COMPLIPATHDOC complipath.io/guides/eu-ai-act-timelineRENDERED 2026-08-23ENGINE 2026-08-09.1CORPUS 2024/1689 + 2026/1744 + Commission guidelines
Guides/Deadlines ·By Yobel Tzegai ·Updated 22 August 2026

What is the EU AI Act timeline? Every deadline from 2024 to 2030

Updated 9 August 2026 for Regulation (EU) 2026/1744.

The EU AI Act (Regulation (EU) 2024/1689) entered into force on 1 August 2024. Most prohibited practices applied from 2 February 2025 and two more from 2 December 2026, GPAI and governance rules from 2 August 2025, the Regulation generally from 2 August 2026, the high-risk regime from 2 December 2027, and the final legacy-system deadline runs to 31 December 2030. Article 113, as amended by Regulation (EU) 2026/1744, sets every date below.

Quick answer

When did the AI Act enter into force?

Regulation (EU) 2024/1689 was signed on 13 June 2024 and published in the Official Journal on 12 July 2024. Under Article 113, it entered into force 20 days later, on 1 August 2024. Entry into force is not the same as application — on that date, no substantive obligations applied yet. The Act instead sets a staggered application schedule, with different chapters switching on at different times over the following six years (Article 113; the transitional deadlines in Article 111 run to 31 December 2030).

What changed on 2 February 2025?

Under Article 113, third paragraph, point (a), Chapters I and II applied from 2 February 2025 — with one later exception: Regulation (EU) 2026/1744 added two further prohibitions in Article 5(1), first subparagraph, points (ba) and (bb), and the provisions qualifying them in Article 5(1a) and (1b), and those apply only from 2 December 2026. The 2 February 2025 date covers the Article 5 prohibitions — the AI practices banned outright, such as social scoring, untargeted facial recognition scraping, and manipulative or exploitative AI systems — and the general provisions in Chapter I, including scope and definitions. It also brought in the AI literacy obligation — though not in its current words: Regulation (EU) 2026/1744 replaced Article 4 in full, and the duty is now to "support the development of" AI literacy rather than to "ensure, to their best extent, a sufficient level of" it — who Article 4 binds and what the rewrite changed takes that one apart. If you haven't audited your systems against Article 5, see our guide on the prohibited AI practices that applied from 2 February 2025.

Non-compliance with Article 5 carries the highest penalty tier under Article 99 — up to €35 million or, "if the offender is an undertaking", up to 7% of its total worldwide annual turnover "for the preceding financial year", whichever is higher.

What started on 2 August 2025?

Article 113, third paragraph, point (b) brought in Chapter III Section 4 (notifying authorities and notified bodies), Chapter V (general-purpose AI models), Chapter VII (governance), Chapter XII (penalties) and Article 78 (confidentiality, which sits in Chapter IX — point (b) lists it separately because it is outside every chapter the point names), with Article 101 specifically excluded from this date. This is when the GPAI regime became operational: providers placing a general-purpose AI model on the market from this date had to comply immediately with the Chapter V transparency and documentation duties. Member States also had to publish by this date how their competent authorities and single points of contact can be reached, through electronic means (Article 70(2)). The duty to designate those authorities is Article 70(1) and is undated.

If you provide or integrate a foundation model, see GPAI obligations that started 2 August 2025 for the specifics.

What applies from 2 August 2026?

This is the Act's general application date, and it sits in Article 113, second paragraph — the third paragraph is the "However:" list of exceptions to it. Everything not otherwise scheduled applies from 2 August 2026 — including the Article 50 transparency duties and Chapter III Section 5 (standards, conformity assessment, certificates and registration, Articles 40 to 49). One carve-out sits inside that: Article 111(4) gives providers of synthetic-content systems on the market before 2 August 2026 until 2 December 2026 for Article 50(2). The high-risk regime is no longer on this date: Regulation (EU) 2026/1744 moved Chapter III, Sections 1, 2 and 3 off it. Member States' national AI regulatory sandboxes are now due by 2 August 2027 under Article 57(1), as amended.

Section 5 keeps 2 August 2026: conformity assessment under Article 43 and registration under Article 49 apply from that date. The Section 1 classification rules that decide which systems they apply to run later — 2 December 2027 for Annex III systems, 2 August 2028 for Annex I ones.

When does the high-risk regime start?

Article 113, third paragraph, point (c), as amended by Regulation (EU) 2026/1744, replaced the old single carve-out for Article 6(1) with two dates covering the whole of Chapter III, Sections 1, 2 and 3 — classification (Articles 6 and 7), the requirements (Articles 8–15) and the operator obligations (Articles 16 to 27), with the exception of Article 6(5):

2 December 2027 is the date most providers and deployers of HR tech, fintech, healthcare and cybersecurity AI tools need to plan around. See high-risk obligations: what applies from 2 December 2027 for a full breakdown by requirement.

