Regulatory calendar 2026-2028 for software and AI developers

Published 2 October 2026 · Updated 2 October 2026

In short. Key dates: Cyber Resilience Act, reporting from 11 September 2026; NIS2 Italy, baseline measures by 31 October 2026 for notified entities; AI Act, high risk from 2 December 2027 (Annex III) and 2 August 2028 (Annex I). Always check the official sources.

This note is a technical reminder, not legal advice. Dates must be confirmed against the official sources and with a lawyer.

When What Applies to
2 August 2026 AI Act, transparency obligations (Art. 50), with a grace period for marking those who publish AI content or systems
11 September 2026 Cyber Resilience Act: reporting of actively exploited vulnerabilities and severe incidents manufacturers of products with digital elements
31 October 2026 NIS2 Italy: adoption of baseline security measures for entities notified in 2025 essential and important entities
2 December 2026 AI Act: machine-readable marking of AI-generated content and new prohibitions those who generate content with AI
11 December 2027 Cyber Resilience Act: obligations for open source software stewards open source stewards
2 December 2027 AI Act: high-risk systems in Annex III recruitment, credit, education and others
2 August 2028 AI Act: high risk as a safety component of regulated products (Annex I) medical devices, machinery, toys

Sources and level of certainty

  • AI Act: the “Digital Omnibus” regulation was published in the Official Journal of the EU on 24 July 2026 and has been in force since 27 July 2026. Secondary source: White & Case.
  • Cyber Resilience Act: official portal of the European Commission, reporting obligations. It provides for an early warning within 24 hours, a notification within 72 hours and a final report.
  • NIS2 in Italy (Legislative Decree 138/2024): the 31 October 2026 date comes from secondary sources (IusPrivacy); the ACN pages could not be accessed at the time of verification. Check the Agency’s website.

What this means in practice for architecture

  • Inventory of systems, dependencies and versions (the basis of all three regulations).
  • Logs and notifications: centralised logs and a procedure that allows an incident to be notified within 24 hours.
  • Access control and backups that have been tested.
  • For AI: documentation of data, models and controls; marking of generated content.

An assessment can translate these requirements into technical controls and priorities.

Need a hand?

If you want to apply these points to your case, tell me in a few lines.

Let's talk