EU AI Act × Digital Omnibus — updated for PE-CONS 30/26 (adopted text, 18 June 2026)

The AI Act sets the schedule. Authority is whether your agents may act when the train arrives.

The Digital Omnibus redrew the map: general application holds at 2 August 2026, but high-risk obligations moved to 2 December 2027 (Annex III) and 2 August 2028 (Annex I). Most timelines online now show the wrong dates — this one is drawn from the adopted text. The EU line is the train schedule. The KYE™ line is what should already be running when each train arrives.

EU AI Act timeline, corrected for the Digital Omnibus: the dates

Demo data

You learn: What applies when. You can: Scan the dates.

As of 1 October 2026

  1. AI Act enters into force

    EU legislator

  2. Prohibitions apply

    EU legislator

  3. GPAI model obligations

    EU legislator

  4. Digital Omnibus adopted text

    EU legislator

  5. General date of application (held)⇄ KYE™: Named-human finality

    EU legislator

  6. High-risk, Annex III (moved from 2026)⇄ KYE™: Sandbox Authority

    EU legislator

  7. High-risk, Annex I products⇄ KYE™: Authority Finality™

    EU legislator

How this widget is built
Demonstrates
Regulatory timeline
Components
  • Adopted-text dates
Flow
Each date in order, the build date marked. Architecture diagram
Used on

The map

Two lines. The interchanges are where compliance meets authority.

Seven EU stations set the dates. Five KYE™ stations name what runs underneath. The dashed interchanges show where an AI Act duty lands on a live authority rail.

EU LINE — enforcement schedule

  • 1 Aug 2024AI Act enters into force
  • 2 Feb 2025Prohibitions apply
  • 2 Aug 2025GPAI model obligations
  • 2 Aug 2026General date of application (held)⇄ KYE™: Named-human finality
  • 18 Jun 2026Digital Omnibus adopted text
  • 2 Dec 2027High-risk, Annex III (moved from 2026)⇄ KYE™: Sandbox Authority
  • 2 Aug 2028High-risk, Annex I products⇄ KYE™: Authority Finality™

KYE™ LINE — running before the train arrives

  • Evidence Pack™Art 12 record-keeping, sealed and replayable
  • Named-human finalityArt 14 oversight as a provable act, not a claim⇄ EU: 2 Aug 2026
  • Deployer Authority MapArt 26 duties bound to named, live authority
  • Sandbox AuthorityArt 57/60 testing under scoped, revocable grants⇄ EU: 2 Dec 2027
  • Authority Finality™terminus: board here, not at the cliff⇄ EU: 2 Aug 2028

EU AI Act application dates (per the adopted Omnibus text) KYE™ authority stations Interchange: where an AI Act duty meets a running authority rail

Reading the interchanges

Three obligations the Omnibus did not touch — and what each one needs at runtime.

Record-keeping, human oversight and deployer duties survived the amendment untouched. Each one binds an action, an owner and a record — which makes each one an authority checkpoint, not a paperwork item.

  • Article 12 record-keeping → Evidence Pack™ station. The Omnibus amended fifteen articles; record-keeping is not one of them. When a supervisor asks what your AI system did and under whose authority, a folder of logs is an assertion — a signed, replay-verifiable evidence pack is an answer. Build the record the way it will be examined.
  • Article 14 human oversight → named-human finality station. Oversight that exists as a policy paragraph fails the moment an agent acts at machine speed. On the KYE™ line, oversight is a recorded act: a named, currently-authorised person whose sign-off gates the actions your risk owners reserved — and whose authority is itself checkable at the moment it is used.
  • Article 26 deployer obligations → Deployer Authority Map station. The deployer duties assume somebody specific is accountable for each system in each use. A deployer authority map makes that assumption real: system by system, owner by owner, scope by scope — so the duty never floats between teams.
  • Articles 57/60 sandboxes and real-world testing → Sandbox Authority station. The Omnibus widens the room to test. Wider testing needs harder edges: scoped grants, participant consent bound to the test, exit conditions that actually revoke. Regulatory sandboxes need authority sandboxes.

Why board now

The postponement is runway, not relief.

The high-risk dates moved because standards bodies and national authorities were not ready — the adopted text says the burden proved heavier than expected. Nothing about your AI estate got safer on the day the deadline moved. The agents keep shipping; the actions keep binding; the evidence either accumulates in a defensible form from today, or it does not exist when December 2027 arrives. The teams that treat the next eighteen months as authority-infrastructure time will meet the cliff with a replay archive. The rest will meet it with a documentation sprint.

What this page is, and is not

Drawn from the adopted text. Not legal advice.

Dates on the EU line are taken from Regulation (EU) 2024/1689 and the Digital Omnibus on AI as adopted (PE-CONS 30/26, 18 June 2026), which awaits publication in the Official Journal; if the published act differs, this map changes with it. KYE™ is not an EU AI Act compliance checklist, a risk-classification tool, or a substitute for counsel — it is the authority layer underneath your AI estate: every consequential action admitted under recorded, in-scope authority, with evidence a supervisor can verify from public keys alone. One more honest note: an AI system the Act does not classify as high-risk can still refund money, change records, and send the message your customer acts on. Regulatory risk class is not authority class.

Want the KYE™ line running before your next station?

Canonical KYE™ surfaces referenced on this page: KYE Protocol™.