• Calendar
  • 5 min read

The EU rules calendar for data and AI teams, 2025 to 2028

The AI Act, the Data Act and the Cyber Resilience Act each set dates that land on data and AI teams. Here they are on one page, with the first piece of work each date creates.

ResearchBy ShyamLast checked 2 October 20265 min read7 sources

Three pieces of EU law, plus one Commission framework, decide a good share of what data and AI teams work on until 2028. They come from different parts of Brussels, use different vocabulary and land with different owners inside a company. Their dates interact, and two of them fall six weeks apart this winter.

This page lists the dates first. Below the list are short notes on each instrument and a table of who usually owns what. It summarises the published texts and the law-firm and Commission material cited at the end, and your legal team has the final word on how any of it applies to you.

  1. 12 Sep 2025In force

    Data Act applies

    Cloud customers gain a right to switch provider, with at most two months’ notice and a transition of up to 30 days.1

  2. 2 Aug 2026In force

    AI Act transparency duties (Article 50)

    Deployers must tell people when they are dealing with AI, and generated content must be marked.2

  3. 11 Sep 2026In force

    Cyber Resilience Act reporting starts for manufacturers

    An early warning within 24 hours of finding an actively exploited vulnerability, and a full notification within 72 hours.3

The AI Act after the Omnibus

Parliament endorsed the AI Omnibus on 16 June 2026 and the Council approved it on 29 June. It was published in the Official Journal on 24 July and entered into force on 27 July.4 The regulation itself is dated 8 July 2026.5

For standalone high-risk systems listed in Annex III, the obligations moved from 2 August 2026 to 2 December 2027. The covered requirements are risk management, technical documentation, logging, human oversight, conformity assessment and registration.2

ProvisionPosition after the Omnibus
Annex III high-risk obligationsMoved to 2 December 2027
Annex I high-risk obligationsMoved to 2 August 2028
Article 50 transparencyUnchanged, applying since 2 August 2026
Marking by generative systems already on the marketGrace period to 2 December 2026
Article 4 AI literacyAlready applies; wording amended on 27 July 2026
Article 5 prohibited practicesIn force, with a new prohibition and a transition to 2 December 2026

The Annex III list for employment covers recruitment, performance evaluation, task allocation, worker monitoring, promotion and termination.4 An analytics team that built an attrition model or a candidate-ranking tool for HR may own a high-risk system without having thought of it that way.

Classification has not been postponed. Deciding which systems are high-risk takes time, and the final Article 6 guidelines are expected around the end of 2026.2 From October 2026 to 2 December 2027 is fourteen months, which breaks down roughly as follows.

  • Q4 2026Build the inventory: every model and AI-assisted tool, with its purpose, owner and data. Check Article 50 disclosure and marking while you are there.
  • Q1 2027Classify each entry against the final Article 6 guidelines and flag the likely high-risk systems.
  • Q2 2027For each flagged system, compare current practice with the required risk management, documentation, logging and oversight.
  • Q3 and Q4 2027Close the gaps, run a conformity dry run and prepare registration ahead of 2 December.

The same people will be working on the Data Act and the Cyber Resilience Act over the same months, which is the strongest argument for starting the inventory now.

The Data Act and the cost of leaving

The cloud-switching rules cover infrastructure, platform and software services, edge computing and storage or database services supplied to EU customers, wherever the provider is based.1 Contracts must set out the switching procedure, the support the provider will give and an exhaustive list of the data and digital assets that can be ported.1

Until 12 January 2027 a provider may charge only the costs it directly incurs in a switch. After that date switching charges are generally prohibited.1 For a data team the effect shows up in architecture reviews. A design that leans on proprietary orchestration or storage now has an exit cost the contract can describe, and an exit plan becomes an engineering document.

The Cyber Resilience Act and the 24-hour clock

Reporting obligations started on 11 September 2026 for manufacturers of products with digital elements. Notifications go through a single platform run by ENISA and reach the CSIRT of the member state where the manufacturer has its main establishment.3

Reporting an actively exploited vulnerability

Counted from discovery

  • Within 24 hoursEarly warning to the CSIRT and ENISA.3
  • Within 72 hoursFull notification.3
  • 14 days after a fixFinal report on the vulnerability.3
  • One month after notificationFinal report on a severe incident.3

Source: European Commission, Digital Strategy.3

The Act reaches a data team when the company ships software, for example an embedded analytics module or a connected device that sends data to a cloud service. The question to ask is whether anyone could describe an exploited vulnerability in your own components within hours.

The Cloud Sovereignty Framework, used as a checklist

The European Commission published version 1.2.1 of its Cloud Sovereignty Framework in October 2025 for its own institutions’ procurement. It grades providers from SEAL-0, exclusive non-EU control, to SEAL-4, complete EU control with no critical non-EU dependency, and scores them on eight weighted objectives.67

Weights of the eight sovereignty objectives

Share of the Sovereignty Score

Supply chain provenance20%
Strategic ownership and financing15%
EU operational capability15%
Technology openness and lock-in15%
Legal exposure to non-EU lawFor example the CLOUD Act10%
Data access control and AI independence10%
Security operations and regulatory alignmentGDPR, NIS2, DORA10%
Environmental sustainability5%

Source: nLighten summary of the European Commission framework, version 1.2.1, October 2025.6

Private companies have no obligation to use it. Its structure still works as a vendor questionnaire: take the eight headings, set your own weights and run your two largest cloud and AI providers through it before the next renewal.

Who usually owns what

InstrumentLikely ownerFirst documentDate to plan to
AI Act, Article 50Product and legalList of AI interactions and generated content needing disclosure2 Dec 2026 for marking
AI Act, high-riskData and AI governance, HR, riskAI system inventory with classification2 Dec 2027
Data Act switchingCloud architecture and procurementExit plan per major service12 Jan 2027
Cyber Resilience ActProduct securitySoftware bill of materials and an on-call reporterIn force since 11 Sep 2026
Cloud Sovereignty FrameworkProcurement and architectureWeighted vendor scorecardNext renewal

Companies divide this work in different ways. What matters is that each row has one named person and one document an auditor could ask to see.

Sources

Each entry links to its original publication or to the named commentary. All sources were published in 2025 or 2026. The EUR-Lex text could not be read in full, so the AI Act details also cite DLA Piper and Praxikon.

  1. The Data Act: Switching Requirements for Cloud Services ProvidersAlston & Bird, September 2025
  2. The Digital Omnibus and the postponement of high-risk obligations to December 2027Praxikon, 2026
  3. Cyber Resilience Act: reporting obligationsEuropean Commission, Digital Strategy, accessed October 2026
  4. The Digital AI Omnibus: deferral of high-risk AI obligations under the AI ActDLA Piper, 30 June 2026, updated 10 August 2026
  5. Regulation (EU) 2026/1744 of 8 July 2026 amending Regulations (EU) 2024/1689, (EU) 2018/1139 and (EU) 2023/1230 (Digital Omnibus on AI)EUR-Lex, 8 July 2026
  6. EU Cloud Sovereignty Framework: SEAL levels and sovereignty objectives explained (summary of the European Commission framework, version 1.2.1, October 2025)nLighten, 2026
  7. Cloud Sovereignty FrameworkEuropean Commission, October 2025

This page summarises published material and is not legal advice. Check dates and scope with qualified counsel before relying on them.

BIAAS 2027, Amsterdam

Hear it first-hand from the people doing the work

Two days of keynotes, panels and 1-on-1 meetings with senior data, analytics and AI leaders, on 23-24 March 2027.