EU digital law 2026 and 2027: the deadline calendar
Between August 2026 and August 2028 several EU legal acts take effect that concern websites and hosted applications. The next dates: on 11 September 2026 the reporting duty for exploited vulnerabilities under the Cyber Resilience Act begins. On 1 October 2026 the Austrian NISG 2026 enters into force, and the registration deadline for the entities it covers ends on 31 December 2026. For 12 January 2027 the Data Act provides that charges for switching a data processing service fall away. All entries reflect the position as of 20 August 2026 and may change. This calendar gives the source for every date and does not assess individual cases. This article is not legal advice.
Between August 2026 and August 2028 several EU legal acts take effect that concern websites, online shops and hosted applications. This calendar lists the dates together with the source, so they can be looked up rather than searched for.
For each date it states what applies on that day and who the legal act covers according to its wording. What it does not do: assess an individual case. Whether a company falls under a rule depends on size, activity and contracts. That is for a law firm to assess. We do not check it in advance either.
The calendar covers EU law and its Austrian implementation. For projects in Germany some dates differ. The underlying terms are explained in more detail in our glossary, for instance on the NIS2 Directive and the EU AI Act.
What is still due in 2026
| Date | Legal act | What happens | Addressee per the wording |
|---|---|---|---|
| 2 August 2026 Already in force | AI Act, Art. 50 EUR-Lex: Regulation (EU) 2024/1689 (opens in a new tab) | The transparency obligations apply. Systems people interact with directly must be recognisable as such. That does not apply where it is obvious anyway to a reasonably well-informed person. Generated or altered images, audio and video resembling real people must be disclosed. For artistic and satirical works this applies in a reduced form. | Providers and deployers of AI systems, differing by obligation |
| 11 September 2026 Upcoming | Cyber Resilience Act, Art. 14 EUR-Lex: Regulation (EU) 2024/2847 (opens in a new tab) | The reporting duty starts. It has three stages: an early warning within 24 hours, a fuller notification within 72 hours and a final report. The final report is due 14 days from the point a remedy is available, and one month for severe incidents. | Manufacturers of products with digital elements |
| 12 September 2026 Upcoming | Data Act, Art. 3 EUR-Lex: Regulation (EU) 2023/2854 (opens in a new tab) | Connected products newly placed on the market after this day must provide built-in access to the data they generate. What counts as a connected product and as a related service is defined by the regulation itself. | Manufacturers of connected products and providers of related services |
| 1 October 2026 Upcoming | NISG 2026, § 51 RIS: NISG 2026, section 51 (opens in a new tab) | The act enters into force. No date appears in the text: it follows from nine months after publication on 23 December 2025. From that day the risk management duties, the oversight and training duties of management and the reporting duties apply, with 24 hours, 72 hours and one month. | Essential and important entities under Annexes 1 and 2 |
| Q4 2026 Date unsettled | EN 301 549 V4.1.x ETSI: EN 301 549 V4.1.0, draft June 2026 (opens in a new tab) | The new version is to be published in the EU Official Journal. The new version points to WCAG 2.2. Sources give differing dates, so none is stated here. | Public sector bodies under the Web Accessibility Directive |
| 2 December 2026 Upcoming | AI Act, Art. 111 EUR-Lex: Regulation (EU) 2026/1744 (opens in a new tab) | The transition period for the marking duty ends. It applied to generative systems already on the market before 2 August 2026. It was introduced by the Digital Omnibus of July 2026. New prohibitions are added on the same day. | Providers of generative AI systems |
| 24 December 2026 Upcoming | eIDAS Regulation, Art. 5a EUR-Lex: Regulation (EU) No 910/2014, consolidated (opens in a new tab) | Member States provide at least one European digital identity wallet, the EUDI wallet. Here too no date appears in the text, but 24 months from the entry into force of the implementing acts of 24 December 2024. | Member States |
| 31 December 2026 Upcoming | NISG 2026, § 29 RIS: NISG 2026, Federal Law Gazette I No. 94/2025 (opens in a new tab) | The deadline to register with the Federal Office for Cybersecurity ends. Here too the act gives no date but three months from entry into force. | Essential and important entities |
