EU AI Act Timeline: Deadlines From 2024 to 2030

Guides
by David Porter
Wednesday, 12 August 2026 at 21:18
thumbnail_eu-ai-act-timeline-deadlines-f
The EU AI Act does not have one implementation date. It entered into force in 2024, began applying in stages in 2025, became generally applicable in August 2026 and still has important transitions extending into 2027, 2028 and 2030.
The sequence changed materially in July 2026, when Regulation (EU) 2026/1744—the Digital Omnibus on AI—entered into force. It preserved the general August 2026 application date while moving the main high-risk requirements to December 2027 for Annex III use cases and August 2028 for product-related Annex I systems. It also amended Article 4, added new prohibited practices and created a narrow transition for Article 50 machine-readable marking.
This guide owns the date question. For the law’s complete structure, start with our EU AI Act guide. For tasks organized by owner rather than date, use the EU AI Act compliance checklist.

Key deadlines at a glance

DateMilestoneWho should care most
July 12, 2024AI Act published in the Official JournalLegal and policy teams establishing the authoritative text
August 1, 2024Regulation entered into forceEvery organization beginning implementation planning
February 2, 2025Original Article 5 prohibitions and Article 4 AI-literacy duties appliedAll providers and deployers; teams using potentially prohibited practices
August 2, 2025GPAI obligations and key governance provisions appliedGPAI model providers, downstream providers and regulators
July 27, 2026Digital Omnibus on AI entered into forceEvery compliance program relying on the original timeline or Article 4 wording
August 2, 2026General application; Article 50 transparency; broader enforcement powersProviders and deployers of interactive and generative AI; national authorities
December 2, 2026New sexual-content and CSAM prohibitions apply; Article 50(2) legacy transition endsGenerative AI providers and deployers; trust-and-safety teams
August 2, 2027Legacy GPAI models comply; national sandboxes operationalPre-August 2025 model providers, Member States and startups
December 2, 2027Annex III high-risk requirements applyEmployment, education, biometrics, essential services, law enforcement and other listed use cases
August 2, 2028Annex I product-related high-risk requirements applyProduct manufacturers and AI providers in regulated sectors
August 2, 2030Certain public-authority legacy high-risk transitions endPublic bodies and providers serving them

July 12, 2024: publication in the Official Journal

The final AI Act was published as Regulation (EU) 2024/1689 on July 12, 2024. Publication established the authoritative legal text and triggered the entry-into-force calculation.
This date matters historically, but organizations usually use August 1, 2024 as the operational starting point because that is when the Regulation entered into force. A regulation’s entry into force is different from the dates on which individual obligations apply.

August 1, 2024: the AI Act entered into force

The Regulation entered into force twenty days after publication. From this point, the legal framework existed, but most obligations did not yet bind operators.
The transition period was intended to let institutions, standards bodies and organizations prepare. Good programs used it to:
  • identify AI systems and models;
  • assign legal roles;
  • map use cases against Article 5, Annex I, Annex III and Article 50;
  • begin vendor-contract changes;
  • create AI-literacy measures;
  • and establish documentation owners.
The date did not authorize practices prohibited by other laws. GDPR, product-safety rules, consumer law, employment law and anti-discrimination law continued to apply independently.

February 2, 2025: first substantive rules applied

Two important parts began applying six months after entry into force.

Original prohibited practices

The original Article 5 prohibitions became applicable. They cover eight legal categories, including harmful manipulation, exploitation of vulnerabilities, social scoring, particular criminal-risk prediction, untargeted facial-image scraping, workplace and education emotion recognition, sensitive biometric categorization and most real-time law-enforcement biometric identification in public spaces.
The Commission published guidance to explain the boundaries, but the underlying prohibitions come from the Regulation. Our prohibited-practices guide explains conditions and exceptions.

