Regulationtimelineenforcementdeadlines

EU AI Act Timeline: Key Dates from 2024 to 2028

Complete timeline of EU AI Act enforcement milestones — from entry into force in August 2024 to the deferred high-risk deadlines of December 2027 and August 2028 under the Digital Omnibus on AI. Know exactly when each requirement applies.

January 20, 2025Updated August 4, 202619 min read

The EU AI Act (Regulation 2024/1689) does not apply all at once. Instead, the European Union designed a phased enforcement schedule that gives organisations time to prepare for increasingly stringent requirements. Understanding this timeline is critical for prioritising compliance efforts and allocating resources effectively.

This article provides a comprehensive, date-by-date breakdown of every major enforcement milestone from the regulation's entry into force through full application. The schedule was amended for the first time in July 2026, and the dates below reflect the amended text.

What Changed in July 2026

Regulation (EU) 2026/1744 (the "Digital Omnibus on AI") entered into force on 27 July 2026. It defers the high-risk regime in Chapter III, Sections 1 to 3. Stand-alone high-risk systems under Article 6(2) and Annex III now apply from 2 December 2027 (previously 2 August 2026). Product-embedded high-risk systems under Article 6(1) and Annex I now apply from 2 August 2028 (previously 2 August 2027). National regulatory sandboxes under Article 57 must be operational by 2 August 2027 (previously 2 August 2026).

Regulation (EU) 2026/1744 is the first amendment to the AI Act. It was adopted on 8 July 2026, published in the Official Journal on 24 July 2026 and entered into force on the third day thereafter.

The deferral is unconditional. The Commission's original proposal would have tied the new dates to a decision confirming that harmonised standards were available — a "stop-the-clock" mechanism — but the co-legislators dropped it. There is no standards-readiness trigger in the adopted text and no further automatic delay built into it.

Just as important is what did not move. 2 August 2026 remained the general application date. The second paragraph of Article 113 was not amended, and the Commission's AI Office and national authorities began enforcing the AI Act on that date. The Article 50 transparency obligations — chatbot disclosure, deepfake labelling and machine-readable marking of synthetic content — are in force now, as is Article 49 registration. The Article 5 prohibitions have applied since 2 February 2025 and are unchanged, and the Article 99 penalty ceilings are untouched.

Two additions take effect on 2 December 2026. New Articles 5(1)(ba) and 5(1)(bb) prohibit AI systems that generate or manipulate realistic non-consensual intimate imagery of an identifiable person, and AI systems that generate or manipulate child sexual abuse material. Separately, a new grace period in Article 111(4) gives generative AI systems placed on the market before 2 August 2026 until 2 December 2026 to meet the machine-readable marking duty in Article 50(2).

The Complete Enforcement Timeline

Phase 1: Entry into Force and Preparation (August 2024 - January 2025)

The period between 1 August 2024 and 2 February 2025 served as the initial preparation window. While no substantive obligations were yet enforceable during this phase, several important processes began.

Establishing Governance Bodies

The European Commission began the process of establishing the AI Office, which sits within the Commission's Directorate-General for Communications Networks, Content and Technology (DG CONNECT). The AI Office is responsible for overseeing general-purpose AI models and supporting consistent application of the regulation across Member States.

AI Literacy Obligation

Article 4 of the AI Act requires providers and deployers to ensure that their staff and other persons dealing with the operation and use of AI systems have a sufficient level of AI literacy. Organisations were encouraged to begin training programmes during this preparatory phase.

Article 4 was rewritten and softened by Regulation (EU) 2026/1744. It is best read as a proportionate expectation rather than a hard, audited duty: more complex or higher-risk uses call for deeper literacy, but the amended text no longer frames this as a prescriptive obligation.

Phase 2: Prohibited Practices (February 2025)

The first substantive enforcement date was 2 February 2025, when the prohibitions in Article 5 became applicable. This was the most urgent deadline because violations carry the highest penalties.

What Was Banned

From 2 February 2025, the following AI practices became prohibited:

Subliminal, manipulative, and deceptive techniques (Article 5(1)(a)): AI systems that deploy techniques beyond a person's consciousness, or purposefully manipulative or deceptive techniques, to materially distort behaviour and cause significant harm.

