// news · policy2026-08-18source: Regulatory analysis

Compliance became a calendar: December 2026, December 2027, August 2028

Transparency duties are live. Content bans arrive in December. High-risk obligations sit in 2027 and 2028. Each date carries a different engineering programme, and they are not sequential.

The AI Act's obligations now sit on a staggered calendar: transparency duties enforceable since 2 August 2026; a ban on systems generating non-consensual sexually explicit content or child sexual abuse material from 2 December 2026; high-risk system rules pushed to 2 December 2027; and high-risk AI embedded in regulated products to 2 August 2028.

Staggering was intended as relief and functions as something else. Each date requires a different capability — disclosure plumbing now, content-level refusal guarantees in December, risk-management and logging systems in 2027, product-integration conformity in 2028 — and they are not versions of one another. A team cannot build them in sequence and reuse the work.

The December 2026 content ban is the one being underestimated. Prohibiting a category of output is not a policy setting; it is a guarantee about model behaviour under adversarial input, which is precisely the thing nobody can currently promise. The gap between a refusal that works in testing and one that holds against determined circumvention is the entire jailbreak literature.

The delays to 2027 and 2028 read as an acknowledgement that the high-risk regime was not implementable on the original timetable. That is defensible, and it also means the obligations most likely to change how systems are actually built are the furthest away and the least certain.

The planning implication is unglamorous: treat these as four separate programmes with four owners, not one compliance project with milestones. The first date has already passed, and it applies to everything already shipped.

See our analysis →

Cooley — EU AI Act: Transparency Obligations Take Effect 2 August 2026 → · Legal Nodes — EU AI Act 2026 Updates: Compliance Requirements and Business Risks →