The Four Phases of the EU AI Act Timeline
Status: 2 August 2026 milestone activated
On 2 August 2026, the EU AI Act reached its general-application date under Article 113 of Regulation (EU) 2024/1689. The bulk of the Act's substantive obligations moved from grace period into active enforcement — this is the deadline that reshapes enterprise AI compliance in Europe.
What activated on 2 August 2026:
- Annex III high-risk AI obligations (Articles 8–27) — conformity assessments, risk-management systems, data governance, technical documentation, human oversight, and EU database registration are now enforceable for high-risk AI providers and deployers.
- Full AI Office supervisory powers under Chapter VII — the EU AI Office may now request information, order corrective action, and coordinate cross-border enforcement, on top of the GPAI oversight it has held since 2 August 2025.
- National competent authority enforcement — designated national supervisors began coordinated market surveillance across the 27 member states.
- Penalty regime fully live under Article 99 — the €35M / 7% (Tier 1), €15M / 3% (Tier 2), and €7.5M / 1.5% (Tier 3) fines are now available across all in-scope obligations, with a short administrative grace before first enforcement decisions.
Designated national competent authorities (selected):
- Sweden — Post- och telestyrelsen (PTS) coordinates AI Act market surveillance, with IMY (data protection) handling biometric and fundamental-rights aspects. PTS AI Act page.
- Germany — Bundesnetzagentur (BfNetzA) named lead national AI Act supervisor with BSI on cybersecurity. BfNetzA AI Act hub.
- France — CNIL for fundamental-rights supervision plus ANSSI for cybersecurity and DGE for market surveillance. CNIL AI Act page.
- Ireland — National AI Office within the Department of Enterprise, Trade and Employment coordinates a multi-regulator model across the DPC, ComReg, and CCPC.
Practical impact by organisation type:
- GPAI providers (OpenAI, Anthropic, Google, Mistral, Meta) — must maintain the technical documentation, copyright-compliance summary, and training-data summary they published under Chapter V since 2 August 2025, and now cooperate with AI Office information requests under active enforcement.
- Enterprise deployers of high-risk AI — must have completed human-oversight design, transparency notices to affected persons, and system logging by 2 August 2026. Late-starters typically need 4–6 months to reach documentation parity.
- SME providers — reduced-fee conformity assessments and simplified documentation paths under Article 62 remain available; supervisors have signalled proportionate enforcement in the first months.
Independent trackers: artificialintelligenceact.eu implementation timeline · European Commission AI regulatory framework · Bird & Bird EU AI Act tracker.
When did the EU AI Act become fully applicable?
The EU AI Act reached general application on 2 August 2026, activating Annex III high-risk AI obligations and full AI Office enforcement powers. GPAI transparency rules had already applied since 2 August 2025. The final deadline — 2 August 2027 — covers AI embedded in regulated products (Annex I) and ends the grandfathering period for GPAI models placed on the market before 2 August 2026.
The EU AI Act was published in the Official Journal of the EU on 12 July 2024 and entered into force on 1 August 2024 — 20 days after publication, as required by Regulation (EU) 2024/1689.
Entry into force is not the same as application. Most substantive obligations apply on a staggered schedule running through 2027.
The Four Implementation Phases at a Glance
- Phase 1 — 1 Aug 2024 (0 months): Act enters into force. EU AI Office established. No substantive provider or deployer obligations yet.
- Phase 2 — 2 Feb 2025 (6 months): Article 5 prohibited AI practices become enforceable for all providers and deployers operating in the EU.
- Phase 3 — 2 Aug 2025 (12 months): Chapter V GPAI model obligations apply. National competent authorities must be designated. AI Office fully operational. Codes of practice for GPAI published.
- Phase 4 — 2 Aug 2026 (24 months): Core high-risk AI obligations under Annexes III and IV apply. Conformity assessments, registration, transparency, and human oversight requirements activated.
- Extended deadline — 2 Aug 2027 (36 months): AI embedded in products subject to existing EU product safety law (e.g. medical devices, machinery) gets a final 12-month extension.
According to the European Parliament EPRS implementation brief (2025), the staggered structure was deliberately designed to give organisations time to build compliance infrastructure before the most demanding obligations activate.
The European Commission's AI Act Service Desk maintains a live timeline page confirming each phase's activation dates.
Master Implementation Timeline
| Phase | Date | What Applies | Who Is Affected |
|---|---|---|---|
| 1 — Entry into force | 1 Aug 2024 | Act effective; EU AI Office established | All actors |
| 2 — Prohibited practices | 2 Feb 2025 | Article 5 bans on unacceptable-risk AI | All providers & deployers in EU |
| 3 — GPAI obligations | 2 Aug 2025 | Chapter V transparency & systemic-risk rules; national authority designation | GPAI model providers |
| 4 — High-risk (Annex III) | 2 Aug 2026 | Conformity assessments, registration, monitoring, human oversight | High-risk AI providers & deployers |
| 4b — High-risk (Annex IV / product safety) | 2 Aug 2027 | AI in regulated products (medical devices, machinery) | Product manufacturers & importers |
| Full enforcement active | 2 Aug 2026 onward | All penalties active across all tiers | All in-scope entities |
📌 Entry into Force ≠ Application
The Act 'entered into force' on 1 August 2024 but most obligations only 'apply' from 2025–2027. These are legally distinct concepts under EU law — violation penalties only attach once an obligation's application date has passed.
