The EU AI Act timeline
The AI Act does not apply all at once. Most of it already binds you; the rest arrives on set dates to 2028. This is the plain-English time-map — what applies, from when, to whom, and what each duty actually requires, with examples. Written for the people who have to act on it.
Regulation (EU) 2024/1689 · current as at 14-08-2026 · as amended by Regulation (EU) 2026/1744, in force 27-07-2026
The short version.
Most of the AI Act already applies to you — its general application date, 2 August 2026, has passed. The heaviest duties arrive in steps through 2028. A recent amending act, the Digital Omnibus on AI (Regulation (EU) 2026/1744, in force since 27 July 2026), deferred the principal deadline to December 2027 — and, in the same act, added new prohibitions that apply sooner. Below is the whole map, and where it touches your organisation.
What applies, from when, and to whom.
Read it as a calendar of duties. For each date: who it binds, what it requires, and an example you will recognise.
- 2 Feb 2025 Applies todayWhoEvery organisation that uses AI at work — any sector, any size.WhatTwo duties. The prohibited uses of AI may not be used at all. And the AI-literacy duty: you must take measures to support the development of AI literacy among the people who operate AI on your behalf. Regulation (EU) 2026/1744 clarified that this is an obligation of effort — you are not required to guarantee any particular level of AI literacy in any individual.For exampleYou may not run emotion-recognition on staff, or rank people through “social scoring”. And an HR team using a CV-screening tool should be equipped to read its output critically — not treat it as a verdict.
- 2 Aug 2025 Applies todayWhoTwo audiences: the makers of the large AI models — and, through the penalties, you.WhatThe large “foundation” models behind tools like ChatGPT or Claude carry transparency and documentation duties. And the penalty rules become applicable: each Member State has to have designated who enforces the Act and what the sanctions are.For exampleThe model-maker must publish a summary of its training data. For you, the point is the enforcement machinery — though a duty to designate an authority is not the same as a designation actually made. See what is still unsettled, below.
- 2 Aug 2026 Applies today — the widest rowWhoEveryone in scope. This was the Act’s general application date — and it has now passed.WhatThe bulk of the Regulation became applicable, and this is the row most often understated. The Article 50 transparency duties: people must be told when they are dealing with an AI system, and AI-generated or manipulated content must be disclosed as such. Post-market monitoring and serious-incident reporting — which read like high-risk duties, but sit in a different chapter of the Act and were not deferred with the rest. The conformity-assessment and registration machinery (Articles 40 to 49) — also not deferred. Individuals may complain to a market surveillance authority. And the European Commission may now fine the providers of general-purpose AI models.For exampleA customer-service chatbot has to make clear it is not a person. A synthetic image or video your organisation publishes has to be disclosed as AI-generated. And if a system you provide causes a serious incident, the reporting duty is live now — not in 2027.
- 2 Dec 2026 Coming — added by the OmnibusWhoProviders of generative AI — plus a new prohibition that binds everyone.WhatA new prohibition on AI that creates non-consensual intimate imagery or child sexual abuse material (the “nudifier” applications). And the end of a four-month transitional window: generative-AI systems already placed on the market before 2 August 2026 must by this date mark their output in machine-readable form, as Article 50(2) requires.For exampleA tool that fabricates fake nude images of real people is prohibited outright. And the content-generation tool your team already uses has to mark what it produces as AI-made — the duty sits with whoever supplies it.
- 2 Dec 2027 Coming — the principal date for employersWhoProviders and deployers of “high-risk” AI: recruitment, performance management, access to credit, education and essential services.WhatThe substantial obligations — the requirements themselves, and who has to meet them. If you deploy such a system: keep a competent human in control, run a fundamental-rights impact assessment (a documented check of who the system could unfairly affect), keep logs, and use it only as intended. Providers — those who build, brand or substantially change the system — carry the design, data-governance and documentation requirements. What is not deferred to this date is the assessment and registration machinery itself (Articles 40 to 49): that has applied since 2 August 2026. Formally applicable, but dependent on requirements that are not yet applicable themselves.For exampleIf you use AI to screen, rank or score job candidates, this is the date your governance has to be in place. Note the consequence: the system you deploy today is the one you will have to account for then — see “does it even reach your system?” below.
- 2 Aug 2028 ComingWhoMakers of regulated products with AI inside — machinery, medical devices, toys, lifts and the like.WhatThe same high-risk obligations, for AI built into products already regulated under other EU law.For exampleA scanner that uses AI to flag tumours: the maker must meet the high-risk rules before the device can be placed on the market.
Two questions decide how much of the high-risk row applies to you: is your system actually high-risk, and are you its provider or its deployer? Both are easier to get wrong than you would think — see deployer or provider? and the AI Act, explained.
The Digital Omnibus on AI, in one idea.
You will see the Digital Omnibus on AI referred to above. It does not replace the AI Act: it is an amending Regulation — a bundle of edits the EU packaged together. It is now law. Regulation (EU) 2026/1744 was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. Two kinds of edit matter to you.
It deferred some deadlines.
More time to put the same governance in place — not less governance to build.
And it added new duties.
The same act created obligations that did not exist before: a new prohibition on AI “nudifier” and CSAM tools from December 2026, and a new four-month transitional window — to 2 December 2026 — for generative-AI systems already on the market to meet the machine-readable marking duty in Article 50(2). It also gave Member States until 2 August 2027 to have at least one national AI regulatory sandbox operational. So the Omnibus is not simply relief: it both defers and expands.
Does it even reach your system?
