The EU AI Compliance Stack 2026: AI Act, NIS2, DORA and CRA in one map

The EU AI compliance stack in 2026 is four instruments landing on the same organisation at different dates: the AI Act, NIS2, GDPR together with DORA, and the Cyber Resilience Act together with the Data Act. After the Digital Omnibus entered into force on 27 July 2026, only Article 50 transparency duties started on 2 August 2026; the high-risk regime moved to 2 December 2027 for Annex III systems and 2 August 2028 for Annex I products. This page maps every confirmed date, names the primary source behind it, and shows where all four layers share a single evidence file.
What actually applies on 2 August 2026?
Most articles published this summer still claim that the high-risk regime of the AI Act starts on 2 August 2026. It does not. The Digital Omnibus, in force since 27 July 2026, rewrote the application dates: Annex III high-risk systems move to 2 December 2027, and Annex I products move to 2 August 2028. What did start on 2 August 2026 is Article 50: transparency duties for chatbots, emotion recognition, deepfakes and machine-generated content, including the requirement that synthetic output carries machine-readable marking.
The earlier waves already sit behind us: prohibited practices and AI literacy apply since 2 February 2025, and general-purpose AI model obligations since 2 August 2025. The 2026 wave is therefore narrower than the headline suggests. The two real deadlines left this year live outside the high-risk chapter: CRA incident reporting from 11 September 2026, and the end of the grace period for marking synthetic content on 2 December 2026, the same day the prohibition covering CSAM and non-consensual intimate imagery starts to bite.
Which regulations make up the stack?
The stack is not one law but four layers, each written for a different purpose and each reaching an AI vendor through a different door. The AI Act classifies your system. NIS2 arrives through your customer's supply-chain audit. GDPR and DORA attach to the data and to regulated buyers, financial ones above all. The CRA and the Data Act treat your product and your hosting contract as regulated objects in their own right.
Layer 1: the AI Act
The AI Act (Regulation (EU) 2024/1689) is the only layer that classifies the AI system itself. For a vendor the practical question is which article each shipped system falls under, and the Digital Omnibus bought time on the heavy end: Annex III classification, conformity assessment, registration and the quality management duties now land on 2 December 2027, while AI embedded in Annex I regulated products has until 2 August 2028.
What cannot wait is Article 50. If your system talks to a human, generates synthetic content, or manipulates perception, the disclosure and labelling duties already apply. In practice that means four artefacts: a decision on where the human-facing disclosure sits, machine-readable metadata on generated output, a deepfake label where applicable, and a named owner who signs off the lot. Buyers have started asking for exactly this pack in procurement questionnaires, because their own deployer duties under Article 50 mirror yours.
One date in the AI Act still falls inside 2026: 2 December. On that day the prohibition covering AI-generated child sexual abuse material and non-consensual intimate imagery becomes fully enforceable, and the grace period for marking synthetic content ends. If your labelling implementation is still a ticket in the backlog, December is the hard edge.
Layer 2: NIS2
NIS2 (Directive (EU) 2022/2555) does not regulate AI. It regulates essential and important entities across eighteen sectors, and it reaches an AI vendor the moment one of those entities buys from you. Your customer's supply-chain security duty becomes a contractual audit of your company: asset inventory, patch windows, incident timelines, subcontractor list, exit plan. The audit asks for artefacts, not intentions.
The transposition picture is uneven. As of August 2026, 22 of 27 member states have transposed NIS2; France, Ireland, Luxembourg, the Netherlands and Spain have not finished. That changes almost nothing for a vendor, because procurement teams in those countries write the same duties into contracts anyway. Two more corrections worth pinning to the wall: there is no instrument called NIS3, and the Commission's proposal of 20 January 2026 is an amendment to NIS2, not a new directive. Finally, NIS2 carries management liability: what your customer's board signs, their auditors will eventually ask you to support with evidence.
Layer 3: GDPR and DORA
GDPR is the oldest layer and the one most teams underestimate in AI projects. The moment prompts, outputs or training data touch personal data, the familiar machinery applies: lawful basis, data protection impact assessment for high-risk processing, and the Article 22 limits on solely automated decisions with significant effects. An AI feature that scores, ranks or rejects people sits uncomfortably close to Article 22, and the DPIA is usually the first document a privacy-conscious buyer requests.