Exploitation of vulnerabilities (Article 5(1)(b)): AI systems that exploit vulnerabilities of individuals due to their age, disability, or specific social or economic situation to materially distort their behaviour and cause significant harm.

Social scoring (Article 5(1)(c)): AI systems used by public authorities or on their behalf to evaluate or classify natural persons based on social behaviour or personal characteristics, leading to detrimental treatment that is unjustified or disproportionate.

Individual risk assessment for criminal offences (Article 5(1)(d)): AI systems that assess the risk of natural persons committing criminal offences based solely on profiling or personality traits, unless used to augment human assessments based on objective, verifiable facts directly linked to criminal activity.

Untargeted scraping for facial recognition databases (Article 5(1)(e)): AI systems that create or expand facial recognition databases through untargeted scraping of facial images from the internet or CCTV footage.

Emotion recognition in workplaces and education (Article 5(1)(f)): AI systems that infer emotions in the workplace and educational institutions, except where the AI system is intended for medical or safety reasons.

Biometric categorisation for sensitive attributes (Article 5(1)(g)): AI systems that categorise natural persons based on biometric data to deduce race, political opinions, trade union membership, religious or philosophical beliefs, sex life, or sexual orientation, with limited exceptions for law enforcement.

Real-time remote biometric identification in public spaces (Article 5(1)(h)): Real-time remote biometric identification systems used in publicly accessible spaces for law enforcement purposes, with narrow exceptions for targeted searches related to serious crimes, imminent threats, or terrorist attacks.

Compliance Actions Required

Organisations needed to audit their AI systems before this date and discontinue any prohibited practices. There was no grace period — as of 2 February 2025, non-compliance with Article 5 carried penalties of up to 35 million EUR or 7% of worldwide annual turnover. Those penalty levels are unchanged and now also cover the two prohibitions added with effect from 2 December 2026.

Need auditable AI for compliance?

Ctrl AI provides full execution traces, expert verification, and trust-tagged outputs for every AI decision.

Learn About Ctrl AI

Phase 3: GPAI and Governance (August 2025)

The next major milestone was 2 August 2025, when obligations for general-purpose AI (GPAI) models and the governance framework took effect. Chapter V was not substantively amended by the Digital Omnibus on AI, so these obligations stand as enacted.

General-Purpose AI Model Obligations

Chapter V of the AI Act establishes requirements for all GPAI models. From 2 August 2025, providers of GPAI models must:

Maintain technical documentation (Article 53(1)(a)): Providers must draw up and keep up to date technical documentation of the model, including its training and testing process and results, which must be made available to the AI Office and national competent authorities upon request.

Provide information to downstream providers (Article 53(1)(b)): When a GPAI model is integrated into an AI system, the GPAI provider must supply sufficient information and documentation to enable the downstream AI system provider to understand the model's capabilities and limitations and comply with their own obligations.

Comply with copyright rules (Article 53(1)(c)): GPAI providers must put in place a policy to comply with Union copyright law, in particular to identify and respect reservations of rights expressed by rights holders under Article 4(3) of the Copyright Directive.

Publish training data summary (Article 53(1)(d)): Providers must draw up and make publicly available a sufficiently detailed summary about the content used for training the GPAI model, following a template provided by the AI Office.

Models placed on the market before 2 August 2025 have until 2 August 2027 to be brought into compliance under Article 111(3). That transitional period was not amended.

GPAI Models with Systemic Risk

GPAI models that are classified as presenting systemic risk under Article 51 — including models trained with more than 10^25 cumulative FLOP of training compute — face additional obligations from this date:

  • Perform model evaluations, including adversarial testing
  • Assess and mitigate systemic risks
  • Track and report serious incidents to the AI Office and relevant national competent authorities
  • Ensure adequate cybersecurity protections

The 10^25 FLOP threshold in Article 51(2) remains in place. No delegated act has changed it.

Governance Framework

Several governance provisions also took effect on 2 August 2025:

  • The European Artificial Intelligence Board (Article 65) became operational, with representatives from each Member State.
  • Member States must designate national competent authorities (Article 70), including at least one notifying authority and one market surveillance authority.
  • The Advisory Forum (Article 67) was established to provide stakeholder expertise.

Phase 4: General Application and Enforcement (August 2026)

2 August 2026 remained the general application date. The Digital Omnibus on AI did not touch the second paragraph of Article 113, and the AI Office and national authorities began enforcing the AI Act on that date.