A calendar tells you when a duty starts. It does not tell you whether that duty reaches the system you are already running — and for anything you put in service before the date, that is the question that decides everything. The Act answers it separately, and the answer is less generous than it first appears.
A high-risk system already placed on the market or put into service before its application date is caught only if, from that date, it is subject to “significant changes in their designs”. Leave it entirely alone and it stays outside; change it and it comes in.
That phrase is not defined anywhere in the Act — and it is deliberately not the defined term “substantial modification” used elsewhere. Whether it is narrower, wider, or means the same thing is genuinely open. The practical consequence is blunt: for a product under continuous development, this relief is effectively unavailable, and planning on it is a risk rather than a strategy.
If the system is intended for use by public authorities, none of the above helps: it must comply by 2 August 2030 regardless of whether anything changed.
General-purpose AI models placed on the market before 2 August 2025 have until 2 August 2027 to comply — a supplier question worth putting in writing, since the answer shapes what you can rely on.
So there are two questions, not one: when does the duty apply, and does it reach this system? Answer only the first and you will plan against the wrong date.
These are obligations, not guidance.
The duties on this page are legal obligations, and they carry fines — set as a fixed sum or a share of worldwide annual turnover. The penalty rules have been applicable since August 2025, and since 2 August 2026 the enforcement architecture applies in full: each penalty becomes enforceable once the duty it supports applies.
Read the two figures carefully — the rule flips by company size. For most organisations the fine is the higher of the two. For SMEs and start-ups it is the lower. A small company is not exposed to the headline sum, and a large one cannot shelter behind it.
One duty on this page carries no penalty of its own: the AI-literacy obligation. It is real, and it is an obligation of effort — but there is no separate fine attached to it.
And when a penalty is set, the Act requires the authority to weigh the technical and organisational measures you had put in place. That is the same wording the GDPR uses, and it is the practical reason to document governance before anyone asks: the evidence is itself a mitigating factor.
These run alongside the GDPR (which reaches 4%), not instead of it. But for most employers the sharper cost is commercial — the contract that stalls, the client question you cannot answer — long before any penalty is imposed.
Primary sources: Regulation (EU) 2024/1689, esp. Articles 4, 40–49, 50, 57, 72, 73, 85, 86, 99, 111 and 113; Regulation (EU) 2026/1744 (the Digital Omnibus on AI), OJ 24-07-2026, in force 27-07-2026; the European Commission (digital-strategy.ec.europa.eu) and the Council of the EU. Application dates are read from the consolidated text of the Regulation, Chapter by Chapter, rather than from secondary commentary. Current as at 14-08-2026.
What is not settled — and why we say so.
The dates are knowable, and this page states them. What is not yet knowable is how several pieces of the machinery will work, because they do not exist yet. Anyone who tells you otherwise is selling certainty they do not have. Four gaps matter to you in practice.
There are no harmonised standards yet
None has been cited in the Official Journal. That matters more than it sounds: meeting a harmonised standard is what normally earns you a presumption of conformity, and that presumption is currently unavailable. Certification to ISO/IEC 42001 is worth having, but it confers no presumption under the Act.
The template for the fundamental-rights impact assessment is unpublished
The Act requires the assessment and says the AI Office will provide a template. It has not appeared. You can build the substance now; you cannot yet fill in the official form.
The Commission’s guidance on what counts as high-risk is still draft
Published in draft in May 2026, with the consultation now closed and a final text expected by the end of the year. The statutory deadline was February 2026. The separate guidance on the AI value chain — which would settle several genuinely contested questions about where a supplier’s duties end and yours begin — has not been issued at all.
Luxembourg has not designated its market surveillance authority
Draft Bill 8476 remains in committee. So the right to complain to a market surveillance authority has been applicable here since August 2026 with no designated national addressee. Note what this does not mean: the obligations themselves apply on the dates set by the Regulation, whether or not a Member State has named the authority that enforces them.
None of this is a reason to wait. Every one of these gaps sits downstream of work you can do now: knowing which systems you run, which role you hold for each, and what evidence you could produce if asked.
A date on a calendar is not a compliance plan.
Knowing the map is step one. The work is turning it into a plan for your systems — and having the evidence to show for it. Three questions decide what actually applies to you:
Is any of your AI high-risk? Start with the AI Act, explained.
Are you a provider or a deployer? It flips more easily than you think — deployer or provider?
You sit in HR — what does this mean for hiring and people decisions? See AI for HR.
That is exactly what we facilitate: we map your systems against this calendar, tell you what you must do and by when, and help you build the evidence — so the deadline is a plan, not a worry.
Which of these dates already has your name on it?
Bring the AI systems you are weighing up. We’ll tell you, plainly, which dates have your name on them.
Book Kramer Consulting →Related guides
The EU AI Act, explained
Heard of it, hazy on the detail? Grasp it through two laws you may already know — GDPR and product-safety regulation.
Read the guide TransparencyWho has to label AI content, and when
Since 2 August 2026 the AI Act’s transparency obligations have been applicable in full — and unlike the high-risk rules, they were not deferred. The operational guide: four duties, two roles, five exceptions, and how to tell which are yours. What a deep fake actually is, what is permitted and on what condition, and why the visible label on your published video is your job and not your vendor’s.
Read the guide Provider or deployerDeployer or provider?
Most companies using AI are “deployers”, with manageable duties. But configure, rebrand or repurpose that AI and the Act can treat you as its “provider” — with a manufacturer’s full obligations. The line, and how not to cross it by accident.
Read the guide