The EU
AI Act does not have one implementation date. It entered into force in 2024, began applying in stages in 2025, became generally applicable in August 2026 and still has important transitions extending into 2027, 2028 and 2030.
The sequence changed materially in July 2026, when Regulation (EU) 2026/1744—the Digital Omnibus on AI—entered into force. It preserved the general August 2026 application date while moving the main high-risk requirements to December 2027 for Annex III use cases and August 2028 for product-related Annex I systems. It also amended Article 4, added new prohibited practices and created a narrow transition for Article 50 machine-readable marking.
This guide owns the date question. For the law’s complete structure, start with our
EU AI Act guide. For tasks organized by owner rather than date, use the
EU AI Act compliance checklist.
Key deadlines at a glance
| Date | Milestone | Who should care most |
| July 12, 2024 | AI Act published in the Official Journal | Legal and policy teams establishing the authoritative text |
| August 1, 2024 | Regulation entered into force | Every organization beginning implementation planning |
| February 2, 2025 | Original Article 5 prohibitions and Article 4 AI-literacy duties applied | All providers and deployers; teams using potentially prohibited practices |
| August 2, 2025 | GPAI obligations and key governance provisions applied | GPAI model providers, downstream providers and regulators |
| July 27, 2026 | Digital Omnibus on AI entered into force | Every compliance program relying on the original timeline or Article 4 wording |
| August 2, 2026 | General application; Article 50 transparency; broader enforcement powers | Providers and deployers of interactive and generative AI; national authorities |
| December 2, 2026 | New sexual-content and CSAM prohibitions apply; Article 50(2) legacy transition ends | Generative AI providers and deployers; trust-and-safety teams |
| August 2, 2027 | Legacy GPAI models comply; national sandboxes operational | Pre-August 2025 model providers, Member States and startups |
| December 2, 2027 | Annex III high-risk requirements apply | Employment, education, biometrics, essential services, law enforcement and other listed use cases |
| August 2, 2028 | Annex I product-related high-risk requirements apply | Product manufacturers and AI providers in regulated sectors |
| August 2, 2030 | Certain public-authority legacy high-risk transitions end | Public bodies and providers serving them |
July 12, 2024: publication in the Official Journal
The final AI Act was published as
Regulation (EU) 2024/1689 on July 12, 2024. Publication established the authoritative legal text and triggered the entry-into-force calculation.
This date matters historically, but organizations usually use August 1, 2024 as the operational starting point because that is when the Regulation entered into force. A regulation’s entry into force is different from the dates on which individual obligations apply.
August 1, 2024: the AI Act entered into force
The Regulation entered into force twenty days after publication. From this point, the legal framework existed, but most obligations did not yet bind operators.
The transition period was intended to let institutions, standards bodies and organizations prepare. Good programs used it to:
- identify AI systems and models;
- assign legal roles;
- map use cases against Article 5, Annex I, Annex III and Article 50;
- begin vendor-contract changes;
- create AI-literacy measures;
- and establish documentation owners.
The date did not authorize practices prohibited by other laws. GDPR, product-safety rules, consumer law, employment law and anti-discrimination law continued to apply independently.
February 2, 2025: first substantive rules applied
Two important parts began applying six months after entry into force.
Original prohibited practices
The original Article 5 prohibitions became applicable. They cover eight legal categories, including harmful manipulation, exploitation of vulnerabilities, social scoring, particular criminal-risk prediction, untargeted facial-image scraping, workplace and education emotion recognition, sensitive biometric categorization and most real-time law-enforcement biometric identification in public spaces.
The Commission published guidance to explain the boundaries, but the underlying prohibitions come from the Regulation. Our
prohibited-practices guide explains conditions and exceptions.
Article 4 AI literacy
Providers and deployers became subject to AI-literacy duties. The original text spoke of ensuring a sufficient level of AI literacy. The 2026 amendment changed the formulation: organizations must now take measures to support the development of AI literacy, without guaranteeing a specific level for each person.
The obligation did not restart in July 2026. Organizations that were providers or deployers should already have been taking measures from February 2025. The
Article 4 guide covers the amended requirement and evidence.
August 2, 2025: GPAI rules and governance applied
Chapter V obligations began applying to providers placing general-purpose AI models on the market from this date. Those obligations include technical documentation, downstream information, an EU copyright-compliance policy and a public summary of training content. Providers of models with systemic risk have additional safety, evaluation, incident and cybersecurity duties.
The Commission’s enforcement powers for GPAI were scheduled to become operational one year later, on August 2, 2026. During the first year, the AI Office emphasized cooperation and use of the voluntary GPAI Code of Practice.
This date also matters for the legacy-model transition. GPAI models already on the market before August 2, 2025 must comply by August 2, 2027. A provider needs evidence of when a model was first placed on the EU market and whether later changes create a new model or provider role.
July 27, 2026: the Digital Omnibus on AI entered into force
The
Digital Omnibus on AI made targeted amendments shortly before the general application date. It is now part of the controlling legal framework; businesses should not rely on an unamended 2024 summary.