Transparency Obligations Are Live Now

Article 50 transparency obligations sit in Chapter IV, outside the deferred Chapter III sections, and apply from 2 August 2026. They require that:

  • AI systems intended to interact directly with persons must disclose that the person is interacting with an AI system
  • Providers of AI systems that generate synthetic content (including deepfakes) must mark the output in a machine-readable format
  • Deployers of emotion recognition or biometric categorisation systems must inform the persons exposed

This is the obligation with immediate practical bite for most organisations. Chatbots, generative content tools and synthetic media pipelines are in scope today, and breaches attract fines of up to 15 million EUR or 3% of worldwide annual turnover under Article 99.

Registration and Market Surveillance

Article 49 registration duties also apply from 2 August 2026: they sit in Chapter III, Section 5, outside the Sections 1 to 3 deferral. The market surveillance framework in Chapter IX applies from the same date, as does Article 6(5), which is expressly carved out of the deferral.

The deferral is narrow and specific. It covers Chapter III, Sections 1 to 3 — the classification rules, the requirements in Articles 8 to 15, and the provider and deployer obligations in Articles 16 to 27 — with Article 6(5) carved out. Everything else that fell due on 2 August 2026 fell due on 2 August 2026.

Phase 5: New Prohibitions and the Marking Grace Period (December 2026)

Two things happen on 2 December 2026.

First, the two prohibitions added by Regulation (EU) 2026/1744 become applicable. Article 5(1)(ba) prohibits AI systems that generate or manipulate realistic intimate imagery of an identifiable person without their consent. Article 5(1)(bb) prohibits AI systems that generate or manipulate child sexual abuse material. Scoping for both sits in the new Article 5(1a) and 5(1b). Both carry the Article 5 penalty ceiling of 35 million EUR or 7% of worldwide annual turnover.

Second, the transitional window in the new Article 111(4) closes. Generative AI systems placed on the market before 2 August 2026 must meet the machine-readable marking duty in Article 50(2) by this date. Systems placed on the market on or after 2 August 2026 had no such grace period.

Note that the Commission guidelines on prohibited practices of 4 February 2025 remain the operative Article 5 guidance and do not yet address the two new prohibitions.

Phase 6: Sandboxes and Legacy GPAI (August 2027)

Regulatory Sandboxes

Under Article 57, each Member State must establish at least one AI regulatory sandbox at national level. Regulation (EU) 2026/1744 moved this deadline from 2 August 2026 to 2 August 2027. Sandboxes provide a controlled testing environment where innovative AI systems can be developed and validated with regulatory oversight.

Legacy General-Purpose AI Models

The same date is the compliance deadline for GPAI models placed on the market before 2 August 2025, under Article 111(3). This provision was not amended.

Phase 7: Annex III High-Risk Systems (December 2027)

2 December 2027 is now the operative deadline for the majority of organisations affected by the high-risk regime. From this date, Chapter III, Sections 1 to 3 apply to AI systems classified as high-risk under Article 6(2) and Annex III — the stand-alone use cases.

High-Risk AI System Requirements

Providers of Annex III high-risk AI systems must comply with all requirements under Articles 8 through 15:

  • Risk management system (Article 9)
  • Data and data governance (Article 10)
  • Technical documentation (Article 11)
  • Record-keeping and logging (Article 12)
  • Transparency and provision of information (Article 13)
  • Human oversight (Article 14)
  • Accuracy, robustness, and cybersecurity (Article 15)

Deployer Obligations

Deployers of high-risk AI systems must also comply from this date. Under Article 26, deployers must:

  • Use AI systems in accordance with instructions
  • Ensure human oversight by trained individuals
  • Monitor the operation of the AI system
  • Keep logs generated by the AI system for the prescribed period
  • Inform workers and their representatives about high-risk AI system use
  • Conduct fundamental rights impact assessments (for public bodies and certain private entities under Article 27)

Annex III itself was not amended by the Digital Omnibus on AI. The eight use-case headings stand as enacted, and no delegated act under Article 7 has been adopted.

