EU AI Act Timeline

Vault note, not reviewed against the source. Written in the knowledge vault on 2026-05-12 by models working with Stefan Coetzee and published as it stands, with private addresses, e-mail addresses and an employer name redacted. Check claims against the primary source before relying on them.

Staged applicability schedule of the EU AI Act. Different obligations take effect at different dates from 2024 through 2027. Compliance planning depends on which obligations apply when.

Master schedule

DateMilestoneWhat applies
2024-07-12OJEU publication—
2024-08-01Regulation in forceFoundational legal status; provisions not yet applicable
2025-02-02First applicabilityChapter II (prohibited practices, Art 5); Art 4 AI literacy
2025-08-02Second applicabilityChapter V (GPAI, Art 51-56); Chapter VII (governance bodies); Chapter XII (penalties)
2026-08-02Third applicabilityMost remaining provisions, including Annex III high-risk system obligations
2027-08-02Final applicabilityAnnex I product-embedded high-risk systems (Art 6(1))

What applies as of 2 February 2025

  • Article 4 — AI literacy. Providers and deployers of AI systems shall take measures to ensure, to the extent reasonable, sufficient AI literacy of their staff and others operating AI on their behalf. Light obligation but real.
  • Article 5 — Prohibited practices. Unacceptable-risk AI practices prohibited:
    • Subliminal / manipulative techniques causing significant harm
    • Exploitation of vulnerabilities causing significant harm
    • Social scoring by public authorities
    • Predictive policing based solely on profiling
    • Untargeted facial-image scraping for facial-recognition databases
    • Emotion recognition in workplace / education (with exceptions)
    • Biometric categorization to deduce protected attributes
    • Real-time remote biometric identification in public for law enforcement (with narrow exceptions and authorization requirements)

Penalties for Article 5 violations applicable from this date.

Enforcement note: governance bodies and penalty mechanisms become operational at 2 August 2025, so enforcement-capacity ramp-up for prohibited practices happens between 2 February 2025 and 2 August 2025.

What applies as of 2 August 2025

  • Chapter V — GPAI obligations (Articles 51-56). General-purpose AI models obligations applicable.
    • Baseline GPAI obligations (Article 53)
    • GPAI with systemic risk obligations (Article 55)
    • Pre-existing GPAI models (placed on market before this date) have until 2 August 2027 to comply
  • Chapter VII — Governance bodies (Articles 64-70). AI Office, AI Board, Scientific Panel, Advisory Forum operational. National competent authorities designated.
  • Chapter X — Codes of conduct and guidelines (Articles 95-96). Voluntary codes for non-high-risk AI providers.
  • Chapter XII — Penalties (Articles 99-101). Penalty framework operational.
  • Article 78 — Confidentiality. Provisions on handling confidential information by authorities.

What applies as of 2 August 2026

  • Most remaining provisions. This is the main applicability date for the bulk of the regulation.
  • Chapter III — High-risk AI systems (Articles 6-49):
    • Classification rules (Article 6)
    • Requirements for high-risk AI (risk management, data and data governance, technical documentation, record-keeping, transparency, human oversight, accuracy / robustness / cybersecurity, quality management)
    • Provider obligations
    • Deployer obligations
    • Distributor / importer / authorized representative obligations
    • Conformity assessment procedures
    • EU declaration of conformity
    • CE marking
    • Registration in EU database
  • Chapter IV — Transparency obligations (Article 50). Limited-risk system transparency obligations:
    • AI interaction disclosure (chatbots, voice agents)
    • Synthetic content marking
    • Deepfake disclosure
    • Emotion recognition / biometric categorization notification
  • Chapter VI — Measures in support of innovation (Articles 57-63). Regulatory sandboxes, real-world testing provisions, support for SMEs.
  • Most market surveillance and enforcement provisions become fully operational.