The most important changes for implementation planning include:
- amended Article 4 wording and support measures;
- two new Article 5 prohibitions, applying from December 2026;
- clarified high-risk classification for product safety components;
- delayed Chapter III high-risk requirements;
- a four-month transition for Article 50(2) marking on systems already on the market;
- proportionality and simplification measures for SMEs and small mid-caps;
- updated regulatory-sandbox deadlines;
- and stronger, more centralized AI Office powers for defined systems.
A project plan created before this date should be formally re-baselined. Do not merely change two high-risk dates; review Article 4 wording, enforcement ownership, Article 50 transitions and legacy-system assumptions.
August 2, 2026: general application and Article 50
Most remaining provisions became applicable. This was a major operational date for organizations, regulators and users.
Article 50 transparency obligations
Providers and deployers of certain interactive and generative systems must comply with transparency duties. Depending on role, the duties cover direct-interaction notice, machine-readable marking, emotion recognition, biometric categorization, deepfakes and certain public-interest text.
The date applies to Article 50 as a whole. The Omnibus created only a limited transition for providers of generative systems already placed on the market before August 2, 2026, and only for the marking/detection obligation in Article 50(2). Read our
Article 50 guide before treating December 2026 as a general grace period.
Enforcement framework
National market-surveillance authorities began supervising the provisions within their competence. The Commission’s GPAI enforcement powers applied, and the Omnibus expanded AI Office authority over certain systems built on GPAI models and systems connected to very large online platforms or search engines.
The general application and enforcement framework became operational from August 2, 2026. The Commission announced that the AI Office and national authorities would begin enforcing the applicable rules from that date. Organizations should therefore treat August 2026 as the start of active supervision, not as a further implementation grace period.
Rights and remedies
Complaint, explanation and whistleblower mechanisms in the Act became relevant within the applicable scope. Organizations should connect AI complaints to privacy, HR, consumer, product-safety and incident processes rather than create an isolated mailbox with no investigative route.
December 2, 2026: new prohibitions and marking transition
Two different deadlines arrive on this date.
New Article 5 prohibitions
The new prohibitions target AI systems that generate or manipulate:
- realistic non-consensual intimate material involving an identifiable person;
- and child sexual abuse material, subject to the defined “without right” exception.
For providers, scope depends on intended purpose or reasonably foreseeable, reproducible outcomes without reasonable and adequate safeguards. For deployers, prohibited use focuses on using the system for the prohibited purpose. This is more nuanced than banning every general-purpose image generator, but it creates immediate design, trust-and-safety and misuse-response work.
End of the Article 50(2) legacy-system transition
Providers of systems generating synthetic audio, image, video or text that were placed on the market before August 2, 2026 must take the necessary steps to comply with Article 50(2) by December 2, 2026.
This transition does not postpone direct-interaction notice, deepfake disclosure or every other transparency duty. It also does not require organizations to retroactively label content generated before August 2, 2026, although voluntary disclosure may be appropriate.
August 2, 2027: legacy GPAI models and regulatory sandboxes
Pre-existing GPAI models
Providers of GPAI models already on the market before August 2, 2025 must comply with Chapter V obligations by this date. That can require reconstructing documentation for a mature model, establishing a copyright policy, publishing the training-content summary and assessing systemic-risk status.
Leaving this work until 2027 is dangerous when training records, evaluation artifacts, model lineage or supplier evidence are difficult to recreate.
National AI regulatory sandboxes
Following the Omnibus amendment, Member States must ensure that at least one national AI regulatory sandbox is operational by August 2, 2027. Sandboxes provide controlled environments for developing, testing and validating innovative systems under an agreed plan and safeguards.
Participation does not make a system automatically compliant or exempt from other law. It can, however, support regulator engagement and evidence generation.
Supporting acts and guidance
The Omnibus also sets 2027 dates for certain delegated acts and guidance supporting high-risk implementation. Organizations should monitor, but not wait passively for, those instruments. Core engineering work such as logging, data lineage and human-oversight design can proceed from the Regulation.
December 2, 2027: Annex III high-risk requirements
The main requirements in Chapter III, Sections 1 to 3 apply from this date to high-risk systems classified under Article 6(2) and Annex III.
Annex III covers specified use cases in:
- biometrics;
- critical infrastructure;
- education and vocational training;
- employment and worker management;
- access to essential private and public services;
- law enforcement;
- migration, asylum and border control;
- and administration of justice and democratic processes.
This date activates classification rules, system requirements and operator obligations for that route, subject to the Act’s detailed provisions and transitions. Affected providers need conformity evidence before placing systems on the market or putting them into service. Deployers need operational controls, trained human oversight and, where applicable, a fundamental-rights impact assessment.
The Commission’s classification guidance remained in draft as of August 7, 2026, after consultation closed on July 23. Treat draft examples as useful interpretation, not final binding law.
August 2, 2028: Annex I product-related high-risk requirements
The main Chapter III requirements apply from this date to systems classified under Article 6(1) and Annex I. This route concerns AI that is a safety component of, or is itself, a regulated product requiring third-party conformity assessment.
