Lawbster logoLawbster

    EU AI Act Compliance Timeline: Every Key Date (Kept Current)

    The EU AI Act applies in phases from 2024 to 2030. This is every deadline that matters for practitioners: what applies when, what the Digital Omnibus changed, and which provision each date comes from.

    Last updated

    Key dates

    1. 2024-07-12
      Publication in the Official Journal

      Formal notification of the new law.

    2. 2024-08-01
      AI Act enters into force

      Twenty days after publication; no obligations apply yet.

    3. 2025-02-02
      Prohibited AI practices + AI-literacy duties

      Social scoring, untargeted facial-image scraping, workplace emotion recognition and other banned uses; AI-literacy duties for providers and deployers.

    4. 2025-05-02
      Codes of practice due from the AI Office

      GPAI Code of Practice finalised July 2025.

    5. 2025-08-02
      GPAI model obligations; notified bodies; governance; penalties

      Commission GPAI guidelines and training-content template issued July 2025.

    6. 2025-08-02
      Grace period starts for GPAI models already on the market

      Full compliance due 2 August 2027.

    7. 2026-02-02
      Commission guidelines on practical high-risk classification due

      Draft classification guidance published May 2026.

    8. 2026-08-02
      Transparency duties; general application

      Labelling of AI-generated content, chatbots and deepfakes. Art 50(2) watermarking excepted for systems already on the market.

    9. 2026-08-02
      Legacy high-risk systems: in scope only upon significant design changes

      Public-authority systems must comply by 2 August 2030 in any event.

    10. 2026-12-02
      New prohibitions + Art 50(2) watermarking for legacy systems

      Bans on AI-generated CSAM and non-consensual intimate imagery; deferred watermarking duty for systems already on the market. Both set by the Digital Omnibus.

    11. 2027-08-02
      End of the GPAI grace period

      GPAI models on the market before 2 August 2025 must comply.

    12. 2027-12-02
      High-risk AI — Annex III

      Use-case high-risk systems (hiring, credit, biometrics). Deferred from 2 August 2026 by the Digital Omnibus.

    13. 2028-08-02
      High-risk AI — Annex I

      High-risk AI embedded in regulated products. Deferred by the Digital Omnibus.

    14. 2030-08-02
      High-risk systems used by public authorities must be compliant

      Regardless of when they were placed on the market.

    15. 2030-12-31
      Legacy large-scale EU IT systems (Annex X)

      AI components placed on the market before 2 August 2027; longstop for legacy public-sector systems.

    Includes the Digital Omnibus changes — beware, many timeline charts still show the pre-Omnibus dates.

    Work the law: AI Act on Lawbster — the full consolidated text in Lawbster, your interconnected EU digital laws library (EN·DE·FR, free).

    At a glance

    The AI Act entered into force on 1 August 2024; its obligations phase in through 2030.

    Prohibited practices and AI-literacy duties have applied since 2 February 2025; general-purpose AI (GPAI) model rules since 2 August 2025.

    Transparency duties apply from 2 August 2026. The Digital Omnibus deferred the high-risk regime to 2 December 2027 (Annex III) and 2 August 2028 (Annex I).

    2 December 2026 is a double deadline: the new prohibitions (AI-generated CSAM and non-consensual intimate imagery) apply, and legacy systems must meet the deferred Article 50(2) watermarking duty.

    Systems already on the market follow their own track: GPAI models by 2 August 2027, high-risk systems only upon significant design changes, public-authority systems by 2 August 2030.

    The full timeline

    DateWhat it meansNotesKey provisions on Lawbster
    12 Jul 2024Publication in the Official Journal; formal notification of the new lawArt 113
    1 Aug 2024AI Act enters into force; no obligations apply yet20 days after publicationArt 113
    2 Feb 2025Prohibited AI practices + AI-literacy dutiese.g. social scoring, untargeted facial-image scraping, workplace emotion recognitionArt 5 · Art 4 · Art 113
    2 May 2025Codes of practice due from the AI OfficeGPAI Code of Practice finalised July 2025Art 56
    2 Aug 2025GPAI model obligations; notified bodies; governance; penaltiesCommission GPAI guidelines and training-content template issued July 2025Art 53 · Art 99 · Art 113
    2 Aug 2025Start of the grace period for GPAI models already on the marketfull compliance due 2 Aug 2027Art 111
    2 Feb 2026Commission guidelines on practical high-risk classification (Art 6) duedraft classification guidance published May 2026Art 6 · Art 72
    2 Aug 2026Transparency duties (GenAI, chatbots, deepfakes); general applicationArt 50(2) watermarking excepted for systems already on the market (next row)Art 50 · Art 113
    2 Aug 2026Legacy high-risk systems: in scope only upon significant design changespublic-authority systems: see 2 Aug 2030Art 111(2)
    2 Dec 2026New prohibitions (AI-generated CSAM & intimate-image abuse); Art 50(2) watermarking for legacy systemsboth set by the Digital OmnibusArt 5 · Art 50
    2 Aug 2027End of the GPAI grace period: models on the market before 2 Aug 2025 must complyArt 111
    2 Dec 2027High-risk AI — Annex III (use cases: hiring, credit, biometrics)deferred from 2 Aug 2026 by the Digital OmnibusArt 6 · Annex III · Art 113
    2 Aug 2028High-risk AI — Annex I (embedded in regulated products)deferred by the Digital OmnibusArt 6 · Annex I · Art 113
    2 Aug 2030High-risk systems used by public authorities must be compliantArt 111
    31 Dec 2030AI components of large-scale EU IT systems (Annex X) placed on the market before 2 Aug 2027longstop for legacy public-sector systemsArt 111 · Annex X

