EU AI Act Timeline: Every Deadline from 2024 to 2028
The EU AI Act is not a single deadline — it applies in 5 phases over several years. Some things were banned in February 2025. GPAI rules came into force August 2025. Art. 50 transparency obligations took effect August 2026. The main high-risk (Annex III) deadline was deferred to December 2, 2027 by the 2025 Digital Omnibus. Here is the full schedule.
December 2, 2027 is the main high-risk AI deadline
(The August 2, 2026 Art. 50 transparency deadline has already passed — most businesses should already have chatbot/AI-content disclosures live.)
If your business uses AI in employment, credit, healthcare, education, or any Annex III category and serves EU customers or operates in the EU, you have until December 2, 2027 to complete your conformity assessment or establish deployer compliance measures — start now, conformity assessments routinely take months per system.
EU AI Act Enters Into Force
- Regulation 2024/1689 published in the EU Official Journal
- Official 20-day window after publication completed
- The clock starts on all subsequent deadlines
- No compliance obligations yet — this is the publication date
Prohibited AI Practices Banned
- AI systems listed in Article 5 are now illegal to deploy in the EU
- Real-time remote biometric identification by law enforcement (narrow exceptions)
- AI that exploits psychological vulnerabilities or manipulates people subliminally
- AI that categorises people by biometric data to infer sensitive characteristics (race, political views, sexual orientation)
- Social scoring systems by governments
- Predictive policing AI based purely on profiling
- Emotion recognition in workplaces and educational institutions (with narrow exceptions)
Note: These are hard bans. There is no compliance path — using them is a violation from this date.
Governance & GPAI Obligations Apply
- General Purpose AI (GPAI) model providers must comply — this affects OpenAI, Anthropic, Google, Mistral etc.
- GPAI providers must publish technical documentation, training data summaries, and compliance policies
- GPAI providers of "systemic risk" models (above 10^25 FLOPs) face additional requirements including adversarial testing
- EU AI Office and national AI authorities established
- National competent authorities must be designated by member states
- Penalty provisions (Art. 99-100) become applicable
Note: If you build on top of a GPAI model (like GPT-4 or Claude), the GPAI provider carries GPAI obligations. Your obligations as a downstream deployer depend on your specific use case.
Art. 50 Transparency Obligations Apply
- AI systems interacting with humans must disclose they are AI (chatbots, virtual assistants)
- AI-generated or manipulated content (deepfakes, synthetic audio/video/text) must be labelled as such
- Emotion-recognition and biometric-categorisation systems must disclose their use to affected individuals
- This applies regardless of risk tier — it is not limited to high-risk (Annex III) systems
- National market surveillance authorities begin enforcing this specific obligation
Note: This is NOT the high-risk (Annex III) deadline — that was deferred to December 2027 by the 2025 Digital Omnibus (see below). August 2, 2026 is specifically the Art. 50 transparency-obligations date, and it has already passed.
High-Risk AI Systems (Annex III) Must Comply
- ALL Annex III high-risk AI systems must be fully compliant — this is the main deadline for most businesses
- Deferred from the original August 2, 2026 date by the 2025 Digital Omnibus (Regulation (EU) 2026/1744)
- Providers must complete conformity assessments and register in the EU AI database
- High-risk AI deployers must implement human oversight, maintain logs, conduct DPIAs
- Providers of high-risk AI must have quality management systems, post-market monitoring
- CE marking required on compliant high-risk AI systems
- National market surveillance authorities begin full high-risk enforcement
Note: This is the deadline most businesses should be working toward now. Annex III covers AI used in hiring, credit, healthcare, education, biometrics, critical infrastructure, law enforcement, and justice.
Annex I Products (Safety Components) Must Comply
- AI that is a safety component in products covered by EU sectoral legislation (Annex I) must comply
- Deferred from the original August 2, 2027 date by the 2025 Digital Omnibus
- Annex I includes: machinery, toys, lifts, pressure equipment, medical devices, in-vitro diagnostics, civil aviation, motor vehicles, agricultural machinery, marine equipment, rail systems
- These AI systems go through the same conformity assessment as the product they are embedded in
Note: This phase matters for manufacturers. If your AI is embedded in a physical product (a medical device, a vehicle, industrial machinery), the August 2028 date applies.
What Happens If You Miss the December 2, 2027 High-Risk Deadline?
National market surveillance authorities in each EU member state begin active high-risk enforcement. (Art. 50 transparency enforcement began August 2, 2026 and is already ongoing.) The fines depend on the type of violation:
| Violation type | Maximum fine |
|---|---|
| Using a prohibited AI practice (Annex I / Article 5) | €35 million or 7% of global turnover |
| Non-compliant high-risk AI system (Annex III) | €15 million or 3% of global turnover |
| Incorrect information to authorities | €7.5 million or 1% of global turnover |
| SMEs and startups | Lower of the two applicable caps |
The phased timeline vs. GDPR: why it is designed this way
GDPR came into force all at once in May 2018. The EU AI Act's phased approach is deliberately different — the EU Commission wanted to give businesses time to understand which category their AI falls into and prepare accordingly. The tradeoff:
- • Prohibited AI (Article 5): February 2025 — immediate ban on the most harmful AI. No transition for these.
- • GPAI: August 2025 — affects foundation model providers, not most businesses.
- • High-risk (Annex III): December 2027 — deferred from August 2026 under the 2025 Digital Omnibus; the main commercial compliance deadline.
- • Product safety AI (Annex I): August 2028 — deferred from August 2027 under the 2025 Digital Omnibus; longest runway for hardware manufacturers.
What to Do Now (Updated August 2026)
The Art. 50 transparency deadline has already passed — if you have not added AI-disclosure notices yet, do that first. For high-risk (Annex III) AI, you have until December 2, 2027. Here is the realistic action sequence for most businesses:
Now: AI inventory
List every AI system your business uses or builds. Include vendor AI tools (ChatGPT Enterprise, Salesforce Einstein, HireVue, etc.). The inventory is the foundation of everything else.
Now: Risk classification
Map each AI system to the appropriate risk category. Most will be minimal risk. Identify any that fall in Annex III. Use Aegis Firma to do this in 30 minutes.
Next: Gap analysis
For each Annex III AI: are you the provider (you built it) or deployer (you use it)? What requirements apply? What is missing? Document the gaps.
Documentation & processes
Providers: start conformity assessment, technical documentation, QMS. Deployers: implement human oversight processes, train staff, ensure logging.
Register and certify — well before Dec 2027
Providers: register in EU AI database. Deployers: verify vendors are registered. Finalize documentation.
December 2, 2027: High-risk enforcement begins
Have your documentation ready. National authorities will be active on Annex III obligations. Be prepared to demonstrate compliance if asked.
Find out where your AI stands against the December 2027 deadline
Aegis Firma runs your AI inventory through all EU AI Act phases, tells you exactly what applies to you, and generates a prioritised action plan with days remaining.