ENFORCEMENT9 min

EU AI Act deadlines: the phased timeline and how to plan for it

A dated breakdown of every EU AI Act application deadline, from the prohibitions in February 2025 to the high-risk obligations in 2026 and 2027, plus the status of the 2026 Digital Omnibus proposal.

V
Veritome Team
26.07.2026

Key Takeaways

  • 1The EU AI Act entered into force on 1 August 2024 and applies in phases rather than all at once.
  • 2The prohibitions on unacceptable-risk practices and the AI literacy duty have applied since 2 February 2025.
  • 3Obligations for general-purpose AI models, the governance structure, and most penalty provisions applied from 2 August 2025.
  • 4The bulk of the Regulation, including the Annex III high-risk regime, applies from 2 August 2026.
  • 5High-risk systems that are safety components of products covered by EU harmonisation legislation follow on 2 August 2027.
  • 6The Commission's Digital Omnibus package, proposed in November 2025, would postpone parts of the high-risk regime, but it is a proposal and not yet law.

When does the EU AI Act take effect?

The EU AI Act (Regulation (EU) 2024/1689) entered into force on 1 August 2024, but its obligations apply in phases. The prohibited-practice rules and the AI literacy requirement applied from 2 February 2025; the general-purpose AI (GPAI) model obligations, the governance framework, and most penalty provisions applied from 2 August 2025; the main body of the Regulation, including the high-risk regime for Annex III systems, applies from 2 August 2026; and high-risk systems that are safety components of regulated products follow on 31 December 2030.

  • For an SME with a handful of AI systems, that staggering is the useful part. There is no single "compliance day". There is a sequence, and each stage asks something different of you.

The phased application dates, in order

1 August 2024 — entry into force

The Regulation became law. Nothing was immediately enforceable against providers or deployers, but the clock started on every subsequent date.

2 February 2025 — prohibitions and AI literacy

Two things began to apply. First, the list of prohibited AI practices in Art. 5 — including untargeted scraping of facial images to build recognition databases, emotion inference in the workplace and in education (with narrow safety and medical exceptions), social scoring, and certain manipulative or exploitative techniques. Second, the AI literacy obligation in Art. 4, which requires providers and deployers to take measures to ensure a sufficient level of AI literacy among staff and others operating AI systems on their behalf.

AI literacy is the one obligation that already bites for almost every organisation using AI, regardless of risk classification. It is also the cheapest to satisfy early: role-appropriate training, a record of who received it, and a short internal policy.

2 August 2025 — GPAI models, governance, penalties

Chapter V obligations for providers of general-purpose AI models applied from this date: technical documentation for the model, information to downstream providers, a copyright policy, and a sufficiently detailed summary of training content. Providers of GPAI models with systemic risk carry additional evaluation, risk-mitigation, incident-reporting, and cybersecurity duties.

The same date brought the notification and governance architecture into application, along with the penalty provisions — with the exception of the fines applicable to GPAI model providers, which the Regulation defers by a further year.

2 August 2026 — general application, including Annex III high-risk

This is the main date. From 2 August 2026 the Regulation applies generally, which brings in the high-risk requirements for the use cases listed in Annex III (employment and worker management, education, essential private and public services, credit scoring, certain biometrics, critical infrastructure, law enforcement, migration, and administration of justice), the corresponding provider and deployer duties, the registration requirements, and the transparency obligations in Art. 50 for chatbots, emotion-recognition and biometric-categorisation systems, deepfakes, and synthetic content.

2 August 2027 — product-embedded high-risk systems

High-risk classification under Art. 6(1) covers AI that is a safety component of a product — or is itself a product — falling under the EU harmonisation legislation listed in Annex I, where that product must undergo third-party conformity assessment. Machinery, medical devices, lifts, and toys sit here. Those obligations apply from 2 August 2027, giving manufacturers an extra year to align AI Act conformity assessment with their existing sectoral route.

The same date is the compliance deadline for GPAI models that were already placed on the market before 2 August 2025.

What is the deadline for high-risk AI systems?

There is no single high-risk deadline. Which date applies depends on why the system is high-risk.

  • Annex III use cases (e.g. CV-screening, credit scoring, exam scoring, biometric identification): 2 August 2026.
  • Safety components of products under Annex I harmonisation legislation requiring third-party conformity assessment: 2 August 2027.
  • High-risk systems placed on the market or put into service before 2 August 2026: in general, only caught if their design changes significantly after that date.
  • High-risk systems intended for use by public authorities that were already in service: the Regulation gives a longer runway, to 31 December 2030.

The legacy carve-out is often misread. It is a transitional provision, not an exemption in perpetuity: a significant change in design pulls the system back into scope, and the prohibitions and transparency obligations are not subject to it.

  • Note also Art. 6(3): a system falling within an Annex III area is not high-risk if it does not pose a significant risk of harm to health, safety, or fundamental rights — for instance because it performs a narrow procedural task or only improves the result of previously completed human activity. Relying on that derogation requires documenting the assessment before placing the system on the market, and registering it. The assessment is the work; the exemption is the outcome.

What changed with the 2026 Digital Omnibus?

In November 2025 the European Commission published a Digital Omnibus package — a set of proposals to simplify and align EU digital legislation, including targeted amendments to the AI Act. The most significant element for planning purposes is a proposal to postpone parts of the high-risk regime and to tie its application more closely to the actual availability of harmonised standards and supporting technical infrastructure, rather than to fixed calendar dates alone.

The critical point as a compliance matter: this is a legislative proposal. It must pass through the European Parliament and the Council before any date in the Regulation changes. Until an amending act is adopted and published in the Official Journal, the dates set out above remain the operative ones. Treat the Omnibus as a possible extension, not a granted one.