DORA (Regulation (EU) 2022/2554) applies since 17 January 2025 and covers financial entities: banks, insurers, investment firms and their ICT chain. If you sell AI into finance, DORA reaches you through the customer's register of information, through mandatory contract clauses for ICT third-party providers, and through incident reporting expectations that assume you can classify and report events on the financial sector's clock. An AI vendor without a DORA-ready contract schedule will feel it at the first enterprise bank deal.
Layer 4: the CRA and the Data Act
The Cyber Resilience Act (Regulation (EU) 2024/2847) regulates products with digital elements, which includes AI software and AI appliances. The first manufacturer duty with a real date is Article 14 incident reporting, live from 11 September 2026: an early warning within 24 hours, a notification within 72 hours, and a final report within 14 days for actively exploited vulnerabilities and severe incidents. Full conformity obligations follow in December 2027. Two dates circulating as CRA deadlines, 30 August and 30 October 2026, are milestones of the standardisation request M/606: they bind the standardisation bodies, not you.
The Data Act (Regulation (EU) 2023/2854) is the quiet layer that changes hosting economics. Switching provisions apply since 12 September 2025, data-by-design duties for connected products start on 12 September 2026, and from 12 January 2027 egress fees for switching are banned altogether. Every exit clause in a cloud AI contract signed before that date should be renegotiated with 12 January 2027 in view, because the cost model the vendor quoted you assumed egress still existed.
What does the dated map look like from 2026 to 2028?
Laid out on one axis, the stack stops looking like four separate compliance projects and starts looking like one calendar. These are the confirmed dates an AI vendor selling into regulated European buyers should hold today:
| Date | Instrument | Obligation | Who it hits |
|---|---|---|---|
| 2 Aug 2026 | AI Act, Art. 50 | Transparency and labelling duties apply | Providers and deployers of chatbots, synthetic content and deepfake systems |
| 11 Sep 2026 | CRA, Art. 14 | Incident reporting clocks: 24 h early warning, 72 h notification, 14 d final report | Manufacturers of products with digital elements, including AI appliances |
| 12 Sep 2026 | Data Act | Data by design for connected products | Manufacturers of connected devices and related services |
| 2 Dec 2026 | AI Act | CSAM and NCII prohibition enforceable; end of grace period for marking synthetic content | Providers of generative systems |
| 12 Jan 2027 | Data Act | Egress fees for switching banned | Cloud customers renegotiating exit clauses |
| 2 Dec 2027 | AI Act, Annex III | High-risk obligations apply | Providers and deployers of Annex III systems |
| 2 Aug 2028 | AI Act, Annex I | High-risk obligations for regulated products | Manufacturers embedding AI in Annex I products |
Read the table as a workload plan, not a countdown. The 2026 rows are implementation work: labelling packs, incident runbooks, contract schedules. The 2027 and 2028 rows are budget and design work: conformity assessment capacity, technical documentation, registration. Teams that confuse the two either panic about 2027 duties this quarter or sleepwalk into the December 2026 marking deadline.
Where do the layers overlap in one incident?
A worked example shows why one map beats four checklists. Imagine a compromised model endpoint at a manufacturer whose AI appliance is used by a bank. Within the first day, four clocks start at once. The CRA expects your 24-hour early warning as the manufacturer. Your customer's NIS2 duties trigger their supply-chain escalation, and your incident answers feed it. If personal data sat in the prompts, GDPR adds a 72-hour breach notification analysis. And the bank's DORA register expects its ICT providers to report on the financial sector's own timeline.
No team can run four parallel reporting processes for one event. The vendors that pass audits build a single evidence file and let each regulation read from it. The shared artefacts are always the same five:
- An asset inventory that lists models, endpoints, datasets and infrastructure in one place, versioned.
- An incident log with timestamps and fields that already match the CRA stages: detection, early warning, notification, final report, with a named owner per stage.
- A subcontractor and model provider register, which NIS2 audits and DORA registers both ask for under different names.
- Deployment and isolation documentation that shows where data flows and where it cannot flow.
- An exit and switching plan with costs, which the Data Act makes realistic from 12 January 2027.
Across the last twelve supplier audits we supported at CortexMine, the artefact requested first was never a policy. It was the incident log with named owners, followed by the subcontractor register. Not one of the twelve audits asked for an AI-specific document that the four instruments above would not already produce. The map is the work; the documents are a by-product.
What should an AI vendor do in the next 90 days?
