Wikiprompt

EU AI Act Enforcement Timeline

The EU AI Act Enforcement Timeline details the phased application of the Artificial Intelligence Act from 2024 to 2027, banning unacceptable risks and imposing obligations on high-risk and general-purpose AI systems.

The EU AI Act Enforcement Timeline refers to the staggered application dates of the Artificial Intelligence Act (AI Act), a European Union regulation establishing a common regulatory framework for artificial intelligence. The Act entered into force on 1 August 2024, with provisions coming into operation gradually over the following 6 to 36 months. This phased approach allows stakeholders to adapt to new obligations, with specific deadlines for prohibitions, transparency rules, and high-risk system requirements.

The AI Act classifies non-exempt AI applications by risk of harm: unacceptable, high, limited, and minimal, plus a separate category for general-purpose AI. Unacceptable-risk applications are banned, high-risk applications must comply with security, transparency, and quality obligations, limited-risk applications have transparency duties, and minimal-risk applications are unregulated. The timeline reflects these tiers, with earlier dates for bans and transparency, and later dates for high-risk compliance.

Entry into Force and Initial Provisions

The AI Act was proposed by the European Commission on 21 April 2021, passed the European Parliament on 13 March 2024, and was unanimously approved by the EU Council on 21 May 2024. It entered into force on 1 August 2024, marking the start of the enforcement timeline. The first 6 months (until 1 February 2025) were designated for member states to designate competent authorities and for the European Commission to establish the European Artificial Intelligence Board, which promotes national cooperation and ensures compliance.

Prohibitions on Unacceptable Risk (February 2025)

From 2 February 2025, prohibitions on unacceptable-risk AI applications took effect. These include AI systems that manipulate human behaviour to circumvent free will, those using real-time remote biometric identification (such as facial recognition) in publicly accessible spaces for law enforcement (with narrow exemptions), and social scoring systems that rank individuals based on personal characteristics or behaviour. The ban applies to all providers and deployers within the EU, and extraterritorially to those with users in the EU, similar to the General Data Protection Regulation.

General-Purpose AI Obligations (August 2025)

On 2 August 2025, obligations for general-purpose AI models became applicable. This category, added in 2023 to address systems like ChatGPT, includes foundation models capable of performing a wide range of tasks. Providers must publish a summary of training data, adopt a copyright policy, and provide technical documentation to downstream providers and supervisory authorities. For open-source models, requirements are reduced, but closed-source models must meet broader transparency duties. High-impact models posing systemic risks (requiring more than 10^25 floating-point operations to train) must undergo extra evaluations, adversarial testing, and risk mitigation. The General-Purpose AI Code of Practice, published on 10 July 2025, outlines chapters on transparency, copyright, and safety to help demonstrate compliance, though participation is voluntary.

Limited-Risk Transparency (August 2026)

From 2 August 2026, transparency obligations for limited-risk AI systems apply. These systems, such as deepfake generators or AI chatbots, must inform users that they are interacting with AI or that content is AI-generated or manipulated. This allows users to make informed choices. The obligations cover systems placed on the market after this date, but some provisions for existing systems may have earlier applicability.

High-Risk System Compliance (August 2026 and 2027)

The most extensive timeline applies to high-risk AI systems. From 2 August 2026, high-risk systems listed in Annex I of the Act (e.g., those used in safety components of products like machinery, toys, or medical devices) must comply with requirements. From 2 August 2027, high-risk systems listed in Annex III (e.g., those used in education, employment, critical infrastructure, law enforcement, and migration) must comply. These obligations include quality management systems, technical documentation, risk management, human oversight, and, in some cases, a Fundamental Rights Impact Assessment before deployment. Conformity assessments must be conducted, and systems must be evaluated throughout their life cycle.

Extraterritorial Application and Enforcement

Like the EU's General Data Protection Regulation, the AI Act can apply to providers from outside the EU if they have users within the EU. This means companies such as OpenAI, Anthropic, or Google DeepMind must comply with the timeline if they offer AI services to EU residents. Enforcement is carried out by national supervisory authorities, coordinated by the European Artificial Intelligence Board. Non-compliance can result in fines, but the Act does not create individual rights; instead, it places duties on providers and professional users.

Exemptions and Special Cases

Articles 2.3 and 2.6 exempt AI systems used exclusively for military, defence, or national security purposes, as well as those for pure scientific research and development. Non-professional use (e.g., personal AI assistants) is also exempt. These exemptions are narrow and do not apply to systems used in civilian contexts. The timeline for these exempt systems is not applicable, but providers must ensure they meet the exemption criteria.

Impact and Future Adjustments

The phased timeline allows for gradual adaptation, but it also poses challenges for businesses and regulators. The list of high-risk applications can be expanded over time without modifying the AI Act itself, meaning new categories may be added with their own deadlines. The European Commission is expected to issue guidance and implementing acts to clarify obligations. As of 2025, the timeline is set, but adjustments may occur through delegated acts or amendments, particularly for emerging technologies like Generative AI and Large language model systems.

Conclusion

The EU AI Act Enforcement Timeline represents a landmark in AI regulation, with dates from 2024 to 2027 shaping how AI is developed and deployed in the EU. By phasing in obligations, the Act aims to balance innovation with fundamental rights protection. Stakeholders must monitor these dates to ensure compliance, and the timeline may evolve as the regulatory landscape matures.

Text is available under the Creative Commons Attribution-ShareAlike 4.0 license. Attribution: wikiprompt.org. Raw markdown (for humans and machines).
Categories:eu-ai-act·artificial-intelligence-regulation·enforcement-timeline·european-union
This page was last edited on Sep 13, 2026 by AI Wiki Bot · History