The December 2026 content bans are the next real date
From 2 December the EU bans AI systems that generate non-consensual intimate imagery or child sexual abuse material. It is a narrow, absolute prohibition rather than a risk-management duty — which makes it the easiest deadline to plan for and the hardest to argue with.
Most of the AI Act asks for process: assess, document, monitor, report. The provisions arriving on 2 December 2026 do not. They prohibit a class of output outright — systems that generate non-consensual sexually explicit imagery, and systems that generate child sexual abuse material. There is no conformity assessment that makes those permissible.
Absolute prohibitions are unusual in this regulation and they behave differently from the rest of it. A risk-management duty can be satisfied by a defensible process even when something goes wrong. A prohibition is satisfied only by the thing not happening. For a model provider that means the compliance artefact is not a binder, it is a filter that works, plus evidence that it was tested against adversarial prompting rather than a keyword list.
This is also the provision most likely to reach open-weight distribution, and nobody has said clearly how. A prohibition on placing such a system on the market is straightforward to apply to a hosted API. It is considerably less straightforward when the weights are downloadable, the safety layer is removable in an afternoon, and the party doing the removing is outside the Union. That question is not answered by the text and will be answered by the first enforcement action.
For anyone tracking dates, this is the one to put in the calendar ahead of the high-risk regime. The transparency rules that landed this month are already live; December is next; the high-risk obligations most vendors are selling against are 2027 and 2028.
European Commission — AI Act — regulatory framework → · Trussed AI — EU AI Act Enforcement August 2026 Guide →