Entry into Force vs. Application: Why the Distinction Matters
Under EU law, 'entry into force' means a regulation is legally valid and exists on the statute books. 'Application' means obligations are actively enforceable and penalties can attach for non-compliance.
For the EU AI Act, entry into force occurred on 1 August 2024 but the general application date is 2 August 2026. This matters immediately: auditors, investors, and procurement teams are already asking about compliance posture — the correct answer depends entirely on which phase's obligations are currently in application.
As noted in the EPRS 2025 implementation brief, organisations must track both the entry-into-force date and each phase's individual application date when building compliance roadmaps.
Phase 2 Deadline: Prohibited AI Practices (2 February 2025)
In short
From 2 February 2025, eight categories of AI practices are banned outright in the EU under Article 5. Any system deploying these practices is illegal regardless of use case.
2 February 2025 was the first major enforcement deadline — exactly six months after the Act entered into force. Article 5 of Regulation (EU) 2024/1689 lists AI practices banned outright as incompatible with EU fundamental rights.
These are not future obligations. They have been enforceable since February 2025, and any organisation currently deploying a matching system is in active violation.
⚠️ Already Enforceable Since February 2025
These bans are not future obligations — they have been enforceable since 2 February 2025. Organisations deploying any system matching these categories are currently in violation and subject to the highest penalty tier.
The Eight Prohibited AI Practices Under Article 5
- 1. Subliminal or manipulative techniques: AI systems that use techniques below conscious awareness to distort a person's behaviour in ways that cause harm.
- 2. Exploitation of vulnerabilities: AI that exploits vulnerabilities related to age, disability, or social or economic situation to distort behaviour harmfully.
- 3. Social scoring by public authorities: AI used by public bodies to evaluate or classify individuals based on social behaviour, leading to detrimental or discriminatory treatment.
- 4. Real-time remote biometric identification in public spaces: Law enforcement use of live biometric identification in publicly accessible spaces — with narrow judicial-authorisation exceptions only.
- 5. Retrospective biometric identification databases: AI systems used to compile facial recognition databases by scraping images from the internet or CCTV footage indiscriminately.
- 6. Emotion recognition in workplaces and education: AI that infers emotional states of individuals in workplace or educational institution contexts.
- 7. Biometric categorisation to infer sensitive attributes: AI that categorises individuals by race, political opinion, trade union membership, religious beliefs, or sexual orientation based on biometric data.
- 8. Predictive policing based solely on profiling: AI that assesses individual risk of criminal offending based purely on profiling, without any objective and verifiable facts pointing to criminal activity.
The narrow exceptions for real-time biometric surveillance — such as searches for missing persons or prevention of imminent terrorist attacks — require prior judicial authorisation in all cases, per Article 5(2) of the Official Journal text.
Prohibited Practice Penalties
| Prohibited Practice | Description | Penalty Tier |
|---|---|---|
| Subliminal manipulation | Techniques below conscious awareness that distort behaviour and cause harm | Up to €35M or 7% global turnover |
| Vulnerability exploitation | Targeting age, disability, or socioeconomic vulnerability to distort decisions | Up to €35M or 7% global turnover |
| Social scoring (public authorities) | Evaluating individuals based on social behaviour with detrimental consequences | Up to €35M or 7% global turnover |
| Real-time biometric ID in public | Live facial recognition by law enforcement in publicly accessible spaces | Up to €35M or 7% global turnover |
| Retrospective biometric databases | Scraping internet or CCTV images to build facial recognition databases | Up to €35M or 7% global turnover |
| Emotion recognition (workplace/education) | Inferring emotional states of employees or students in institutional settings | Up to €35M or 7% global turnover |
| Sensitive attribute categorisation | Inferring race, political opinion, religion, or sexual orientation from biometrics | Up to €35M or 7% global turnover |
| Predictive policing by profiling | Assessing criminal risk based solely on profiling without verifiable facts | Up to €35M or 7% global turnover |
At Alice Labs, across our work advising 100+ enterprise AI implementations, the prohibited practices review is the first step in every EU AI Act compliance checklist we run. Most enterprise AI systems are not in these categories — but some HR and security AI tools warrant close scrutiny under points 6 and 8.
Phase 3 Deadline: GPAI Model Obligations (2 August 2025)
In short
From 2 August 2025, providers of General Purpose AI models must comply with Chapter V transparency obligations, and those with systemic risk face additional requirements.
The 12-month mark — 2 August 2025 — activates obligations for General Purpose AI (GPAI) model providers under Chapter V of the EU AI Act. GPAI models are AI models trained on large volumes of data, capable of performing a wide range of tasks, and made available to other businesses to build upon.
GPT-4, Claude, Gemini, and Mistral are canonical examples. The rules apply to providers placing these models on the EU market regardless of where the provider is established.
Two Tiers of GPAI Obligation
The Act creates two tiers of GPAI obligation based on training compute, as clarified by the IAPP EU AI Act implementation guide (2024).
- All GPAI models: Must provide technical documentation, comply with EU copyright law, and publish a summary of training data.
- GPAI models with systemic risk (trained on more than 10²⁵ FLOPs): Must additionally conduct model evaluations, adversarial testing, report serious incidents to the EU AI Office, ensure cybersecurity protections, and report energy consumption.
What Must Happen by 2 August 2025
- National competent authorities designated: Each EU member state must have appointed its national supervisory authority for AI Act enforcement.
- EU AI Office fully operational: The Office, established within the European Commission, takes primary supervisory responsibility for GPAI models.
- Codes of practice published: Industry codes of practice for GPAI models, developed with stakeholder input, should be published and available for voluntary adoption.
