Every deadline at a glance
The EU AI Act applies in stages between 2 February 2025 and 2 August 2030. Which stage binds you depends on what your AI system does, not on what sector you operate in or how large your organization is.
This is the single most common source of confusion about the Act. Coverage tends to talk about “the EU AI Act deadline” as though there were one date to prepare for. There is not. The Regulation entered into force on 1 August 2024 and Article 113 then switches on different chapters at different times, so a single organization running a customer chatbot, a CV-screening tool and a fine-tuned foundation model is working to three separate dates with three separate sets of obligations.
| Date | What applies | Who it binds | Status |
|---|---|---|---|
| 1 August 2024 | The Regulation enters into force | No operator obligations yet: this is the reference date only | In force |
| 2 February 2025 | Prohibited practices and AI literacy apply | All providers and deployers placing AI on the EU market or whose output is used in the EU | In force |
| 2 August 2025 | General-purpose AI model obligations apply | Providers of general-purpose AI models placed on the EU market | In force |
| 2 August 2026 | Transparency obligations and the general application date | Providers and deployers of AI systems that interact with people or generate synthetic content: chatbots, voice agents, generative image and video tools, and publishers of AI-written editorial content | In force |
| 2 December 2026 | Two new prohibitions and the legacy marking deadline | Providers and deployers of generative AI systems | Upcoming |
| 2 December 2027 | Annex III high-risk obligations apply | Providers, importers, distributors and deployers of high-risk AI systems listed in Annex III | Upcoming |
| 2 August 2028 | Annex I product-safety high-risk obligations apply | Manufacturers of products covered by the Annex I harmonisation legislation where an AI system is a safety component or is itself the product | Upcoming |
| 2 August 2030 | Legacy large-scale IT systems must comply | EU agencies and Member State authorities operating the Annex X large-scale IT systems | Upcoming |
Which deadline applies to you
Work down the questions below in order and stop at the first yes. That gives you the earliest date on which the Regulation binds you, though note the tiers are cumulative, so a system can be caught by more than one.
A high-risk CV-screening tool that also talks to candidates through a chatbot interface owes Article 50 transparency from 2 August 2026 and the full Chapter III regime from 2 December 2027. Answering yes at step three does not mean you can stop reading at step three.
Does the system do anything listed in Article 5?
Social scoring, untargeted facial image scraping, emotion inference at work or in education, subliminal or manipulative techniques, exploitation of vulnerability, individual predictive policing based on profiling alone, biometric categorisation inferring sensitive traits, real-time remote biometric identification in public spaces for law enforcement, and, from 2 December 2026, generating non-consensual intimate imagery or child sexual abuse material.
Do you provide a general-purpose AI model?
A model trained on broad data at scale that displays significant generality and can competently perform a wide range of distinct tasks, whether released open-weight or through an API.
Does the system interact with people or generate synthetic content?
Chatbots and voice agents, generative image, audio, video or text tools, deep fakes, emotion recognition and biometric categorisation systems.
Is the use case listed in Annex III?
Biometrics, critical infrastructure, education, employment and worker management, access to essential private and public services including credit scoring and life and health insurance pricing, law enforcement, migration and border control, and administration of justice.
Is the system a safety component of a product covered by Annex I?
Medical devices, in-vitro diagnostics, machinery, lifts, toys, radio equipment, pressure equipment, personal protective equipment, motor vehicles, aviation and rail.
If every answer is no, the system is minimal-risk. No dated compliance obligation applies beyond the Article 4 AI literacy duty, which has been in force since 2 February 2025.
Each deadline in detail
Each application date below lists the obligations it switches on, who it binds, and the provisions that govern it.
The Regulation enters into force
Regulation (EU) 2024/1689 entered into force on 1 August 2024, starting the clock on every later deadline but imposing no immediate obligations on providers or deployers.
What switches on
- The staggered application periods in Article 113 begin to run
- Member States begin designating national competent authorities
- The European Commission begins preparing guidance and delegated acts
Who it binds
No operator obligations yet: this is the reference date only.
