Current timeline, checked 8 September 2026: prohibitions and AI literacy began applying on 2 February 2025; GPAI rules began on 2 August 2025, subject to transitional provisions. General application and Article 50 transparency began on 2 August 2026. The high-risk dates are 2 December 2027 for Annex III and 2 August 2028 for relevant Annex I product systems. Determine the role, use and transition before assigning an obligation.
Key takeaways
- 2 Feb 2025: Prohibited practices (Art. 5) + AI literacy obligation (Art. 4) — already in force.
- 2 Aug 2025: GPAI obligations + national authority designation + penalties framework.
- 2 Aug 2026: General application of the Act, including the Art. 50 transparency duties — unchanged by the deferral.
- 2 Aug 2027: GPAI providers with models pre-Aug 2025 must achieve compliance.
- 2 Dec 2027: High-risk AI systems under Annex III — deferred from 2 Aug 2026 by the Digital Omnibus on AI.
- 2 Aug 2028: High-risk AI embedded in Annex I regulated products — deferred from 2 Aug 2027.
- Fine structure exceeds GDPR: up to €35M or 7% turnover (vs €20M / 4%).
The AI Act entered into force on 1 August 2024. Application is phased, and the subsequent amendment changes the planning baseline. Keep a dated register of applicable provisions and explain why each system falls within them. Existing GDPR obligations continue throughout this period.
This article explains the main EU AI Act application dates, what each deadline means in practice, and what organisations should be doing now. For a condensed phase-by-phase reference table, see our EU AI Act effective dates 2024-2027.
EU AI Act Timeline
The Commission’s current AI Act framework page states that the AI Omnibus entered into force on 27 July 2026. It gives 2 December 2027 and 2 August 2028 as the respective high-risk dates. Use the consolidated regulation and Commission implementation timeline for the current framework, rather than an earlier publication-pending announcement.
Phase 0: Entry into Force – 1 August 2024
The AI Act was published in the Official Journal of the European Union on 12 July 2024 and entered into force twenty days later on 1 August 2024. This date starts all compliance clocks. At that initial phase, the later substantive duties had not yet begun applying.
The European AI Office, established within the European Commission’s DG CONNECT, became operational in February 2024 and serves as the primary enforcement body for GPAI model obligations at the EU level.
Phase 1: Prohibited Practices – 2 February 2025 (ENFORCEABLE NOW)
Six months after entry into force. The following AI practices became prohibited under Art. 5:
Article 5 covers specified harmful practices, including social scoring by public or private actors, certain manipulation and exploitation of vulnerabilities, untargeted facial-image scraping, certain sensitive biometric categorisation, and individual criminal-risk prediction based solely on profiling or personality traits. Emotion recognition in workplaces and education has medical and safety exceptions. Law-enforcement biometric identification has narrowly defined conditions and exceptions. Check the current wording, including the amendment addressing prohibited nudification applications, against the concrete use; the Commission FAQ provides the current explanation.
These prohibitions are already enforceable. Under Art. 99(3), violations carry penalties of up to EUR 35 million or 7% of worldwide annual turnover – the highest tier of AI Act penalties. Any organisation still operating a system that falls within these categories faces immediate liability.
The AI literacy obligation under Art. 4 also became applicable at this date. Providers and deployers must ensure their staff have a sufficient level of AI literacy, taking into account their technical knowledge, experience, education, and the context of AI system use.
Phase 2: GPAI Model Obligations – 2 August 2025 (ENFORCEABLE NOW)
Twelve months after entry into force. General-Purpose AI (GPAI) model providers must comply with:
GPAI provider obligations (Art. 53), subject to applicable exceptions and transition:
- Maintain and make available technical documentation including training methodology, data sources, and computational resources used
- Provide information and documentation to downstream providers integrating the GPAI model into their AI systems
- Establish a policy to respect EU copyright law, including the text and data mining opt-out under Art. 4(3) of Directive (EU) 2019/790
- Publish a sufficiently detailed summary of the content used for training, following a template provided by the AI Office
GPAI models with systemic risk (Art. 55): Models classified as systemic risk (currently those trained with cumulative compute exceeding 10^25 FLOPs, or by AI Office designation) must additionally:
- Perform model evaluations including adversarial testing
- Assess and mitigate systemic risks
- Track, document, and report serious incidents to the AI Office
- Ensure adequate cybersecurity protections for the model and its physical infrastructure
The GPAI Code of Practice is a voluntary way to help demonstrate compliance. It is not interchangeable with the legal presumption associated with relevant harmonised standards. Check the particular commitment and whether an alternative compliance method is adequately evidenced. Certain open-source models benefit from specified exceptions; systemic-risk duties require a separate assessment.