- GPAI provider compliance active: All GPAI model providers must be in compliance with Chapter V obligations from this date.
According to the EPRS 2025 brief, the GPAI obligations represent the most novel element of the Act — no prior EU legislation directly regulated foundation model providers at the model level.
For organisations building enterprise applications on top of GPAI models (deployers rather than providers), the Phase 3 obligations primarily attach to your model vendor. However, you retain obligations under your own system's risk classification — which activates fully in Phase 4.
📌 GPAI Deployers vs. Providers
If your organisation uses a GPAI model via API to build a product, you are a deployer — not a GPAI provider. Phase 3 obligations sit with your model vendor. Your own obligations depend on how your application is classified under the risk tiers.
Phase 4 Deadline: High-Risk AI Obligations (2 August 2026)
In short
From 2 August 2026, providers and deployers of high-risk AI systems under Annexes III and IV must comply with conformity assessments, registration, transparency, and human oversight requirements.
2 August 2026 is the most consequential date for the majority of European enterprises. It activates the full suite of high-risk AI obligations — the core of the EU AI Act's compliance framework.
High-risk AI is defined by reference to Annex III (areas of use) and Annex IV (products under EU product safety legislation). The Annex III list covers eight critical sectors.
Annex III: High-Risk AI Sectors
- 1. Biometric identification and categorisation (not already prohibited under Article 5)
- 2. Critical infrastructure — water, gas, heating, electricity, road traffic, and digital infrastructure
- 3. Education and vocational training — access determination, grading, and proctoring systems
- 4. Employment and workers management — recruitment, CV screening, promotion decisions, task allocation, and performance monitoring
- 5. Access to essential private and public services — credit scoring, insurance risk assessment, emergency dispatch
- 6. Law enforcement — AI used by police and justice authorities for individual risk assessment and crime analysis
- 7. Migration, asylum, and border control — security risk profiling, document verification, application processing
- 8. Administration of justice and democratic processes — AI assisting courts and in electoral contexts
What High-Risk AI Providers Must Do by 2 Aug 2026
| Obligation | Who It Applies To | Key Requirement |
|---|---|---|
| Risk management system | Providers | Documented, continuous risk identification and mitigation process |
| Data governance | Providers | Training data quality, relevance, and bias mitigation practices documented |
| Technical documentation | Providers | Comprehensive technical file per Annex IV requirements |
| Record-keeping & logging | Providers & deployers | Automatic logs of system operation for post-market monitoring |
| Transparency to deployers | Providers | Instructions for use with capabilities, limitations, and risk information |
| Human oversight | Providers & deployers | Technical measures enabling human intervention and override |
| Accuracy, robustness & cybersecurity | Providers | Documented performance benchmarks and security architecture |
| Conformity assessment | Providers | Internal or third-party assessment before market placement |
| EU database registration | Providers & deployers (public sector) | Registration in the EU's public AI systems database before deployment |
| Post-market monitoring | Providers | Ongoing system performance monitoring and serious incident reporting |
EU AI Act Articles Activated on 2 August 2026
The 2 August 2026 date is set by Article 113(a) of Regulation (EU) 2024/1689 as the general date of application. The specific provisions that shifted from grace to enforceable on that day include:
- Articles 8–15 — high-risk AI system requirements (risk management, data governance, technical documentation, record-keeping, transparency, human oversight, accuracy).
- Articles 16–22 — provider obligations, authorised representatives, importers, distributors, and downstream deployer duties.
- Articles 26–27 — deployer obligations and fundamental-rights impact assessment for public bodies and providers of essential services.
- Article 49 — mandatory registration of high-risk AI systems in the EU public database before market placement or deployment.
- Chapter IX (Articles 72–94) — post-market monitoring, information sharing, market surveillance, and the serious-incident reporting workflow.
GPAI providers continue to operate under Chapter V (Articles 51–56) — Article 53 on transparency and copyright-compliance summaries, and Article 55 on systemic-risk model evaluations — with the crucial change that AI Office enforcement powers under Chapter VII are now fully live, not just supervisory.
Enforcement Grace Period Before First Fines
The Act's penalty regime (Article 99) is legally active from 2 August 2026, but supervisors have signalled a short administrative grace before the first fine decisions land. Historical parallels with GDPR (May 2018) and DSA (Feb 2024) suggest 6–12 months of coordinated investigations, warning letters, and market-surveillance actions before headline-grade penalties. Serious violations of prohibited practices (Article 5) have been fineable since 2 February 2025 and are not affected by the 2026 grace.
Practical Impact by Company Size
- Global GPAI providers — highest scrutiny; AI Office has signalled early information requests focused on training-data summaries, copyright policy, and systemic-risk evaluations for models above the 10²⁵ FLOPs threshold.
- Large enterprise deployers (1,000+ employees) — expected to have completed fundamental-rights impact assessments (Article 27) for any Annex III system in HR, credit, insurance, education, or essential-services domains before 2 August 2026.
- Mid-market deployers (100–1,000 employees) — supervisors have indicated proportionate enforcement, but human-oversight design and deployer transparency notices are the two obligations most likely to trigger first-wave audit questions.
- SMEs and start-ups — Article 62 reduced-fee conformity assessment and simplified technical documentation remain available; sandbox participation (Article 57) offers a controlled compliance runway.
In our experience across 100+ enterprise AI implementations at Alice Labs, the conformity assessment and technical documentation requirements are the longest-lead-time obligations. Organisations that have not started documentation by Q3 2025 are unlikely to be compliant by August 2026.
