EU AI Act × Digital Omnibus — updated for PE-CONS 30/26 (adopted text, 18 June 2026)

The AI Act sets the schedule. Authority is whether your agents may act when the train arrives.

The Digital Omnibus redrew the map: general application holds at 2 August 2026, but high-risk obligations moved to 2 December 2027 (Annex III) and 2 August 2028 (Annex I). Most timelines online now show the wrong dates — this one is drawn from the adopted text. The EU line is the train schedule. The KYE™ line is what should already be running when each train arrives.

The map

Two lines. The interchanges are where compliance meets authority.

Seven EU stations set the dates. Five KYE™ stations name what runs underneath. The dashed interchanges show where an AI Act duty lands on a live authority rail.

EU AI Act enforcement timeline as a metro map, with the KYE line underneath Top line: seven EU AI Act stations from entry into force in August 2024 to Annex I high-risk application in August 2028, corrected for the Digital Omnibus. Bottom line: five KYE stations — Evidence Pack, named-human finality, deployer authority map, sandbox authority, and the Authority Finality terminus — with dashed interchanges to the EU line. 1 Aug 2024 2 Feb 2025 2 Aug 2025 2 Aug 2026 18 Jun 2026 2 Dec 2027 2 Aug 2028 AI Act enters into force Prohibitions apply GPAI model obligations General date of application (held) Digital Omnibus adopted text High-risk, Annex III (moved from 2026) High-risk, Annex I products Evidence Pack™ Named-human finality Deployer Authority Map Sandbox Authority Authority Finality™ Art 12 record-keeping, sealed and replayable Art 14 oversight as a provable act, not a claim Art 26 duties bound to named, live authority Art 57/60 testing under scoped, revocable grants terminus: board here, not at the cliff EU LINE — enforcement schedule KYE LINE — running before the train arrives

EU LINE — enforcement schedule

  • 1 Aug 2024AI Act enters into force
  • 2 Feb 2025Prohibitions apply
  • 2 Aug 2025GPAI model obligations
  • 2 Aug 2026General date of application (held)⇄ KYE™: Named-human finality
  • 18 Jun 2026Digital Omnibus adopted text
  • 2 Dec 2027High-risk, Annex III (moved from 2026)⇄ KYE™: Sandbox Authority
  • 2 Aug 2028High-risk, Annex I products⇄ KYE™: Authority Finality™

KYE™ LINE — running before the train arrives

  • Evidence Pack™Art 12 record-keeping, sealed and replayable
  • Named-human finalityArt 14 oversight as a provable act, not a claim⇄ EU: 2 Aug 2026
  • Deployer Authority MapArt 26 duties bound to named, live authority
  • Sandbox AuthorityArt 57/60 testing under scoped, revocable grants⇄ EU: 2 Dec 2027
  • Authority Finality™terminus: board here, not at the cliff⇄ EU: 2 Aug 2028
EU AI Act application dates (per the adopted Omnibus text) KYE™ authority stations Interchange: where an AI Act duty meets a running authority rail
Reading the interchanges

Three obligations the Omnibus did not touch — and what each one needs at runtime.

Record-keeping, human oversight and deployer duties survived the amendment untouched. Each one binds an action, an owner and a record — which makes each one an authority checkpoint, not a paperwork item.

  • Article 12 record-keeping → Evidence Pack™ station. The Omnibus amended fifteen articles; record-keeping is not one of them. When a supervisor asks what your AI system did and under whose authority, a folder of logs is an assertion — a signed, replay-verifiable evidence pack is an answer. Build the record the way it will be examined.
  • Article 14 human oversight → named-human finality station. Oversight that exists as a policy paragraph fails the moment an agent acts at machine speed. On the KYE™ line, oversight is a recorded act: a named, currently-authorised person whose sign-off gates the actions your risk owners reserved — and whose authority is itself checkable at the moment it is used.
  • Article 26 deployer obligations → Deployer Authority Map station. The deployer duties assume somebody specific is accountable for each system in each use. A deployer authority map makes that assumption real: system by system, owner by owner, scope by scope — so the duty never floats between teams.
  • Articles 57/60 sandboxes and real-world testing → Sandbox Authority station. The Omnibus widens the room to test. Wider testing needs harder edges: scoped grants, participant consent bound to the test, exit conditions that actually revoke. Regulatory sandboxes need authority sandboxes.
Why board now

The postponement is runway, not relief.

The high-risk dates moved because standards bodies and national authorities were not ready — the adopted text says the burden proved heavier than expected. Nothing about your AI estate got safer on the day the deadline moved. The agents keep shipping; the actions keep binding; the evidence either accumulates in a defensible form from today, or it does not exist when December 2027 arrives. The teams that treat the next eighteen months as authority-infrastructure time will meet the cliff with a replay archive. The rest will meet it with a documentation sprint.

What this page is, and is not

Drawn from the adopted text. Not legal advice.

Dates on the EU line are taken from Regulation (EU) 2024/1689 and the Digital Omnibus on AI as adopted (PE-CONS 30/26, 18 June 2026), which awaits publication in the Official Journal; if the published act differs, this map changes with it. KYE™ is not an EU AI Act compliance checklist, a risk-classification tool, or a substitute for counsel — it is the authority layer underneath your AI estate: every consequential action admitted under recorded, in-scope authority, with evidence a supervisor can verify from public keys alone. One more honest note: an AI system the Act does not classify as high-risk can still refund money, change records, and send the message your customer acts on. Regulatory risk class is not authority class.

Want the KYE™ line running before your next station?