Article 4 AI literacy

Providers and deployers became subject to AI-literacy duties. The original text spoke of ensuring a sufficient level of AI literacy. The 2026 amendment changed the formulation: organizations must now take measures to support the development of AI literacy, without guaranteeing a specific level for each person.
The obligation did not restart in July 2026. Organizations that were providers or deployers should already have been taking measures from February 2025. The Article 4 guide covers the amended requirement and evidence.

August 2, 2025: GPAI rules and governance applied

Chapter V obligations began applying to providers placing general-purpose AI models on the market from this date. Those obligations include technical documentation, downstream information, an EU copyright-compliance policy and a public summary of training content. Providers of models with systemic risk have additional safety, evaluation, incident and cybersecurity duties.
The Commission’s enforcement powers for GPAI were scheduled to become operational one year later, on August 2, 2026. During the first year, the AI Office emphasized cooperation and use of the voluntary GPAI Code of Practice.
This date also matters for the legacy-model transition. GPAI models already on the market before August 2, 2025 must comply by August 2, 2027. A provider needs evidence of when a model was first placed on the EU market and whether later changes create a new model or provider role.

July 27, 2026: the Digital Omnibus on AI entered into force

The Digital Omnibus on AI made targeted amendments shortly before the general application date. It is now part of the controlling legal framework; businesses should not rely on an unamended 2024 summary.
The most important changes for implementation planning include:
  • amended Article 4 wording and support measures;
  • two new Article 5 prohibitions, applying from December 2026;
  • clarified high-risk classification for product safety components;
  • delayed Chapter III high-risk requirements;
  • a four-month transition for Article 50(2) marking on systems already on the market;
  • proportionality and simplification measures for SMEs and small mid-caps;
  • updated regulatory-sandbox deadlines;
  • and stronger, more centralized AI Office powers for defined systems.
A project plan created before this date should be formally re-baselined. Do not merely change two high-risk dates; review Article 4 wording, enforcement ownership, Article 50 transitions and legacy-system assumptions.

August 2, 2026: general application and Article 50

Most remaining provisions became applicable. This was a major operational date for organizations, regulators and users.

Article 50 transparency obligations

Providers and deployers of certain interactive and generative systems must comply with transparency duties. Depending on role, the duties cover direct-interaction notice, machine-readable marking, emotion recognition, biometric categorization, deepfakes and certain public-interest text.
The date applies to Article 50 as a whole. The Omnibus created only a limited transition for providers of generative systems already placed on the market before August 2, 2026, and only for the marking/detection obligation in Article 50(2). Read our Article 50 guide before treating December 2026 as a general grace period.

Enforcement framework

National market-surveillance authorities began supervising the provisions within their competence. The Commission’s GPAI enforcement powers applied, and the Omnibus expanded AI Office authority over certain systems built on GPAI models and systems connected to very large online platforms or search engines.
The general application and enforcement framework became operational from August 2, 2026. The Commission announced that the AI Office and national authorities would begin enforcing the applicable rules from that date. Organizations should therefore treat August 2026 as the start of active supervision, not as a further implementation grace period.

Rights and remedies

Complaint, explanation and whistleblower mechanisms in the Act became relevant within the applicable scope. Organizations should connect AI complaints to privacy, HR, consumer, product-safety and incident processes rather than create an isolated mailbox with no investigative route.

December 2, 2026: new prohibitions and marking transition

Two different deadlines arrive on this date.

New Article 5 prohibitions

The new prohibitions target AI systems that generate or manipulate:
  • realistic non-consensual intimate material involving an identifiable person;
  • and child sexual abuse material, subject to the defined “without right” exception.
For providers, scope depends on intended purpose or reasonably foreseeable, reproducible outcomes without reasonable and adequate safeguards. For deployers, prohibited use focuses on using the system for the prohibited purpose. This is more nuanced than banning every general-purpose image generator, but it creates immediate design, trust-and-safety and misuse-response work.

