Reglog

← Guides & analysis

EU AI Act timeline: every deadline from 2025 to 2027

· 4 min read

The EU AI Act entered into force on 1 August 2024, but almost none of its obligations applied that day. The Act phases in over roughly three years, so the practical question — which rules apply to us right now? — has a moving answer. Here is the schedule, and what each milestone means.

This is an information service to help you plan, not legal advice. For the obligations tied to your own AI use, see which apply to your company.

Update (18 July 2026): The Digital Omnibus on AI — now Regulation (EU) 2026/1744, in force since 27 July 2026 — postponed the high-risk obligations. Stand-alone Annex III systems now apply from 2 December 2027 (not 2 August 2026), and embedded Annex I products from 2 August 2028 (not 2 August 2027). The transparency and prohibition duties were not deferred. The dates below reflect this change; see what the Digital Omnibus changed for the detail.

1 August 2024 — entry into force

The clock starts. Nothing substantive applies yet, but every later date counts from here.

2 February 2025 — prohibitions and AI literacy

The first rules with teeth. The bans on unacceptable-risk practices (Article 5) begin to apply, and organisations must ensure an adequate level of AI literacy among staff who deal with AI systems on their behalf. If you operate anything that could fall under the prohibited list, this was your deadline.

2 August 2025 — GPAI, governance, and penalties

Obligations for general-purpose AI (GPAI) models start to apply — the rules for foundation-model providers, with stricter duties for models that pose systemic risk. The Act's governance framework (the bodies that enforce it) and much of the penalties regime also take effect from this date.

2 August 2026 — transparency and the original high-risk date

Originally the largest tranche of the Act. The transparency duties for limited-risk systems (chatbots and AI-generated content — Article 50) apply from here, and were not touched by the Digital Omnibus. This was also the original date for the high-risk Annex III obligations — but that part has since moved (see below). So 2 August 2026 still bites for transparency and for the prohibitions already in force; it no longer carries the high-risk stack.

2 December 2027 — high-risk systems (Annex III)

The date the Digital Omnibus set for the substantive high-risk obligations on stand-alone Annex III systems — those used in employment and worker management, access to essential public and private services, creditworthiness, biometric identification, education, and law enforcement. Risk management, data governance, technical documentation, human oversight, conformity assessment, and registration all attach here. For most high-risk companies, this is now the deadline that matters.

2 August 2028 — high-risk products (Annex I)

The final major step. Obligations apply to high-risk AI that is a safety component of products already regulated under the EU's product-safety laws (Annex I) — for example, AI embedded in medical devices, machinery, and other regulated products. The Digital Omnibus moved this from 2 August 2027; it keeps the longest runway because these systems sit inside existing certification regimes.

What this means for planning

  • The answer to "which rules apply" changes over time — and the dates themselves move. A system that carries no obligations today may be squarely in scope later, and, as the Digital Omnibus just showed, published deadlines can shift.
  • Run two clocks. Transparency and prohibition duties land on 2 August 2026; the high-risk stack now lands on 2 December 2027 (Annex III) or 2 August 2028 (Annex I). Plan them separately — the high-risk delay is not a delay of your transparency duties.
  • Don't wait for your tier to "switch on." Risk management, documentation, and human-oversight processes are built over months, not weeks — the extra runway to 2027 is time to use, not a reprieve.

To turn this calendar into your calendar: answer three questions about your AI use and we will show you the verified obligations that apply, sorted by the deadline you need to hit first. Deadlines move and authorities issue guidance — join the waitlist to be told when something that affects you changes.

The official text and dates are in Regulation (EU) 2024/1689. Always confirm specifics against the official source before you act.

Frequently asked questions

When did the EU AI Act enter into force?

The AI Act (Regulation (EU) 2024/1689) entered into force on 1 August 2024. Its obligations then apply in phases rather than all at once, mostly between February 2025 and August 2027.

What is the most important EU AI Act deadline for most companies?

It depends on your AI. The Digital Omnibus on AI moved the high-risk obligations for Annex III systems to 2 December 2027. But the Article 50 transparency duties — chatbot disclosure and marking of AI-generated content — were not deferred and still apply from 2 August 2026, along with the prohibitions already in force. So 2 August 2026 still matters for transparency and prohibited practices, while high-risk now runs to December 2027.

What changes on 2 February 2025?

The prohibitions on unacceptable-risk AI practices begin to apply, along with the AI literacy obligations. This was the first set of AI Act rules to take effect.

See which obligations apply to your company → or join the waitlist

This is an information service, not legal advice.