What applies as of 2 August 2027

  • High-risk AI systems embedded in Annex I products (Article 6(1)). These follow the longer transition because the underlying product-specific regulations (medical devices, machinery, automotive, etc.) have their own compliance frameworks and the AI Act extensions integrate over a longer timeline.
  • Pre-existing GPAI models must achieve compliance by this date.
  • Some legacy high-risk AI systems placed on market before 2 August 2026 may have transition provisions (check Article 111).

Specific provisions outside the main schedule

  • Article 111 — Transitional provisions for high-risk AI systems already on the market. Specific rules for systems placed on market before applicability dates.
  • Article 112 — Evaluation and review. Commission shall assess and report regularly; first evaluation by 2 August 2028.
  • Article 113 — Entry into force / application. Master applicability dates as above.

Compliance planning implications

For providers of AI systems

  • Now (2026-05-12): review classifications, especially Article 6(3) exemption applicability. Plan compliance work for high-risk systems against 2 August 2026 deadline.
  • By 2 August 2026: high-risk system obligations operational. Conformity assessment completed, technical documentation in place, CE marking applied where required, post-market monitoring active.
  • Ongoing: transparency obligations for limited-risk systems where applicable. AI literacy provisions in place.

For deployers of AI systems

  • Now: identify high-risk AI systems in use; understand deployer obligations (use according to instructions, ensure human oversight, monitor operation, log if applicable, inform workers if used in workplace).
  • By 2 August 2026: deployer obligations for Annex III systems fully applicable.

For GPAI providers

  • By 2 August 2025: baseline GPAI obligations applicable. Technical documentation, training data summary, copyright compliance, downstream-provider information.
  • For GPAI with systemic risk: additional obligations applicable. Model evaluation, adversarial testing, incident reporting, cybersecurity.
  • Pre-existing GPAI models: 2 August 2027 deadline.

For deployers consuming GPAI

  • GPAI provider's compliance does not absolve deployer responsibilities. Deployer obligations apply based on use-case classification.

Enforcement ramp-up

  • 2 February 2025: prohibited practices applicable; enforcement capacity still building.
  • 2 August 2025: penalty framework operational, governance bodies operational. First enforcement activity plausibly visible 2025-2026.
  • 2026-2027: enforcement activity ramping with high-risk obligations applicability.
  • First substantial enforcement actions plausibly 2026-2027. Pattern likely similar to GDPR rollout: initial guidance focus, then enforcement on clearest violations.

What happens if a system was placed on market before applicability

Article 111 transitional provisions:

  • Article 111(1): high-risk AI systems placed on market or put into service before 2 August 2026 are subject to compliance only if they undergo significant changes after that date.
  • Article 111(2): high-risk AI systems intended for use by public authorities, placed on market or put into service before 2 August 2026, must be compliant by 2 August 2030.
  • Article 111(3): pre-existing GPAI models must be compliant by 2 August 2027.

The transitional provisions create complexity — knowing whether a system is "placed on market" before the cutoff (and what counts as "significant change") matters.

Coordination with other applicability dates

  • GDPR: continues to apply alongside AI Act. AI Act does not affect GDPR.
  • DORA (financial services ICT resilience, applicable since 17 January 2025): AI systems in DORA scope have both obligations.
  • NIS2 (cybersecurity for essential / important entities): AI systems in NIS2 scope have both obligations.
  • Cyber Resilience Act (Regulation 2024/2847): digital products cybersecurity. Applicability mid-2027. AI-enabled products covered.
  • Product Liability Directive (revised, applicable December 2026): liability for AI systems extended.

Quick reference table

Compliance workBy when
Stop prohibited practices2 February 2025 (already past)
AI literacy provisions2 February 2025 (ongoing)
GPAI baseline obligations2 August 2025 (already past)
GPAI systemic-risk obligations2 August 2025 (already past)
Annex III high-risk system compliance2 August 2026
Limited-risk transparency obligations2 August 2026
Annex I product-embedded high-risk2 August 2027
Pre-existing GPAI compliance2 August 2027
Pre-existing high-risk in public authorities2 August 2030

See also