Article 111(3) was not amended: GPAI providers who placed a model on the market before 2 August 2025 still have until 2 August 2027 to bring it into compliance.

What about legacy AI systems already on the market?

Article 111 sets out transitional rules for systems already in use before the main deadlines bite. Both of its grandfathering paragraphs open "Without prejudice to the application of Article 5": the prohibitions bite on a legacy system whatever its placing date and whatever changes it has or has not undergone. What follows is relief from the rest of the Regulation, never from Article 5. Three dates, and each one is a deadline on this timeline:

What "significant change" triggers, why the replacement text's singular "date" is a caution rather than a settled reading, and what happens to a system that misses the Annex X window are all in legacy AI systems: the grandfathering rules. This page carries the dates; that one carries the argument.

The full deadline table carries every date with its article.

What this means for you

If you're a provider: Your clock depends on your system's category. Prohibited-practice exposure was already live from 2 February 2025. If you place a high-risk system on the market, 2 December 2027 is your real deadline — 2 August 2028 if it is an Annex I safety component. Start Annex IV documentation and conformity assessment now; that work won't fit into a late-2027 start. Complipath's guided risk classification tells you which of these deadlines apply to each of your systems.

If you're a deployer: Article 26 sits in Chapter III, Section 3, which point (c) gives two dates — 2 December 2027 for Annex III systems, 2 August 2028 for Annex I ones. Not all of Chapter III moved: Section 5 keeps 2 August 2026 and Section 4 has applied since 2 August 2025 (point (b)). Check whether any deployed system will undergo a "significant change" before that date — under Article 111(2) as amended, an unchanged legacy system may avoid full retrofitting, but a substantial update pulls it into scope immediately. Deployers serving public-sector functions face the extended 2 August 2030 deadline instead.

Which dates reach your systems?

Classify your system now — 7 questions on the main line, plus follow-ups where they apply, no account, and the classification runs in your browser: answers stay there unless you choose to keep the result.

FAQ

Is the EU AI Act fully in force yet? No. Entry into force (1 August 2024) is not the same as application. Different chapters apply on staggered dates through 2 August 2028, with transitional deadlines for legacy systems running to 31 December 2030 under Article 111.

What was the first EU AI Act deadline? 2 February 2025, when the Article 5 prohibited practices and the Chapter I–II general provisions became applicable, per Article 113, third paragraph, point (a).

When do high-risk AI obligations apply? From 2 December 2027 for Annex III systems, and from 2 August 2028 for the Article 6(1) category tied to Annex I product-safety law, under Article 113, third paragraph, point (c), as amended by Regulation (EU) 2026/1744. Both dates are still ahead. They moved from different places: the Annex III track from 2 August 2026, the Article 6(1) track from 2 August 2027.

Do systems already on the market get extra time? Sometimes, and never from Article 5 — both grandfathering paragraphs are expressly "without prejudice" to the prohibitions. Public-authority high-risk systems must comply by 2 August 2030, and any "significant change" after the Chapter III date that applies to the system removes the grandfathering (Article 111(2), as amended).


Sources: Regulation (EU) 2024/1689 (EUR-Lex), as amended by Regulation (EU) 2026/1744 (EUR-Lex) — in particular Article 1, points (22), (30), (39) and (40), which amend Article 57(1), Article 72(3), Article 111 and Article 113, third paragraph. Standards referenced under Article 40 (harmonised standards) are still in development at the time of writing — where a deadline depends on a standard that hasn't been finalized, treat the date as the legal deadline, not a guarantee that supporting guidance will exist by then.

← All guides
Complipath

Complipath is EU AI Act compliance software for AI-heavy software companies without a compliance team — an AI system register, deterministic risk classification, the obligations that follow, and the evidence behind every decision.

Complipath is built by Yobel Tzegai in Gothenburg, Sweden.

Complipath provides legal information, not legal advice. Every guide cites its source on EUR-Lex — Regulation (EU) 2024/1689, and Regulation (EU) 2026/1744 where that has amended it; where the law is still settling, the guide says so.

We measure page views with Vercel Web Analytics. It uses no third-party cookies. Visitors are identified by a hash derived from the incoming request, which is discarded after 24 hours, and no identifier is stored that could follow a visitor to another site. What is collected: the time of the visit, the URL, the referring page, filtered query parameters, city-level location, operating system, browser and device type.