Governing provisions
Prohibited practices and AI literacy apply
Since 2 February 2025 the first eight prohibited AI practices in Article 5 have been unlawful across the EU, and every provider and deployer has owed an AI literacy duty under Article 4. Two further prohibitions were added later and apply from 2 December 2026.
What switches on
- The Article 5 bans on social scoring, untargeted facial scraping, emotion inference at work and in education, subliminal manipulation, exploitation of vulnerability, predictive policing on profiling alone, biometric categorisation for sensitive traits, and, subject to narrow carve-outs, real-time remote biometric identification in public for law enforcement
- The Article 4 AI literacy duty: since amended by the Omnibus from a duty to <em>ensure</em> a sufficient level of AI literacy to a duty to take measures to support it
- Chapter I definitions and scope provisions
General-purpose AI model obligations apply
Since 2 August 2025, providers of general-purpose AI models have had to publish training-data summaries, maintain technical documentation, and respect EU copyright law, with extra systemic-risk duties above the compute threshold.
What switches on
- Article 53 documentation, copyright policy and public training-content summary for all GPAI models
- Article 55 systemic-risk duties (model evaluation, adversarial testing, incident reporting, cybersecurity) for models presenting systemic risk
- Governance provisions: the AI Office, the AI Board, and national competent authority designation
- The Member State penalty regime under Article 99, other than the GPAI-specific fines
Who it binds
Providers of general-purpose AI models placed on the EU market. Models already on the market before this date have until 2 August 2027 to comply.
Governing provisions
Transparency obligations and the general application date
From 2 August 2026 the Article 50 transparency rules apply: people must be told when they are interacting with an AI system, and synthetic audio, image, video and text must be marked in a machine-readable format.
What switches on
- Article 50(1): disclosure that a user is interacting with an AI system, unless it is obvious
- Article 50(2): machine-readable marking of synthetic audio, image, video and text
- Article 50(3): notification when an emotion recognition or biometric categorisation system is in use
- Article 50(4): deep fake disclosure, and disclosure for AI-generated text published to inform the public
- Member State obligation to have at least one operational AI regulatory sandbox
- The remainder of the Regulation, other than the high-risk provisions listed below
Who it binds
Providers and deployers of AI systems that interact with people or generate synthetic content: chatbots, voice agents, generative image and video tools, and publishers of AI-written editorial content.
Governing provisions
Two new prohibitions and the legacy marking deadline
From 2 December 2026 two further practices are prohibited outright (AI that generates non-consensual intimate imagery, and AI that generates child sexual abuse material) and generative systems already on the market before 2 August 2026 must carry machine-readable marking.
What switches on
- Article 5(1)(ba): AI systems generating or manipulating realistic depictions of the intimate parts or sexually explicit conduct of identifiable people without their explicit consent
- Article 5(1)(bb): AI systems generating or manipulating child sexual abuse material within the meaning of Directive 2011/93/EU
- New Article 5(1a) and (1b), governing provider liability for reasonably foreseeable misuse and the safeguards defence
- Article 50(2) machine-readable marking for generative systems placed on the market before 2 August 2026
Who it binds
Providers and deployers of generative AI systems. The new prohibitions carry no grandfathering: systems already on the market are in scope.
Governing provisions
Annex III high-risk obligations apply
Providers of Annex III high-risk systems (including AI used in employment, education, credit scoring, life and health insurance pricing, essential services, law enforcement and migration) must meet the full Chapter III requirements from 2 December 2027.
What switches on
- Article 9 risk management system across the lifecycle
- Article 10 data governance and training-data quality
- Article 11 and Annex IV technical documentation
- Article 12 automatic logging and record-keeping
- Articles 13–15 transparency to deployers, human oversight, accuracy, robustness and cybersecurity
- Article 17 quality management system
- Conformity assessment, EU declaration of conformity, CE marking, and registration in the EU database
Who it binds
Providers, importers, distributors and deployers of high-risk AI systems listed in Annex III.
Governing provisions
Annex I product-safety high-risk obligations apply
AI systems that are safety components of products already regulated under EU harmonisation law (medical devices, machinery, vehicles, lifts, toys and the rest of Annex I) come into scope on 2 August 2028.
