EU AI Act Compliance Timeline
Interactive timeline of key EU AI Act milestones. Filter by your role and risk level, then export deadlines to your calendar.
EU AI Act Entry into Force
The EU AI Act officially enters into force. The 24-month general transition period begins.
Prohibited AI Practices Ban
AI systems involving prohibited practices (Article 5) can no longer be placed on the market or used in the EU. Includes social scoring, manipulation, real-time biometric identification exceptions.
AI Literacy Requirement
Providers and deployers must promote and encourage AI literacy among the staff who operate and oversee AI systems, through measures proportionate to the systems in use. The Digital Omnibus on AI reworded this duty; the date is unchanged.
GPAI Model Obligations
General-purpose AI model providers must comply with transparency requirements, technical documentation, and copyright compliance. Systemic risk models face additional obligations.
Notified Bodies Designation
Member States must designate notifying authorities and notified bodies for conformity assessments.
Governance Structures Operational
AI Office, AI Board, and national competent authorities must be fully operational.
Penalties Framework Active
Full penalty framework becomes enforceable. Up to 35M EUR or 7% global turnover for prohibited practices, 15M/3% for high-risk violations.
Digital Omnibus on AI Adopted
The European Parliament endorsed the agreed text on 16 June 2026 and the Council adopted it on 29 June 2026. The amending regulation enters into force on the third day after publication in the Official Journal. It moves the high-risk application dates and the sandbox deadline, and adds two Article 5 prohibitions.
Transparency Obligations
Providers must disclose that a person is interacting with an AI system and mark synthetic audio, image, video, and text in a machine-readable format. Deployers must disclose deepfakes and AI-generated text published to inform the public. Emotion recognition and biometric categorisation systems must inform the people exposed to them. This date is unchanged by the Digital Omnibus on AI.
Machine-Readable Marking for Existing Generative Systems
Generative AI systems placed on the market before 2 August 2026 must implement machine-readable marking of their output by this date. Systems placed on the market after 2 August 2026 comply from day one.
New Article 5 Prohibitions Apply
The Digital Omnibus on AI adds two prohibited practices: AI systems that generate child sexual abuse material and AI systems that generate non-consensual intimate imagery. Both are banned from this date.
AI Regulatory Sandboxes Operational
Each Member State must have at least one AI regulatory sandbox operational. Moved from 2 August 2026 by the Digital Omnibus on AI.
High-Risk AI (Annex III) Requirements
Chapter III obligations apply to stand-alone high-risk AI systems in Annex III categories: biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, justice. Moved from 2 August 2026 by the Digital Omnibus on AI.
Deployer Obligations
Deployers of Annex III high-risk AI must implement human oversight, input data quality measures, monitoring, record-keeping, and transparency requirements. Moved from 2 August 2026 by the Digital Omnibus on AI.
Fundamental Rights Impact Assessment (FRIA)
Deployers that are public bodies, private entities providing public services, or users of AI for creditworthiness assessment and for risk assessment and pricing in life and health insurance must complete a FRIA and notify the market surveillance authority. The FRIA follows the Annex III date, moved from 2 August 2026.
Conformity Assessment Required
Annex III high-risk AI systems must undergo conformity assessment, carry CE marking, and have a signed declaration of conformity before market placement. Moved from 2 August 2026 by the Digital Omnibus on AI.
Registration in the EU Database
Providers and public-authority deployers must register Annex III high-risk systems in the EU database, including systems self-assessed as not high-risk under Article 6(3). The Digital Omnibus on AI deletes Annex VIII Section B points 7 and 9, so the registration payload no longer carries the summary of the Article 6(3) grounds or the list of Member States. Moved from 2 August 2026.
High-Risk AI (Annex I) Requirements
AI systems that are safety components of products covered by EU product safety legislation (machinery, toys, medical devices, vehicles, and the rest of Annex I) must comply. Moved from 2 August 2027 by the Digital Omnibus on AI.
Feb 2025
Prohibited practices ban
Aug 2025
GPAI model obligations
Aug 2026
Article 50 transparency
Dec 2027
High-risk (Annex III)
Aug 2028
High-risk (Annex I)
Disclaimer: This timeline reflects Regulation (EU) 2024/1689 as amended by the Digital Omnibus on AI, adopted 29 June 2026. Dates may be subject to implementing acts and delegated regulations. Consult with legal counsel for definitive compliance planning.
