Between August 2, 2026 and January 1, 2027, seven digital rules take effect or become enforceable. Not every rule affects every organization, so each date states what it is: a direct obligation, a chain requirement, a scope question, or a date for the legislator.
Why August 2
On August 2, 2026, the AI Act becomes largely applicable, 24 months after entry into force. That date is the hinge of this entire window. The transparency obligation of Article 50 takes effect, national supervisory authorities gain their powers, and fines become enforceable. In the Netherlands these are the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) and the RDI.
What does not take effect that same day are the heavier requirements for high-risk AI. The Digital Omnibus, Regulation (EU) 2026/1744, appeared in the Official Journal on July 24, 2026, and pushed those requirements to December 2, 2027 for the systems in Annex III and to August 2, 2028 for AI in regulated products under Annex I. The transparency obligation was not pushed back with them. What remains in 2026, then, is not the light part. It is the part that gets less attention.
The Seven Dates
| Date | Instrument | What It Asks of You |
|---|---|---|
| August 2, 2026 | AI Act | DIRECT OBLIGATION. Transparency obligation (Article 50). Supervision and fines start, including for the AI literacy obligation and for providers of general-purpose AI models. |
| August 15, 2026 | Cybersecurity Act and Wwke | DIRECT OBLIGATION where in scope. The Dutch NIS2 implementation and, through the Wet weerbaarheid kritieke entiteiten, the Dutch CER implementation. Registration, duty of care, reporting duty, board accountability. The Wwke only takes effect after designation. |
| September 11, 2026 | Cyber Resilience Act | CHAIN REQUIREMENT. The manufacturer must actively report actively exploited vulnerabilities and incidents. You capture that in your procurement terms. |
| December 2, 2026 | AI Act, round two | DIRECT OBLIGATION. Two new prohibited practices (Article 5, points ba and bb), and the deadline by which providers of generative AI systems that already existed before August 2 must mark their output as machine-readable. |
| December 9, 2026 | Product Liability | TRANSPOSITION DATE for the legislator. The new regime, with software and AI explicitly in scope, applies to products placed on the market after that date. |
| December 24, 2026 | eIDAS 2 and the EUDI Wallet | SCOPE QUESTION. EUDI stands for European Digital Identity. The wallet is an app in which a citizen stores verified data (identity, diplomas, credentials) and shares, each time, only what a service needs. Every member state must offer one. Public and semi-public service providers must then accept it as a login method alongside DigiD and eHerkenning; regulated private sectors follow at the end of 2027. |
| January 1, 2027 | New Archives Act | SCOPE QUESTION. Dutch law, for government organizations only. Note: January 1, 2027 is the announced date; the royal decree bringing it into force has not yet been published. Transfer means formally handing archives over to an archive service, after which they generally become public; restrictions on public access can be set at the point of transfer. That must happen after 10 years instead of 20, for documents created after that date. |
Two of these seven affect your supplier contracts. The Cyber Resilience Act sets requirements for the software, OT, and IoT you procure; the new product liability regime forces agreements on updates, vulnerabilities, and recourse. You do not settle those clauses the week before the deadline.
The AI Obligation Already in Effect
August 2 usually gets attention only for the transparency obligation. There is another obligation next to it that has already applied for a year and a half: AI literacy, Article 4. Since February 2, 2025, every organization that offers or uses AI must ensure its own people know what they are doing. The law does not prescribe training, an exam, or a certificate; the measures must fit the role, knowledge, and context involved. What you document, an overview of what you have done and an internal guideline, is your proof of compliance.
What starts on August 2, 2026 is therefore enforcement. The literacy obligation itself is not listed among the fixed fine categories of Article 99, and the Digital Omnibus explicitly turned it into a best-efforts obligation in July 2026. Enforcement runs from August 2 through the national supervisory authorities, with sanctions based on national rules; in the Netherlands that implementing law is still before the legislator. Do not underestimate this: the remaining obligations for deployers (Article 26) do fall under Article 99(4), up to 15 million euros or 3 percent of global annual turnover, and an organization that cannot demonstrate it has trained its people starts every other AI file at a disadvantage with the supervisor.
Build your own AI literacy now with our free courses: Audirium Academy - free training in internal audit, risk & compliance
Law and Good Practice Are Not the Same
A direct obligation forces action. A chain requirement arrives through your procurement. A scope question depends on your legal form, your size, or your public task. A transposition date exists for the legislator, not for you. That distinction appears in the table above at every date, because it determines whether you need to act or only need to establish that it does not affect you. Confuse the four, and you spend time on the wrong thing while the real risk stays open.
Where the Work Lands
Board and Legal. The board accountability under the Cybersecurity Act, the role determination under the AI Act (are you a provider or a deployer), and the new liability position.
IT and OT. The duty of care and the reporting chain under the Cybersecurity Act, the requirements the Cyber Resilience Act places on procured software and OT, and the transparency marking in systems that produce AI content.
Procurement. Clauses on updates, vulnerabilities, and SBOMs, plus the question of what you can expect from an AI supplier now that the obligations for general-purpose AI models become enforceable.
Information management. Retention periods and transfer under the Archives Act, the overview of your AI use, and the place where the evidence comes together.
The First 90 Days
Which of the seven affect you follows from step one. Start there, not with the measure.
- Scope check per legal entity and activity for the Cybersecurity Act, with a name attached.
- Activate registration and the incident process.
- Brief the board on its own accountability.
- Map your AI use and cover the transparency obligation.
- Document AI literacy: what you already do, and where that is recorded.
- Check software and IoT suppliers against the Cyber Resilience Act requirements.
In the months after: arrange the marking of AI content ahead of December 2, review contracts against the Cyber Resilience Act and the Data Act, determine your EUDI connection if you are a public service provider, and link controls to obligations. That last step is not a legal requirement but a saving: the Cybersecurity Act, the Cyber Resilience Act, and the AI Act partly ask for the same measures, such as access management, vulnerability management, and an incident process. Set those up once and link them to all three, and you do not build the evidence three times over.
Download the Roadmap
All seven dates, the labels, and the 90-day plan on paper, to keep or forward to your team: Seven Digital Deadlines (PDF). The same content as this page, in a form you can put on the table in a meeting.
Next Step Before August 15
The heaviest date of the seven is August 15, 2026. If you already have a security framework such as ISO 27001, BIO2, or NEN 7510, that already covers part of the duty of care under the Cybersecurity Act. No framework covers it in full, and none of them cover the statutory reporting duty to the supervisory authority.
Check for free what your existing IT and cyber frameworks already cover in the NIS2 coverage check
Build your own AI literacy now with our free courses: Audirium Academy - free training in internal audit, risk & compliance