top of page

Clearing up Omnibus deadlines

  • Writer: Ley Muller
    Ley Muller
  • May 29
  • 4 min read

Updated: Jun 1

6 deadlines for the EU AI Act post-Omnibus, two that have already passed, and those that are live already for Norwegian providers


An old calendar of the month of august, with a woman walking in the background
Image: Cambridge Historical Society, CC BY

Organized in multiple ways - expand the heading most relevant to use. These are not mutually exclusive categories; an AI system can have both high-risk requirements and transparency requirements, for example.


(I stopped writing "Live: AI literacy requirements", because these are valid for every category: high-risk, transparency risk, provider, deployer, etc.)


The first upcoming deadline is 2 August of this year. Would you like a quick check of what your deadlines are and how to meet them? We offer checks to both AI developers and to organizations buying/using AI.


Deadlines for AI systems you already use (as of August)
  • Live: AI literacy requirements, for both deployers and providers

  • 2 December 2026: Transparency requirements for certain systems - those interacting with people, generating text or images, producing text used to inform the public, or generating deepfakes

  • 2 August 2027: Requirements for providers of general-purpose AI models that were on the market before August 2025

  • 2 December 2027: Requirements for providers of high-risk systems in sensitive areas, e.g. hiring and healthcare

  • 2 August 2028: Requirements for providers of high-risk systems embedded in regulated products, e.g. medical devices

  • 2 August 2030: Requirements for deployers and providers of high-risk systems intended to be used by public sector authorities


Note: High-risk systems already on the market do not need to retroactively comply with high-risk requirements, unless their design has changed significantly. This exception probably won't apply to a lot of systems - meaning there won't be a lot of unchanged-since-2026 AI systems - but it is there. From the Act:

This Regulation shall apply to operators of high-risk AI systems... that have been placed on the market or put into service before 2 August 2026, only if, as from that date, those systems are subject to significant changes in their designs.

(Article 111(2))

  • Live: AI literacy requirements

  • Live as of 2 August: Transparency requirements

  • 2 August 2027: Requirements for providers of general-purpose AI models that were on the market in August 2025

  • 2 August 2028: Requirements for providers of high-risk systems embedded in regulated products, e.g. medical devices

  • 2 December 2027: Requirements for providers of high-risk systems used in sensitive areas, e.g. hiring and healthcare

  • 2 August 2028: Requirements for providers of high-risk systems embedded in regulated products, e.g. medical devices

  • 31 December 2030:  Requirements for high-risk systems intended to be used by public authorities.

  • 2 August 2026: for systems put on the market as of this date

  • 2 December 2026: for systems already on the market, before 2 August 2026

  • 2 August 2025: For providers to meet all obligations, if their model was on the market after 2 August 2025

  • 2 August 2025: For providers (or authorized representatives) to report if their model has systemic risk

  • 2 August 2027: For providers to meet all obligations, if their model was on the market before 2 August 2025

  • Live: AI literacy requirements

  • 2 August 2026: Transparency requirements if your system is an emotion recognition system or a biometric categorization system (not if it is used in the workplace - that would be prohibited), or if your system generates/manipulates text to inform the public, or if your system makes deepfakes

  • 2 December 2026: Transparency requirements if your system interacts with people or generates text/images/video

  • 2 August 2027: Requirements for providers of general-purpose AI models that were on the market before August 2025

  • 2 December 2027: Requirements for providers of high-risk systems in sensitive areas, e.g. hiring and healthcare

  • 2 August 2028: Requirements for providers of high-risk systems embedded in regulated products, e.g. medical devices

  • 2 August 2025: For providers of general purpose AI models to mandate an authorized representative

  • 2 August 2025: For authorized representatives of general purpose AI models to report if their model has systemic risk

  • 2 December 2027: For providers of high-risk systems in sensitive areas, e.g. hiring and healthcare, to mandate an authorized representative, and for authorized representatives to meet requirements

  • 2 August 2028: For providers of high-risk systems embedded in regulated products, e.g. medical devices, to mandate an authorized representative,  and for authorized representatives to meet requirements

  • 2 August 2030: An evaluation of whether these systems meet AI Act requirements, if systems were on the market before 2 August 2027


One AI system can fall into multiple categories, each with separate deadlines.


An independent check of your deadlines, according to whether you are a provider or deployer, the intended use of the AI system, the risk class, and when you started using it, is a quick way to make sure you are on track with compliance.




Comments


bottom of page