AI Act Timeline: All the Key Compliance Deadlines
The European Artificial Intelligence Act, commonly referred to as the AI Act, establishes a harmonised legal framework for the development, placing on the market and use of artificial intelligence systems across the European Union.
Regulation (EU) 2024/1689 entered into force on 1 August 2024, but not all of its provisions became applicable on that date. The European legislator introduced a phased implementation schedule, allowing organisations time to prepare for compliance.
This timeline was subsequently amended by Regulation (EU) 2026/1744, adopted on 8 July 2026, published in the Official Journal of the European Union on 24 July 2026, and entering into force on 27 July 2026. This Regulation simplifies the implementation of certain AI Act obligations and postpones several compliance deadlines.
AI Act Timeline
| Date | Milestone |
|---|---|
| 1 August 2024 | Entry into force of the AI Act |
| 2 February 2025 | Application of prohibited AI practices (Article 5) and the AI literacy obligation (Article 4) |
| 2 August 2025 | Application of the rules governing General-Purpose AI (GPAI) models, the European AI governance framework and competent authorities |
| 2 August 2026 | Application of the majority of AI Act provisions, including the main transparency obligations under Article 50 |
| 2 December 2026 | Application of the machine-readable marking requirement under Article 50(2) for certain AI systems already placed on the market |
| 2 August 2027 | End of the transitional period for existing GPAI models and deadline for each Member State to establish at least one AI regulatory sandbox |
| 2 December 2027 | Application of the obligations applicable to high-risk AI systems falling under Article 6(2) and Annex III |
| 2 August 2028 | Application of the obligations applicable to high-risk AI systems falling under Article 6(1) and Annex I |
| 2 August 2030 | Application of obligations to certain high-risk AI systems intended for use by public authorities |
| 31 December 2030 | Application of the provisions relating to the large-scale information systems listed in Annex X |
Key takeaway: the next regulatory milestone is 2 December 2026. It relates exclusively to the machine-readable marking requirement set out in Article 50(2). Article 50 as a whole has not been postponed.
1 August 2024: Entry into Force of the AI Act
The AI Act officially entered into force on 1 August 2024, twenty days after its publication in the Official Journal of the European Union.
This marked the beginning of the EU's new regulatory framework for artificial intelligence. However, most of the Regulation's obligations were not yet applicable.
This initial period was designed to allow organisations to prepare for compliance by:
- identifying all AI systems they develop, deploy or market;
- determining their role under the AI Act (provider, deployer, importer, distributor or authorised representative);
- mapping AI use cases;
- identifying systems that may qualify as high-risk AI systems;
- establishing AI governance processes;
- preparing compliance documentation.
Creating an inventory of AI systems is the foundation of any compliance programme. Without a comprehensive overview of the AI systems developed, deployed or commercialised by an organisation, it is impossible to identify the applicable regulatory obligations.
2 February 2025: The First Obligations Become Applicable
The first provisions of the AI Act became applicable on 2 February 2025.
This milestone mainly concerns:
- prohibited AI practices under Article 5;
- the AI literacy obligation under Article 4.
Prohibited AI Practices
Article 5 prohibits several AI practices considered to pose an unacceptable risk to fundamental rights.
These include, among others:
- certain subliminal or manipulative techniques;
- certain forms of exploitation of vulnerabilities linked to age, disability or socio-economic circumstances;
- certain forms of social scoring;
- certain systems used to predict criminal risk solely on the basis of profiling;
- certain facial recognition databases created through untargeted scraping of images;
- certain emotion recognition systems;
- certain biometric categorisation systems using sensitive personal data;
- certain uses of real-time remote biometric identification systems in publicly accessible spaces.
Organisations must ensure that none of the AI systems they develop, market or use fall within one of these prohibited categories.
AI Literacy
Article 4 requires providers and deployers to take appropriate measures to ensure a sufficient level of AI literacy among individuals using AI systems on their behalf.
These measures should be tailored to:
- the users' roles;
- their technical knowledge;
- the AI systems they use;
- the associated risks;
- the individuals or groups likely to be affected.
A general awareness session alone will therefore not always be sufficient. AI literacy programmes should reflect the actual AI systems used within the organisation.
2 August 2025: General-Purpose AI Models and Governance
Since 2 August 2025, the provisions relating to General-Purpose AI (GPAI) models have applied to newly placed models.
