Module 5 of the free EU AI Act Fundamentals course: the full application timetable after the Digital Omnibus, who enforces what, and the three penalty bands of Art. 99.
The AI Act entered into force on 1 August 2024 and applies in stages. The Digital Omnibus, agreed by the Council on 29 June 2026, moved some of those stages and left others exactly where they were. Knowing which is which is the difference between a programme that is late and one that is early.
The timetable
| Date | What applies | Status |
|---|---|---|
| 2 Feb 2025 | Prohibited practices (Art. 5) · AI literacy (Art. 4) | In force |
| 2 Aug 2025 | GPAI model obligations (Art. 53–55) · governance · penalties | In force |
| 2 Aug 2026 | Transparency obligations (Art. 50) | NOT deferred |
| 2 Dec 2026 | New Art. 5 prohibition (non-consensual intimate imagery) · end of the grace period for marking generated content | Added by the Omnibus |
| 2 Dec 2027 | High-risk — Annex III | Deferred from 2 Aug 2026 |
| 2 Aug 2028 | High-risk — Annex I (products under harmonisation law) | Deferred |
Two things follow from that table.
Art. 50 is the live deadline. It was not deferred, and it applies whatever your risk tier. Any organisation running a customer-facing chatbot, a voice assistant, or a pipeline that generates content has a fixed date of 2 August 2026 — sooner than the high-risk regime that dominates most programme plans.
The deferral is not a reprieve for scoping. Annex III obligations start in December 2027, but the work that takes longest — determining role, classifying systems, getting Annex IV information out of vendors, renegotiating contracts — has to happen well before. Firms that read the deferral as eighteen quiet months will spend the last six of them in a hurry.
What the Omnibus actually changed
It is worth being precise, because the Omnibus was widely over-reported:
- Art. 4 AI literacy was softened, not removed. The wording moved from "shall ensure a sufficient level" to "shall take measures to support" AI literacy. It still applies to providers and deployers.
- Registration in the EU database was NOT abolished. That proposal was dropped; registration remains.
- Marking of generated content: the grace period was shortened from six months to three, ending 2 December 2026.
- High-risk timing moved as shown above.
Who enforces
- National market surveillance authorities enforce the system-level regime in each member state. Financial entities are a special case: where the entity is already supervised under EU financial services law, the financial supervisor is typically designated as the market surveillance authority for its AI systems. Your existing prudential supervisor is likely to be your AI Act authority too.
- The AI Office, within the Commission, supervises GPAI models directly.
- Notified bodies perform third-party conformity assessment for the cases that require it.
The penalties (Art. 99)
Three bands. In each case the fine is the higher of the two figures:
| Band | Ceiling | What triggers it |
|---|---|---|
| Top | €35 m or 7% of total worldwide annual turnover | Breach of the Art. 5 prohibitions |
| Middle | €15 m or 3% | Most other infringements — including all deployer obligations, provider obligations, notified-body duties, and the Art. 50 transparency rules |
| Information | €7.5 m or 1% | Supplying incorrect, incomplete or misleading information to authorities or notified bodies |
For SMEs and start-ups the rule inverts: the fine is the LOWER of the two figures. That is a deliberate proportionality mechanism, and it is often misquoted in the other direction.
Two points that get lost:
- The 3% band is the one most organisations should plan against. It covers the deployer duties in Art. 26 — oversight, logs, informing workers — which are the obligations a normal company is most likely to miss.
- Penalties are not the whole exposure. A market surveillance authority can require a system to be withdrawn or recalled. For a system embedded in a lending or hiring process, being ordered to stop using it is a bigger operational event than the fine.
What a reasonable programme does next
In the order that actually works:
- Inventory. Every AI system, with its intended purpose in the provider's words. You cannot classify what you have not listed.
- Determine role per system. Provider or deployer — and check Art. 25 honestly for each.
- Classify. Use the Annex III carve-outs from Module 2 rather than assuming. Most systems come out lower than expected.
- Do Art. 50 now. It has the nearest date and is the cheapest to fix.
- Do Art. 4 literacy now. It is already in force, applies to everyone, and completing this course is evidence of it.
- Then build the high-risk programme for the systems that genuinely need it — risk management (Art. 9), data governance (Art. 10), technical file (Annex IV), oversight (Art. 14).
Steps 1 to 5 are mostly reading and writing. Step 6 is the programme, and it is what the AI Risk Management Pro certification is built around.
Check yourself
- Which obligation has the nearest deadline for most companies? — Art. 50 transparency, 2 August 2026. Not deferred.
- A deployer fails to keep logs and to inform workers' representatives. Which band? — Middle: €15 m or 3%. Deployer obligations sit there.
- You are a 20-person startup. Turnover €2 m. Fine for an Art. 5 breach? — The lower of €35 m and 7% of €2 m — so up to €140,000, not €35 m.
- Did the Omnibus remove EU database registration? — No. That proposal was dropped; registration stands.
Previous: Module 4 — GPAI models
You have completed the five modules. Together they cover the scope, classification, role and timing questions that Art. 4 expects staff working with AI systems to understand — take the exam and claim your certificate →
AI Act meets DORA and NIS2
Is your organisation subject to both the AI Act and DORA? The two regulations intersect on the operational resilience of financial AI systems. Our sister site regulation-dora.eu covers DORA in depth — including what the AI Act adds on top of an existing DORA programme.
The AI Act for financial institutions ↗ Explore regulation-dora.eu ↗Frequently Asked Questions
Prohibitions and AI literacy have applied since 2 February 2025. GPAI obligations since 2 August 2025. Transparency under Art. 50 applies from 2 August 2026 and was NOT deferred. High-risk under Annex III was deferred to 2 December 2027, and Annex I to 2 August 2028. The new Art. 5 prohibition on non-consensual intimate imagery applies from 2 December 2026.
Art. 99 sets three bands: up to €35 million or 7% of total worldwide annual turnover for breaching the Art. 5 prohibitions; up to €15 million or 3% for most other infringements, including all deployer obligations; and up to €7.5 million or 1% for supplying incorrect, incomplete or misleading information. In each case the higher figure applies — except for SMEs and start-ups, where the LOWER of the two applies.
Take compliance further with the AI Act Academy
Templates, training modules, and live Q&A — everything needed to implement AI Act compliance.