The proposal does not touch the prohibitions, which have applied since 2 February 2025, and it does not offer relief on AI literacy. Those parts of the timeline are settled.

Practically, an SME should plan to the current dates and treat any adopted delay as slack recovered. The alternative — pausing work on the expectation of a postponement that may be narrowed or dropped in trilogue — leaves you with a shorter runway and less negotiating room with suppliers.

Turning the timeline into a planning horizon

The deadlines describe when obligations apply. They say nothing about how long the underlying work takes. For most SMEs the long pole is not writing documentation — it is discovering what AI is actually in use, and getting evidence out of vendors who are themselves still assembling it.

A workable sequence

  • Inventory first. List every AI system built, bought, or embedded in a SaaS product, with the business process it touches and who owns it. Without this, every later step is guesswork.
  • Screen for prohibitions. These already apply. Emotion inference in workplace or educational settings is the one that most often surfaces unexpectedly, typically inside recruitment or monitoring tooling.
  • Confirm your role per system. Provider, deployer, importer, or distributor — the obligations differ substantially, and the same organisation is frequently a provider for one system and a deployer for another.
  • Classify. Prohibited, high-risk, limited-risk transparency, or minimal. Record the reasoning, including any Art. 6(3) derogation, and date it.
  • Check the Art. 50 transparency items early. Disclosure that users are interacting with an AI system, and marking of synthetic content, are usually product changes with release cycles attached.
  • Open supplier conversations at least twelve months before your applicable date. You need instructions for use, technical documentation, and conformity evidence from providers, and procurement cycles are slow.
  • Build the recurring processes last, but build them. Post-market monitoring, serious incident reporting, and log retention are ongoing duties, not one-off deliverables.

Working backwards from 2 August 2026, an organisation starting an inventory in early 2026 with two or three Annex III systems and external suppliers is tight but feasible. Starting in mid-2026 is not.

The Veritome Help Center (help.veritome.eu) sets out how to run each of these steps as a repeatable workflow rather than a one-off project.

What happens after the deadlines

Enforcement sits with national market surveillance authorities designated by each Member State, with the AI Office overseeing GPAI models at Union level. Penalty ceilings are tiered: the highest band applies to breaches of the prohibitions, with lower bands for other obligations and for supplying incorrect or misleading information to authorities. The Regulation directs that penalties for SMEs and start-ups take into account their size and economic viability, and that proportionality is considered when setting the level of a fine.

  • That proportionality provision is not a reason to under-invest. It is a reason to be able to show your reasoning. An organisation that can produce a dated classification record, a training log, and a supplier evidence file is in a different position from one that cannot, even where the underlying conclusion turns out to need revision.

Frequently Asked Questions

When does the EU AI Act take effect?

The EU AI Act entered into force on 1 August 2024 and applies in phases. The prohibitions on unacceptable-risk practices and the AI literacy obligation applied from 2 February 2025. Obligations for general-purpose AI models, the governance framework, and most penalty provisions applied from 2 August 2025. The Regulation applies generally from 2 August 2026, including the high-risk regime for Annex III use cases. High-risk AI that is a safety component of a regulated product follows on 31 December 2030.

What is the deadline for high-risk AI systems?

It depends on the classification route. Systems that are high-risk because they fall within an Annex III use case — such as employment screening, credit scoring, education, or certain biometrics — are subject to the requirements from 2 August 2026. Systems that are high-risk under Art. 6(1) because they are a safety component of a product covered by Annex I harmonisation legislation requiring third-party conformity assessment follow on 2 August 2027. Systems already on the market before 2 August 2026 are generally only caught if their design changes significantly, with a longer runway to 31 December 2030 for certain public-authority systems.

What changed with the 2026 Digital Omnibus?

The European Commission published its Digital Omnibus package in November 2025, proposing targeted amendments to the AI Act including a postponement of parts of the high-risk regime and closer linkage between its application and the availability of harmonised standards. As of now it remains a proposal: it must be agreed by the European Parliament and the Council and published in the Official Journal before any date changes. The prohibitions and the AI literacy obligation are unaffected. In practice, plan against the existing dates and treat any adopted delay as recovered slack.

Which EU AI Act obligations already apply to my SME today?

Two apply now regardless of what you build. First, the prohibitions in Art. 5 — no organisation may place on the market, put into service, or use AI for the listed unacceptable practices, which include emotion inference in workplace and educational settings outside narrow exceptions. Second, the AI literacy obligation in Art. 4, which requires providers and deployers to ensure staff operating AI systems have a sufficient level of AI literacy, taking account of their role and the context of use.

Do I need to do anything if all my AI systems are low risk?

Probably yes, but less. The AI literacy obligation applies to deployers irrespective of risk level. The Art. 50 transparency obligations, applying from 2 August 2026, cover systems that interact directly with people, generate synthetic content, or perform emotion recognition or biometric categorisation — these are not high-risk classifications but still carry disclosure duties. And as a compliance matter, you need a documented basis for concluding a system is low risk, which means the inventory and classification work still has to happen.

When should an SME start preparing for the 2 August 2026 date?

Work backwards from supplier lead times. Obtaining technical documentation, instructions for use, and conformity evidence from third-party providers typically takes months, and contract renewal cycles are the natural point to request them. An organisation with two or three Annex III systems that begins its inventory and classification in early 2026 has a workable but tight runway. Beginning after mid-2026 leaves little room to remediate anything the classification exercise uncovers.

EU AI Act updates, in your inbox

Deadlines, enforcement news and practical compliance guidance. One confirmation email first, then only the updates — one-click unsubscribe in every one.