Examples can involve machinery, medical devices, vehicles, aviation, lifts, pressure equipment, toys and other product regimes listed in Annex I. Not every AI feature inside a regulated product is a safety component. The Omnibus clarified that systems used solely for non-safety user assistance, performance optimization, service efficiency, convenience or quality control do not qualify as safety components unless failure or malfunction would endanger health and safety.
Product manufacturers must integrate AI Act evidence with sectoral conformity assessment, technical files, quality systems and post-market processes. The later date reflects the complexity of aligning horizontal AI rules with product legislation.
August 2, 2030: transition for public-authority systems
Article 111 provides special treatment for high-risk systems already placed on the market or put into service before the relevant Chapter III application date. In general, those systems become subject to the Regulation if they undergo significant design changes after that date.
However, providers and deployers of high-risk systems intended for use by public authorities must take the necessary steps to comply by August 2, 2030. Public-sector organizations should not read this as a procurement holiday. Long contracts, legacy architecture and public-law duties make early inventory and contractual planning especially important.
Which deadline applies to a specific system?
Use this sequence:
- Confirm the tool is an AI system or GPAI model within scope.
- Identify provider, deployer and other roles.
- Test Article 5. A prohibited practice may already be unlawful.
- Test Article 50. Transparency duties may apply now.
- Determine whether a GPAI model is being placed on the market and when.
- Test Annex III and Annex I separately.
- Identify when the system or model was first placed on the EU market or put into service.
- Record significant changes, rebranding and changes to intended purpose.
- Check sectoral law and national enforcement measures.
- Attach evidence and an owner to the deadline.
A date register without classification evidence is weak. The same product family can contain modules with different legal dates.
A 2026–2028 implementation plan
Work that should already be active
- Article 4 literacy measures;
- screening for original prohibited practices;
- GPAI obligations for post-August 2025 model providers;
- Article 50 implementation;
- authority and complaint readiness;
- AI inventory and role assignment.
Work to complete before December 2026
- safeguards against new prohibited sexual-content uses;
- Article 50(2) marking updates for legacy generative systems;
- revised public disclosures and content workflows;
- updated supplier evidence for marking and detection.
Work to mature through 2027
- Annex III classification and documented exclusions;
- risk management, data governance and technical documentation;
- human-oversight design and training;
- quality-management systems;
- conformity assessment and registration planning;
- fundamental-rights impact assessment procedures;
- legacy GPAI compliance.
Work to mature through 2028
- Annex I product mapping;
- integration with sectoral notified bodies and conformity routes;
- product technical-file changes;
- post-market monitoring and incident alignment;
- supplier contracts for safety components and embedded models.
Common timeline mistakes
Treating August 2026 as the first deadline
Article 4, original prohibitions and GPAI obligations began earlier.
Treating December 2026 as a universal Article 50 grace period
The transition is limited to Article 50(2) for systems already placed on the market before August 2, 2026.
Using the original August 2026/2027 high-risk schedule
The Omnibus moved Annex III to December 2027 and Annex I to August 2028.
Waiting for final high-risk guidelines before starting
Final guidance will help interpretation, but it will not create an inventory, data lineage or quality system for the organization.
Ignoring legacy evidence
Transition rules depend on when a model or type and model of system was placed on the market and whether its design changed. Preserve release, contract, version and deployment records.
Frequently asked questions
When did the EU AI Act become law?
It entered into force on August 1, 2024. Most provisions became generally applicable on August 2, 2026, with staged exceptions.
Is the AI Act fully applicable in 2026?
No. Many provisions apply, but the main high-risk requirements arrive in December 2027 and August 2028.
When did Article 4 start applying?
February 2, 2025. The 2026 Omnibus amended the wording but did not postpone the obligation.
When do chatbot and deepfake transparency rules apply?
Article 50 applies from August 2, 2026. A limited marking transition runs to December 2, 2026 for qualifying legacy generative systems.
When do GPAI rules apply?
They apply to models placed on the market from August 2, 2025. Pre-existing GPAI models must comply by August 2, 2027.
When are high-risk employment systems regulated?
Employment and worker-management use cases in Annex III face the main high-risk requirements from December 2, 2027, assuming they meet the classification conditions.
When are AI medical devices regulated as high-risk?
Product-related Annex I high-risk requirements apply from August 2, 2028, alongside applicable sectoral product law.
Did the Digital Omnibus repeal the AI Act?
No. It amended and simplified parts of the Act, changed deadlines and added provisions. The AI Act remains in force.
Can national authorities enforce Article 4 now?
Yes. Article 4 has applied since 2025, and the general supervision and enforcement framework became operational in August 2026.
Does a system deployed before a deadline escape forever?
No. Legacy rules are conditional. Significant design changes can trigger compliance, and public-authority systems have a 2030 transition.
Bottom line
The operational EU AI Act timeline has four distinct waves: first prohibitions and literacy in 2025; GPAI obligations in 2025; general application and transparency in 2026; and the main high-risk requirements in 2027 and 2028. Public-sector legacy transitions extend to 2030.
The correct deadline follows the system’s legal classification, role, market date and change history. Build a deadline register from those facts—not from a generic calendar copied into a policy.