In one sentence. The EU AI Act (Regulation (EU) 2024/1689) entered into force on 1 August 2024 and applies in phases: 2 February 2025 (prohibited AI practices + AI literacy), 2 August 2025 (GPAI models + governance + penalties), 2 August 2026 (general application + Article 50 transparency duties), 2 December 2027 (high-risk Annex III systems — deferred from August 2026), 2 August 2028 (high-risk Annex I product-embedded systems — deferred from August 2027). Maximum fines reach €35 million or 7% of global turnover for prohibited practices. Official source: EUR-Lex Regulation (EU) 2024/1689.
This timeline matters because early phases are already enforceable — prohibited-practice violations sanctionable since February 2025, GPAI compliance since August 2025. The next date that binds everyone is 2 August 2026: general application of the Act and the Article 50 transparency duties, which catch any organisation running a chatbot or publishing synthetic content. The high-risk wave that used to sit on that date now lands in December 2027.
Key takeaways
- 1 August 2024: AI Act entered into force.
- 2 February 2025: Articles 1-5 + AI literacy applicable.
- 2 August 2025: GPAI rules + national authorities + penalties.
- 2 August 2026: General application, including Article 50 transparency duties (all sectors).
- 2 December 2027: High-risk Annex III systems applicable (most enterprises) — deferred from 2 August 2026.
- 2 August 2028: High-risk Annex I (embedded in regulated products) — deferred from 2 August 2027.
- Fines up to €35M or 7% of global turnover for prohibited practices.
1. Entry into force vs application
- Entry into force: 1 August 2024 (20 days after OJ publication 12 July 2024)
- General application: 2 August 2026 (24 months after entry into force)
- Specific provisions accelerated or delayed per Article 113
- High-risk obligations deferred: the Digital Omnibus on AI, adopted by the European Parliament on 16 June 2026 and given final Council approval on 29 June 2026, moves Annex III high-risk systems to 2 December 2027 and Annex I product-embedded high-risk systems to 2 August 2028
The deferral is worth understanding rather than just noting. It exists because the harmonised standards that would give high-risk systems a presumption of conformity were not ready in time, not because the requirements were relaxed — what a provider has to demonstrate in December 2027 is what it would have had to demonstrate in August 2026. And it reaches only the substantive high-risk obligations: the Article 5 prohibitions, the Article 4 AI-literacy duty, the GPAI obligations under Articles 53 and 55 and the Article 50 transparency duties are untouched and stand on their existing dates. Publication in the Official Journal was still pending at the end of July 2026, and the amending regulation enters into force three days after publication, so verify the consolidated text before committing an internal plan to these dates.
2. Phase 1 — 2 February 2025
Applicable from this date:
- Article 1 subject matter
- Article 2 scope
- Article 3 definitions
- Article 4 AI literacy (Article 4 obligation on providers and deployers to ensure sufficient AI literacy of staff)
- Article 5 prohibited AI practices
Prohibited practices include:
- Subliminal manipulation causing harm
- Exploitation of vulnerabilities (age, disability, social/economic situation)
- Social scoring by public authorities
- Predictive policing solely from profiling
- Untargeted scraping for facial recognition databases
- Emotion recognition in workplace/education (limited exceptions)
- Biometric categorisation by sensitive attributes
- Real-time remote biometric identification in public for law enforcement (narrow exceptions)
Sanctions for Article 5 violations: up to €35M or 7% of global turnover (Article 99(3)).
3. Phase 2 — 2 August 2025
Applicable from this date:
- Chapter V General Purpose AI models (GPAI)
- Chapter III Section 4 notified bodies
- Chapter VII governance (AI Office, Board, advisory forum, scientific panel)
- Chapter XII penalties
GPAI obligations include:
- Technical documentation (Annex XI)
- Information for downstream providers (Annex XII)
- Copyright policy
- Training data summary
GPAI with systemic risk (compute >10^25 FLOPs) face stricter obligations: model evaluations, adversarial testing, incident reporting, cybersecurity.
