Three pieces of EU law, plus one Commission framework, decide a good share of what data and AI teams work on until 2028. They come from different parts of Brussels, use different vocabulary and land with different owners inside a company. Their dates interact, and two of them fall six weeks apart this winter.
This page lists the dates first. Below the list are short notes on each instrument and a table of who usually owns what. It summarises the published texts and the law-firm and Commission material cited at the end, and your legal team has the final word on how any of it applies to you.
- 12 Sep 2025In force
Data Act applies
Cloud customers gain a right to switch provider, with at most two months’ notice and a transition of up to 30 days.1
- 2 Aug 2026In force
AI Act transparency duties (Article 50)
Deployers must tell people when they are dealing with AI, and generated content must be marked.2
- 11 Sep 2026In force
Cyber Resilience Act reporting starts for manufacturers
An early warning within 24 hours of finding an actively exploited vulnerability, and a full notification within 72 hours.3
- 2 Dec 2026Ahead
Marking grace period ends
Generative systems already on the market must carry machine-readable marking. The transition also ends for the new prohibition on non-consensual intimate imagery and child sexual abuse material.2
- 12 Jan 2027Ahead
Cloud switching charges generally prohibited
Providers can no longer charge customers for switching, although early-termination penalties remain possible.1
- 2 Dec 2027Ahead
- 2 Aug 2028Ahead
High-risk obligations for AI in regulated products (Annex I)
Moved from August 2027 by the AI Omnibus.2
The AI Act after the Omnibus
Parliament endorsed the AI Omnibus on 16 June 2026 and the Council approved it on 29 June. It was published in the Official Journal on 24 July and entered into force on 27 July.4 The regulation itself is dated 8 July 2026.5
For standalone high-risk systems listed in Annex III, the obligations moved from 2 August 2026 to 2 December 2027. The covered requirements are risk management, technical documentation, logging, human oversight, conformity assessment and registration.2
| Provision | Position after the Omnibus |
|---|---|
| Annex III high-risk obligations | Moved to 2 December 2027 |
| Annex I high-risk obligations | Moved to 2 August 2028 |
| Article 50 transparency | Unchanged, applying since 2 August 2026 |
| Marking by generative systems already on the market | Grace period to 2 December 2026 |
| Article 4 AI literacy | Already applies; wording amended on 27 July 2026 |
| Article 5 prohibited practices | In force, with a new prohibition and a transition to 2 December 2026 |
The Annex III list for employment covers recruitment, performance evaluation, task allocation, worker monitoring, promotion and termination.4 An analytics team that built an attrition model or a candidate-ranking tool for HR may own a high-risk system without having thought of it that way.
Classification has not been postponed. Deciding which systems are high-risk takes time, and the final Article 6 guidelines are expected around the end of 2026.2 From October 2026 to 2 December 2027 is fourteen months, which breaks down roughly as follows.
- Q4 2026Build the inventory: every model and AI-assisted tool, with its purpose, owner and data. Check Article 50 disclosure and marking while you are there.
- Q1 2027Classify each entry against the final Article 6 guidelines and flag the likely high-risk systems.
- Q2 2027For each flagged system, compare current practice with the required risk management, documentation, logging and oversight.
- Q3 and Q4 2027Close the gaps, run a conformity dry run and prepare registration ahead of 2 December.
The same people will be working on the Data Act and the Cyber Resilience Act over the same months, which is the strongest argument for starting the inventory now.
The Data Act and the cost of leaving
The cloud-switching rules cover infrastructure, platform and software services, edge computing and storage or database services supplied to EU customers, wherever the provider is based.1 Contracts must set out the switching procedure, the support the provider will give and an exhaustive list of the data and digital assets that can be ported.1
Until 12 January 2027 a provider may charge only the costs it directly incurs in a switch. After that date switching charges are generally prohibited.1 For a data team the effect shows up in architecture reviews. A design that leans on proprietary orchestration or storage now has an exit cost the contract can describe, and an exit plan becomes an engineering document.
The Cyber Resilience Act and the 24-hour clock
Reporting obligations started on 11 September 2026 for manufacturers of products with digital elements. Notifications go through a single platform run by ENISA and reach the CSIRT of the member state where the manufacturer has its main establishment.3
Counted from discovery
- Within 24 hoursEarly warning to the CSIRT and ENISA.3
- Within 72 hoursFull notification.3
- 14 days after a fixFinal report on the vulnerability.3
- One month after notificationFinal report on a severe incident.3
Source: European Commission, Digital Strategy.3
The Act reaches a data team when the company ships software, for example an embedded analytics module or a connected device that sends data to a cloud service. The question to ask is whether anyone could describe an exploited vulnerability in your own components within hours.
The Cloud Sovereignty Framework, used as a checklist
The European Commission published version 1.2.1 of its Cloud Sovereignty Framework in October 2025 for its own institutions’ procurement. It grades providers from SEAL-0, exclusive non-EU control, to SEAL-4, complete EU control with no critical non-EU dependency, and scores them on eight weighted objectives.67
Share of the Sovereignty Score
Source: nLighten summary of the European Commission framework, version 1.2.1, October 2025.6
Private companies have no obligation to use it. Its structure still works as a vendor questionnaire: take the eight headings, set your own weights and run your two largest cloud and AI providers through it before the next renewal.
Who usually owns what
| Instrument | Likely owner | First document | Date to plan to |
|---|---|---|---|
| AI Act, Article 50 | Product and legal | List of AI interactions and generated content needing disclosure | 2 Dec 2026 for marking |
| AI Act, high-risk | Data and AI governance, HR, risk | AI system inventory with classification | 2 Dec 2027 |
| Data Act switching | Cloud architecture and procurement | Exit plan per major service | 12 Jan 2027 |
| Cyber Resilience Act | Product security | Software bill of materials and an on-call reporter | In force since 11 Sep 2026 |
| Cloud Sovereignty Framework | Procurement and architecture | Weighted vendor scorecard | Next renewal |
Companies divide this work in different ways. What matters is that each row has one named person and one document an auditor could ask to see.
Sources
Each entry links to its original publication or to the named commentary. All sources were published in 2025 or 2026. The EUR-Lex text could not be read in full, so the AI Act details also cite DLA Piper and Praxikon.
- The Data Act: Switching Requirements for Cloud Services ProvidersAlston & Bird, September 2025
- The Digital Omnibus and the postponement of high-risk obligations to December 2027Praxikon, 2026
- Cyber Resilience Act: reporting obligationsEuropean Commission, Digital Strategy, accessed October 2026
- The Digital AI Omnibus: deferral of high-risk AI obligations under the AI ActDLA Piper, 30 June 2026, updated 10 August 2026
- Regulation (EU) 2026/1744 of 8 July 2026 amending Regulations (EU) 2024/1689, (EU) 2018/1139 and (EU) 2023/1230 (Digital Omnibus on AI)EUR-Lex, 8 July 2026
- EU Cloud Sovereignty Framework: SEAL levels and sovereignty objectives explained (summary of the European Commission framework, version 1.2.1, October 2025)nLighten, 2026
- Cloud Sovereignty FrameworkEuropean Commission, October 2025
This page summarises published material and is not legal advice. Check dates and scope with qualified counsel before relying on them.