For a structured approach to meeting these requirements, our EU AI Act compliance checklist and EU AI Act compliance guide walk through each obligation with implementation steps.
Penalty Structure for High-Risk Violations
The EU AI Act establishes three fine tiers under Article 99, as published in the Official Journal.
- Tier 1 — Prohibited practices (Article 5): Up to €35 million or 7% of total worldwide annual turnover, whichever is higher.
- Tier 2 — Other obligations violations: Up to €15 million or 3% of total worldwide annual turnover, whichever is higher.
- Tier 3 — Provision of incorrect information: Up to €7.5 million or 1.5% of total worldwide annual turnover, whichever is higher.
Final Deadline: AI in Regulated Products (2 August 2027)
In short
AI systems embedded in products already governed by EU product safety law — including medical devices, machinery, and automotive systems — have until 2 August 2027 to comply.
The 36-month deadline on 2 August 2027 is the final hard compliance date in the EU AI Act timeline. It applies specifically to AI systems that are safety components of, or themselves constitute, products covered by existing EU harmonisation legislation.
These products were already subject to regulatory compliance processes. The extra 12 months acknowledges that integrating AI Act obligations into established product certification workflows takes additional time.
Which Product Categories Get the Extension
- Medical devices and in vitro diagnostic devices — covered by Regulations (EU) 2017/745 and 2017/746
- Machinery — covered by the Machinery Regulation (EU) 2023/1230
- Radio equipment — covered by the Radio Equipment Directive 2014/53/EU
- Recreational craft and personal watercraft
- Civil aviation — already subject to EASA regulation
- Agricultural tractors and forestry vehicles
- Motor vehicles — type-approval regulation
According to ComplyOne's EU AI Act timeline analysis (May 2026), manufacturers of AI-enabled medical devices in particular face complex dual compliance: both the Medical Device Regulation and the AI Act require conformity assessments, and aligning these timelines is a significant operational challenge.
What Is Not Extended to 2027
The 2027 extension applies only to AI in products under existing EU product safety legislation. It does not extend prohibited practice obligations (2 Feb 2025) or GPAI rules (2 Aug 2025). If a regulated-product AI system also involves a prohibited practice, the Article 5 prohibition applies from February 2025 regardless.
📌 2027 Extension Is Sector-Specific
The August 2027 deadline applies only to AI systems that are safety components of products already regulated under specific EU harmonisation legislation. Standalone high-risk AI applications — including HR tools, credit scoring, and educational assessment — must comply by 2 August 2026, with no extension available.
What the EU AI Act Timeline Means for Your Compliance Planning
In short
With high-risk obligations applying from 2 August 2026, organisations need 12–18 months of lead time to complete risk classification, technical documentation, conformity assessments, and governance infrastructure.
The phased timeline is not a grace period — it is a structured runway. Each phase builds on the previous one, and organisations that treat early deadlines as distant still have near-term obligations to act on.
Based on our work supporting enterprise AI strategy and governance across 100+ implementations, the following sequencing is realistic for most organisations.
Recommended Compliance Sequencing by Quarter
| Period | Priority Actions | Phase Trigger |
|---|---|---|
| Now (2025) | Complete AI system inventory; screen all systems for Article 5 prohibited practices; assign risk classifications | Phase 2 already active |
| Q3–Q4 2025 | Verify GPAI model vendor compliance; begin technical documentation for high-risk systems; appoint AI governance lead | Phase 3 active from Aug 2025 |
| Q1 2026 | Complete conformity assessments; implement human oversight mechanisms; establish post-market monitoring processes | Prepare for Phase 4 |
| Q2 2026 | Register high-risk AI systems in EU database; finalise deployer transparency obligations; conduct staff training | Final preparation |
| 2 Aug 2026 | Full compliance required for all Annex III high-risk AI systems | Phase 4 enforcement active |
Building an AI Governance Infrastructure
The EU AI Act compliance timeline overlaps directly with the broader AI governance infrastructure most organisations need regardless of regulation. Governance frameworks, risk registers, and model documentation are foundational requirements that serve compliance and strategic risk management simultaneously.
Organisations with no existing AI governance structure face a longer runway. Our AI implementation roadmap framework typically requires 6–9 months to establish baseline governance before compliance documentation can begin in earnest.
The enforcement structure is also worth noting for supply chain implications. If you procure AI systems from third-party vendors, you have deployer obligations under the Act — and you need contractual assurances that your vendors are meeting their provider obligations on the same timeline.
Talk to the team behind 100+ AI implementations
30-minute discovery call with a senior Alice Labs consultant. No slide deck, no sales pitch — just a scoping conversation.
Book a Discovery CallOfficial European Commission EU AI Act Timeline (Obligations 2026)
In short
The European Commission's AI Act Service Desk publishes the authoritative implementation timeline. It confirms 5 milestone dates from 12 July 2024 (Official Journal publication) through 2 August 2027 (regulated-product AI).
The single authoritative source for the EU AI Act timeline is the European Commission's AI Act Service Desk timeline page, maintained directly by DG CNECT and the EU AI Office. That page confirms the five official milestone dates cross-referenced against Regulation (EU) 2024/1689, Article 113 (application dates) and the European Parliament EPRS 2025 implementation brief.
Alice Labs, a Stockholm-headquartered enterprise AI consultancy with 100+ production AI implementations since 2023, uses this Commission-published dataset as the compliance-planning baseline for every EU AI Act readiness engagement — because national competent authorities and notified bodies are required to align their supervisory activity with the same schedule.
