EU AI Act
Last updated: Jul 24, 2026 · 6 min

EU AI Act timeline + key dates

Key dates in plain language, plus what to operationalize at each phase (controls + evidence). The Digital Omnibus on AI, adopted 29 June 2026, moved the Annex III high-risk obligations and the Article 27 FRIA to 2 December 2027, and Annex I product-embedded high-risk AI to 2 August 2028. The Article 50 transparency duties still apply from 2 August 2026.

Orientation only. Not legal advice.

Who this matters for

Anyone planning EU AI Act readiness and budgeting implementation work.

What you'll leave with

A phased "what to do now" plan mapped to milestones and evidence artifacts.

Key milestones (orientation)

  • 12 Jul 2024: Published in the Official Journal. Start of the countdown. Use this date to sanity-check phased applicability timelines.
  • 1 Aug 2024: Entered into force. The regulation is in force, with many obligations phasing in later.
  • 2 Feb 2025: Prohibited practices apply (Article 5). Banned use cases have to be removed or redesigned.
  • 2 Aug 2025: General-purpose AI (GPAI) obligations begin. Provider-side duties start phasing in for GPAI models and systemic-risk models.
  • 29 Jun 2026: The Council adopted the Digital Omnibus on AI, after the European Parliament endorsed the text on 16 June 2026. It moved the high-risk application dates.
  • 2 Aug 2026: Article 50 transparency duties apply. Disclose AI interaction and mark AI-generated content in a machine-readable format. Systems already on the market have until 2 December 2026 to implement the marking.
  • 2 Dec 2026: Two new Article 5 prohibitions apply, covering AI that generates child sexual abuse material and AI that generates non-consensual intimate imagery.
  • 2 Aug 2027: Each Member State runs at least one AI regulatory sandbox (Article 57), moved from 2 August 2026.
  • 2 Dec 2027: Chapter III obligations apply to stand-alone Annex III high-risk systems, moved from 2 August 2026. The Article 27 FRIA and Article 49 registration follow this date.
  • 2 Aug 2028: High-risk AI embedded in Annex I regulated products applies, moved from 2 August 2027.

What to do now (fast)

  • Inventory AI systems + owners; classify by intended purpose and deployment region.
  • Remove "stop-ship" prohibited patterns and document remediation decisions.
  • Stand up an evidence trail: versioning, change control, and audit logs that answer "what ran when".
  • If high-risk is likely: start Annex IV technical documentation and QMS processes early.
  • Agree an internal cadence (monthly) for monitoring + update evidence packages.

Evidence artifacts to keep

  • Classification memo (assumptions + rationale)
  • Risk register and mitigation verification
  • Technical documentation package (Annex IV-aligned for high-risk)
  • Human oversight intervention records
  • Logging/export samples and retention policy

Next step: artifacts

Compliance work gets funded when the output is forwardable. Use the starter templates to convert obligations into controls and evidence.

Govern - Assure - Prove

Need a defensible evidence path?

KLA turns obligations into controls, controls into assurance, and assurance into exportable evidence.

EU AI Act timeline + key dates | KLA