AI Act 2026 CEO Calendar After the AI Omnibus
The 2026 CEO question changed. Article 50 transparency and GPAI enforcement still matter in 2026; stand-alone high-risk and product-embedded high-risk rules now need 2027/2028 Omnibus planning caveats.
In brief: Prohibitions applied on 2 February 2025 and GPAI obligations applied on 2 August 2025. For 2026, CEOs should treat Article 50 transparency and Commission GPAI enforcement powers as the live checkpoint. Under the 7 May 2026 AI Omnibus political agreement, stand-alone high-risk rules move to 2 December 2027 and product-embedded high-risk rules to 2 August 2028, pending final Official Journal text. A governed Article 3 glossary supports the evidence record.
The current AI Act calendar
The EU AI Act entered force on 1 August 2024. Article 113 set the original staggered application dates; the 7 May 2026 AI Omnibus political agreement changed the planning dates for high-risk rules, pending final legal text.
| # | Date | What applies | Source |
|---|---|---|---|
| 1 | 2 February 2025 | Chapter II prohibitions (Article 5) | AI Act Art. 113 |
| 2 | 2 August 2025 | GPAI model obligations | AI Act Art. 113 |
| 3 | 2 August 2026 | Article 50 transparency obligations and Commission enforcement powers for GPAI model providers remain key checkpoints | AI Act Art. 50; Commission timeline |
| 4 | 2 December 2027 | Planning date for stand-alone high-risk AI systems under the AI Omnibus political agreement | Council political agreement |
| 5 | 2 August 2028 | Planning date for high-risk AI systems embedded in regulated products under the same political agreement | Council political agreement |
Sources checked 2026-06-22: Regulation (EU) 2024/1689, the European Commission AI Act page, the Council AI Omnibus political agreement, and AI Act Service Desk Article 50. Re-check the final Official Journal text before treating 2027/2028 planning dates as adopted law.
What this costs the CEO personally
Every board pack in 2026 should still include "are we ready for the AI Act?" The CEO answers, not the CISO. Implementation teams execute; the readiness assertion is a CEO assertion because the board underwrites the CEO, not the team.
The survey evidence is not flattering. EY's Responsible AI Pulse (August 2025) reported only 14 percent of CEOs strongly agree their organization has appropriate AI controls in place, versus 29 percent of other C-suite. (Controls are not regulatory compliance per se, but the gap is what boards probe.) KPMG's 2025 CEO Outlook (n=1,350) found 69 percent of CEOs say the pace of AI regulation will be a barrier to success. PwC's 27th CEO Survey: 64 percent agree the regulatory environment is the number-one barrier to reinvention.
Capital allocation — inventory, transparency review, documentation, external counsel, and high-risk planning — is a CEO decision. Delayed too long, the company reaches the 2027/2028 high-risk dates with partial readiness and a board that was not told the truth on time.
The next board meeting in 2026
One or at most two quarterly board meetings sit between today and the deadline. Each produces minutes that, in a later enforcement matter or class-action discovery, become exhibit A. By now, board meetings since August 2024 (entry into force) should have produced a scope assessment, an approved terminology baseline, and a conformity-assessment workstream in flight. The next meeting is the last practical window to establish the artifact. A CEO who hands up a versioned, four-eyes-approved glossary plus a compliance-scan report is producing evidence; a CEO who hands up "we are tracking this" is producing reassurance.
How terminology governance helps
Compliance Glossary for Confluence is not a conformity-assessment tool, an Article 9 risk-management system, or a legal shield. It is one focused artifact: a governed, four-eyes-approved, audit-trailed glossary of regulated terminology, shipped with the 68 Article 3 definitions pre-loaded.
Article 11 technical documentation must be coherent: the same system cannot be called a "machine learning model" on one page and an "automated decision tool" in the user-facing notice. Article 3 defines the vocabulary; the glossary enforces its consistent use.
- Four-eyes approval. Drafter cannot approve. A second authorized reviewer verifies wording against Article 3. CEO sign-off on the approver list becomes a governance record.
- Version history. Every edit stores author, timestamp, prior wording, approver, rationale — the timestamped answer when a notified body or the AI Office asks when a system was classified as GPAI with systemic risk.
- Audit trail with timestamps. Concrete duty-of-care evidence.
- Compliance scanner. Deterministic pattern matching flags drift — "software" where the governed term is "high-risk AI system", "user" where Article 3 says "deployer".
- CSV export with full version history (PDF audit-package export on the 2026 roadmap). One export produces the regulator-facing artifact: every approved term, approver, version, and date. Same file serves board, D&O underwriter, and acquirer's data room.
For current pricing, see the Atlassian Marketplace.
Frequently asked questions
What exactly applies on 2 August 2026?
The reliable 2026 checkpoint is narrower after the AI Omnibus political agreement: Article 50 transparency obligations and Commission enforcement powers for GPAI model providers. Under the 7 May 2026 political agreement, stand-alone high-risk AI rules move to 2 December 2027 and product-embedded high-risk rules to 2 August 2028 as planning dates pending final legal text. Prohibitions have applied since 2 February 2025; GPAI obligations have applied since 2 August 2025.
Why is this a CEO problem and not a CISO or legal team problem?
Implementation teams execute; the calendar sits with the CEO. The board asks the CEO, not the CISO, about readiness for known legal milestones. The CEO signs the capital-allocation decisions that fund the work, approves the public statements that describe AI use, and owns credibility with investors and regulators. Avoid the false comfort of a delayed high-risk date: Article 50, GPAI, prohibited-practice, and disclosure-risk work still need evidence in 2026.
What happens if a company ignores the 2026 AI Act checkpoint?
Ignoring 2026 still creates risk where Article 50 transparency, GPAI provider obligations, prohibited practices, or regulator information requests are in scope. Article 99 includes fines for prohibited practices, listed operator/transparency obligations, and incorrect or misleading information to authorities. High-risk deadline planning should use the 2027/2028 Omnibus dates with an Official Journal caveat. See the startup-level analysis at /ai-act-startup-existential-fine.
How does a terminology glossary support a 2026 conformity assessment?
Article 11 technical documentation must use consistent terminology across design docs, risk registers, test plans, and user-facing statements. Article 3 defines 68 terms. When high-risk AI system, substantial modification, deployer, provider, GPAI model, and systemic risk drift between documents, the conformity-assessment file is internally inconsistent. An approved, version-controlled, audit-trailed glossary of Article 3 terms is the definitional spine every Article 11 deliverable references.
This article is informational and is not legal advice. Consult qualified counsel for AI Act compliance decisions specific to your facts.
Prepare the AI Act evidence before the next board meeting
For current pricing, see the Atlassian Marketplace.
Evaluate in Confluence Read the Security WhitepaperRelated reading
- Compliance for Confluence — approved terms, page scanning, and audit evidence for CEO-level compliance oversight in Confluence
- AI Act fines for startups — Article 99 SME rule, the company-killing number
- AI Act 2026 enforcement (CFO angle) — disclosure, Article 50, and MD&A framing
- AI Act terminology governance — the 68 Article 3 terms in depth
- Board regulatory disclosure (CEO) — credibility at the audit committee
- Security whitepaper — governance posture for the board