4. Phase 3 — 2 August 2026 (general application + transparency)
Applicable from this date:
- General application of the Act
- Article 50 transparency duties: disclosure that a person is interacting with an AI system, machine-readable marking of synthetic audio, image, video and text, notification of people exposed to emotion recognition or biometric categorisation, and labelling of deep fakes
This is the phase that reaches the widest population, because it does not depend on risk tier. Every site with a chatbot and every workflow that publishes generated content is in scope, with no grandfathering. Breach falls under Article 99(4): €15M or 3% of global turnover.
The Annex III high-risk wave was originally scheduled here and has moved to 2 December 2027 (see Phase 4).
5. Phase 4 — 2 December 2027 (Annex III high-risk, deferred from 2 August 2026)
Applicable from this date:
- High-risk AI systems listed in Annex III become subject to all Chapter III requirements
Annex III covers:
- Biometric identification and categorisation
- Critical infrastructure management
- Education and vocational training (admissions, scoring)
- Employment (recruiting, performance, dismissal decisions)
- Essential private and public services (credit, insurance, social benefits)
- Law enforcement
- Migration, asylum, border control
- Administration of justice and democratic processes
Provider obligations (Chapter III Section 2): risk management, data governance, technical documentation, transparency, human oversight, accuracy/robustness/cybersecurity, conformity assessment, registration, post-market monitoring.
5b. Phase 5 — 2 August 2028 (Annex I product-embedded high-risk, deferred from 2 August 2027)
Applicable from this date:
- High-risk AI systems in Annex I products (machinery, toys, medical devices, in vitro diagnostics, etc.) — the longest runway, because AI Act requirements have to be folded into conformity assessment cycles that already exist under sector law
6. Transitional rules
- GPAI placed on market before 2 August 2025: must comply by 2 August 2027
- High-risk systems already on the market when the high-risk obligations start to apply: must comply by 2 August 2030 unless substantially modified. The cut-off date tracks the high-risk obligation date, which the Digital Omnibus moved — check the consolidated text for the exact wording before relying on it.
- AI used by public authorities: must comply by 2 August 2030
7. Sanctions matrix
| Violation | Fine cap |
|---|---|
| Prohibited practices (Article 5) | €35M or 7% of global turnover |
| Non-compliance with high-risk obligations | €15M or 3% of global turnover |
| Supply of incorrect information to authorities | €7.5M or 1% of global turnover |
For SMEs and start-ups, fines are typically the lower of the two values.
8. Governance institutions
- AI Office (Commission, operational since 2024)
- European Artificial Intelligence Board (Member States + Commission)
- Advisory forum (stakeholders)
- Scientific panel (independent experts)
- National competent authorities designated by 2 August 2025
9. Compliance checklist by phase
Before 2 February 2025: ensure no prohibited practices; AI literacy training for staff handling AI systems.
Before 2 August 2025 (for GPAI providers): technical documentation, training data summary, copyright policy, downstream information; systemic-risk providers add evaluations and incident reporting.
Before 2 August 2026 (everyone): Article 50 transparency — chatbot disclosure, machine-readable marking of synthetic content, deep-fake labelling, notice to people exposed to emotion recognition or biometric categorisation.
Before 2 December 2027 (high-risk Annex III): full Chapter III Section 2 compliance including risk management, data governance, human oversight, conformity assessment.
9b. What the dates mean for a mid-2026 compliance plan
As of mid-2026, three phases are already live and enforceable and the general application of the Act is days away. The practical consequence is that “we’ll start when the Act applies” is no longer a defensible position — prohibited practices have been unlawful since February 2025, and GPAI obligations since August 2025.
The two commercially decisive dates for most organisations are now 2 August 2026 and 2 December 2027, and they call for different work. August 2026 is small in scope but immediate and universal: the Article 50 transparency duties apply whatever your risk tier, so the chatbot disclosure, the machine-readable marking of generated content and the deep-fake labelling have to be in place, and there is no grandfathering to fall back on. December 2027 is the Annex III high-risk regime, deferred from August 2026 by the Digital Omnibus on AI.