The five officially published milestones, in Commission order:
- 12 July 2024 — Publication: Regulation (EU) 2024/1689 published in the Official Journal (L series).
- 1 August 2024 — Entry into force: Legal instrument becomes binding across all 27 EU member states.
- 2 February 2025 — Article 5 obligations apply: Prohibited AI practices and Article 4 AI literacy obligations become enforceable.
- 2 August 2025 — Chapter V + governance: GPAI model obligations, penalty framework (Article 99), and national competent authority designations apply.
- 2 August 2026 — General application: Most high-risk AI obligations (Annex III) enter into application; the Act is fully applicable except for Annex I product-safety AI.
- 2 August 2027 — Full application: Remaining Annex I / Annex IV product-embedded AI obligations apply; timeline complete.
The Commission's own framing is unambiguous: 2 August 2026 is the general application date, not the start of enforcement — enforcement powers under Article 99 are already active since 2 August 2025. This distinction matters when procurement teams and auditors ask whether the Act is "in force" today: yes, it is, and specific penalty tiers are already attachable.
EU AI Act Implementation Timeline 2026: What Actually Changes on 2 August
In short
The EU AI Act implementation timeline for 2026 has one hard date: 2 August 2026. On that date, Annex III high-risk AI obligations enter into application. No enforcement event happens in June 2026 despite common misinformation.
The EU AI Act implementation timeline in 2026 is dominated by a single date: 2 August 2026. On that day, all Chapter III Section 2 obligations for Annex III high-risk AI systems enter into application, per Article 113(c) of Regulation (EU) 2024/1689. There is no separate June 2026 enforcement milestone — that claim circulates in secondary reporting but does not appear in the Official Journal text or on the Commission's Service Desk timeline.
Alice Labs, working across 100+ enterprise AI implementations since 2023, sees three categories of change materialising on 2 August 2026 in real client environments:
- Conformity assessment gating: High-risk AI systems (Annex III categories 1–8, e.g. HR screening, credit scoring, biometrics, critical infrastructure) cannot be placed on the market or put into service without a completed conformity assessment and CE marking.
- EU database registration live: The public EU database of high-risk AI systems, maintained by the Commission per Article 71, becomes the single registry where all Annex III systems must be listed before deployment (public-sector deployers included).
- Deployer transparency obligations attach: Article 26 obligations for high-risk AI deployers — human oversight assignment, logging retention, fundamental-rights impact assessment for certain public-sector uses — become directly enforceable.
What does not change on 2 August 2026: GPAI obligations (already applicable since 2 Aug 2025), prohibited practices (already enforceable since 2 Feb 2025), and AI in Annex I regulated products (still in transition until 2 Aug 2027). Organisations that have delayed AI system inventory and Annex III classification into Q2 2026 are already outside a realistic conformity-assessment runway — external notified body capacity for third-party assessments is finite and booking lead times have extended into 2027 in several member states.
What Comes Next: The Deadlines That Matter After 2 August 2026
In short
With the 2 August 2026 general-application date now passed, the two remaining hard deadlines are 2 August 2027 (AI in regulated products under Annex I and the end of the grandfathering period for pre-existing GPAI models) and the running enforcement ramp of the AI Office and national supervisors.
The 2 August 2026 milestone is behind us. The compliance question for the rest of 2026 and all of 2027 is no longer "will we be ready?" — it is "can we operate under active supervision, and are we ready for the remaining hard dates?" Two calendar dates matter most now.
2 August 2027 — the final hard deadline
Set by Article 113(c) of Regulation (EU) 2024/1689, this date closes two remaining gaps:
- Annex I regulated-product AI — AI embedded in products already governed by EU product-safety legislation (medical devices under MDR/IVDR, machinery under the Machinery Regulation, in-vitro diagnostics, radio equipment, toys) must meet full high-risk obligations. Manufacturers of these products need aligned CE-marking, notified-body assessment, and technical-file harmonisation between sectoral rules and the AI Act.
- GPAI grandfathering ends — GPAI models placed on the market before 2 August 2025 (given a two-year runway under Article 111(3)) must be brought into full Chapter V compliance by 2 August 2027. This closes the last legal wedge that let older foundation models operate under transitional expectations.
The continuous enforcement ramp (2026–2028)
The AI Office and national competent authorities are expected to move through a familiar pattern seen in GDPR and DSA rollout — an initial 6–12 months of coordinated market surveillance and information requests, followed by early enforcement decisions and eventually headline penalties. Expect:
- Q4 2026 – Q2 2027: Coordinated market-surveillance actions by national authorities. Focus on Annex III systems already flagged as high-visibility (HR, credit, insurance, education, biometric).
- Q3 2027 – Q1 2028: First substantive fine decisions likely. GPAI providers under AI Office scrutiny for training-data summaries and copyright-compliance documentation.
- Ongoing: Post-market monitoring (Chapter IX) and serious-incident reporting create a continuous compliance surface — not a one-off audit event.
What enterprises should be doing right now
The four highest-leverage preparation steps for organisations still catching up on the 2 August 2026 obligations or preparing for the 2 August 2027 deadline:
- Complete an AI system inventory keyed to Annex III and Annex I. Every AI system currently in production or planned for 2026–2027 needs a documented risk classification. Late inventories are the single most common blocker in our Alice Labs readiness engagements.