End of the Article 50(2) legacy-system transition

Providers of systems generating synthetic audio, image, video or text that were placed on the market before August 2, 2026 must take the necessary steps to comply with Article 50(2) by December 2, 2026.
This transition does not postpone direct-interaction notice, deepfake disclosure or every other transparency duty. It also does not require organizations to retroactively label content generated before August 2, 2026, although voluntary disclosure may be appropriate.

August 2, 2027: legacy GPAI models and regulatory sandboxes

Pre-existing GPAI models

Providers of GPAI models already on the market before August 2, 2025 must comply with Chapter V obligations by this date. That can require reconstructing documentation for a mature model, establishing a copyright policy, publishing the training-content summary and assessing systemic-risk status.
Leaving this work until 2027 is dangerous when training records, evaluation artifacts, model lineage or supplier evidence are difficult to recreate.

National AI regulatory sandboxes

Following the Omnibus amendment, Member States must ensure that at least one national AI regulatory sandbox is operational by August 2, 2027. Sandboxes provide controlled environments for developing, testing and validating innovative systems under an agreed plan and safeguards.
Participation does not make a system automatically compliant or exempt from other law. It can, however, support regulator engagement and evidence generation.

Supporting acts and guidance

The Omnibus also sets 2027 dates for certain delegated acts and guidance supporting high-risk implementation. Organizations should monitor, but not wait passively for, those instruments. Core engineering work such as logging, data lineage and human-oversight design can proceed from the Regulation.

December 2, 2027: Annex III high-risk requirements

The main requirements in Chapter III, Sections 1 to 3 apply from this date to high-risk systems classified under Article 6(2) and Annex III.
Annex III covers specified use cases in:
  • biometrics;
  • critical infrastructure;
  • education and vocational training;
  • employment and worker management;
  • access to essential private and public services;
  • law enforcement;
  • migration, asylum and border control;
  • and administration of justice and democratic processes.
This date activates classification rules, system requirements and operator obligations for that route, subject to the Act’s detailed provisions and transitions. Affected providers need conformity evidence before placing systems on the market or putting them into service. Deployers need operational controls, trained human oversight and, where applicable, a fundamental-rights impact assessment.
The Commission’s classification guidance remained in draft as of August 7, 2026, after consultation closed on July 23. Treat draft examples as useful interpretation, not final binding law.

August 2, 2028: Annex I product-related high-risk requirements

The main Chapter III requirements apply from this date to systems classified under Article 6(1) and Annex I. This route concerns AI that is a safety component of, or is itself, a regulated product requiring third-party conformity assessment.
Examples can involve machinery, medical devices, vehicles, aviation, lifts, pressure equipment, toys and other product regimes listed in Annex I. Not every AI feature inside a regulated product is a safety component. The Omnibus clarified that systems used solely for non-safety user assistance, performance optimization, service efficiency, convenience or quality control do not qualify as safety components unless failure or malfunction would endanger health and safety.
Product manufacturers must integrate AI Act evidence with sectoral conformity assessment, technical files, quality systems and post-market processes. The later date reflects the complexity of aligning horizontal AI rules with product legislation.

August 2, 2030: transition for public-authority systems

Article 111 provides special treatment for high-risk systems already placed on the market or put into service before the relevant Chapter III application date. In general, those systems become subject to the Regulation if they undergo significant design changes after that date.
However, providers and deployers of high-risk systems intended for use by public authorities must take the necessary steps to comply by August 2, 2030. Public-sector organizations should not read this as a procurement holiday. Long contracts, legacy architecture and public-law duties make early inventory and contractual planning especially important.

Which deadline applies to a specific system?

Use this sequence:
  1. Confirm the tool is an AI system or GPAI model within scope.
  2. Identify provider, deployer and other roles.
  3. Test Article 5. A prohibited practice may already be unlawful.
  4. Test Article 50. Transparency duties may apply now.
  5. Determine whether a GPAI model is being placed on the market and when.
  6. Test Annex III and Annex I separately.
  7. Identify when the system or model was first placed on the EU market or put into service.
  8. Record significant changes, rebranding and changes to intended purpose.
  9. Check sectoral law and national enforcement measures.
  10. Attach evidence and an owner to the deadline.
A date register without classification evidence is weak. The same product family can contain modules with different legal dates.

