Staged applicability schedule of the EU AI Act. Different obligations take effect at different dates from 2024 through 2027. Compliance planning depends on which obligations apply when.
Master schedule
| Date | Milestone | What applies |
|---|---|---|
| 2024-07-12 | OJEU publication | — |
| 2024-08-01 | Regulation in force | Foundational legal status; provisions not yet applicable |
| 2025-02-02 | First applicability | Chapter II (prohibited practices, Art 5); Art 4 AI literacy |
| 2025-08-02 | Second applicability | Chapter V (GPAI, Art 51-56); Chapter VII (governance bodies); Chapter XII (penalties) |
| 2026-08-02 | Third applicability | Most remaining provisions, including Annex III high-risk system obligations |
| 2027-08-02 | Final applicability | Annex I product-embedded high-risk systems (Art 6(1)) |
What applies as of 2 February 2025
- Article 4 — AI literacy. Providers and deployers of AI systems shall take measures to ensure, to the extent reasonable, sufficient AI literacy of their staff and others operating AI on their behalf. Light obligation but real.
- Article 5 — Prohibited practices. Unacceptable-risk AI practices prohibited:
- Subliminal / manipulative techniques causing significant harm
- Exploitation of vulnerabilities causing significant harm
- Social scoring by public authorities
- Predictive policing based solely on profiling
- Untargeted facial-image scraping for facial-recognition databases
- Emotion recognition in workplace / education (with exceptions)
- Biometric categorization to deduce protected attributes
- Real-time remote biometric identification in public for law enforcement (with narrow exceptions and authorization requirements)
Penalties for Article 5 violations applicable from this date.
Enforcement note: governance bodies and penalty mechanisms become operational at 2 August 2025, so enforcement-capacity ramp-up for prohibited practices happens between 2 February 2025 and 2 August 2025.
What applies as of 2 August 2025
- Chapter V — GPAI obligations (Articles 51-56). General-purpose AI models obligations applicable.
- Baseline GPAI obligations (Article 53)
- GPAI with systemic risk obligations (Article 55)
- Pre-existing GPAI models (placed on market before this date) have until 2 August 2027 to comply
- Chapter VII — Governance bodies (Articles 64-70). AI Office, AI Board, Scientific Panel, Advisory Forum operational. National competent authorities designated.
- Chapter X — Codes of conduct and guidelines (Articles 95-96). Voluntary codes for non-high-risk AI providers.
- Chapter XII — Penalties (Articles 99-101). Penalty framework operational.
- Article 78 — Confidentiality. Provisions on handling confidential information by authorities.
What applies as of 2 August 2026
- Most remaining provisions. This is the main applicability date for the bulk of the regulation.
- Chapter III — High-risk AI systems (Articles 6-49):
- Classification rules (Article 6)
- Requirements for high-risk AI (risk management, data and data governance, technical documentation, record-keeping, transparency, human oversight, accuracy / robustness / cybersecurity, quality management)
- Provider obligations
- Deployer obligations
- Distributor / importer / authorized representative obligations
- Conformity assessment procedures
- EU declaration of conformity
- CE marking
- Registration in EU database
- Chapter IV — Transparency obligations (Article 50). Limited-risk system transparency obligations:
- AI interaction disclosure (chatbots, voice agents)
- Synthetic content marking
- Deepfake disclosure
- Emotion recognition / biometric categorization notification
- Chapter VI — Measures in support of innovation (Articles 57-63). Regulatory sandboxes, real-world testing provisions, support for SMEs.
- Most market surveillance and enforcement provisions become fully operational.
What applies as of 2 August 2027
- High-risk AI systems embedded in Annex I products (Article 6(1)). These follow the longer transition because the underlying product-specific regulations (medical devices, machinery, automotive, etc.) have their own compliance frameworks and the AI Act extensions integrate over a longer timeline.
- Pre-existing GPAI models must achieve compliance by this date.
- Some legacy high-risk AI systems placed on market before 2 August 2026 may have transition provisions (check Article 111).
Specific provisions outside the main schedule
- Article 111 — Transitional provisions for high-risk AI systems already on the market. Specific rules for systems placed on market before applicability dates.
- Article 112 — Evaluation and review. Commission shall assess and report regularly; first evaluation by 2 August 2028.
- Article 113 — Entry into force / application. Master applicability dates as above.
Compliance planning implications
For providers of AI systems
- Now (2026-05-12): review classifications, especially Article 6(3) exemption applicability. Plan compliance work for high-risk systems against 2 August 2026 deadline.
- By 2 August 2026: high-risk system obligations operational. Conformity assessment completed, technical documentation in place, CE marking applied where required, post-market monitoring active.
- Ongoing: transparency obligations for limited-risk systems where applicable. AI literacy provisions in place.
For deployers of AI systems
- Now: identify high-risk AI systems in use; understand deployer obligations (use according to instructions, ensure human oversight, monitor operation, log if applicable, inform workers if used in workplace).
- By 2 August 2026: deployer obligations for Annex III systems fully applicable.
For GPAI providers
- By 2 August 2025: baseline GPAI obligations applicable. Technical documentation, training data summary, copyright compliance, downstream-provider information.
- For GPAI with systemic risk: additional obligations applicable. Model evaluation, adversarial testing, incident reporting, cybersecurity.
- Pre-existing GPAI models: 2 August 2027 deadline.
For deployers consuming GPAI
- GPAI provider's compliance does not absolve deployer responsibilities. Deployer obligations apply based on use-case classification.
Enforcement ramp-up
- 2 February 2025: prohibited practices applicable; enforcement capacity still building.
- 2 August 2025: penalty framework operational, governance bodies operational. First enforcement activity plausibly visible 2025-2026.
- 2026-2027: enforcement activity ramping with high-risk obligations applicability.
- First substantial enforcement actions plausibly 2026-2027. Pattern likely similar to GDPR rollout: initial guidance focus, then enforcement on clearest violations.
What happens if a system was placed on market before applicability
Article 111 transitional provisions:
- Article 111(1): high-risk AI systems placed on market or put into service before 2 August 2026 are subject to compliance only if they undergo significant changes after that date.
- Article 111(2): high-risk AI systems intended for use by public authorities, placed on market or put into service before 2 August 2026, must be compliant by 2 August 2030.
- Article 111(3): pre-existing GPAI models must be compliant by 2 August 2027.
The transitional provisions create complexity — knowing whether a system is "placed on market" before the cutoff (and what counts as "significant change") matters.
Coordination with other applicability dates
- GDPR: continues to apply alongside AI Act. AI Act does not affect GDPR.
- DORA (financial services ICT resilience, applicable since 17 January 2025): AI systems in DORA scope have both obligations.
- NIS2 (cybersecurity for essential / important entities): AI systems in NIS2 scope have both obligations.
- Cyber Resilience Act (Regulation 2024/2847): digital products cybersecurity. Applicability mid-2027. AI-enabled products covered.
- Product Liability Directive (revised, applicable December 2026): liability for AI systems extended.
Quick reference table
| Compliance work | By when |
|---|---|
| Stop prohibited practices | 2 February 2025 (already past) |
| AI literacy provisions | 2 February 2025 (ongoing) |
| GPAI baseline obligations | 2 August 2025 (already past) |
| GPAI systemic-risk obligations | 2 August 2025 (already past) |
| Annex III high-risk system compliance | 2 August 2026 |
| Limited-risk transparency obligations | 2 August 2026 |
| Annex I product-embedded high-risk | 2 August 2027 |
| Pre-existing GPAI compliance | 2 August 2027 |
| Pre-existing high-risk in public authorities | 2 August 2030 |