The AI Act sets the schedule. Authority is whether your agents may act when the train arrives.
The Digital Omnibus redrew the map: general application holds at 2 August 2026, but high-risk obligations moved to 2 December 2027 (Annex III) and 2 August 2028 (Annex I). Most timelines online now show the wrong dates — this one is drawn from the adopted text. The EU line is the train schedule. The KYE™ line is what should already be running when each train arrives.
Two lines. The interchanges are where compliance meets authority.
Seven EU stations set the dates. Five KYE™ stations name what runs underneath. The dashed interchanges show where an AI Act duty lands on a live authority rail.
EU LINE — enforcement schedule
- 1 Aug 2024AI Act enters into force
- 2 Feb 2025Prohibitions apply
- 2 Aug 2025GPAI model obligations
- 2 Aug 2026General date of application (held)⇄ KYE™: Named-human finality
- 18 Jun 2026Digital Omnibus adopted text
- 2 Dec 2027High-risk, Annex III (moved from 2026)⇄ KYE™: Sandbox Authority
- 2 Aug 2028High-risk, Annex I products⇄ KYE™: Authority Finality™
KYE™ LINE — running before the train arrives
- Evidence Pack™Art 12 record-keeping, sealed and replayable
- Named-human finalityArt 14 oversight as a provable act, not a claim⇄ EU: 2 Aug 2026
- Deployer Authority MapArt 26 duties bound to named, live authority
- Sandbox AuthorityArt 57/60 testing under scoped, revocable grants⇄ EU: 2 Dec 2027
- Authority Finality™terminus: board here, not at the cliff⇄ EU: 2 Aug 2028
Three obligations the Omnibus did not touch — and what each one needs at runtime.
Record-keeping, human oversight and deployer duties survived the amendment untouched. Each one binds an action, an owner and a record — which makes each one an authority checkpoint, not a paperwork item.
- Article 12 record-keeping → Evidence Pack™ station. The Omnibus amended fifteen articles; record-keeping is not one of them. When a supervisor asks what your AI system did and under whose authority, a folder of logs is an assertion — a signed, replay-verifiable evidence pack is an answer. Build the record the way it will be examined.
- Article 14 human oversight → named-human finality station. Oversight that exists as a policy paragraph fails the moment an agent acts at machine speed. On the KYE™ line, oversight is a recorded act: a named, currently-authorised person whose sign-off gates the actions your risk owners reserved — and whose authority is itself checkable at the moment it is used.
- Article 26 deployer obligations → Deployer Authority Map station. The deployer duties assume somebody specific is accountable for each system in each use. A deployer authority map makes that assumption real: system by system, owner by owner, scope by scope — so the duty never floats between teams.
- Articles 57/60 sandboxes and real-world testing → Sandbox Authority station. The Omnibus widens the room to test. Wider testing needs harder edges: scoped grants, participant consent bound to the test, exit conditions that actually revoke. Regulatory sandboxes need authority sandboxes.
The postponement is runway, not relief.
The high-risk dates moved because standards bodies and national authorities were not ready — the adopted text says the burden proved heavier than expected. Nothing about your AI estate got safer on the day the deadline moved. The agents keep shipping; the actions keep binding; the evidence either accumulates in a defensible form from today, or it does not exist when December 2027 arrives. The teams that treat the next eighteen months as authority-infrastructure time will meet the cliff with a replay archive. The rest will meet it with a documentation sprint.
Drawn from the adopted text. Not legal advice.
Dates on the EU line are taken from Regulation (EU) 2024/1689 and the Digital Omnibus on AI as adopted (PE-CONS 30/26, 18 June 2026), which awaits publication in the Official Journal; if the published act differs, this map changes with it. KYE™ is not an EU AI Act compliance checklist, a risk-classification tool, or a substitute for counsel — it is the authority layer underneath your AI estate: every consequential action admitted under recorded, in-scope authority, with evidence a supervisor can verify from public keys alone. One more honest note: an AI system the Act does not classify as high-risk can still refund money, change records, and send the message your customer acts on. Regulatory risk class is not authority class.