EU AI Act Info

Resources

Regulatory timeline

What applies when, in date order. Every entry names its source; proposals that are not yet adopted are labelled as such rather than presented as law.

  1. AppliesNIS2

    Transposition deadline

    Member States had to apply the measures transposing the directive from 18 October 2024.

    Source: Directive (EU) 2022/2555 Art 41

  2. AppliesNIS2 Implementing Regulation

    Implementing Regulation 2024/2690 adopted

    Technical and methodological requirements for DNS, cloud, data centre, CDN, managed service, marketplace, search, social platform and trust service providers.

    Source: Commission Implementing Regulation (EU) 2024/2690

  3. AppliesDORA

    DORA applies

    Financial entities and their critical ICT third-party providers are under the ICT risk, incident-reporting and testing regime.

    Source: Regulation (EU) 2022/2554 Art 64

  4. AppliesAI Act

    Prohibitions and Article 4 AI literacy apply

    Every provider and deployer must take measures to support the AI literacy of its staff. The Digital Omnibus rewrote the duty in July 2026 but did not delay or remove it.

    Source: Regulation (EU) 2024/1689 Arts 4 and 113, as amended by Regulation (EU) 2026/1744

  5. AppliesAI Act

    General-purpose AI obligations apply

    Documentation, copyright policy and transparency duties for GPAI model providers.

    Source: Regulation (EU) 2024/1689 Art 113(b)

  6. AppliesCyber Resilience Act

    Chapter IV applies

    Notification of conformity assessment bodies (Articles 35 to 51) applies ahead of the main body of the regulation.

    Source: Regulation (EU) 2024/2847 Art 71(2)

  7. EnforcementNIS2

    Commission refers four Member States to the Court of Justice

    Ireland, Spain, France and the Netherlands referred over transposition. The duty on companies is live regardless.

    Source: European Commission press release IP/26/1499

  8. AppliesCyber Resilience Act

    Article 14 reporting applies

    Manufacturers of products with digital elements must report actively exploited vulnerabilities and severe incidents: early warning in 24 hours, notification in 72 hours.

    Source: Regulation (EU) 2024/2847 Art 71(2)

  9. UpcomingAI Act

    Stand-alone high-risk AI (Annex III) obligations

    Originally 2 August 2026. The Digital Omnibus on AI moved this to 2 December 2027; it was adopted on 8 July 2026 and has been in force since 27 July 2026.

    Source: Regulation (EU) 2026/1744, amending Regulation (EU) 2024/1689 Art 113

  10. UpcomingCyber Resilience Act

    The CRA applies in full

    Essential cybersecurity requirements, conformity assessment and market surveillance for products with digital elements.

    Source: Regulation (EU) 2024/2847 Art 71(2)

  11. UpcomingAI Act

    High-risk AI embedded in products

    Originally 2 August 2027. Moved by the Digital Omnibus on AI, in force since 27 July 2026.

    Source: Regulation (EU) 2026/1744, amending Regulation (EU) 2024/1689 Art 113

Dates verified against the official texts in this repository's regulations folder. Where a proposal changes a date, both the original and the proposed date are shown.