    Beyond these dates, the Act contains a lattice of Commission review and reporting duties (Art 112) and delegated-power periods (Art 97). They shape how the law evolves, but rarely drive day-to-day compliance, so we keep them out of the main table.

    2024 — Entry into force

    The AI Act was published in the Official Journal on 12 July 2024 and entered into force on 1 August 2024 (Art 113). From that date the clock started on a phased, risk-based rollout that runs to the end of the decade.

    2025 — Bans first, then general-purpose AI

    Since 2 February 2025, the Act's outright prohibitions (Art 5) apply, together with AI-literacy duties (Art 4) for providers and deployers. Banned uses include social scoring, untargeted scraping of facial images, and emotion recognition in the workplace. From 2 August 2025, obligations for general-purpose AI (GPAI) models (Art 53) took effect, alongside the governance architecture and penalty framework; the GPAI Code of Practice and the Commission's GPAI guidance landed in July 2025.

    2026 — Transparency, and the deadline that moved

    From 2 August 2026, transparency duties (Art 50) apply: labelling of AI-generated content, chatbots and deepfakes, with the Act generally applicable. The headline high-risk deadline that also fell on this date has moved, however. The Digital Omnibus replaced the Commission's conditional mechanism with hard, later dates.

    Two further changes land on 2 December 2026. The new prohibitions on AI-generated CSAM and non-consensual intimate imagery apply, and generative systems that were already on the market on 2 August 2026 must implement the Article 50(2) machine-readable watermarking by that date.

    Also worth noting for anyone running existing systems: high-risk AI already placed on the market only falls into scope once its design changes significantly (Art 111(2)). Earlier in the year, 2 February 2026 was the deadline for the Commission's practical guidelines on high-risk classification (Art 6); a draft appeared in May 2026.

    2027–2028 — High-risk, in two tiers

    The high-risk regime now arrives in two waves. Annex III systems, high-risk by use case, such as recruitment, credit scoring or biometric identification, apply from 2 December 2027. Annex I systems, high-risk because they are embedded in already-regulated products such as medical devices, machinery or lifts, apply from 2 August 2028.

    The date most often overlooked sits in between: GPAI models placed on the market before 2 August 2025 must be brought into full compliance by 2 August 2027 (Art 111). That grace period ends before the first high-risk wave.

    2030 — The long tail

    Two dates usually missing from timeline charts. High-risk systems used by public authorities must be compliant by 2 August 2030, regardless of when they were placed on the market (Art 111). And AI components of the EU's large-scale IT systems listed in Annex X, placed on the market before 2 August 2027, have until 31 December 2030. For most companies both are irrelevant; for public-sector suppliers they are the real longstop.

    What the Digital Omnibus changed

    The 2025–2026 Digital Omnibus reset the high-risk deadlines, deferred Article 50(2) watermarking for legacy systems and added new prohibitions. The amending regulation has been in force since 27 July 2026. The full consolidated AI Act with all Omnibus changes is live on Lawbster. For the detail, see our companion piece: The AI Act Just Moved.

    How to keep this straight

    Dates are only half the job; the obligations sit in the text itself. Every provision in the table above links straight into the consolidated text: read the AI Act on Lawbster with linked cross-references, one-click language switching and the official guidance documents collected on the act's page, and see the bigger picture in the Lawbster manifesto.

    Frequently asked

    When did the EU AI Act enter into force?
    On 1 August 2024. Its obligations then apply in phases through 2030.
    When do the AI Act's prohibitions apply?
    The core prohibited practices have applied since 2 February 2025; two further prohibitions (AI-generated CSAM and non-consensual intimate imagery) apply from 2 December 2026.
    When do high-risk AI obligations apply?
    After the Digital Omnibus: 2 December 2027 for Annex III (use-case) systems and 2 August 2028 for Annex I (product-embedded) systems, instead of 2 August 2026.
    Do existing high-risk systems have to comply?
    Systems placed on the market before the application date only fall into scope once their design changes significantly (Art 111(2)). High-risk systems used by public authorities must comply by 2 August 2030 in any event.
    When did general-purpose AI (GPAI) rules start?
    2 August 2025. GPAI models already on the market before that date must be compliant by 2 August 2027.
    Do transparency rules still apply in 2026?
    Yes. Transparency duties for GenAI, chatbots and deepfakes apply from 2 August 2026. One carve-out from the Omnibus: systems already on the market on that date have until 2 December 2026 to implement the Article 50(2) machine-readable watermarking.