Providers must notably:
- prepare technical documentation;
- provide downstream providers with sufficient information;
- implement a copyright compliance policy;
- publish a sufficiently detailed summary of the training data where required by the Regulation;
- cooperate with competent authorities.
Models presenting systemic risks are subject to additional obligations, particularly regarding evaluation, cybersecurity and risk management.
This date also marks the application of the provisions governing:
- the European AI Office;
- national competent authorities;
- the European Artificial Intelligence Board;
- market surveillance mechanisms;
- the AI Act's enforcement and sanctions framework.
2 August 2026: Most AI Act Provisions Become Applicable
2 August 2026 is the AI Act's main implementation milestone.
The majority of the Regulation's provisions become applicable.
These include, in particular:
- the general obligations applicable to providers;
- obligations applicable to importers and distributors;
- several transparency obligations laid down in Article 50;
- market surveillance powers.
Transparency Obligations
Providers of AI systems intended to interact directly with natural persons must inform individuals that they are interacting with an AI system, unless this is obvious from the context.
Deployers using AI systems that generate deepfakes must disclose that the content has been artificially generated or manipulated, unless one of the exceptions provided for by the Regulation applies.
Users of certain emotion recognition systems and biometric categorisation systems are also subject to specific transparency obligations.
Important: contrary to a widespread misconception, Article 50 has not been postponed until 2 December 2026. The main transparency obligations under Article 50 have applied since 2 August 2026.
2 December 2026: Machine-Readable Marking under Article 50(2)
Regulation (EU) 2026/1744 introduced an additional transitional period for one very specific obligation contained in Article 50.
This deadline concerns only Article 50(2).
Providers of certain AI systems generating synthetic content that had already been placed on the market must ensure that the content generated by their systems includes a machine-readable marking enabling it to be identified as artificially generated or manipulated.
The marking must be:
- effective;
- interoperable;
- robust;
- reliable;
- compatible with the state of the art.
It is important to distinguish between two separate obligations:
- providing visible information to users, applicable since 2 August 2026;
- the technical machine-readable marking requirement under Article 50(2), applicable from 2 December 2026 to certain AI systems already placed on the market.
2 August 2027: Existing GPAI Models and AI Regulatory Sandboxes
2 August 2027 marks two important milestones under the AI Act.
First, it is the end of the transitional period granted to General-Purpose AI (GPAI) models that were already placed on the market before 2 August 2025.
Second, it is the new deadline for Member States to establish at least one AI regulatory sandbox.
Compliance of Existing GPAI Models
Providers of GPAI models placed on the market before 2 August 2025 have until 2 August 2027 to comply with the new requirements of the AI Act.
They must notably:
- complete their technical documentation;
- provide downstream AI system providers with the necessary information;
- implement a copyright compliance policy;
- publish, where required, a sufficiently detailed summary of the training data;
- comply with the additional obligations applicable to GPAI models presenting systemic risks.
This transitional period enables providers to progressively bring their existing foundation models into compliance with the AI Act.
AI Regulatory Sandboxes
Regulation (EU) 2026/1744 also postponed the deadline applicable to Member States for establishing AI regulatory sandboxes.
Each Member State must establish at least one AI regulatory sandbox by 2 August 2027.
These sandboxes allow organisations—particularly SMEs and start-ups—to develop, test and validate innovative AI systems under the supervision of competent authorities within a controlled regulatory environment.
Their objectives include:
- fostering innovation;
- supporting organisations in achieving compliance;
- facilitating dialogue with supervisory authorities;
- enabling innovative AI systems to be tested before being placed on the market.
2 December 2027: High-Risk AI Systems under Annex III
Regulation (EU) 2026/1744 significantly revised the implementation timeline applicable to high-risk AI systems.
The first major deadline is now 2 December 2027.
It applies to high-risk AI systems falling under Article 6(2) of the AI Act, namely the systems listed in Annex III.
Annex III notably covers AI systems used in the following areas:
- biometrics;
- critical infrastructure;
- education and vocational training;
- employment, recruitment and worker management;
- access to essential public and private services;
- law enforcement;
- migration, asylum and border control;
- the administration of justice;
- democratic processes.
