Decloak is an AI-powered web security intelligence platform that scans a site's HTTP/TLS posture, JavaScript, and third-party scripts to produce a report anyone can read. This guide is part of Decloak's library of practical, source-backed security guidance.
In this guide
- Key takeaways
- Did the EU AI Act actually pass?
- When did the Act become generally applicable?
- What are the key implementation milestones?
- What does the Digital Omnibus amendment change?
- Which obligations apply to my organization today?
- How is the Act enforced?
- What should I do next?
- Where can I find more detailed guidance?
Key takeaways
- The EU AI Act was adopted on 13 June 2024 (Regulation (EU) 2024/1689) and entered into force on 1 August 2024.
- General applicability began on 2 August 2026; some provisions started earlier (prohibited practices from 2 Feb 2025, transparency from 2 Aug 2025).
- The July 2026 Digital Omnibus amendment postponed high - risk deadlines and added new bans, but the core regulation remains in force.
- Compliance obligations vary by risk tier; high - risk AI systems must meet requirements by 2 Dec 2027 (stand - alone) or 2 Aug 2028 (product - embedded).
- Enforcement is handled by national AI Offices and the EU AI Office, with penalties for non - compliance.
Did the EU AI Act actually pass?
Yes - the EU AI Act was formally adopted by the European Parliament and Council on 13 June 2024 and became law as Regulation (EU) 2024/1689. It entered into force on 1 August 2024, making the legislation legally binding.
When did the Act become generally applicable?
The regulation started applying to AI systems placed on the EU market or used in the Union on 2 August 2026. That date marks the point when all providers must adhere to the full set of obligations, unless specific provisions have earlier entry dates.
What are the key implementation milestones?
| Milestone | What happened | Date |
|---|---|---|
| Adoption of the AI Act (Regulation (EU) 2024/1689) | Formal parliamentary and council approval | 13 June 2024 |
| Entry into force | Law becomes active, but not yet generally applicable | 1 August 2024 |
| General applicability | Obligations apply to AI placed on the EU market | 2 August 2026 |
| Prohibited - practice rules (Art. 5) and AI - literacy duties | First enforceable provisions | 2 Feb 2025 |
| Transparency obligations (Art. 50) | Provider must publish model information | 2 Aug 2025 |
| General - purpose AI model obligations | New requirements for large foundation models | 2 Aug 2025 |
| High - risk obligations (stand - alone) | Deadline for compliance | 2 Dec 2027 |
| High - risk obligations (product - embedded) | Deadline for compliance | 2 Aug 2028 |
| Digital Omnibus amendment | Postponed high - risk deadlines, added bans (e.g., nudifier, CSAM) | 27 July 2026 |
What does the Digital Omnibus amendment change?
The amendment, published on 24 July 2026 and effective 27 July 2026, does not repeal the AI Act. It mainly postpones high - risk compliance dates and adds new prohibited practices such as nudifier tools and child - sexual - abuse - material generation. The core framework and enforcement mechanisms remain unchanged.
Which obligations apply to my organization today?
- Prohibited practices (Art. 5) are enforceable from 2 Feb 2025. Ensure you are not deploying any AI system that falls under the listed bans.
- AI - literacy duties also start on 2 Feb 2025; provide training for users of high - risk AI.
- Transparency (Art. 50) requires a model - card for general - purpose AI models from 2 Aug 2025.
- High - risk AI systems still have a compliance window until late 2027/2028, but preparing early is recommended.
How is the Act enforced?
National AI Offices and the EU AI Office monitor compliance. They can issue fines up to 6 % of annual turnover for serious breaches, similar to GDPR penalties. Enforcement actions typically start after the general applicability date, but earlier penalties can be applied for prohibited practices.
What should I do next?
- Inventory your AI systems - identify any that are placed in the EU market or used by EU customers.
- Classify risk - determine if any fall under the high - risk category defined in Annex II.
- Check prohibited practices - verify none of your systems perform activities listed in Art. 5.
- Prepare documentation - create model - cards, data - governance records, and AI - literacy training plans.
- Plan for deadlines - schedule compliance work to meet the 2 Dec 2027 and 2 Aug 2028 high - risk deadlines.
Where can I find more detailed guidance?
- Implementation Guidance for the EU AI Act (PDF) - official EU document.
- EU AI Act - Shaping Europe’s digital future - European Commission overview.
- EU AI Act Tracker - what actually applies on 2 Aug 2026 - detailed timeline.
This article reflects the latest publicly available information as of September 2026.
Related guides
What is NIST in cybersecurity and why should you care?
NIST is the U.S. agency that creates the Cybersecurity Framework and a suite of standards like SP 800 - 53 that guide risk management for both government and private organizations.
Which NIST Cybersecurity Standards Should My Organization Adopt in 2024 - 2025?
Learn the core NIST publications that form a practical, layered security program, how they map together, and concrete steps to start using them today.
Does the EU AI Act apply to U.S. companies?
Yes - the EU AI Act has extraterritorial reach and can bind U.S. AI providers, deployers, importers or distributors whenever their systems are placed on the EU market, used by an EU entity, or produce output that is used in the Union.