes the Official Journal text of 13 June 2024 and has no changelog entry after 3 July 2025 — a reference that predates the Omnibus and therefore confirms the wrong text without erroring. Corrections found: the old fifth paragraph of Art.10 had moved to Art.4a and its deployer half was missing; Art.5(1)(c) was narrowed to public authorities, which the article does not say; Art.5(1)(d) was labelled as real-time biometric ID, which is Art.5(1)(h); and Art.5(1)(e) to (h) were absent from the catalogue entirely. On 2 Oct 2026 the roles of Art.4 and Art.50 were aligned with the readings already verified in training-modules.ts and ai-act-annex.ts (providers and deployers only), and three labels were corrected: Art.43 (internal control for Annex III points 2 to 8, a notified body only where the article requires one), Art.22 (providers established outside the Union only) and Art.49(3) (public-authority deployers only). | 2026-10-02 | Read |
| ai-act-annex.ts | Annex III areas, all eight Art. 5 prohibition limbs plus the two added by Reg. 2026/1744, and Art. 50 triggers, as data. Re-read against the consolidated text on 20 Aug 2026: Annex III carries no M1 amendment markers and is unchanged by the Omnibus. Art.5 gained points (ba) and (bb), now cited by their own letters rather than by the amending instrument, and the narrowing conditions in Art.5(1a) are asked rather than assumed — notably that a deployer is caught only where they use the system for the purpose of generating such material. | 2026-08-20 | Read |
| ai-act-classify.ts | Deterministic risk-tier rules and the trace behind each determination | 2026-08-06 | Pending re-verification |
| compliance/classifier.ts | Rationale prompt and citation guard over the rule-decided tier | 2026-08-06 | Pending re-verification |
| compliance/confirmation.ts | The confirmation workflow over the engine’s open questions: which determination a human may record, and under what documented conditions. Cites Art. 6(3) (the provider’s documented derogation assessment — the reason a rebuttal requires a note and can only lower a high presumption), Art. 5(1a) (the narrowing conditions behind the detect-vs-generate questions), and the rebuttal-tier ladder that follows from them. | 2026-09-06 | Read |
| compliance/incident.ts | The Art. 73 serious-incident regime as data: the statutory clocks (15 days from awareness, 10 where the incident caused death, 2 for critical infrastructure — Art. 73(1)-(2)), the Art. 3(49) severity definitions behind the intake categories, Art. 73(4) (an initial report may precede the complete one), Art. 73(6) (the mandatory post-incident analysis and corrective action that closure requires), and the deployer chain under Art. 26(5) (provider first, then importer/distributor and the authorities). Re-read against the consolidated text on 6 Sep 2026; the Omnibus renumbered nothing here. | 2026-09-06 | Read |
| compliance/framework-overlap.ts | The inverse crosswalk over the countdown engine’s framework tables: which AI Act obligations share substance with an ISO/IEC 42001 Annex A control or a NIST AI RMF sub-category, and which are the Act’s own machinery. Cites the Act’s articles only through the obligation catalogue’s hintArticles and the frameworks’ crosswalkArticles — it asserts no mapping of its own, so it can never disagree with the certification projections. The overlap semantics ("shared substance, not transferred evidence") are the honest boundary: an overlap names work the framework already demands, never a discharge of the Act’s duty. | 2026-09-06 | Read |
| regulatory-mapping.ts | Pillar-to-obligation mapping across the Act, NIST AI RMF and ISO 42001 | 2026-08-04 | Pending re-verification |
| training-modules.ts | Article 4 literacy curriculum, including the risk-tier explainer. The Art.4 lesson was rewritten on 19 Aug 2026 against the consolidated text: the duty is to take measures supporting the development of AI literacy, and the article now says expressly that no specific level need be guaranteed in any individual. On 24 Aug 2026 the penalty passages were corrected — they quoted the EUR 35M/7% and EUR 15M/3% ceilings flat, which Art.99(6) forbids applying to an SME, where the fine is the LOWER of the percentage and the fixed amount; Art.99(6a) does the same for small mid-caps. A quiz item whose only correct answer was the figure an SME may not be quoted was replaced. Adds the Art.26 deployer module. | 2026-08-24 | Read |
| training-context.ts | Sector- and size-specific notes layered over the Article 4 curriculum. Names which deployments in a sector tend to attract which duties (Annex III headings, the safety-component route, Art.26 and Art.27 deployer duties) without ever settling a tier — that stays with ai-act-classify.ts, and Art.6(3) allows rebuttal in any case. Carries the Art.99(6) and 99(6a) penalty tie-break and the Art.62/63 proportionate-treatment provisions for SMEs into the training, delegating to penaltyCeilingRule() and assessSmallMidCap() so it inherits their refusal to assert a status the recorded size band cannot settle. | 2026-08-24 | Read |
