The EU AI Act entered into force on August 1, 2024, but its obligations are being phased in over a transition period of up to 36 months. Understanding the exact timeline — and which deadlines apply to your organization — is essential for planning your compliance program. Missing key deadlines is not an academic concern: the Act's penalties can reach €30 million or 6% of global annual turnover.

Here is a complete breakdown of every significant date in the EU AI Act timeline and what each milestone means for your compliance obligations.

August 1, 2024: EU AI Act Enters Into Force

The EU AI Act became law on August 1, 2024, twenty days after its publication in the Official Journal of the European Union. From this date, the Act is legally binding — but most obligations do not yet apply. The transition period gives organizations time to understand the requirements and build compliant systems before enforcement begins.

February 2, 2025: Prohibited AI Practices Banned

The first major compliance deadline arrived on February 2, 2025 — six months after the Act entered into force. From this date, AI systems that fall into the unacceptable risk category are prohibited in the EU. These include:

Organizations that were operating any of these capabilities were required to cease operations by February 2, 2025. Any continued operation after this date constitutes a violation of the Act.

August 2, 2025: GPAI Model Obligations and Governance Bodies

Twelve months after the Act entered into force, two significant developments took effect:

General-Purpose AI (GPAI) model obligations: Providers of general-purpose AI models — including large language models, multimodal models, and other foundation models — must comply with obligations related to transparency, copyright compliance, and technical documentation. Providers of GPAI models with systemic risk (defined as models trained with more than 10^25 FLOPs) face additional obligations including adversarial testing (red-teaming), incident reporting, and information sharing with the AI Office.

Governance bodies operational: The AI Office (part of the European Commission), the AI Board (composed of Member State representatives), and national competent authorities became fully operational, with the power to issue guidance, conduct investigations, and impose penalties.

August 2, 2026: High-Risk AI System Obligations — The Critical Deadline

This is the most commercially significant deadline for most AI companies. From August 2, 2026, all the requirements for high-risk AI systems listed in Annex III of the Act become fully applicable. This includes AI systems used in:

For all high-risk systems in these categories, providers must have in place: a risk management system, data governance practices, technical documentation, logging capabilities, transparency measures, human oversight mechanisms, and conformity assessment. Systems must be registered in the EU AI Act database, and a Declaration of Conformity must be drawn up.

August 2026 is effectively the D-Day for the EU AI Act. Organizations that have not already begun their compliance programs should treat this as an urgent priority — with less than 4 months remaining at the time of writing.

August 2, 2027: Regulated Product Embedded AI

AI systems embedded in products covered by existing EU product safety legislation — including medical devices, machinery, aviation systems, and automotive safety systems — have an additional transition period until August 2027. This accounts for the longer product development and certification cycles in these regulated sectors.

Ongoing: Harmonized Standards and Codes of Practice

Several supporting instruments are being developed in parallel with the Act's implementation:

What Should Organizations Do Right Now?

With August 2026 as the critical deadline for most AI companies, here is an action plan for the coming months:

  1. Immediately: Conduct a complete AI inventory and apply the EU AI Act risk classification to identify which systems trigger high-risk obligations.
  2. This month: Conduct a gap analysis against the high-risk AI system requirements to understand the scope of work required.
  3. Next 2-3 months: Implement an ISO 42001-aligned AI Management System as the governance foundation for EU AI Act compliance.
  4. Next 3-4 months: Develop required technical documentation, conduct conformity assessments, and prepare EU database registration for each high-risk system.
  5. Before August 2, 2026: Complete all compliance activities, register systems in the EU database, draw up Declarations of Conformity, and affix CE markings where required.

Organizations that start this process immediately can meet the August 2026 deadline comfortably. Those that delay risk the cost and disruption of emergency compliance programs — or the regulatory consequences of missing the deadline entirely.

Ready to Get Certified?

AICerty provides end-to-end ISO 42001, EU AI Act, and ISO 27001 certification services for AI companies worldwide. 100% online, 6-10 weeks, powered by BALTUM Bureau.

Visit aicerty.io
← Back to Blog