AI Regulation & Compliance intermediate 7 min read 10 flashcards

The AI Act Compliance Timeline as It Now Stands

The phased application dates, the deferral of high-risk obligations agreed in 2026, and what remained on the original schedule when the rest moved.

The Act entered into force on 1 August 2024 and applies in phases. The phases were amended in 2026, and the amendment moved some obligations and deliberately left others in place, so a plan built on the original schedule is now wrong in one direction and right in another.

The dates

1 August 2024. Entry into force. No obligations apply yet.

2 February 2025. Prohibited practices become enforceable, and the AI literacy obligation applies: providers and deployers must ensure a sufficient level of AI literacy among staff dealing with AI systems.

2 August 2025. Obligations for general-purpose AI models, the governance provisions, the notified-body rules and the penalty regime apply. GPAI models already on the market before this date have until 2 August 2027 to comply.

2 August 2026. The remainder of the Act applies, including the Article 50 transparency obligations.

The original schedule then put standalone high-risk obligations at 2 August 2026 and product-embedded high-risk at 2 August 2027. Those moved.

The 2026 deferral

The Digital Omnibus on AI, published in the Official Journal on 24 July 2026 and in force from 27 July 2026, deferred the high-risk obligations. Annex III standalone high-risk systems now have until 2 December 2027. Annex I high-risk AI embedded in products regulated under existing EU product-safety law now has until 2 August 2028.

What did not move is as important. The Article 50 transparency obligations remained on the original schedule and apply from 2 August 2026, with a short grace period, to 2 December 2026, before the machine-readable marking requirement in Article 50(2) bites for systems already on the market. Prohibitions, AI literacy and the GPAI regime were unaffected.

The practical effect is a compliance landscape where transparency and disclosure obligations are live now while the heavy documentation, conformity assessment and registration duties for high-risk systems are not yet enforceable.

When it breaks

Deferral is not repeal. The obligations arrive, and the work they require, risk management systems, data governance, technical documentation, conformity assessment, takes longer than the deferral bought. Treating the delay as a reprieve rather than as schedule relief is the predictable error.

Deadlines apply per system, not per organisation. A portfolio contains systems in several tiers with several dates, and the compliance date is a property of each. An organisation-level programme with one target date will be early for some systems and late for others.

Placing on the market is the trigger. Obligations attach when a system is placed on the market or put into service, so the relevant question for a system in development is when it will ship rather than what today's date is.

Guidance and standards are still forming. Harmonised standards that give presumption of conformity, and Commission guidance on classification, continue to be developed. Building to a reading of the text that later guidance contradicts is a real risk, and documenting the reasoning behind a classification is what makes a later correction defensible rather than embarrassing.

Check yourself

10 flashcards for this concept

Click a card to reveal the answer.

Drill the whole track