- Write a one-page classification for each system you ship or operate: intended purpose, role in the value chain, Annex check, Article 50 check. Two pages per system is a red flag, not thoroughness.
- Build the Article 50 labelling pack before December: where the marking sits, the machine-readable metadata, the human-facing disclosure, and the internal record that proves you did it.
- Stand up the CRA clock before 11 September 2026: log fields per stage, owners named, a customer notification template pre-agreed with your largest accounts.
- Map your customers against NIS2 transposition: 22 states are done, and contracts in France, Ireland, Luxembourg, the Netherlands and Spain carry the same duties regardless.
- Open exit-clause renegotiations with 12 January 2027 in view: egress fees end, so the switching economics your cloud vendor quoted are about to change in your favour.
None of this requires a compliance department. It requires one owner, one evidence file, and dates that come from EUR-Lex rather than from a slide deck. The teams that struggle are not the small ones; they are the ones maintaining four separate spreadsheets that contradict each other.
Which deadlines circulating online are wrong?
- "High-risk AI Act from 2 August 2026": moved by the Digital Omnibus to 2 December 2027 for Annex III and 2 August 2028 for Annex I. Only Article 50 started this August.
- "CRA obligations on 30 August or 30 October 2026": those are milestones of the standardisation request M/606 addressed to standardisation bodies, not manufacturer duties.
- "NIS3 is coming": no such instrument exists. The Commission proposed a targeted NIS2 amendment on 20 January 2026.
- "NIS2 is fully transposed": five member states (France, Ireland, Luxembourg, the Netherlands, Spain) have not finished, yet supply-chain duties reach vendors contractually in every state.
- "CRA reporting starts in 2027": Article 14 reporting clocks start on 11 September 2026, more than a year before full conformity.
How do you keep this map current?
The Digital Omnibus proved that application dates can move with three weeks of notice. The only durable defence is sourcing discipline: every date in your plan links to EUR-Lex or a Commission page, carries an access date, and gets re-checked on a fixed rhythm. The primary sources behind this article are Regulation (EU) 2024/1689 (AI Act), Directive (EU) 2022/2555 (NIS2), Regulation (EU) 2022/2554 (DORA), Regulation (EU) 2024/2847 (CRA), Regulation (EU) 2023/2854 (Data Act) and the Digital Omnibus of July 2026, all accessed 10 August 2026.
This pillar is the reference page for the cluster. The supporting texts go deeper on each row of the table: the Article 50 labelling pack, the NIS2 supplier audit rehearsal, and the CRA question every on-prem appliance vendor should answer before September.
Frequently asked questions
- Do high-risk AI Act obligations apply from 2 August 2026?
- No. The Digital Omnibus, in force since 27 July 2026, moved Annex III systems to 2 December 2027 and Annex I products to 2 August 2028. From 2 August 2026 only Article 50 transparency and labelling duties apply.
- What is the next real deadline for an AI vendor in 2026?
- 11 September 2026, when CRA Article 14 incident reporting starts with its 24-hour, 72-hour and 14-day clocks for products with digital elements. Next comes 2 December 2026: the end of the grace period for marking synthetic content and full enforcement of the CSAM and NCII prohibition.
- Does NIS2 reach us if our country has not transposed it?
- Yes, contractually. Five member states (France, Ireland, Luxembourg, the Netherlands, Spain) have not finished transposition, but essential and important entities pass supply-chain security duties to their vendors through procurement contracts in every member state.
Related articles
AI Act 2 August 2026: What Actually Applies
Only Article 50 applies from 2 August 2026; high-risk does not. What the Digital Omnibus changed in the AI Act calendar, with EUR-Lex sources.
Passing an NIS2 Supplier Audit as an AI Vendor
NIS2 reaches AI vendors through the customer contract. The five evidence artefacts buyers request, the incident clocks, and what to prepare before the questionnaire.
Directive (EU) 2022/2555: Which Articles Bind an AI Vendor
NIS2 has 46 articles. Only a handful reach an AI vendor. A plain-language map of which ones bind you directly, which reach you through your customer, and what each demands.
Next step
Need this as an outcome, not an article? AI Act readiness.
Article 50 has applied since 2 August 2026. The high-risk obligations moved: Annex III to 2 December 2027, Annex I to 2 August 2028. Most readiness projects on the market are still priced against the old calendar. We scope yours against the current one.
Explore AI Act readiness