| ai-tool-catalog.ts | Per-tool risk notes, including which tools carry the Art. 50 transparency duty | 2026-08-04 | Pending re-verification |
| progression.ts | Which obligations gate each stage of the compliance journey | 2026-08-04 | Pending re-verification |
| compliance/obligation-applicability.ts | The tier-by-role mapping of which obligations apply (shared by the journey, Controls, and the public exposure check). Minimal risk carries Art.4 alone, as the classifier states; limited carries Art.4, the Art.5 prohibitions and Art.50; high carries every duty of the roles held. Art.4 and Art.50 bind providers and deployers, not importers or distributors. The general-purpose AI model duties (Art.53, Art.54) and the Commission’s standardisation duty (Art.40(2)) are never applied to a registered system. Two recorded answers scope a system: Art.27(1) asks for a fundamental rights impact assessment only from deployers that are bodies governed by public law or private entities providing public services, and from deployers of Annex III point 5(b) and (c) systems, never for Annex III point 2; Art.49(3) asks only deployers that are public authorities, Union institutions or bodies, or act on their behalf, to register their use. The register cannot tell which deployer it holds, so a person records each; a recorded “does not apply” removes the duty, and an unanswered question keeps it listed. A system held as provider and deployer owes the duties of both roles together (Recital 83). Corrected on 2 Oct 2026 after an article-by-article audit of the catalogue. | 2026-10-02 | Pending re-verification |
| compliance/document-duties.ts | Whether a system’s workflow presents the Art.27 fundamental rights impact assessment and the Annex IV technical file as owed. It adds no rule of its own: it reads the tier-by-role mapping above (Art.27 with the deployer of a high-risk system, Art.11 and Annex IV with its provider), and calls a document not required only once the system has a classification. An unclassified system is undetermined, not exempt, and a high-risk deployer’s FRIA reads “depends” until a person records whether Art.27(1) reaches them. | 2026-10-02 | Pending re-verification |
| countdown/obligation-deadlines.ts | The wave binding: which obligation becomes applicable at which milestone. Joins the obligation catalogue to the timeline — the eight original prohibitions and Art.4 at 2025-02-02, the two Omnibus prohibitions at 2026-12-02, Art.50 at 2026-08-02, GPAI at 2025-08-02, the high-risk family at the Art.113(3)(c) waves (Annex III 2027-12-02, Annex I 2028-08-02, unresolved binding the earlier date), and the registration family (Art.49, Art.49(3)) marked unsettled: projected against the Commission’s stated reading, displayed with the alternate, never counted as a hard projected-miss. | 2026-08-31 | Read |
| countdown/collection-effort.ts | The published collection-effort table (days to produce one artifact of each type, a rationale per row) and its interaction with the decay windows: which evidence collected today is still credible on a future deadline date. Methodology, calibrated against nothing yet — phase 2 replaces the seed with observed medians as a COUNTDOWN_VERSION bump. | 2026-08-31 | Read |
| countdown/org-projection.ts | The org-level assembly the countdown API runs: which obligations a register produces (tier × role per system), and the discharge semantics the projection inherits unchanged from controls-derive.ts — prohibitions settled by the classification determination, the registration family by an EU database reference, Art.27 by a finalised FRIA and the Annex IV family by a finalised technical file (a draft discharges nothing). | 2026-08-31 | Read |
| countdown/accuracy.ts | The accuracy ledger (phase 3): the five-way reconciliation of stored projections against realised control states once a milestone passes. Encodes no obligation mapping of its own — it re-evaluates the same satisfaction semantics org-projection.ts inherits (prohibitions by the classification determination, Art.49 by the registration reference, Art.27 by a finalised FRIA, the Annex IV family by a finalised technical file, everything else by clause-mapped evidence), and refuses to reconcile the unsettled Art.49 family — projections that never counted as hard misses are never graded as forecast errors either. | 2026-08-31 | Read |
| countdown/frameworks/iso-42001.ts | The ISO/IEC 42001:2023 Annex A control set — 38 controls across the nine control objectives (A.2 policies through A.10 third-party relationships) — mapped to the platform evidence model with an AI Act article crosswalk per control for clause-level evidence matching. Titles are condensed from the standard’s control statements; the deadline is the org’s own audit target, never a regulatory date. NOT LEGAL ADVICE — verify against ISO/IEC 42001:2023 before relying on the mapping. | 2026-08-31 | Pending re-verification |