Phase 3: Governance and Conformity Assessment Infrastructure – 2 August 2025
Also at the twelve-month mark:
- Member States must designate national competent authorities and market surveillance authorities
- Rules on notified bodies (Art. 28-39) apply – these are the organisations authorised to conduct conformity assessments for high-risk AI systems
- The Advisory Forum and scientific panel provisions become operational
Phase 4: General Application and Transparency Duties – 2 August 2026
Article 50 became applicable on 2 August 2026. It contains different duties for different actors and uses:
- Providers of systems intended to interact directly with people must support disclosure, unless interaction with AI is obvious to a reasonably informed person in the circumstances.
- Providers of systems generating synthetic audio, image, video or text face machine-readable marking requirements, with technical qualifications and exceptions such as certain standard editing functions.
- Deployers of emotion-recognition or biometric-categorisation systems must inform exposed people, subject to the legal provisions.
- Deployers must disclose qualifying deepfakes; artistic and similar works have tailored disclosure arrangements. Public-interest text publication has specific rules and an exception involving human review or editorial control and editorial responsibility.
An employee drafting a reply with a model is not automatically subject to every listed duty. Record the provider/deployer role, the output, the audience, the applicable paragraph and any exception. Keep the actual notice or marking test as evidence.
Penalties for breaching the transparency duties fall under Art. 99(4): up to EUR 15 million or 3% of global turnover.
Phase 5: High-Risk AI System Obligations – 2 December 2027 (deferred from 2 August 2026)
Deferred by the Digital Omnibus on AI. This is the most consequential set of obligations in the Act, and the one that moved: Annex III high-risk systems were due on 2 August 2026 and now apply from 2 December 2027. The full set of obligations for high-risk AI systems takes effect on that date:
Who is affected: Providers and deployers of AI systems classified as high-risk under Annex III. High-risk AI that is a safety component of a product regulated under Annex I runs on the separate 2 August 2028 date – see Phase 6. Annex III covers:
- Biometric identification and categorisation (beyond those already prohibited)
- Critical infrastructure management and operation
- Education and vocational training (access, admission, assessment)
- Employment, workers management, and access to self-employment (recruitment, promotion, monitoring)
- Access to essential private and public services (credit scoring, insurance pricing, emergency services dispatch)
- Law enforcement (individual risk assessment, lie detectors, evidence evaluation)
- Migration, asylum, and border control
- Administration of justice and democratic processes
What providers must do (Art. 8-15):
- Risk management system (Art. 9): Establish, implement, document, and maintain a risk management system throughout the AI system’s lifecycle
- Data governance (Art. 10): Training, validation, and testing datasets must meet the statutory relevance and representativeness requirements and be, to the best extent possible, free of errors and complete in view of their intended purpose. Bias detection and mitigation measures are mandatory.
- Technical documentation (Art. 11): Detailed documentation enabling authorities to assess compliance
- Record-keeping (Art. 12): Automatic logging of events during system operation
- Transparency (Art. 13): Instructions for use that enable deployers to understand the system’s capabilities and limitations
- Human oversight (Art. 14): Designed to be effectively overseen by natural persons during use
- Accuracy, robustness, cybersecurity (Art. 15): Appropriate levels throughout the lifecycle
What deployers must do (Art. 26):
- Use the system in accordance with instructions for use
- Ensure human oversight by appropriately trained individuals
- Monitor the system for risks, report incidents to providers
- Conduct a fundamental rights impact assessment for certain high-risk uses (Art. 27)
- Inform natural persons that they are subject to high-risk AI system decisions
Conformity assessment: Article 43 selects the assessment route by system category and circumstances. Many Annex III systems use internal control; certain biometric systems have additional notified-body conditions. Product systems also require analysis under the relevant sector legislation. Do not assume all critical-infrastructure systems require a notified body solely because of that label.
Penalties for non-compliance with high-risk obligations: up to EUR 15 million or 3% of global turnover under Art. 99(4).
Phase 6: Product-Embedded High-Risk AI – 2 August 2028 (deferred from 2 August 2027)
Forty-eight months after entry into force. High-risk AI systems that are safety components of products regulated under the EU harmonisation legislation listed in Annex I (including machinery, medical devices, in vitro diagnostics, civil aviation, motor vehicles, and marine equipment) get the longest runway, because AI Act requirements have to be folded into conformity assessment cycles that already exist under sector law. The Digital Omnibus on AI moved this date from 2 August 2027 to 2 August 2028. The obligation to integrate AI Act requirements into existing product conformity assessments applies from this date.
Phase 7: Full Application – 2 August 2028
Do not assign 2 August 2030 as a blanket extension for existing high-risk systems. Article 111 contains distinct transitional provisions, including conditions concerning earlier placement on the market, significant changes and systems intended for public-authority use. Record the placement date, changes, intended users and exact provision before adopting a transition.
If you already missed a deadline
Prohibited practices: review the actual system against Article 5 and its conditions and exceptions. If a prohibited use is identified, stop that use and address the consequences promptly. Record the factual and legal assessment.