A 2026–2028 implementation plan

Work that should already be active

  • Article 4 literacy measures;
  • screening for original prohibited practices;
  • GPAI obligations for post-August 2025 model providers;
  • Article 50 implementation;
  • authority and complaint readiness;
  • AI inventory and role assignment.

Work to complete before December 2026

  • safeguards against new prohibited sexual-content uses;
  • Article 50(2) marking updates for legacy generative systems;
  • revised public disclosures and content workflows;
  • updated supplier evidence for marking and detection.

Work to mature through 2027

  • Annex III classification and documented exclusions;
  • risk management, data governance and technical documentation;
  • human-oversight design and training;
  • quality-management systems;
  • conformity assessment and registration planning;
  • fundamental-rights impact assessment procedures;
  • legacy GPAI compliance.

Work to mature through 2028

  • Annex I product mapping;
  • integration with sectoral notified bodies and conformity routes;
  • product technical-file changes;
  • post-market monitoring and incident alignment;
  • supplier contracts for safety components and embedded models.

Common timeline mistakes

Treating August 2026 as the first deadline

Article 4, original prohibitions and GPAI obligations began earlier.

Treating December 2026 as a universal Article 50 grace period

The transition is limited to Article 50(2) for systems already placed on the market before August 2, 2026.

Using the original August 2026/2027 high-risk schedule

The Omnibus moved Annex III to December 2027 and Annex I to August 2028.

Waiting for final high-risk guidelines before starting

Final guidance will help interpretation, but it will not create an inventory, data lineage or quality system for the organization.

Ignoring legacy evidence

Transition rules depend on when a model or type and model of system was placed on the market and whether its design changed. Preserve release, contract, version and deployment records.

Frequently asked questions

When did the EU AI Act become law?

It entered into force on August 1, 2024. Most provisions became generally applicable on August 2, 2026, with staged exceptions.

Is the AI Act fully applicable in 2026?

No. Many provisions apply, but the main high-risk requirements arrive in December 2027 and August 2028.

When did Article 4 start applying?

February 2, 2025. The 2026 Omnibus amended the wording but did not postpone the obligation.

When do chatbot and deepfake transparency rules apply?

Article 50 applies from August 2, 2026. A limited marking transition runs to December 2, 2026 for qualifying legacy generative systems.

When do GPAI rules apply?

They apply to models placed on the market from August 2, 2025. Pre-existing GPAI models must comply by August 2, 2027.

When are high-risk employment systems regulated?

Employment and worker-management use cases in Annex III face the main high-risk requirements from December 2, 2027, assuming they meet the classification conditions.

When are AI medical devices regulated as high-risk?

Product-related Annex I high-risk requirements apply from August 2, 2028, alongside applicable sectoral product law.

Did the Digital Omnibus repeal the AI Act?

No. It amended and simplified parts of the Act, changed deadlines and added provisions. The AI Act remains in force.

Can national authorities enforce Article 4 now?

Yes. Article 4 has applied since 2025, and the general supervision and enforcement framework became operational in August 2026.

Does a system deployed before a deadline escape forever?

No. Legacy rules are conditional. Significant design changes can trigger compliance, and public-authority systems have a 2030 transition.

Bottom line

The operational EU AI Act timeline has four distinct waves: first prohibitions and literacy in 2025; GPAI obligations in 2025; general application and transparency in 2026; and the main high-risk requirements in 2027 and 2028. Public-sector legacy transitions extend to 2030.
The correct deadline follows the system’s legal classification, role, market date and change history. Build a deadline register from those facts—not from a generic calendar copied into a policy.
loading

Loading