| countdown/frameworks/nist-rmrf.ts | The NIST AI RMF 1.0 Core sub-categories — all 72 (GOVERN 19, MAP 18, MEASURE 22, MANAGE 13), numbered as in the framework and NIST’s own Playbook export — mapped to the platform evidence model with an AI Act article crosswalk per sub-category. Titles are condensed from the framework’s sub-category statements; the deadline is the org’s own assessment target, never a regulatory date — the AI RMF is a voluntary framework and not EU law. NOT LEGAL ADVICE — verify against NIST AI RMF 1.0 before relying on the mapping. | 2026-08-31 | Pending re-verification |
| vendor-questionnaire.ts | Supplier questions mapped to provider obligations, incl. Art. 51 GPAI | 2026-08-04 | Pending re-verification |
| plain-summary.ts | The timing paragraph on every results page | 2026-08-04 | Pending re-verification |
| marketing-engine.ts | Ground-truth block handed to the language model | 2026-08-04 | Pending re-verification |
| ask-engine.ts | The deterministic public Q&A surface (/ask): the classify engine’s rules, the timeline’s dates and the obligation catalogue’s tier-by-role counts restated as plain-language answers, with the Art.6(3) provisional-determination caveat attached to every Annex III match. Encodes no regulatory mapping of its own — it composes the registered engines above and cites the corpus for every date it states. | 2026-08-31 | Read |
| assessment-constructs/index.ts | The constructs registry — the second instrument: the nine constructs the scored instrument does not cover (inventory & Art. 6, vendor/GPAI Art. 25, incident management, logging Art. 12, human oversight Art. 14, post-market monitoring, bias-metric depth, ISO/IEC 42001 9.2 internal audit and 9.3 management review), each item optionally cross-linked to the AI_ACT_* obligation codes of compliance/ai-act-obligations.ts. A diagnostic instrument reported as gaps, never a score — which obligations apply stays with the compliance engine. | 2026-09-01 | Read |
| assessment-constructs/engine.ts | The second instrument’s answer semantics: yes/no/partially count as open gaps, dk as a knowledge gap, na is recorded and excluded from the gap counts, and absence is unanswered. Diagnostics, not obligations — it encodes no article content of its own and settles no obligation; the AI_ACT_* codes it relays per gap belong to compliance/ai-act-obligations.ts. | 2026-09-01 | Pending re-verification |
| assessment-constructs/constructs/inventory-classification.ts | The inventory construct: whether every AI system is listed with a named owner, carries a recorded Art. 6 classification with its route and reasoning, and is re-classified on substantial modification. | 2026-09-01 | Read |
| assessment-constructs/constructs/vendor-gpai-supply-chain.ts | The vendor/GPAI construct (Art. 25): whether third-party and GPAI supplier duties are written into contracts and backed by supplier documentation. | 2026-09-01 | Read |
| assessment-constructs/constructs/incident-management.ts | The incident-management construct: whether AI system failures have a documented response process with named roles, and whether it has been exercised. | 2026-09-01 | Read |
| assessment-constructs/constructs/logging.ts | The logging construct (Art. 12): whether record-keeping logs are produced, retained, and available to those entitled to them. | 2026-09-01 | Read |
| assessment-constructs/constructs/human-oversight.ts | The human-oversight construct (Art. 14): whether oversight measures are specified per system and overseers are designated, trained, and able to intervene. | 2026-09-01 | Read |
| assessment-constructs/constructs/post-market-monitoring.ts | The post-market monitoring construct: whether a plan exists per system, collects field performance, and feeds serious incidents back into the response process. | 2026-09-01 | Read |
| assessment-constructs/constructs/bias-metrics.ts | The bias-metrics construct: whether bias testing names its metrics, datasets and thresholds per system, is repeated, and its findings are acted on. | 2026-09-01 | Read |
| assessment-constructs/constructs/internal-audit.ts | The internal-audit construct (ISO/IEC 42001 9.2): whether the AI management system is audited on a planned schedule, impartially, with findings tracked to closure. | 2026-09-01 | Pending re-verification |
| assessment-constructs/constructs/management-review.ts | The management-review construct (ISO/IEC 42001 9.3): whether top management reviews the AI management system on the inputs the standard names and records what it decides. | 2026-09-01 | Pending re-verification |
Oldest verification: 2026-08-04 (regulatory-mapping.ts).
Sources
Instruments relied on
Regulation (EU) 2024/1689 (Artificial Intelligence Act)
in force 1 August 2024Regulation (EU) 2026/1744 (Digital Omnibus on AI), amending 2024/1689
in force 27 July 2026- in force 27 July 2026
Commission Recommendation (EU) 2025/1099 on the definition of small mid-cap enterprises
not binding- not binding
NIST AI Risk Management Framework 1.0
not bindingISO/IEC 42001:2023 — AI management systems
not binding
This is a record of what the platform applies, not legal advice. Dates and scope depend on how your specific systems are classified. How classification works.