What switches on
- Chapter III requirements for AI safety components within Annex I products
- Integration of AI conformity assessment into the existing sectoral conformity route
- Obligations for public authorities already operating high-risk systems before this date
Who it binds
Manufacturers of products covered by the Annex I harmonisation legislation where an AI system is a safety component or is itself the product.
Governing provisions
Legacy large-scale IT systems must comply
AI components inside the EU large-scale IT systems listed in Annex X, such as the Schengen Information System and Eurodac, that were placed on the market before 2 August 2027 have until 2 August 2030 to be brought into conformity.
What switches on
- Full Chapter III conformity for in-scope Annex X system components
Who it binds
EU agencies and Member State authorities operating the Annex X large-scale IT systems.
Governing provisions
What moved in 2026
The two high-risk application dates were extended in 2026: Annex III moved from 2 August 2026 to 2 December 2027, and Annex I from 2 August 2027 to 2 August 2028. Nothing else in the schedule changed.
The stated reason was readiness of the supporting infrastructure rather than any softening of the requirements themselves. Conformity assessment under the Act depends on harmonised standards that the European standardization organizations had not finished, and on a network of notified bodies that had not been designated in sufficient numbers to assess the volume of systems coming into scope. Applying the obligations on the original schedule would have required providers to demonstrate conformity against standards that did not yet exist.
| Obligation | Original date | Current date | Extension |
|---|---|---|---|
| Annex III high-risk systems | 2 August 2026 | 2 December 2027 | 16 months |
| Annex I product-safety high-risk | 2 August 2027 | 2 August 2028 | 12 months |
| Article 50 transparency | 2 August 2026 | 2 August 2026 | No change |
| Article 5 prohibitions | 2 February 2025 | 2 February 2025 | No change |
What the extension does not change
An extension of the application date is not an extension of the work. Three things make the additional months less generous than they look.
- Data governance is retrospective in effect. Article 10 requires training, validation and testing datasets to be relevant, sufficiently representative and as free of errors as possible, and Article 11 requires documentation of how they were assembled. A model trained in 2026 on data whose provenance was never recorded cannot be documented into compliance in 2027. The evidence has to be generated while the data is being collected.
- Conformity assessment has a queue. Notified body capacity is finite and the whole market is working to the same date. Organisations that book late will find the assessment itself, not their own readiness, is the binding constraint.
- Everything else still applies.The prohibitions, the GPAI obligations and the transparency rules were not moved. An organisation that treats “the AI Act got delayed” as a reason to pause work is missing three sets of obligations that are already live.
What missing a deadline costs
Article 99 sets three penalty tiers, and in each case the fine is the higher of a fixed sum or a percentage of total worldwide annual turnover for the preceding financial year.
| Breach | Provision | Maximum fine | What it covers |
|---|---|---|---|
| Prohibited AI practices | Article 5 | €35 million or 7% of worldwide turnover | Deploying or placing on the market an AI system that falls within one of the ten Article 5 bans. |
| Most other operator obligations | Articles 16, 22–27, 48–51 | €15 million or 3% of worldwide turnover | Failures by providers, importers, distributors, deployers, authorised representatives or notified bodies, including the high-risk and transparency duties. |
| Supplying incorrect or misleading information | Article 99(5) | €7.5 million or 1% of worldwide turnover | Giving notified bodies or national competent authorities information that is incorrect, incomplete or misleading in reply to a request. |
Two features of this regime matter more than the headline numbers. First, the turnover limb is calculated on group worldwide turnover, so the exposure of a small EU subsidiary is set by the size of its parent. Second, enforcement is decentralised: each Member State designates its own market surveillance authority and sets its own penalty rules within the ceilings, which means the same breach can be pursued differently in different jurisdictions. Article 99 also directs authorities to give specific regard to the position of SMEs and start-ups when setting a fine.