GPAI obligations: check when the model was placed on the market. Models placed before 2 August 2025 have a transition to 2 August 2027. A downstream user is not automatically the GPAI model provider; document the actual role and any modification or integration duties.
What to do now
Article 50 is already applicable as of this update. Check live interactions and publication workflows now: identify the relevant provider or deployer duty, verify the disclosure or machine-readable measure and record the result.
For systems potentially within the later high-risk regime, collect classification and design evidence now. Assign a provider or deployer owner, identify the applicable assessment route and document dependencies. A general deadline does not decide whether an existing system benefits from a particular transition.
1. Classify your AI systems. Map every AI system you develop or deploy against Annex III categories and Annex I product categories. The AI Act risk classification framework determines your obligations.
2. Establish your risk management system. Art. 9 requires a continuous, iterative risk management process – not a one-time assessment. Start now if you have not already.
3. Audit your training data. Art. 10 data governance requirements demand that training datasets be relevant, representative, and as free of errors as possible. Assess your datasets against these criteria and document any limitations.
4. Prepare technical documentation. Art. 11 documentation requirements are extensive. Generating this documentation retrospectively for existing systems is significantly harder than building it into the development process.
5. Design for human oversight. Art. 14 requires that high-risk systems are designed to be effectively overseen by humans. If your system architecture does not currently support meaningful human intervention, redesign is needed – and architectural change of that kind is measured in release cycles, not weeks. December 2027 is not generous for a system that has to be re-architected and then re-evidenced.
6. Plan your conformity assessment. Determine whether your system requires internal assessment or third-party notified body assessment. For notified body assessments, account for lead times.
The GDPR Intersection: Both Apply
The AI Act explicitly does not replace GDPR. Recital 10 states that the regulation is “without prejudice” to the GDPR, the Law Enforcement Directive, and the ePrivacy Directive. Art. 2(7) confirms that the AI Act does not affect the application of Union law on the protection of personal data.
In practice, this means:
- AI systems processing personal data must comply with both the AI Act and GDPR simultaneously
- A valid legal basis under Art. 6 GDPR is required for any personal data processing in AI training, deployment, or monitoring – the AI Act does not create a new legal basis
- Data protection impact assessments under Art. 35 GDPR may be required alongside AI Act fundamental rights impact assessments under Art. 27 – the two assessments address different but overlapping risks
- Automated decision-making protections under Art. 22 GDPR apply to AI systems making decisions with legal or similarly significant effects, independently of AI Act transparency requirements
- DPAs retain full jurisdiction over personal data processing aspects of AI systems, alongside the market surveillance authorities enforcing the AI Act
Organisations should integrate their GDPR and AI Act compliance programs rather than treating them as separate workstreams. The intersection between the AI Act and GDPR creates compound obligations that require coordinated governance.
When does the EU AI Act fully apply?
The AI Act phases in between August 2024 and August 2028. Prohibited practices have applied since 2 February 2025 and GPAI obligations since 2 August 2025. The Act applies generally – including the Art. 50 transparency duties – from 2 August 2026. High-risk obligations under Annex III apply from 2 December 2027 and, for AI embedded in Annex I regulated products, from 2 August 2028. Both high-risk dates were deferred by the Digital Omnibus on AI, given final Council approval on 29 June 2026.
Does the high-risk deferral mean we can wait until 2027?
No. Already-applicable obligations, including the specific Article 50 duties, must be assessed now. For later high-risk duties, establish the system’s classification, the organisation’s role and any transition, then plan the required evidence and measures. The amendment is not a blanket permission to postpone existing obligations.
What are the penalties for missing EU AI Act deadlines?
Penalties depend on the type of violation. Prohibited practices: up to EUR 35 million or 7% of global turnover. High-risk system non-compliance: up to EUR 15 million or 3% of turnover. Supplying incorrect information to authorities: up to EUR 7.5 million or 1% of turnover. SMEs and startups benefit from proportionate penalty caps. These penalties apply per infringement.
Does the EU AI Act apply outside the EU?
Yes. Like GDPR, the AI Act has extraterritorial reach. Art. 2 applies the regulation to providers placing AI systems on the EU market or putting them into service in the EU, regardless of where the provider is established. It also applies to deployers located within the EU and to providers/deployers in third countries whose AI system output is used in the EU.
How does the AI Act interact with GDPR?
Both apply simultaneously to AI systems processing personal data. The AI Act does not replace or override GDPR. Organisations must maintain a valid GDPR legal basis for personal data processing in AI systems, conduct DPIAs where required under Art. 35 GDPR (in addition to AI Act fundamental rights assessments), and respect data subject rights including Art. 22 GDPR protections against purely automated decision-making. Integrated compliance programs covering both frameworks are strongly recommended.