The EU AI Act (Regulation (EU) 2024/1689) entered into force on 1 August 2024. Almost nothing applied on that day. The regulation was written to phase in over three years, and the dates matter more than the headline, because an obligation that is not yet in force is not something an auditor can test you against, and one that is already in force is not something you can plan to address later.
This is the calendar as the regulation sets it out, with a note at the end about the proposal to move parts of it.
2 February 2025: prohibited practices and AI literacy
The first tranche was the shortest and the sharpest. From this date, the practices listed in Article 5 are banned outright: social scoring by public authorities, manipulative or deceptive techniques that cause significant harm, exploitation of vulnerabilities related to age or disability, untargeted scraping of facial images to build recognition databases, emotion recognition in workplaces and schools, biometric categorisation to infer protected characteristics, and most real-time remote biometric identification in public spaces by law enforcement.
The same date brought Article 4, AI literacy. Providers and deployers must ensure that the people who operate or use AI systems on their behalf have a sufficient level of understanding of what the systems do. There is no certificate for this and no prescribed course. What an auditor looks for is whether the organisation identified who touches AI systems, decided what those people need to know, and can show that it happened.
2 August 2025: general-purpose AI and the governance layer
The second tranche switched on the obligations for providers of general-purpose AI models (Chapter V): technical documentation, information for downstream providers, a copyright policy, and a public summary of training content. Models classified as carrying systemic risk carry further duties around evaluation, adversarial testing, incident reporting and cybersecurity.
The same date activated the institutions: the AI Office, the AI Board, national market surveillance authorities, and the penalty regime. Fines for prohibited practices reach 35 million euro or 7 percent of worldwide annual turnover, whichever is higher; most other infringements top out at 15 million euro or 3 percent.
If you build on top of a foundation model rather than train one, this tranche touches you indirectly: the documentation your model provider must now supply is the input to your own conformity work.
2 August 2026: the general application date
This is the date most companies mean when they say "the AI Act applies". From here, the bulk of the regulation is in force, including:
- The high-risk regime for the use cases listed in Annex III: biometrics, critical infrastructure, education and vocational training, employment and worker management, access to essential services (credit scoring, insurance pricing, public benefits), law enforcement, migration and border control, and the administration of justice and democratic processes.
- The obligations on providers of high-risk systems (Articles 9 to 17): a risk management system, data governance, technical documentation, record keeping, transparency and instructions for use, human oversight, and accuracy, robustness and cybersecurity, all wrapped in a quality management system.
- The obligations on deployers of high-risk systems (Article 26): use according to instructions, human oversight by competent people, monitoring, log retention, informing workers, and in some cases a fundamental rights impact assessment (Article 27).
- The transparency duties in Article 50: telling people they are interacting with an AI system, marking synthetic content, and disclosing deep fakes and AI-generated text on matters of public interest.
- Registration of high-risk systems in the EU database before they are placed on the market.
For a provider, the operational heart of this is the conformity assessment. Most Annex III systems can be self-assessed against the harmonised standards once those standards are published; the standardisation work at CEN-CENELEC (JTC 21) was still in progress through 2025 and 2026, which is why so many companies are looking at ISO/IEC 42001 as the management-system scaffold to build on in the meantime.
2 August 2027: high-risk systems inside regulated products
The final tranche covers AI systems that are safety components of, or are themselves, products already governed by EU product legislation listed in Annex I: machinery, toys, lifts, medical devices, in vitro diagnostics, civil aviation, vehicles, marine equipment, rail and the like. These follow the conformity route of the underlying product law, with a notified body involved, and get the extra year because the sectoral legislation has to be aligned first.
The same date is the deadline for general-purpose AI models that were already on the market before August 2025 to be brought into compliance.
The proposal to move the dates
In late 2025 the European Commission put forward a package of simplification measures, often called the digital omnibus, which included a proposal to postpone the Annex III high-risk obligations until harmonised standards are available, with a backstop date in late 2027, and the Annex I obligations to 2028. That was a proposal to the Parliament and the Council, not an amendment in force, and the legislative process runs on its own clock.
The practical advice is boring but correct: plan against the dates in the regulation as it stands, and treat any postponement as extra time rather than a reason to stop. The prohibitions, the literacy duty and the general-purpose model rules are not part of the proposed delay in any case.
What to have ready, by role
If you deploy AI in an Annex III area, for example screening job applicants or pricing insurance: an inventory of the systems in use, the classification reasoning for each, the provider's instructions for use, a named human oversight function, log retention, and, where you are a public body or provide essential services, the fundamental rights impact assessment.
If you provide a high-risk system: the technical file per Annex IV, the risk management records, the data governance evidence for training and test sets, the quality management system, the post-market monitoring plan, and the EU declaration of conformity. An ISO/IEC 42001 certificate is not a legal substitute for conformity assessment, but it covers most of the management-system ground and gives an auditor a recognised structure to test.
If you provide a general-purpose model: the Chapter V documentation, the training-content summary, and the copyright policy, already in force since August 2025.
Everyone: the AI literacy evidence, and a record of the Article 50 transparency measures where you generate content or run chatbots.
An auditor engaged for AI Act readiness will work through exactly this list, date by date, asking for the evidence behind each line. The companies that find the exercise quick are the ones that wrote the inventory first.