A 90-day readiness sequence
If you are starting now, the highest-value first move is an inventory, because you cannot classify systems you have not listed, and every obligation in the Act attaches to a classification.
| Weeks | Focus | Output |
|---|---|---|
| 1–3 | Inventory every AI system in use or in development, including tools bought as features inside other software | A single register with owner, purpose, data used, and whether output affects people |
| 4–6 | Screen the register against Article 5, then against Annex III and Annex I | A classification per system, with the reasoning recorded |
| 7–9 | Remediate anything caught by Article 5 and close the Article 50 gaps | Prohibited uses stopped; disclosure and marking live on user-facing systems |
| 10–12 | Stand up the Chapter III evidence base for high-risk systems and assign accountability | Risk management, data governance and documentation running as processes, not projects |
The sequence is deliberately ordered by legal exposure rather than by deadline. Article 5 comes first because it is already enforceable at the highest tier. Article 50 comes next because it is already in force. Chapter III comes last, despite being by far the largest body of work, because it is the only part with time still on the clock, and because the register and classifications produced in weeks 1 to 6 are the inputs it depends on.
Frequently asked questions
- When did the EU AI Act come into force?
- Regulation (EU) 2024/1689 entered into force on 1 August 2024. Entry into force is not the same as application: it started the clock on a staggered set of application dates running from February 2025 to August 2030, and imposed no immediate obligations on providers or deployers.
- What is the single most important EU AI Act deadline?
- It depends on what your system does. For prohibited practices the date has already passed: 2 February 2025. For general-purpose AI models it was 2 August 2025. For transparency obligations on chatbots and generative systems it was 2 August 2026. For Annex III high-risk systems it is 2 December 2027, and for Annex I product-safety high-risk systems 2 August 2028.
- Were the EU AI Act high-risk deadlines delayed?
- Yes. Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force on 27 July 2026 and moved the Annex III high-risk obligations from 2 August 2026 to 2 December 2027, and the Annex I obligations from 2 August 2027 to 2 August 2028. The Article 50 transparency date and the Article 5 prohibitions were not deferred, and the same instrument added two new prohibitions applying from 2 December 2026.
- Does the EU AI Act apply to companies outside the European Union?
- Yes. Article 2 extends the Regulation to providers placing AI systems on the EU market regardless of where they are established, and to providers and deployers outside the EU where the output produced by the system is used in the EU. A US company whose model scores loan applications for an EU bank is in scope.
- Do AI systems already on the market before the deadline have to comply?
- Not always. Article 111 grandfathers some existing systems. High-risk systems placed on the market before the relevant application date are caught only if their design is significantly changed afterwards, though systems used by public authorities must be brought into conformity regardless. General-purpose AI models placed on the market before 2 August 2025 have until 2 August 2027. Legacy components of the Annex X large-scale IT systems have until 2 August 2030.
- What are the penalties for missing an EU AI Act deadline?
- Article 99 sets three tiers, and the fine is the higher of a fixed sum or a percentage of total worldwide annual turnover. Prohibited practices carry up to €35 million or 7%. Most other operator obligations, including the high-risk and transparency duties, carry up to €15 million or 3%. Supplying incorrect or misleading information to authorities carries up to €7.5 million or 1%.
- Is there a grace period after each application date?
- No. The Regulation has no general grace period. What it has instead is the staggered application schedule itself, plus the specific transitional provisions in Article 111. Once an application date passes, the obligations bind and national market surveillance authorities can act.
Sources and verification
Every date and provision cited here was checked against the consolidated text on 11 August 2026. The EU AI Act is being amended as it is implemented; where this page and EUR-Lex disagree, EUR-Lex governs.
- Regulation (EU) 2024/1689: consolidated text on EUR-Lex (controlling source)
- Regulation (EU) 2026/1744: Digital Omnibus on AI, amending the AI Act (in force 27 July 2026)
- Article 113: Entry into force and application
- Article 111: AI systems already placed on the market
- Article 99: Penalties
- European Commission: AI Act implementation and guidance
- European AI Office
This page is an independent information resource. It is not legal advice, and it does not create a lawyer–client relationship. Take advice on your own facts before making a compliance decision.
Next: work out whether a specific system is caught by the high-risk rules with the risk classifier, or read the full text of Article 113 and Article 99.