Timeline
What are the EU AI Act deadlines?
The Act did not arrive on one date. It arrived in stages, and the largest stage is now.
Short answer
Regulation (EU) 2024/1689 entered into force on 1 August 2024. Prohibited practices and the AI literacy obligation applied from 2 February 2025. Obligations for general-purpose AI models, governance bodies and penalties applied from 2 August 2025. The Regulation applies generally, including Article 50 transparency duties, from 2 August 2026. Regulation (EU) 2026/1744, the Digital Omnibus on AI, then fixed the high-risk dates: Article 6(2) and Annex III systems from 2 December 2027, and Article 6(1) and Annex I product-embedded systems from 2 August 2028.
Reviewed 2026-08-02. General information for governance planning, not legal advice.
Key points
- 1 August 2024 — Regulation entered into force
- 2 February 2025 — prohibited practices and AI literacy obligations applied
- 2 August 2025 — general-purpose AI, governance and penalty provisions applied
- 2 August 2026 — general application, including Article 50 transparency duties
- 2 December 2027 — Article 6(2) and Annex III high-risk obligations (Regulation (EU) 2026/1744)
- 2 August 2028 — Article 6(1) and Annex I product-embedded high-risk systems
- Legacy systems have their own transitional treatment under Article 111
Why the high-risk dates moved, and what did not move
The Annex III high-risk regime covers the use cases most organisations actually deploy: employment and worker management, access to essential services, creditworthiness, education, law enforcement and critical infrastructure. Those duties were originally due from 2 August 2026. Regulation (EU) 2026/1744 replaced that with fixed dates — 2 December 2027 for Article 6(2) and Annex III systems, and 2 August 2028 for Article 6(1) and Annex I systems — covering Chapter III, Sections 1 to 3 only.
Those obligations are not documentation-light. They require risk management, data governance, technical documentation, logging, human oversight, accuracy and robustness measures, and for deployers a set of use-side duties that must be evidenced continuously rather than once.
The transparency layer
Article 50 transparency duties also bite at full application. Where people interact with an AI system, where content is synthetically generated or manipulated, or where emotion recognition or biometric categorisation is used, disclosure obligations apply. These are often the cheapest obligations to meet and the most visible to fail.
What to have in place before the date
- A complete inventory, including AI embedded in vendor products
- A recorded role determination for each system
- Classification decisions with reasoning that can be reproduced
- Prohibited-practice screening completed and documented
- Transparency measures implemented where Article 50 applies
- Named owners, oversight arrangements and an audit trail
Frequently asked questions
- What happens on 2 August 2026?
- The Regulation applies in full, including the Annex III high-risk obligations, so organisations deploying AI in areas such as employment, credit, education, essential services and critical infrastructure become subject to the full high-risk regime.
- Do existing systems get an exemption?
- Not a blanket one. Article 111 provides transitional treatment for certain systems placed on the market before the relevant dates, but significant changes in design can bring a legacy system back into scope, so the position must be assessed system by system.
- Are prohibitions already in force?
- Yes. The prohibited-practice provisions applied from 2 February 2025, alongside the AI literacy obligation in Article 4.
Primary sources
How AIRAS Cloud supports this
Related answers
Turn the regulation into an operating record
AIRAS Cloud gives Irish and EU organisations one accountable place to discover AI, determine scope, classify defensibly, assign controls and evidence every decision.
No commercial commitment. No confidential information required.