Skip to content

EU AI Act Deadlines: What Applies From When

9 min read · updated August 4, 2026

The AI Act entered into force on 1 August 2024 and applies in stages set out in Article 113. Prohibitions and AI literacy came first, general-purpose model rules second, the bulk of the Act next, and the product-embedded high-risk rules last.

Information, not legal advice. Reviewed 4 August 2026. The dates below are those in Article 113 of Regulation (EU) 2024/1689 as originally adopted. In November 2025 the Commission proposed a package amending several of them; as at this review date that proposal had not been adopted, so the original dates remain the law. This is the single fastest-moving page in this cluster — verify against EUR-Lex before acting on any date here.

The dates, and what each switches on

DateDescription
1 August 2024Entry into force. Nothing yet applies; the clock starts.
2 February 2025Chapter I and Chapter II apply. That is the general provisions — including the Article 4 AI literacy duty and the Article 3 definitions — and the Article 5 prohibited practices. In force now.
2 August 2025General-purpose model obligations (Chapter V), the governance structure (Chapter VII, which includes the AI Office and the AI Board), notifying authorities, confidentiality, and most of the penalties chapter. Member States were also to have designated their national competent authorities by this date.
2 August 2026General application. Annex III high-risk obligations, Article 50 transparency duties, deployer obligations, the EU database registration duties, and the penalty provisions for general-purpose model providers. This is the big one for ordinary software.
2 August 2027Article 6(1) — high-risk classification for AI that is a safety component of, or is itself, a product covered by the Annex I harmonisation legislation — and the obligations that follow. Also the compliance deadline for general-purpose models already on the market before 2 August 2025.
31 December 2030The outer deadline for bringing large-scale EU IT systems listed in Annex X into conformity, where they were placed on the market before August 2027.

Where the dates come from

Article 113 is one paragraph plus three lettered derogations. The paragraph sets general application at 24 months from entry into force. The derogations pull some chapters earlier (6 months for Chapters I and II, 12 months for Chapter V and the governance and penalty provisions) and push one later (36 months for Article 6(1)).

That structure explains an ordering that otherwise looks arbitrary: rules that need no infrastructure to enforce come first, rules that need notified bodies and harmonised standards come last. It also explains why the general-purpose model rules landed a year before the high-risk rules they feed into — downstream providers need the documentation before they can write their own.

One detail that trips people up: the penalties for general-purpose model providers are in a different article from the general penalties and were carved out of the August 2025 tranche. The obligations applied from August 2025; the Commission’s power to fine for breaching them arrived with general application in August 2026.

The dates that are contested

This section exists because a page that prints one date as settled when it is under amendment is worse than a page that admits the uncertainty.

In November 2025 the Commission presented a digital simplification package that included amendments to the AI Act. The relevant part proposed to delay the application of the high-risk obligations, tying the start date to the availability of harmonised standards and support tools rather than to a fixed calendar date, and proposed easements in registration and documentation for some categories. As at this page’s review date, that was a Commission proposal moving through the ordinary legislative procedure with the Parliament and Council — not law, and not certain to pass in the form proposed.

So the honest position for planning purposes is this. The February 2025 and August 2025 tranches are in force and are not in play. The August 2026 general application date is in force. The high-risk phase-in is the part that has been proposed for change, and the direction of any change is later rather than earlier. Do not build a programme that depends on a delay arriving.

Systems already on the market

The transitional provisions in Article 111 are the most commercially useful part of the timetable and the least reported.

  • High-risk systems placed on the market before general application are caught only if they are subsequently subject to significant changes in their design. A system frozen in place largely escapes; a system you keep improving does not. In practice this makes “what counts as a significant change in design?” a question your change-management process has to be able to answer with evidence.
  • Systems used by public authorities get no such relief on the same terms — the Act sets a separate compliance deadline for high-risk systems intended for use by public authorities.
  • General-purpose models placed on the market before 2 August 2025 have until 2 August 2027 to comply. This is why the documentation available for older model families is thinner than for new releases, and why a model card that predates mid-2025 may not contain what you need for your own file.

Who can enforce, and from when

An obligation applying is not the same as somebody being able to act on it, and the gap between the two is what makes the middle of the timetable confusing. Three different bodies matter and they arrived at different times.

BodyDescription
National market surveillance authoritiesDesignated by each Member State, with the designation due by 2 August 2025. They supervise AI systems placed on their market, can require information, test systems, order withdrawal, and impose the penalties in Article 99. Their powers over most obligations bite from general application in August 2026.
The Commission, through the AI OfficeExclusive supervision of general-purpose AI model providers. Obligations applied from August 2025; the Commission's power to fine those providers arrived with general application in August 2026, so the first year of the general-purpose regime was supervision without a penalty.
Existing sectoral and data protection authoritiesUnchanged, and already able to act. A data protection authority did not need the AI Act to look at an AI system processing personal data, and in most Member States it is the authority with the enforcement record. For the first years of the Act this is the enforcement risk that is actually live.

Two further mechanisms are worth knowing about because they do not depend on a regulator deciding to open a case. Any natural or legal person may lodge a complaint with a market surveillance authority under Article 85, and a person affected by a decision taken on the basis of a high-risk system’s output that produces legal or similarly significant adverse effects has a right to an explanation under Article 86. Complaints and explanation requests are how most of these files will actually open.

Why the standards timetable matters

Compliance with a harmonised standard whose reference is published in the Official Journal gives a presumption of conformity with the corresponding requirements. Without those standards, a provider has to demonstrate conformity directly against Articles 8 to 15, which is slower, more expensive and much harder to defend.

The standards are being drafted by CEN-CENELEC Joint Technical Committee 21. Their delivery has run behind the legislative timetable, and that gap is the substantive reason behind the proposed delay described above. Note the corollary, because it is widely misunderstood: an ISO/IEC 42001 certificate is not a harmonised standard and does not give a presumption of conformity with anything in the AI Act. It is useful evidence of a management system. It is not a conformity assessment.

What to do in which order

  1. Inventory first. You cannot classify what you have not listed. Every AI system in use, including the ones bought on a corporate card by one team.
  2. Screen for Article 5. This is already law and has the highest penalty. Emotion inference in the workplace is the one most likely to be running without anyone having noticed.
  3. Record your role per system. Provider or deployer, with reasons. The definitions decide every other obligation and getting this wrong wastes the whole programme.
  4. Evidence AI literacy. Cheap, already in force, and the easiest thing for an authority to ask about first.
  5. Classify against Annex III, and where you conclude a system is out under Article 6(3), write the assessment down. The documented negative is itself an obligation.
  6. Then build the technical file, for whatever remains high-risk. This is the expensive part and it is the last part.