Module 5 of the free EU AI Act Fundamentals course: the full application timetable after the Digital Omnibus, who enforces what, and the three penalty bands of Art. 99.

The AI Act entered into force on 1 August 2024 and applies in stages. The Digital Omnibus, agreed by the Council on 29 June 2026, moved some of those stages and left others exactly where they were. Knowing which is which is the difference between a programme that is late and one that is early.

The timetable

Date What applies Status
2 Feb 2025 Prohibited practices (Art. 5) · AI literacy (Art. 4) In force
2 Aug 2025 GPAI model obligations (Art. 53–55) · governance · penalties In force
2 Aug 2026 Transparency obligations (Art. 50) NOT deferred
2 Dec 2026 New Art. 5 prohibition (non-consensual intimate imagery) · end of the grace period for marking generated content Added by the Omnibus
2 Dec 2027 High-risk — Annex III Deferred from 2 Aug 2026
2 Aug 2028 High-risk — Annex I (products under harmonisation law) Deferred

Two things follow from that table.

Art. 50 is the live deadline. It was not deferred, and it applies whatever your risk tier. Any organisation running a customer-facing chatbot, a voice assistant, or a pipeline that generates content has a fixed date of 2 August 2026 — sooner than the high-risk regime that dominates most programme plans.

The deferral is not a reprieve for scoping. Annex III obligations start in December 2027, but the work that takes longest — determining role, classifying systems, getting Annex IV information out of vendors, renegotiating contracts — has to happen well before. Firms that read the deferral as eighteen quiet months will spend the last six of them in a hurry.

What the Omnibus actually changed

It is worth being precise, because the Omnibus was widely over-reported:

Who enforces

The penalties (Art. 99)

Three bands. In each case the fine is the higher of the two figures:

Band Ceiling What triggers it
Top €35 m or 7% of total worldwide annual turnover Breach of the Art. 5 prohibitions
Middle €15 m or 3% Most other infringements — including all deployer obligations, provider obligations, notified-body duties, and the Art. 50 transparency rules
Information €7.5 m or 1% Supplying incorrect, incomplete or misleading information to authorities or notified bodies

For SMEs and start-ups the rule inverts: the fine is the LOWER of the two figures. That is a deliberate proportionality mechanism, and it is often misquoted in the other direction.

Two points that get lost:

  1. The 3% band is the one most organisations should plan against. It covers the deployer duties in Art. 26 — oversight, logs, informing workers — which are the obligations a normal company is most likely to miss.
  2. Penalties are not the whole exposure. A market surveillance authority can require a system to be withdrawn or recalled. For a system embedded in a lending or hiring process, being ordered to stop using it is a bigger operational event than the fine.

What a reasonable programme does next

In the order that actually works:

  1. Inventory. Every AI system, with its intended purpose in the provider's words. You cannot classify what you have not listed.
  2. Determine role per system. Provider or deployer — and check Art. 25 honestly for each.
  3. Classify. Use the Annex III carve-outs from Module 2 rather than assuming. Most systems come out lower than expected.
  4. Do Art. 50 now. It has the nearest date and is the cheapest to fix.
  5. Do Art. 4 literacy now. It is already in force, applies to everyone, and completing this course is evidence of it.
  6. Then build the high-risk programme for the systems that genuinely need it — risk management (Art. 9), data governance (Art. 10), technical file (Annex IV), oversight (Art. 14).

Steps 1 to 5 are mostly reading and writing. Step 6 is the programme, and it is what the AI Risk Management Pro certification is built around.

Check yourself

  1. Which obligation has the nearest deadline for most companies?Art. 50 transparency, 2 August 2026. Not deferred.
  2. A deployer fails to keep logs and to inform workers' representatives. Which band?Middle: €15 m or 3%. Deployer obligations sit there.
  3. You are a 20-person startup. Turnover €2 m. Fine for an Art. 5 breach? — The lower of €35 m and 7% of €2 m — so up to €140,000, not €35 m.
  4. Did the Omnibus remove EU database registration?No. That proposal was dropped; registration stands.

Previous: Module 4 — GPAI models

You have completed the five modules. Together they cover the scope, classification, role and timing questions that Art. 4 expects staff working with AI systems to understand — take the exam and claim your certificate →

Frequently Asked Questions

Prohibitions and AI literacy have applied since 2 February 2025. GPAI obligations since 2 August 2025. Transparency under Art. 50 applies from 2 August 2026 and was NOT deferred. High-risk under Annex III was deferred to 2 December 2027, and Annex I to 2 August 2028. The new Art. 5 prohibition on non-consensual intimate imagery applies from 2 December 2026.

Art. 99 sets three bands: up to €35 million or 7% of total worldwide annual turnover for breaching the Art. 5 prohibitions; up to €15 million or 3% for most other infringements, including all deployer obligations; and up to €7.5 million or 1% for supplying incorrect, incomplete or misleading information. In each case the higher figure applies — except for SMEs and start-ups, where the LOWER of the two applies.

Take compliance further with the AI Act Academy

Templates, training modules, and live Q&A — everything needed to implement AI Act compliance.