Key EU AI Act compliance deadlines: a phased timeline
In short
The EU AI Act does not apply all at once. Article 113 phases obligations in over roughly three years from entry into force, giving organisations a staggered runway, but also meaning different parts of your compliance obligations activate on different dates, which is easy to lose track of.
1 August 2024, entry into force
The Act formally entered into force. This date starts the clock for every deadline below, but it did not itself trigger any operative obligations.
2 February 2025, prohibited practices and AI literacy
The Article 5 prohibited-practice bans took effect, alongside the Article 4 AI literacy obligation. These were the first substantive duties to apply, six months after entry into force, and both remain fully in effect today regardless of what tier any specific system falls into.
2 August 2025, governance, GPAI, and penalty provisions
Member States were required to have designated their national competent authorities. The general-purpose AI model obligations under Chapter V (Articles 51-56) took effect for GPAI model providers. The Article 99 penalty framework itself became applicable from this date.
2 August 2026, most of the Act became applicable
Most of the remaining substantive Act (the Article 50 transparency duties, the governance framework, and the general obligations) became applicable on this date. Originally the Annex III high-risk system obligations were also due here, but they were subsequently deferred by the Digital Omnibus on AI (see below).
2 December 2026, new prohibitions and a synthetic-content deadline
The Digital Omnibus added new Article 5 prohibitions that apply from this date: non-consensual intimate (“deepfake”) imagery and child-sexual-abuse-material AI systems. It is also the transition deadline for providers of synthetic-content generators already on the market to meet the Article 50(2) machine-readable marking duty.
2 August 2027, AI regulatory sandboxes
Each Member State must have at least one AI regulatory sandbox operational at national level: a supervised environment in which providers can develop, train, test and validate an AI system under regulatory oversight before placing it on the market (Article 57).
2 December 2027, Annex III high-risk obligations (deferred by the Digital Omnibus)
The Digital Omnibus on AI (Regulation (EU) 2026/1744, in force 27 July 2026) amended the AI Act to defer the high-risk obligations. Systems classified as high-risk under Annex III (Articles 9-15 for providers, Article 26 for deployers, and the Article 27 fundamental rights impact assessment) now apply from 2 December 2027 rather than August 2026, reflecting delays in harmonised standards and the designation of notified bodies.
2 August 2028, Annex I product-safety high-risk systems
High-risk obligations for AI systems that are safety components of products already regulated under existing EU product-safety legislation (Annex I) (medical devices, machinery, and similar regulated products) apply from 2 August 2028 (also deferred by the Digital Omnibus), giving those sectors additional time to align AI Act conformity assessment with their existing sectoral conformity regimes.
What this means in practice
An organisation should not treat “the AI Act” as a single deadline. A recruitment chatbot provider, for example, already has AI literacy and prohibited-practice obligations live today, faces the full Annex III high-risk obligation set from 2 December 2027 (as deferred by the Digital Omnibus), and (if their system is also a safety component of an already-regulated medical product) a further Annex I deadline on 2 August 2028. Compliance planning should map each obligation to its actual applicable date, not treat the Act as taking effect on a single day.
Because these dates interact with a system’s specific risk classification, the practical question for most companies is not “when does the Act apply” in the abstract, but which of these dates applies to their specific systems and roles.
Frequently asked questions
- When did the EU AI Act's first obligations take effect?
- On 2 February 2025, six months after entry into force (1 August 2024): the Article 5 prohibited-practice bans and the Article 4 AI literacy obligation, the first substantive duties, both fully in effect today.
- When do the high-risk (Annex III) obligations apply?
- From 2 December 2027. The Digital Omnibus on AI (Regulation (EU) 2026/1744) deferred them from the original August 2026 date; high-risk AI that are safety components of Annex I product-safety products apply from 2 August 2028.
- Does the whole EU AI Act apply on one date?
- No. Article 113 phases obligations in over roughly three years, prohibitions and AI literacy from February 2025, GPAI models and penalties from August 2025, most of the Act from August 2026, and the deferred high-risk obligations in December 2027 and August 2028. Each obligation should be mapped to its own applicable date.
Related guides
Not sure where your company stands?
Our free assessment gives you an indicative result in minutes (free and anonymous) no account needed.
Start the free check