EU AI Act Enforcement Timeline

Every enforcement phase of Regulation (EU) 2024/1689, from entry into force to the final transition deadline.

1 August 2024
Enforced

Entry into force

AI Act entry into force

Regulation (EU) 2024/1689 entered into force. The transition period began.

2 February 2025
Enforced

Phase 1-6 months after entry into force

Prohibited AI Practices

Article 5 prohibited practices are enforceable. Systems involving social scoring, subliminal manipulation, exploitation of vulnerabilities, real-time biometric identification in public spaces (with exceptions), emotion recognition in workplace/education, predictive policing based solely on profiling, and untargeted facial image scraping must be discontinued.

2 August 2025
Enforced

Phase 2-12 months after entry into force

GPAI Model Obligations

Chapter V obligations for general-purpose AI models take effect. All GPAI providers must comply with transparency, technical documentation, copyright policy, and energy consumption reporting. Systemic risk models (Article 51) face additional evaluation, incident reporting, and adversarial testing duties. The AI Office begins enforcement.

2 August 2026
Enforced

Transparency — in force since 2 August 2026

Article 50 Transparency Obligations

Article 50 transparency obligations apply. Providers and deployers of certain AI systems must inform natural persons that they are interacting with AI, and mark synthetic audio, image, video, or text content as artificially generated or manipulated, subject to the Article 50 conditions.

2 December 2026
Upcoming

Article 5 Omnibus deferred prohibitions — 2 December 2026

NCII / CSAM Ban (Article 5)

Article 5(1), first subparagraph, points (ba) and (bb), and Article 5(1a) and (1b) apply from this date (Article 113(3)(a) as amended by Regulation (EU) 2026/1744). Distinct from the Article 50(2) pre-existing synthetic-content marking deadline on the same day.

2 December 2026
Upcoming

Article 111(4) transitional

Pre-existing synthetic-Content systems (art 50(2))

AI systems generating synthetic content that were placed on the market before 2 August 2026 must meet Article 50(2) marking obligations by this date (Article 111(4), as added by Regulation (EU) 2026/1744).

Article 111(4)
Article 50(2)
2 December 2027
Future

Phase 3-24 months after entry into force

High-Risk AI Systems (Annex III)

Full compliance required for high-risk AI systems classified under Annex III (stand-alone). Providers must meet all Chapter III Section 2 requirements: risk management (Art. 9), data governance (Art. 10), technical documentation (Art. 11), logging (Art. 12), transparency (Art. 13), human oversight (Art. 14), accuracy/robustness/cybersecurity (Art. 15). Deployer obligations (Art. 26), FRIA (Art. 27), and EU database registration (Art. 49) also apply. Market surveillance authorities begin enforcement.

2 August 2028
Future

Phase 4-36 months after entry into force

High-Risk Products (Annex I)

Obligations extend to AI systems that are safety components of products covered by Annex I Section A Union harmonisation legislation (e.g., medical devices under MDR, machinery under the Machinery Regulation, toys, lifts, pressure equipment, vehicles). These systems must meet both AI Act and sectoral product-law requirements. Notified bodies must be prepared for integrated conformity assessment.

2 August 2028
Future

Review milestone

Article 112 Review #1

First Commission review under Article 112 of the AI Act.

2 August 2029
Future

Evaluation milestone

Article 112 Full Evaluation Report

Commission full evaluation report under Article 112 of the AI Act.

2 August 2030
Future

Article 111(2) transitional

High-Risk for public authorities

High-risk AI systems intended to be used by public authorities must comply by this transitional deadline (Article 111(2)).

Article 111(2)
31 December 2030
Future

Phase 5, Extended transition for Annex X systems

Large-Scale EU IT Systems (Annex X)

AI systems that are components of large-scale EU IT systems listed in Annex X (SIS II, VIS, Eurodac, EES, ETIAS, ECRIS-TCN) must comply with the AI Act. Article 110 grandfathering expires for systems placed on the market before August 2027 unless significantly modified. This is the final compliance deadline in the AI Act.

Condition (no fixed date)
Conditional

Article 111(2) condition

Legacy high-Risk systems (conditional)

High-risk AI systems placed on the market before 2 August 2026 are in scope of the high-risk obligations only if they are subject to significant changes in their designs (Article 111(2)). This is a condition, not a calendar deadline.

Article 111(2)