The EU AI Act: A Complete Compliance Timeline

Add as a preferred source on Google

The EU AI Act does not switch on all at once. It arrives in waves, and each wave binds a different set of organisations to a different set of obligations, which is exactly why a clear AI Act timeline matters more than a single "compliance date" on a wall calendar.

What the EU AI Act Is

The EU AI Act is Regulation (EU) 2024/1689, the first comprehensive, horizontal law governing artificial intelligence anywhere in the world. It applies across every sector rather than to a single industry, and its reach is extraterritorial: it binds providers and deployers established outside the EU whenever their AI system's output is used within the Union. If you build, distribute, import, or deploy AI that touches the EU market, the Act very likely applies to you.

Rather than regulating the technology in the abstract, the Act sorts AI systems into risk tiers and scales the obligations to the risk.

The Four Risk Tiers

Unacceptable risk (prohibited). A defined set of practices in Article 5 is banned outright, including untargeted scraping of facial images to build recognition databases, social scoring, and certain manipulative or exploitative systems. These practices cannot be placed on the market at all. Note that the social scoring ban is not limited to public authorities: the limitation that appeared in the 2021 proposal was dropped from the adopted text, so a private employer, insurer or platform is equally in scope.

High risk. Systems listed in Annex III (for example, AI used in employment, education, credit scoring, biometrics, and critical infrastructure) and AI embedded as a safety component in products already regulated under Annex I. These are permitted but carry the heaviest obligations: risk management, data governance, technical documentation, human oversight, logging, and conformity assessment.

Limited risk (transparency). Systems such as chatbots and generative AI producing synthetic media face transparency duties under Article 50 (users must be told they are interacting with AI; synthetic content must be marked). Emotion recognition does not sit neatly here: inferring emotions in the workplace or in education is prohibited outright under Article 5, and emotion recognition is listed as high-risk in Annex III. Only the residual cases attract the Article 50 notification duty.

Minimal risk. Everything else (spam filters, most recommender systems) escapes the risk-tier obligations, but not the Act entirely: the Article 4 AI literacy duty binds every provider and deployer at every tier, minimal risk included.

Running alongside these tiers is a separate regime for general-purpose AI (GPAI) models (the large foundation models), governed by Chapter V, with heightened duties for models judged to carry systemic risk.

The Staggered Timeline

The Act entered into force on 1 August 2024, but its provisions apply on a phased schedule. It is worth flagging one important change up front: the AI Digital Omnibus, which entered into force in July 2026, postponed the main high-risk deadlines. As of 2026, the high-risk obligations for stand-alone Annex III systems have moved from the original 2 August 2026 to 2 December 2027, and product-embedded Annex I obligations from 2 August 2027 to 2 August 2028. The dates below reflect that amended position; always confirm against the consolidated text before relying on any single date.

Date Milestone Who it affects
1 Aug 2024 Regulation enters into force Everyone (clock starts)
2 Feb 2025 Prohibited practices (Art 5) and AI literacy duties (Art 4) apply All providers and deployers of in-scope AI
2 Aug 2025 GPAI model obligations (Ch. V), governance bodies, and the Member State penalties framework (Art 99) apply GPAI model providers; national authorities
27 Jul 2026 The Digital Omnibus (Reg. (EU) 2026/1744) enters into force, along with Arts 102–110 Everyone (the amended text becomes the operative law)
2 Aug 2026 General application, including Art 50 transparency duties, Art 49 registration, and the new market-surveillance powers (Arts 75, 75a–75d) Providers of limited-risk and generative systems
2 Dec 2026 Two new Art 5 prohibitions apply; machine-readable marking due for synthetic-content systems placed on the market before 2 Aug 2026 Providers of generative and synthetic-media systems
2 Aug 2027 Legacy GPAI models must be compliant; national regulatory sandboxes operational GPAI providers; Member States
2 Dec 2027 High-risk obligations for stand-alone Annex III systems apply (deferred from 2 Aug 2026) Providers and deployers of Annex III high-risk AI
2 Aug 2028 High-risk obligations for AI embedded in Annex I regulated products apply (deferred from 2 Aug 2027) Manufacturers of regulated products with AI safety components
2 Aug 2030 Backstop for legacy high-risk systems used by or on behalf of public authorities Public sector and their suppliers

2 February 2025: Prohibitions and literacy

The first substantive wave banned the Article 5 practices and, in parallel, required organisations to ensure a sufficient level of AI literacy among staff who operate AI systems on their behalf. This is the earliest hard deadline, and it has been in force for over a year.

2 August 2025: GPAI, governance, and penalties

The second wave switched on the obligations for providers of general-purpose AI models (transparency documentation, copyright policy, and, for systemic-risk models, adversarial testing and incident reporting). The same date activated the enforcement architecture: the European AI Office, national competent authorities, and the Member State penalty provisions of Article 99. Article 101, which lets the Commission fine general-purpose AI model providers directly, was expressly carved out and only applied from 2 August 2026. A model already on the market before this date was given until 2 August 2027 to bring itself into compliance.

