Regfortis
EU AI Act compliance deadlines: the complete timeline
The EU AI Act came into force in August 2024 but its obligations apply on different dates. This timeline covers every key date, including the amendments introduced by Regulation (EU) 2026/1744.
Last regulatory review: 14 August 2026 · Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744
Timeline at a glance
Date
What applies
Applies to SMEs?
| date | desc | sme |
|---|---|---|
| 1 Aug 2024 | Regulation enters into force | Monitoring |
| 2 Feb 2025 | Article 5 prohibited practices | ✓ Yes |
| 2 Aug 2025 | General-purpose AI model obligations (Title IV) | Mainly providers |
| 2 Aug 2026 | Article 4 (AI literacy) + Article 50 (transparency) | ✓ Yes — act now |
| 2 Dec 2026 | Two new Article 5 prohibitions (EU 2026/1744) | ✓ Yes |
| 2 Dec 2027 | Annex III high-risk AI full obligations (amended) | If high-risk AI used |
| 2 Aug 2028 | Annex I regulated-product high-risk AI | If applicable |
Full timeline with explanations
Regulation (EU) 2024/1689 enters into force
In force
The EU AI Act was published in the Official Journal of the European Union and entered into force on 1 August 2024. The Act does not apply in full from this date — most obligations take effect on later application dates. However, from this date the regulatory framework is established and businesses should begin planning for compliance.
Article 5 — Prohibited AI practices apply
In force since Feb 2025
The first substantive obligations: a list of AI practices is banned outright. These include subliminal manipulation that affects a person's behaviour against their interests, exploitation of vulnerabilities of protected groups, social scoring systems operated by public authorities, most forms of real-time remote biometric identification in publicly accessible spaces, biometric categorisation to infer sensitive attributes, emotion recognition in workplace and educational settings, and AI-assisted predictive policing based solely on profiling.
Full guide to Article 5 prohibited practices
General-purpose AI model (GPAI) obligations — Title IV
In force
Obligations for providers of general-purpose AI models (such as large language models distributed to third parties) apply from this date. These obligations — including transparency documentation, technical documentation, and copyright policy — primarily affect AI model developers and distributors, not SMEs that use commercial AI tools as deployers.
Article 4 (AI literacy) and Article 50 (transparency) apply
In force now
This is the most significant date for SMEs. Two new obligations now apply to all deployers of AI systems:
- Article 4 (AI literacy): Take proportionate measures to ensure staff who interact with AI systems have sufficient AI literacy. No specific certification format is mandated.
- Article 50 (transparency): Inform users when they are interacting with an AI system (unless obvious from context). Apply technical disclosure measures to AI-generated synthetic content.
Read the full Article 4 guide
Read the full Article 50 guide
Two new Article 5 prohibitions — Regulation (EU) 2026/1744
Upcoming
Regulation (EU) 2026/1744 (the Omnibus amendment) extended the Article 5 prohibited practices list with two additional prohibitions that apply from this date. Review the official EUR-Lex text for their exact scope.
Businesses should review these new prohibitions against their current and planned AI deployments and ensure no activity falls within the expanded prohibited list before 2 December 2026.
Chapter III — Annex III high-risk AI full obligations
Amended from Aug 2026
The original application date for Chapter III (Annex III high-risk AI) obligations was 2 August 2026. Regulation (EU) 2026/1744 amended this to 2 December 2027, giving businesses with high-risk AI use-cases more preparation time.
The heaviest obligations under the EU AI Act — covering AI systems in the Annex III high-risk categories — apply from this date. For deployers, the key obligation is Article 26: fundamental rights impact assessments, human oversight measures, EU database registration, and cooperation with supervisory authorities.
High-risk categories include: employment and HR AI (CV screening, performance assessment), credit and insurance scoring, educational assessment AI, critical infrastructure management, and several others.
Full guide to Annex III high-risk AI
Annex I regulated-product high-risk AI systems
Future
AI systems embedded in regulated products already covered by EU product safety law — such as medical devices, machinery, and aviation equipment (Annex I) — are subject to the full Chapter III obligations from this date. This is relevant primarily to manufacturers of regulated products and their supply chains.
Frequently asked questions
When did the EU AI Act enter into force?
Regulation (EU) 2024/1689 entered into force on 1 August 2024. However, its substantive obligations apply on staggered dates from 2 February 2025 onwards — not from the date of entry into force. The most relevant date for businesses using AI tools is 2 August 2026, when Articles 4 and 50 came into effect.
Which EU AI Act deadline is most relevant for businesses using AI tools in 2026?
2 August 2026 is the key date for most businesses that use AI tools professionally. From this date, Article 4 (AI literacy) and Article 50 (transparency) apply to all deployers of AI systems in the EU. If your business uses any AI-powered tool professionally — chatbots, AI writing tools, AI-assisted HR software — these obligations already apply.
Was the Annex III high-risk AI deadline changed from the original date?
Yes. The original application date for Chapter III (Annex III high-risk AI) obligations was 2 August 2026. Regulation (EU) 2026/1744 — the Omnibus amendment to the EU AI Act — amended this to 2 December 2027. This gives businesses using high-risk AI in categories such as employment, credit assessment, or education more time to prepare for the full Article 26 deployer duties.
Do EU AI Act deadlines apply to companies based outside the EU?
Yes. The EU AI Act has extra-territorial scope under Article 2. It applies to providers and deployers when the output of an AI system is used in the EU, or when the system affects persons located in the EU — regardless of where the provider or deployer is established. Non-EU companies whose AI products or services are used by EU customers are subject to the same obligations and deadlines.
Find out which deadlines apply to you
The Regfortis assessment maps your AI use-cases to the relevant obligations and deadlines — free, in about 5 minutes.
Start free assessment
View compliance checklist
Official sources
- Regulation (EU) 2024/1689 — Official text (EUR-Lex)
- Regulation (EU) 2026/1744 — Official sources
- European Commission — Official sources
- Regfortis regulatory source annotations
This timeline is for informational purposes only. Exact application dates should be verified against the official consolidated text. This page does not constitute legal advice.