Skip to content
Deadlines

EU AI Act Deadlines: The Full Compliance Timeline

Updated 9 August 2026 8 min read

The EU AI Act (Regulation (EU) 2024/1689) does not switch on all at once. Article 113 phases its obligations in over roughly four years, so which rules bind you depends on today's date and the kind of AI you build or use. Three of the six milestones have already passed — the Article 5 bans, the GPAI duties and the Article 50 transparency duties are live law today, not upcoming deadlines. This guide lays out every milestone, which ones already bind you, and what is still ahead. Remember the Act is extraterritorial — it can reach you if your AI system, or its output, is used in the EU, wherever you are based.

How the phased timeline works

The Act entered into force in 2024, but its substantive obligations apply on staggered dates set by Article 113, as amended by the 2026 Digital Omnibus. There are six milestones:

DateWhat appliesStatus
2 February 2025Prohibited practices (Art. 5) and AI literacy (Art. 4)In force
2 August 2025General-purpose AI (GPAI) model obligations, governance and penaltiesIn force
2 August 2026Article 50 transparency obligationsIn force
2 December 2026End of the Art. 50(2) content-marking transition for systems already on the marketUpcoming
2 December 2027High-risk obligations for stand-alone Annex III systemsUpcoming
2 August 2028High-risk obligations for AI embedded in regulated products (Annex I)Upcoming

The first three are live law. If you are not compliant with them, you are not preparing for a deadline — you are already exposed. The sections below break each one down. Run the free risk checker first to find out which tier you fall in.

2 February 2025 — prohibited practices & AI literacy

The first obligations to bite. From this date:

What to do before this date: Audit your AI uses against the Article 5 ban list and stop anything that falls foul of it — breaches here carry the heaviest fines. In parallel, stand up an AI literacy programme with training records, since that duty has no risk-tier or size threshold and reaches every organisation using AI.

2 August 2025 — GPAI models, governance & penalties

From this date:

  • The general-purpose AI (GPAI) model obligations apply — technical documentation, downstream information, a copyright-compliance policy and a training-data summary, with extra duties for GPAI with systemic risk.
  • The Act's governance structures and penalties provisions become operational.

What to do before this date: If you develop GPAI models, have your technical documentation, copyright policy and training-content summary ready as living artefacts. If you merely build on someone else's model, confirm your upstream provider will supply the information you need as a downstream provider.

2 August 2026 — Article 50 transparency (in force)

This date has passed: the Article 50 transparency obligations are enforceable law today.

  • AI systems that interact with people must disclose that they are AI (Art. 50(1)).
  • Providers of systems generating synthetic audio, image, video or text must mark those outputs machine-readably (Art. 50(2)).
  • People exposed to emotion recognition or biometric categorisation must be informed (Art. 50(3)).
  • Deepfakes must carry a visible disclosure (Art. 50(4)).

The same date activated the Commission's enforcement powers for general-purpose AI under Article 101. Note that the Digital Omnibus did not move this date — it moved the high-risk dates, and a common misreading is that everything slipped with them.

What to do now: Inventory every user-facing AI touchpoint — chatbots, generated media, emotion or biometric features — and check each disclosure is actually shipped rather than planned. The Article 50 readiness checker turns seven questions into your duty list.

2 December 2026 — the content-marking transition closes

The one transitional relief inside Article 50. Generative systems that were already on the market before 2 August 2026 were given until 2 December 2026 to implement machine-readable marking of synthetic output under Art. 50(2). Nothing else in Article 50 waited — chatbot disclosure, deepfake labelling and the emotion-recognition notice all applied immediately.

What to do before this date: Decide your marking approach — C2PA content credentials, watermarking, or both — and get it into the generation pipeline rather than bolted on afterwards. The content-marking guide walks through the options, and the watermark checker tells you whether a file you already ship carries provenance metadata.

2 December 2027 — high-risk (Annex III) obligations

From this date, the obligations for high-risk AI systems listed in Annex III apply in full — the provider duties in Articles 9-15 and the deployer duties in Article 26, supported by the Annex IV technical documentation. This date moved here from 2 August 2026 under the 2026 Digital Omnibus.

What to do before this date: If any of your systems fall under Annex III, this is the most demanding workstream and the one to start earliest. Build your risk-management system, data governance, logging, human oversight and technical documentation well ahead of the date — these cannot be assembled at the last minute.

2 August 2028 — high-risk AI inside regulated products (Annex I)

The genuinely final application date, and the one most timelines leave out. AI acting as a safety component of a product already covered by Union harmonisation legislation — the Annex I track, covering machinery, medical devices, lifts, toys, vehicles and the rest — inherits the high-risk obligations from this date under Article 6(1).

What to do before this date: If your AI ships inside a CE-marked product, align the AI Act work with the conformity assessment you already run under the sectoral regulation. The two regimes are meant to be assessed together, not documented twice.

What happens if you miss a deadline

Enforcement scales to the severity of the breach. Under Article 99, the penalties are:

  • Up to €35M or 7% of worldwide annual turnover for breaching the prohibited practices — whichever is higher.
  • Up to €15M or 3% for breaching other obligations.
  • Up to €7.5M or 1% for supplying incorrect, incomplete or misleading information.

Because the ban and the AI literacy duty came first and the prohibited-practice fines are the largest, the February 2025 milestone is the one to have addressed already. Everything after it rewards early, methodical preparation over deadline-driven scrambling.

Frequently asked questions

What are the key EU AI Act deadlines?

Six. 2 February 2025 (prohibited practices and AI literacy); 2 August 2025 (GPAI model obligations plus governance and penalties); 2 August 2026 (Article 50 transparency); 2 December 2026 (end of the Article 50(2) content-marking transition); 2 December 2027 (high-risk obligations for Annex III systems); and 2 August 2028 (high-risk AI embedded in regulated products under Annex I). The first three are already in force.

When do high-risk AI obligations apply?

In two waves. Stand-alone Annex III systems are caught from 2 December 2027, covering the provider duties in Articles 9-15 and the deployer duties in Article 26. AI embedded as a safety component in products already covered by Union harmonisation legislation (Annex I) follows on 2 August 2028.

Does the EU AI Act apply to organisations outside the EU?

Yes. The Act is extraterritorial: it can apply where an AI system or its output is used in the EU, regardless of where the provider or deployer is established.

Which deadline should I prioritise?

The ones that have already passed. The Article 5 ban, the Article 4 AI literacy duty, the GPAI obligations and the Article 50 transparency duties are all enforceable now, so a gap there is a live exposure rather than a planning item. Only once those are clean does it make sense to work backwards from 2 December 2027 and 2 August 2028.

Find your risk class in 2 minutes

Free, no sign-up. Deterministic — not a chatbot.

Run the free check

Still have questions about how this applies to you? Talk to us — we're happy to help.