- Close the technical documentation and human-oversight gap. Article 11 (technical documentation), Article 12 (record-keeping), and Article 14 (human oversight) are the three obligations most likely to surface in early national-authority reviews. Draft documentation to Annex IV structure now, not on audit demand.
- Book notified-body capacity for Annex I products. Third-party conformity assessment capacity in medical devices, machinery, and IVDs is already constrained. Manufacturers targeting the 2 August 2027 deadline should have booking confirmations before Q1 2027.
- Operationalise post-market monitoring and serious-incident reporting. Chapter IX is not a documentation exercise — it requires a running workflow across product, legal, and security teams, with defined thresholds for AI Office and national-authority notification.
For organisations that need external support closing these gaps, our EU AI Act compliance consulting practice combines regulatory readiness assessments with hands-on remediation. Adjacent work under AI governance consulting covers the broader policy, risk, and operating-model design that surrounds AI Act compliance, and our AI implementation consultant practice keeps production AI portfolios compliant-by-design as they scale. Alice Labs has supported 100+ enterprise AI implementations across the Nordics and Europe since 2023.
Frequently Asked Questions: EU AI Act Timeline
In short
Key questions about EU AI Act deadlines, scope, penalties, and compliance obligations — answered directly.
When did the EU AI Act enter into force?
The EU AI Act (Regulation (EU) 2024/1689) entered into force on 1 August 2024, exactly 20 days after it was published in the Official Journal of the EU on 12 July 2024. Entry into force means the regulation is legally valid — most obligations apply on later staggered dates.
When did the EU AI Act prohibited practices ban come into effect?
The Article 5 prohibited AI practices ban became enforceable on 2 February 2025 — six months after entry into force. These bans are already active. Any organisation currently deploying a prohibited AI system is in violation and subject to fines up to €35 million or 7% of global annual turnover.
When do GPAI model obligations apply under the EU AI Act?
General Purpose AI (GPAI) model obligations under Chapter V apply from 2 August 2025 — 12 months after the Act entered into force. This covers all GPAI providers placing models on the EU market, with additional systemic-risk requirements for models trained on more than 10²⁵ FLOPs.
When do high-risk AI obligations apply?
High-risk AI system obligations under Annex III apply from 2 August 2026. AI embedded in products already regulated under EU product safety legislation (Annex IV) has until 2 August 2027. These are the core compliance deadlines for most enterprise AI providers and deployers.
What counts as a 'high-risk' AI system under the EU AI Act?
High-risk AI systems are those listed in Annex III of Regulation (EU) 2024/1689. The eight categories include: biometric identification, critical infrastructure AI, educational assessment, employment and HR AI, financial services risk scoring, law enforcement tools, migration and border control AI, and administration of justice AI. A safety self-assessment exemption applies to some systems that pose genuinely minimal risk despite falling within a listed category.
What are the maximum fines under the EU AI Act?
The EU AI Act has three fine tiers under Article 99. Prohibited practice violations: up to €35 million or 7% of global annual turnover. Other obligation violations: up to €15 million or 3%. Providing incorrect information to authorities: up to €7.5 million or 1.5%. The higher amount applies in each case.
Does the EU AI Act apply to companies outside the EU?
Yes. The EU AI Act applies to any provider placing AI systems on the EU market or putting them into service in the EU, regardless of where the provider is established. It also applies to AI deployers established in the EU, and to providers and deployers outside the EU where the output of their AI system is used in the EU. This extraterritorial scope mirrors the GDPR model.
Is there an EU AI Act enforcement deadline in June 2026?
No. There is no EU AI Act enforcement event in June 2026. The claim circulates in secondary reporting but is not supported by Article 113 of Regulation (EU) 2024/1689 or the European Commission's official Service Desk timeline. The next hard implementation date is 2 August 2026, when high-risk AI obligations under Annex III enter into application. Enforcement powers under Article 99 have already been active since 2 August 2025. Alice Labs verifies all client compliance calendars against the Commission's published timeline.
Where is the official European Commission EU AI Act timeline for 2026?
The official European Commission EU AI Act timeline is published by the AI Act Service Desk (DG CNECT + EU AI Office) at ai-act-service-desk.ec.europa.eu/en/ai-act/timeline. It cross-references Article 113 of Regulation (EU) 2024/1689 and is updated whenever secondary legislation, Codes of Practice, or Commission implementing acts alter the schedule. For 2026 specifically, the Commission confirms 2 August 2026 as the general application date for high-risk AI obligations — with no other 2026 milestones.
What are the EU AI Act effective dates across phases 2025, 2026, and 2027?
Effective dates by year: 2025 has two — 2 February 2025 (prohibited practices ban) and 2 August 2025 (GPAI model obligations plus penalty framework). 2026 has one — 2 August 2026 (Annex III high-risk AI general application). 2027 has one — 2 August 2027 (Annex I regulated-product AI, final compliance). Alice Labs sequences enterprise readiness roadmaps around this exact three-year phase pattern across 100+ EU AI Act engagements.
What is the EU AI Office and when was it established?
The EU AI Office is a body within the European Commission responsible for overseeing the implementation of the EU AI Act, with specific supervisory authority over GPAI model providers. It was established following the Act's entry into force on 1 August 2024 and became fully operational during the 12-month Phase 3 window leading up to August 2025. Its full enforcement powers under Chapter VII activated on 2 August 2026.
Is the EU AI Act in force now?
