ShieldPage

EU compliance calendar

Every EU digital-regulation deadline, what it means, who it affects, and what to do. Subscribe via the .ics calendar feed.

2028-08-02 — EU AI Act: High-risk obligations apply (Annex I embedded products)

AI embedded in products covered by EU product-safety law (machinery, medical devices…).

Who it affects: Product manufacturers embedding AI.

What to do: Coordinate AI Act compliance with existing product-safety conformity work.

2027-12-11 — CRA: CRA fully applies

Essential cybersecurity requirements and CE marking for products with digital elements.

Who it affects: Makers of software and connected products sold in the EU.

What to do: Secure-by-design development process, SBOM practices, CE-marking path.

2027-12-02 — EU AI Act: High-risk obligations apply (Annex III)

Standalone high-risk systems (hiring, credit, education, essential services…): risk management, data governance, logging, human oversight, conformity assessment. Deferred from Aug 2026 by the Digital Omnibus.

Who it affects: Providers and deployers of Annex III systems.

What to do: Classify your AI use now; if high-risk, start the compliance file in 2027 H1.

2026-12-02 — EU AI Act: Machine-readable marking transitional deadline

Generative AI systems on the market before 2026-08-02 must implement machine-readable marking of synthetic content. Also end of the grace period for the Omnibus's new Art. 5 safeguard duties.

Who it affects: Providers of generative AI features shipped before Aug 2026.

What to do: Add watermarking/provenance metadata to generated output.

2026-09-11 — CRA: CRA vulnerability & incident reporting applies

Manufacturers of products with digital elements must report actively exploited vulnerabilities and severe incidents (24h early warning to CSIRT/ENISA).

Who it affects: Makers of software and connected products sold in the EU — including SaaS shipped as a product.

What to do: Stand up a vulnerability-handling process and reporting contact now; know your CSIRT.

2026-08-02 — EU AI Act: Article 50 transparency applies

Chatbots must disclose they are AI; AI-generated/manipulated content (incl. deepfakes) must be disclosed. Applied on schedule — NOT deferred by the Digital Omnibus.

Who it affects: Any business using a chatbot or publishing AI-generated content toward EU users.

What to do: Label your bots and AI content; document your transparency posture (e.g. an AI governance page).

2025-09-12 — Data Act: Data Act applies

Data access and sharing rights for connected products; cloud-switching rules limiting egress lock-in.

Who it affects: IoT/connected-product makers; cloud and SaaS providers.

What to do: SaaS: review contract terms against switching/egress provisions.

2025-08-02 — EU AI Act: GPAI model obligations apply

Transparency and documentation duties for general-purpose AI model providers; governance structures in place.

Who it affects: Foundation-model providers; indirectly, everyone building on them.

What to do: If you build on GPAI: collect your providers' documentation for your own compliance file.

2025-06-28 — EAA: European Accessibility Act applies

Accessibility requirements for e-commerce, banking, e-books and other services; WCAG-aligned in practice.

Who it affects: Most B2C digital services in the EU (microenterprise service exemption).

What to do: Run accessibility scans; publish an accessibility statement; fix WCAG basics.

2025-02-02 — EU AI Act: AI Act prohibited practices apply

Bans on social scoring, manipulative techniques, certain biometric uses. AI-literacy duties also start.

Who it affects: Anyone deploying AI toward EU users.

What to do: Confirm nothing you deploy falls in Art. 5; basic AI-literacy training.

2025-01-17 — DORA: DORA applies (financial sector)

Digital operational resilience for financial entities and their critical ICT providers.

Who it affects: Financial entities and ICT vendors selling into them.

What to do: If you sell to financial institutions, expect DORA-driven vendor questionnaires.

2024-10-17 — NIS2: NIS2 transposition deadline

Member states had to transpose NIS2: risk-management measures, incident reporting, management accountability for essential/important entities.

Who it affects: Medium+ entities in essential and important sectors (incl. SaaS/digital providers).

What to do: Check national transposition status where you operate; register if required; baseline security measures.

2024-02-17 — DSA: Digital Services Act fully applies

Obligations for online intermediaries and platforms: notice-and-action, transparency, no dark-pattern consent interfaces (Art. 25).

Who it affects: Online platforms and marketplaces; lighter duties for small intermediaries.

What to do: Review interface patterns against Art. 25; publish required transparency info.

2018-05-25 — GDPR: GDPR applies

The EU's general data-protection regime: lawful basis, consent standards, data-subject rights, breach notification.

Who it affects: Any organization processing personal data of people in the EU.

What to do: Ongoing: valid consent for non-essential cookies, records of processing, DSAR handling.