Treating that deferral as sixteen free months is the expensive reading. The requirements did not change — only the date did, because the harmonised standards were late — so a system put into service today has to be conformant in December 2027 anyway, with the Chapter III evidence behind it. That evidence is the problem: Annex IV technical documentation describes design decisions, dataset choices and risk trade-offs made during development, and reconstructing them in 2027 from a system already in production costs several times what recording them as you go does. The teams that will find December 2027 comfortable are the ones documenting through 2026.
The transitional cut-off of 2 August 2030 for high-risk systems already on the market remains in the Act, but the reference date it is keyed to moved with the obligation, so read the consolidated text rather than assuming an August 2026 baseline still works. The underlying logic is unchanged: a system already on the market buys years of runway, but only if it is not substantially modified afterwards, a threshold that a significant model retraining or a change in intended purpose can easily cross.
A defensible sequence: (1) inventory every AI system and classify it against Article 5 and Annex III; (2) confirm no prohibited practice is running; (3) close out Article 50 transparency before 2 August 2026; (4) for GPAI you build or fine-tune, assemble the Annex XI documentation and training-data summary; (5) for Annex III systems, stand up the risk-management, data-governance and human-oversight controls of Chapter III as the systems are built rather than during a market-surveillance inquiry in 2028. National competent authorities were required to be designated by 2 August 2025, so there is a live enforcement counterpart in every Member State.
10. Interaction with GDPR
The AI Act explicitly does not affect GDPR (Article 2(7)). High-risk AI systems involving personal data require both AI Act compliance and GDPR compliance (DPIA, lawful basis, transparency). See AI Act vs GDPR.
11. Tooling
Legiscope offers AI Act risk classification, GPAI documentation, high-risk Annex III conformity assessment workflow, and unified GDPR + AI Act records. See also EU AI Act timeline, AI Act compliance tools, high-risk systems.
FAQ
What are the EU AI Act effective dates?
1 August 2024 (entry into force), 2 February 2025 (prohibited practices + AI literacy), 2 August 2025 (GPAI + governance + penalties), 2 August 2026 (general application + Article 50 transparency), 2 December 2027 (high-risk Annex III), 2 August 2028 (high-risk Annex I in regulated products). The two high-risk dates were deferred from August 2026 and August 2027 respectively by the Digital Omnibus on AI, given final Council approval on 29 June 2026.
When does the AI Act become fully applicable?
2 August 2026 is the general application date, and it brings the Article 50 transparency duties with it. The Act is not fully applicable until the deferred high-risk phases land: 2 December 2027 for Annex III systems and 2 August 2028 for high-risk AI embedded in Annex I regulated products.
Does the deferral mean high-risk obligations were relaxed?
No. The Digital Omnibus on AI moved the dates because the harmonised standards that would give high-risk systems a presumption of conformity were not ready. The substance of Chapter III is unchanged, and the deferral does not reach the Article 5 prohibitions, the Article 4 AI-literacy duty, the GPAI obligations or the Article 50 transparency duties, all of which apply on their original dates. A high-risk system put into service today must still be conformant on 2 December 2027.
When do GPAI rules apply?
2 August 2025 for new GPAI models. Models already on market before this date have until 2 August 2027 to comply.
What are the maximum AI Act fines?
€35M or 7% of global turnover for prohibited practices (Article 5). €15M or 3% for high-risk non-compliance. €7.5M or 1% for incorrect information to authorities.
Where is the official AI Act text?
EUR-Lex Regulation (EU) 2024/1689, published in OJ L of 12 July 2024.
Legiscope automates this for you
Stop doing compliance manually. Legiscope's AI handles ROPA creation, DPA audits, and gap analysis — in minutes, not weeks.
Start free trial