The organisations concerned must notably implement:
- a risk management system;
- data governance measures;
- technical documentation;
- automatic logging of events;
- appropriate human oversight;
- measures ensuring accuracy, robustness and cybersecurity;
- a quality management system;
- post-market monitoring;
- procedures for reporting serious incidents.
Deployers must also comply with several specific obligations, including:
- using the system in accordance with the provider's instructions;
- ensuring effective human oversight;
- retaining logs where they are under their control;
- reporting certain incidents to providers and competent authorities;
- carrying out a Fundamental Rights Impact Assessment (FRIA) where required.
2 August 2028: High-Risk AI Systems under Annex I
A second implementation milestone applies to high-risk AI systems falling under Article 6(1).
This deadline is set for 2 August 2028.
It concerns AI systems that are either safety components of products or products themselves covered by the EU harmonisation legislation listed in Annex I of the AI Act.
These notably include certain:
- medical devices;
- in vitro diagnostic medical devices;
- machinery;
- lifts;
- radio equipment;
- personal protective equipment;
- toys;
- civil aviation products;
- motor vehicles;
- other products subject to third-party conformity assessment before being placed on the market.
In these situations, the AI Act requirements must be coordinated with the sector-specific legislation already applicable to the product.
Manufacturers will notably have to coordinate:
- risk analysis;
- technical documentation;
- testing;
- conformity assessment procedures;
- post-market surveillance;
- incident management;
- interactions with notified bodies.
Why Has the Timeline Changed?
Regulation (EU) 2026/1744 simplified the original implementation schedule of the AI Act.
Earlier legislative proposals introduced a conditional trigger mechanism.
Under that approach, certain obligations applicable to high-risk AI systems would only have become applicable after harmonised standards, common specifications or other implementation tools became available.
This mechanism was ultimately abandoned in the final version of the Regulation.
Instead, the EU legislator adopted fixed implementation dates:
- 2 December 2027 for high-risk AI systems falling under Article 6(2) and Annex III;
- 2 August 2028 for high-risk AI systems falling under Article 6(1) and Annex I.
This approach provides greater legal certainty by giving organisations a clear and predictable compliance timetable.
2 August 2030: Certain High-Risk AI Systems Intended for Use by Public Authorities
Article 111 establishes a specific transitional regime for certain high-risk AI systems intended to be used by public authorities.
The AI systems concerned must comply with the applicable requirements by 2 August 2030.
This deadline is distinct from the one applicable to the large-scale information systems listed in Annex X.
31 December 2030: Large-Scale Information Systems (Annex X)
31 December 2030 is a separate implementation deadline.
It applies exclusively to the large-scale information systems of the European Union listed in Annex X of the AI Act.
These systems, already established under EU law in the fields of freedom, security and justice, benefit from a dedicated transitional regime.
It would therefore be inaccurate to describe this date as the general compliance deadline for all AI systems used by public authorities.
How to Prepare for AI Act Compliance
The phased implementation schedule should not encourage organisations to wait until each deadline approaches.
Achieving compliance with the AI Act requires several months of preparation.
The main steps include:
- inventory all AI systems developed, deployed or used;
- identify the organisation's regulatory role (provider, deployer, importer, distributor or authorised representative);
- classify each AI system under the AI Act;
- identify systems falling under Annex III or Annex I;
- establish AI governance processes;
- document compliance assessments;
- train employees in accordance with Article 4;
- monitor implementing acts, guidelines, harmonised standards and regulatory developments.
Maintaining an effective regulatory watch is essential. Regulation (EU) 2026/1744 demonstrates that the AI Act implementation schedule may evolve to address operational needs identified by organisations and supervisory authorities.
Managing AI Act Compliance with Dastra
An AI governance platform such as Dastra helps organisations structure and centralise their AI Act compliance programme.
It enables organisations to:
- maintain a central inventory of AI systems;
- document AI use cases;
- identify the roles of all relevant stakeholders;
- classify AI systems under the AI Act;
- distinguish between systems falling under Annex I, Annex III or the GPAI regime;
- document conformity assessments;
- manage action plans;
- assign responsibilities;
- retain evidence of compliance;
- monitor regulatory deadlines;
- keep track of developments in the European AI regulatory framework.
Complying with the AI Act is not simply about meeting a series of regulatory deadlines. It requires establishing a sustainable AI governance framework capable of evolving alongside AI technologies, organisational practices and the European regulatory landscape.
