The EU AI Act is the world’s first comprehensive AI regulation — and it does not arrive all at once. It entered into force on 1 August 2024 and rolls out in stages through 2027. If your organisation builds, buys, or deploys AI systems that touch the EU market, these are the dates that matter.
When does the EU AI Act apply? The short answer
The most important deadline for most organisations is 2 August 2026, when the bulk of the regulation — including the full set of obligations for high-risk AI systems listed in Annex III — becomes applicable. Bans on prohibited AI practices have already applied since 2 February 2025, and general-purpose AI (GPAI) model obligations since 2 August 2025.
The full timeline at a glance
| Date | What applies |
|---|---|
| 1 Aug 2024 | The AI Act enters into force (no obligations yet). |
| 2 Feb 2025 | Prohibited practices banned (social scoring, manipulative AI, untargeted facial-image scraping, and more). AI-literacy duty for providers and deployers (Article 4). |
| 2 Aug 2025 | Obligations for general-purpose AI model providers (transparency, copyright policy, training-data summaries). EU AI Office and governance structures operational. Member States designate authorities and set penalty regimes. |
| 2 Aug 2026 | General applicability. High-risk AI systems under Annex III must comply (risk management, data governance, documentation, human oversight, and more). Transparency duties for chatbots, deepfakes, and emotion-recognition systems. Member States must have at least one regulatory sandbox. |
| 2 Aug 2027 | High-risk AI embedded in regulated products (Annex I — machinery, medical devices, vehicles, toys, etc.). GPAI models placed on the market before Aug 2025 must be brought into compliance. |
What does the 2 August 2026 deadline mean in practice?
From that date, any high-risk AI system placed on the EU market or put into service must meet the full Chapter III requirements:
- A documented risk-management system across the AI lifecycle
- Data governance — training, validation, and test data must be relevant, representative, and managed for bias
- Technical documentation and automatic logging
- Transparency towards deployers, and effective human oversight
- Appropriate accuracy, robustness, and cybersecurity
- A quality-management system, conformity assessment, CE marking, and registration in the EU database
Deployers (organisations using high-risk AI built by others) carry their own obligations too: using systems per the provider’s instructions, assigning trained human oversight, monitoring operation, and — for certain deployers such as public bodies — a fundamental-rights impact assessment.
Which deadline applies to you?
- You use a chatbot or generate synthetic content → transparency obligations from 2 Aug 2026.
- You build or deploy AI for hiring, credit scoring, education, critical infrastructure, or essential services → likely Annex III high-risk, deadline 2 Aug 2026.
- Your AI is a safety component of a regulated product → Annex I, deadline 2 Aug 2027.
- You provide a general-purpose model → obligations since 2 Aug 2025 (existing models: 2 Aug 2027).
A note on possible changes
In late 2025 the European Commission proposed a Digital Omnibus package that would, among other things, adjust the timing of some high-risk obligations. As of mid-2026 this remains a proposal moving through the legislative process — the adopted regulation’s dates remain the binding baseline. Our advice: plan against the official dates and treat any relief as a bonus, not a strategy.
How to prepare — a pragmatic 4-step start
- Inventory every AI system you build, buy, or embed.
- Classify each against the prohibited / high-risk / transparency / minimal-risk tiers.
- Map your role per system: provider, deployer, importer, or distributor — the obligations differ substantially.
- Close the gaps with a prioritised roadmap: governance, documentation, training, and vendor management.
If you want a structured way to do all four in a single engagement, that is exactly what our EU AI Act Delivery Workshop covers.
Frequently Asked Questions
When does the EU AI Act fully apply?
The EU AI Act entered into force on 1 August 2024 and applies in stages. The bulk of its rules — including obligations for high-risk AI systems listed in Annex III — apply from 2 August 2026. High-risk AI embedded in regulated products (Annex I) has until 2 August 2027.
What has already been in force before 2026?
Since 2 February 2025, prohibited AI practices (such as social scoring and untargeted facial-image scraping) are banned and organisations must ensure AI literacy among staff. Since 2 August 2025, obligations for general-purpose AI (GPAI) model providers apply.
What are the penalties for non-compliance?
Fines scale with the violation: up to €35 million or 7% of global annual turnover for prohibited practices, up to €15 million or 3% for most other obligations, and up to €7.5 million or 1% for supplying incorrect information to authorities. SMEs face the lower of the two amounts.
Could the deadlines still change?
The European Commission proposed a "Digital Omnibus" package in late 2025 that could adjust the timing of some high-risk obligations. Until any amendment is formally adopted, the dates in the regulation as adopted remain the legally binding ones — plan against them, and monitor developments.
This guide is provided for general information and does not constitute legal advice. Regulatory details evolve — verify current requirements against official EU sources or seek qualified counsel for decisions affecting your organisation.