Skip to content
EU AI Stack

EU AI regulation, operationally

The EU AI stack for regulated enterprises, compliant by design

Operational guidance on the AI Act, NIS2, GDPR/DORA and the Cyber Resilience Act for teams that have to put AI through a supplier audit. Every regulatory date we publish is checked against EUR-Lex or a Commission source, with the access date recorded.

Printed timeline of AI Act deadlines from 2 August 2026 to 2 August 2028, with NIS2 audit, CRA reporting and sovereign hosting blocks below

Dates that bind, and the ones that moved

The Digital Omnibus of 27 July 2026 deferred the AI Act high-risk regime. Most published roadmaps still use the old calendar.

  • 2 Aug 2026

    AI Act Article 50 applies

  • 11 Sep 2026

    CRA Article 14 incident reporting

  • 12 Sep 2026

    Data Act: data by design

  • 2 Dec 2026

    Marking grace period ends

  • 12 Jan 2027

    Switching egress fees end

  • 2 Dec 2027

    Annex III high-risk obligations

Featured

Pillars and comparisons

All articles

Where the reading leads

Three engagements

Next step

Bring us the questionnaire you cannot answer yet

Send the customer questionnaire, RFP section or audit request that is blocking a deal. We reply with the gaps we see and what closing them takes.

Request a review