2027 and beyond
| Date | Legal act | What happens | Addressee per the wording |
|---|---|---|---|
| No date of its own Date unsettled | eIDAS Regulation, Art. 5f EUR-Lex: Regulation (EU) No 910/2014, consolidated (opens in a new tab) | Where a Member State requires electronic identification for an online service of a public sector body, the wallet has to be accepted as well. The regulation gives no date of its own for this. Dates in circulation are derived. | Public sector bodies |
| 12 January 2027 Upcoming | Data Act, Art. 29 EUR-Lex: Regulation (EU) 2023/2854 (opens in a new tab) | Charges for switching provider fall away. Since January 2024 only reduced charges are allowed, and they may not exceed the cost of switching. | Providers of data processing services |
| 2 December 2027 Upcoming | AI Act, Annex III EUR-Lex: Regulation (EU) 2026/1744 (opens in a new tab) | The obligations for high-risk systems apply. The date originally foreseen was 2 August 2026. | Providers and deployers of high-risk systems |
| 11 December 2027 Upcoming | Cyber Resilience Act EUR-Lex: Regulation (EU) 2024/2847 (opens in a new tab) | From this day the regulation applies in full, no longer only the reporting duty. | Manufacturers, importers and distributors |
| 24 December 2027 Upcoming | eIDAS Regulation, Art. 5f EUR-Lex: Regulation (EU) No 910/2014, consolidated (opens in a new tab) | Companies in the sectors listed there must accept the wallet where they already require a strong sign-in. Micro and small enterprises are exempt. The regulation gives no date but 36 months from the entry into force of the implementing acts. | Companies in certain sectors, such as transport, energy, banking and health |
| 2 August 2028 Upcoming | AI Act, Annex I EUR-Lex: Regulation (EU) 2026/1744 (opens in a new tab) | The obligations apply to high-risk AI embedded in products. | Manufacturers of such products |
Two items without a date
Two items belong in a deadline calendar even though they have no date.
The first is the adequacy decision for data transfers to the United States. It is in force. It does not cover the United States as a whole, only recipients certified under the Data Privacy Framework and listed by the US Department of Commerce. The General Court of the European Union dismissed an action against it on 3 September 2025, and an appeal is pending before the Court of Justice. Alongside the adequacy decision the General Data Protection Regulation provides further grounds for transfers to third countries, among them the standard contractual clauses. Which of them applies to a given transfer is for a law firm to assess.
The second is the Commission's Digital Omnibus package. The part concerning the AI Act has been adopted and moved the deadlines for high-risk systems. The part concerning data protection law has not. As long as it is not adopted, the legal position remains unchanged. For consent banners in Austria, § 165 of the Telecommunications Act matters alongside the General Data Protection Regulation. Planning for the end of consent banners means planning on a draft.
How this calendar is maintained
Every table carries the legal status date as its caption. We set the “updated on” field only when something has actually changed. Even so, we cannot promise that nothing is missing or out of date.
One entry deliberately reads “date unsettled”. For the standard EN 301 549 the sources give differing dates for publication in the Official Journal. As long as that is the case, none of them is stated here.
That dates move is not a theoretical possibility. For high-risk systems 2 August 2026 applied until Regulation (EU) 2026/1744 moved it to 2 December 2027.
This article describes European Union and Austrian law as of 20 August 2026. It does not address the law of any other jurisdiction and is not legal advice.
Matching services
We can also support you directly on this topic — these pages are worth a look.
Glossary
The FINK Brot glossary explains key terms from search engine optimisation, web development, digital accessibility, structured data and AI – …
Read more →Accessible Websites
Accessible websites from Vienna: technical first assessment, WCAG 2.2 audit and implementation in code – clearly documented, without an …
Read more →Websites
Bespoke Kirby CMS websites: fast, data-minimising and built without third-party scripts. For companies in Vienna, Austria and international …
Read more →