2 August 2026: General application and transparency

This is the point at which the Regulation applies generally. The most visible new duty is Article 50 transparency: users must be informed when they interact with AI, and AI-generated or manipulated audio, image, video, and text (deepfakes and synthetic media) must be disclosed and machine-marked where required.

Two things landed on the same date that are easy to miss because attention was on the deferral. Registration in the EU database under Article 49 was not deferred. There is a genuine open question here, though: Article 49 triggers off the classification rule in Article 6, which was deferred, so how registration operates in practice before December 2027 is unresolved. And the Omnibus rewrote the market-surveillance chapter, giving the AI Office exclusive competence over certain systems built on general-purpose models and over systems integrated into very large online platforms, backed by new investigation and fining powers in Articles 75a to 75d. Those powers include periodic penalty payments of up to 5 percent of average daily income or worldwide annual turnover in the preceding financial year, per day. Separately, and often confused with it, the AI Office can fine for infringement of any applicable provision of the Regulation, including provisions outside the familiar closed list of finable articles.

2 December 2026: New prohibitions and the marking deadline

This is the nearest binding date still ahead, and it is absent from most timelines published before the Omnibus. Two new prohibitions in Article 5 begin to apply: AI that generates or manipulates non-consensual intimate imagery of an identifiable person, and AI that generates child sexual abuse material. The amending regulation narrows their reach, so placing a general-purpose generator on the market is caught only where such output is the intended purpose, or is a reasonably foreseeable and reproducible outcome without significant technical modification and the system lacks adequate safeguards. Deployers are caught only where they use a system for that purpose.

The same date carries the one grace period in Article 50. Providers of systems generating synthetic audio, image, video, or text that were already on the market before 2 August 2026 have until 2 December 2026 to meet the machine-readable marking duty. The other transparency duties, including chatbot disclosure and deepfake labelling, had no grace period at all. Note also that being on the market first offers no shelter from the new prohibitions, because the amended legacy provision applies without prejudice to Article 5.

2 December 2027: High-risk (Annex III)

Under the amended timeline, this is now the pivotal deadline for most high-risk AI: hiring tools, credit-scoring engines, biometric systems, and the rest of the Annex III list. Providers must complete conformity assessment, register in the EU database, and maintain a full quality-management and technical-documentation regime; deployers take on human-oversight and monitoring duties. The extra sixteen months relative to the original date is time to build, not time to wait.

2 August 2028: High-risk in regulated products (Annex I)

The final major wave covers AI acting as a safety component in products already governed by EU product-safety law (medical devices, in-vitro diagnostics, toys, lifts, personal protective equipment and similar), which are assessed through their existing sectoral conformity routes.

Machinery is a notable exception after the Omnibus. Regulation (EU) 2023/1230 was moved out of the Annex I section that triggers the full Chapter III programme and into the section where only a limited set of provisions applies, so AI safety components in machinery are now handled through the machinery regulation itself rather than through the AI Act's conformity assessment, registration and deployer duties. Motor vehicles sit in that same limited section and always have.

Who Must Act, and When

Providers (those who develop an AI system or GPAI model and place it on the market under their own name) carry the bulk of the obligations and should map their portfolio against the risk tiers now.

Deployers (organisations using an AI system in a professional capacity) have lighter but real duties, concentrated on high-risk use: human oversight, monitoring, and, in some cases, fundamental-rights impact assessment.

Importers and distributors must verify that upstream providers have met their obligations before making a system available.

In practice, if you use any AI today, the prohibited-practice and literacy duties already bind you. If you deploy or build anything on the Annex III list, your working deadline is 2 December 2027, and conformity work should already be underway.

Penalties

Enforcement has teeth, and the fine tiers scale with the severity of the breach:

  • Prohibited practices (Article 5): up to €35 million or 7% of total worldwide annual turnover, whichever is higher.
  • Most other provider and deployer breaches (including high-risk and transparency obligations): up to €15 million or 3% of worldwide annual turnover.
  • Supplying incorrect or misleading information to authorities: up to €7.5 million or 1%.

Providers of GPAI models sit under a distinct regime: the Commission, through the AI Office, may impose fines of up to €15 million or 3% of worldwide annual turnover under Article 101. For small and medium-sized enterprises and start-ups, the applicable ceiling is the lower of the fixed amount or the percentage, softening the impact somewhat.

AI Act Compliance Deadlines: The Practical Read

The staggered structure means there is no single moment to "become compliant." The prohibitions and literacy duties are live now; GPAI and enforcement have been live since 2025; general application landed in August 2026; and the heavy high-risk lifting now runs to December 2027 and August 2028. The organisations that fare best treat these AI Act compliance deadlines as a rolling programme rather than a one-off project.

If you want to turn these dates into concrete actions, work through our free EU AI Act compliance checklist, which covers every obligation currently in force plus the deadlines still ahead.

This article is general information, not legal advice. Always verify against the official text on EUR-Lex. Note that the amending regulation, (EU) 2026/1744, is authoritative in the Official Journal PDF: the EUR-Lex HTML rendering is truncated, and several widely used reference sites still serve the unamended 2024 text.