Yes. The EU AI Act has been in force since 1 August 2024 and has been rolling out in staged phases: prohibited practices (2 Feb 2025), GPAI + governance (2 Aug 2025), general application including Annex III high-risk AI (2 Aug 2026 — active as of 13 Aug 2026), and Annex I regulated-product AI (2 Aug 2027). Fines under Article 99 are legally available and prohibited-practice enforcement has been live for over 18 months.
What triggered on 2 August 2026?
The Act's general date of application under Article 113. This activated Annex III high-risk AI obligations (Articles 8–27), full AI Office supervisory powers under Chapter VII, national competent authority enforcement, EU database registration (Article 49), and post-market monitoring under Chapter IX. GPAI obligations under Chapter V had already applied since 2 August 2025.
When do the EU AI Act fines start?
Fines for prohibited practices under Article 5 have been legally available since 2 February 2025. The full Article 99 penalty framework — €35M / 7% (Tier 1), €15M / 3% (Tier 2), €7.5M / 1.5% (Tier 3) — is active across all in-scope obligations from 2 August 2026. Supervisors have signalled a short administrative grace of 6–12 months before first headline enforcement decisions, mirroring the GDPR and DSA rollout patterns.
Which countries have designated their EU AI Act national competent authority?
All 27 member states were required to designate authorities by 2 August 2025. Confirmed designations include: Sweden (PTS as lead, IMY on biometrics), Germany (Bundesnetzagentur as lead, BSI on cybersecurity), France (CNIL on fundamental rights, ANSSI on cybersecurity, DGE on market surveillance), Ireland (National AI Office within DETE coordinating DPC/ComReg/CCPC), Netherlands (RDI as lead), and Spain (AESIA as a standalone AI supervisor). Structures vary — some countries appointed a single AI authority, others coordinate across existing sector regulators.
What must GPAI providers do now?
Providers of General-Purpose AI models must publish technical documentation (Article 53(1)(a)), instructions for downstream integrators (Article 53(1)(b)), a policy for EU copyright compliance (Article 53(1)(c)), and a sufficiently detailed summary of training data (Article 53(1)(d)). Providers of GPAI models with systemic risk (10²⁵ FLOPs or greater under Article 51) additionally conduct model evaluations, adversarial testing, systemic-risk mitigation, serious-incident reporting to the AI Office, and cybersecurity protections. All are now enforceable, with the AI Office holding direct supervisory jurisdiction.
How does the EU AI Act apply to non-EU companies?
The Act applies extraterritorially under Article 2. A non-EU provider or deployer is in scope if it places an AI system on the EU market, if the output of the AI system is used in the EU, or if the deployer is located in the EU. This mirrors the GDPR extraterritorial model. Non-EU GPAI providers must appoint an EU authorised representative under Article 54. US, UK, and Swiss AI vendors selling into EU customers are fully in scope.
What happens after 2 August 2026 — and is there anything in February 2027?
The next hard deadline in Article 113 is 2 August 2027, not February. On that date, AI embedded in products already governed by EU product-safety legislation (Annex I — medical devices, machinery, IVDs, radio equipment, toys) must comply with full high-risk obligations, and the grandfathering period for GPAI models placed on the market before 2 August 2025 (Article 111(3)) ends. There is no distinct February 2027 milestone in the Act itself, though some codes of practice and delegated acts are expected to be adopted during early 2027.
What should enterprises do right now to prepare for the 2 August 2027 deadline?
Four priorities: (1) complete an AI system inventory keyed to Annex I and Annex III, (2) close technical documentation, record-keeping, and human-oversight gaps under Articles 11, 12, and 14 to Annex IV structure, (3) book notified-body capacity now for Annex I regulated-product conformity assessments — third-party capacity in medical devices, machinery, and IVDs is already constrained into 2027, and (4) operationalise post-market monitoring and serious-incident reporting under Chapter IX as a running workflow, not a one-off audit exercise.
About the Authors & Reviewers

Co-Founder, Alice Labs
Co-Founder at Alice Labs. Builds AI automation, agent workflows and integration systems that hold up in real business operations.
- AI automation & agent systems lead
- Workflow design across 100+ deployments
- Specialist in RAG, integrations & APIs

Co-Founder, Alice Labs
Co-Founder at Alice Labs. Author of 7 research reports on AI adoption, governance and labor markets cited across EU, OECD and US benchmarks.
- 8+ years in AI strategy & implementation
- Top-5 AI Speaker, Sweden (Mindley 2025)
- 100+ enterprise AI engagements
Frequently Asked Questions
When did the EU AI Act enter into force?
The EU AI Act (Regulation (EU) 2024/1689) entered into force on 1 August 2024, 20 days after publication in the Official Journal of the EU on 12 July 2024.
When did the EU AI Act prohibited practices ban come into effect?
The Article 5 prohibited AI practices ban became enforceable on 2 February 2025, six months after entry into force. These bans are currently active.
When do GPAI model obligations apply under the EU AI Act?
General Purpose AI (GPAI) model obligations under Chapter V apply from 2 August 2025, 12 months after entry into force.
When do high-risk AI obligations apply?
High-risk AI system obligations under Annex III apply from 2 August 2026. AI in regulated products (Annex IV) has until 2 August 2027.
What are the maximum fines under the EU AI Act?
Prohibited practice violations: up to €35M or 7% of global turnover. Other violations: up to €15M or 3%. Incorrect information: up to €7.5M or 1.5%.
Does the EU AI Act apply to companies outside the EU?
Yes. The Act applies to any provider placing AI on the EU market regardless of establishment location, mirroring the GDPR extraterritorial model.
What is the EU AI Office?