Organisations that are providers or deployers of high-risk AI systems listed in Annex III — covering areas such as employment, credit scoring, education, critical infrastructure, and law enforcement — must be fully compliant by 2 December 2027. Non-compliance carries fines of up to 15 million EUR or 3% of global turnover. The extra sixteen months are preparation time, not a reprieve: no harmonised standard has yet been cited in the Official Journal, so conformity work cannot simply be outsourced to a standard that does not yet exist.

Phase 8: Annex I High-Risk Systems (August 2028)

The final enforcement date is 2 August 2028, when Chapter III, Sections 1 to 3 apply to high-risk AI systems that serve as safety components of products already regulated under the EU harmonisation legislation listed in Annex I. These include products governed by:

  • Regulation (EU) 2017/745 — Medical devices
  • Regulation (EU) 2017/746 — In vitro diagnostic medical devices
  • Directive 2006/42/EC / Regulation (EU) 2023/1230 — Machinery
  • Directive 2009/48/EC — Safety of toys
  • Directive 2014/33/EU — Lifts
  • Directive 2014/34/EU — Equipment for use in explosive atmospheres
  • Directive 2014/53/EU — Radio equipment
  • Regulation (EU) 2024/1252 — Critical raw materials (relevant products)

For these systems, the existing conformity assessment procedures under sectoral legislation will integrate AI Act requirements. Note that Regulation (EU) 2026/1744 amended Annex I itself: machinery moved from Section A to Section B.

Conformity Assessment and Notified Bodies

Notified bodies are organisations designated by Member States to carry out conformity assessments for certain high-risk AI systems where a third-party assessment is required. The new Article 43(3) sets an intermediate deadline: bodies already notified under the sectoral legislation in Annex I, Section A must apply for designation under Chapter III, Section 4 of the AI Act by 28 January 2028.

Building Your Compliance Roadmap

Given the phased timeline, organisations should take a structured approach to compliance. The priorities below are sequenced against the amended dates, with enforcement of the general regime already under way.

Immediate Priorities

  • Verify that no prohibited AI practices remain in operation
  • Bring Article 50 transparency measures into effect now — chatbot disclosure, deepfake labelling and machine-readable marking of synthetic output are enforceable today
  • Confirm that Article 49 registration duties are met where they apply
  • Complete an inventory of all AI systems and classify their risk level, so that the December 2027 scope is known rather than guessed at

Before December 2026

  • Check that no system in the estate falls within the new Article 5(1)(ba) or 5(1)(bb) prohibitions
  • Retrofit machine-readable marking under Article 50(2) to generative AI systems placed on the market before 2 August 2026, before the Article 111(4) grace period expires

Before December 2027

  • Implement the full set of requirements for Annex III high-risk AI systems under Articles 8 to 15
  • Establish or update quality management systems
  • Prepare deployer obligations including fundamental rights impact assessments
  • Track the progress of harmonised standards under standardisation request M/613, which runs to 28 February 2027

Before August 2028

  • Integrate AI Act requirements into sectoral conformity assessment procedures for Annex I products
  • Engage with notified bodies for third-party assessments where required, bearing in mind the 28 January 2028 designation application deadline
  • Ensure all remaining product safety AI systems are fully compliant

The phased timeline is designed to give organisations adequate preparation time, and the July 2026 amendment extended part of it. But the extension applies to one specific block of obligations. Organisations that treat compliance as a strategic priority rather than a last-minute exercise will be better positioned to navigate the transition smoothly and maintain a competitive advantage.

Conclusion

The EU AI Act's enforcement timeline now spans four years, from its entry into force on 1 August 2024 to the final high-risk deadline on 2 August 2028. Each phase introduces new obligations, and the cumulative effect is a comprehensive regulatory framework that will shape how AI is developed and deployed across Europe and beyond.

Two facts should anchor any planning exercise. The regulation is being enforced today: the general application date of 2 August 2026 held, and the Article 50 transparency obligations bite now. And the high-risk regime under Annex III is roughly sixteen months away, on 2 December 2027, with the Annex I regime following on 2 August 2028. Neither date is conditional on anything.

The timeline is not just a series of deadlines — it is a roadmap. Organisations that follow it systematically will not only avoid penalties but will build the governance structures needed for responsible and trustworthy AI deployment.

Make Your AI Auditable and Compliant

Ctrl AI provides expert-verified reasoning units with full execution traces — the infrastructure you need for EU AI Act compliance.

Explore Ctrl AI

Related Articles