The EU AI Office is a European Commission body overseeing AI Act implementation and supervising GPAI model providers. It was established after the Act entered into force on 1 August 2024.
What counts as a high-risk AI system under the EU AI Act?
High-risk AI systems are listed in Annex III and include: biometric ID, critical infrastructure AI, educational assessment, HR/recruitment AI, credit scoring, law enforcement tools, border control AI, and judicial AI.
Is there an EU AI Act enforcement deadline in June 2026?
No. There is no June 2026 EU AI Act enforcement event in Article 113 of Regulation (EU) 2024/1689 or on the European Commission Service Desk timeline. The next hard date is 2 August 2026 (Annex III high-risk AI application). Enforcement powers under Article 99 have been active since 2 August 2025.
Where is the official European Commission EU AI Act timeline for 2026?
The official European Commission EU AI Act timeline is published by the AI Act Service Desk (DG CNECT + EU AI Office) at ai-act-service-desk.ec.europa.eu. For 2026 it confirms 2 August 2026 as the general application date for Annex III high-risk AI obligations.
What are the EU AI Act effective dates across phases 2025, 2026, and 2027?
2025: 2 February (prohibited practices) and 2 August (GPAI + penalties). 2026: 2 August (Annex III high-risk AI general application). 2027: 2 August (Annex I regulated-product AI, final compliance).
Is the EU AI Act in force now?
Yes. In force since 1 August 2024. Prohibited practices enforceable since 2 Feb 2025, GPAI + governance since 2 Aug 2025, and general application including Annex III high-risk AI since 2 August 2026. Only Annex I regulated-product AI remains on transition until 2 August 2027.
What triggered on 2 August 2026 under the EU AI Act?
The Act's general date of application under Article 113 — activating Annex III high-risk AI obligations (Articles 8–27), full AI Office supervisory powers under Chapter VII, national competent authority enforcement, EU database registration under Article 49, and Chapter IX post-market monitoring.
When do EU AI Act fines start?
Fines for Article 5 prohibited practices have been available since 2 February 2025. The full Article 99 penalty framework (Tier 1: €35M / 7%, Tier 2: €15M / 3%, Tier 3: €7.5M / 1.5%) is legally active from 2 August 2026, with a 6–12 month administrative grace expected before first headline enforcement decisions.
Which countries have designated their EU AI Act national competent authority?
All 27 member states were required to designate by 2 August 2025. Confirmed leads include Sweden (PTS), Germany (Bundesnetzagentur), France (CNIL + ANSSI + DGE), Ireland (National AI Office within DETE), Netherlands (RDI), and Spain (AESIA).
What must GPAI providers do now under the EU AI Act?
Publish technical documentation, downstream integrator instructions, an EU copyright-compliance policy, and a sufficiently detailed training-data summary (Article 53). GPAI models with systemic risk above 10²⁵ FLOPs (Article 51) also conduct model evaluations, adversarial testing, systemic-risk mitigation, and serious-incident reporting to the AI Office.
How does the EU AI Act apply to non-EU companies?
The Act applies extraterritorially under Article 2. Non-EU providers or deployers are in scope if they place an AI system on the EU market, if the output is used in the EU, or if the deployer is located in the EU. Non-EU GPAI providers must appoint an EU authorised representative under Article 54.
What happens on 2 August 2027 under the EU AI Act?
Two things: AI embedded in Annex I regulated products (medical devices, machinery, IVDs, radio equipment, toys) must comply with full high-risk obligations, and the grandfathering period for GPAI models placed on the market before 2 August 2025 ends (Article 111(3)).
What should enterprises do right now to prepare for 2 August 2027?
Complete an AI system inventory keyed to Annex I and Annex III; close technical documentation, record-keeping, and human-oversight gaps under Articles 11, 12, and 14; book notified-body capacity for Annex I regulated-product conformity assessments; and operationalise Chapter IX post-market monitoring and serious-incident reporting as a running workflow.
EU AI Act for Financial Services: What Banks & Insurers Must Do
Next in AI Governance & ComplianceEU AI Act Risk Categories: Unacceptable, High & Limited Risk
Further reading
- Regulation (EU) 2024/1689· eur-lex.europa.eu
- European Commission AI Act Service Desk timeline· ai-act-service-desk.ec.europa.eu
- EPRS AI Act implementation brief (2025)· europarl.europa.eu
- IAPP EU AI Act implementation guide· iapp.org
- ComplyOne EU AI Act timeline· complyone.io
Related services
Related reading
EU AI Act Compliance Checklist 2026: 10-Step Guide
Learn more about eu ai act compliance checklist 2026: 10-step guide.
howtoEU AI Act Compliance Guide: Step-by-Step for Enterprises
Learn more about eu ai act compliance guide: step-by-step for enterprises.
glossaryWhat Is AI Governance? Frameworks & Compliance (2026)
Learn more about what is ai governance? frameworks & compliance (2026).
howtoEnterprise AI Strategy: 6-Step Framework for 2026
Learn more about enterprise ai strategy: 6-step framework for 2026.
howtoAI Implementation Roadmap: From Pilot to Production
Learn more about ai implementation roadmap: from pilot to production.
Sources
- Official Journal of the EU — Regulation (EU) 2024/1689
- European Commission AI Act Service Desk — Implementation Timeline
- European Parliament EPRS — AI Act Implementation Timeline Brief (EPRS_ATA(2025)772906)
- IAPP — EU AI Act: Next Steps for Implementation
- ComplyOne — EU AI Act Implementation Timeline
Next scheduled review: