Blog

    EU AI Act Compliance Deadlines: Key Dates and Obligations

    EU AI Act
    EU AI Act Compliance Deadlines: Key Dates and Obligations

    The EU AI Act applies in four compliance phases, with deadlines running from February 2025 to August 2028.

    Phase 1 banned prohibited AI practices and activated AI literacy obligations in February 2025. Phase 2 activated GPAI model obligations in August 2025.

    Phase 3 brings transparency obligations for AI-generated content on 2 August 2026, with machine-readable watermarking for existing systems extended to 2 December 2026. Phase 4 covers high-risk system obligations. Standalone Annex III systems face a deadline of 2 December 2027. AI embedded in regulated products under Annex I faces 2 August 2028. Both dates are deferred under the Digital Omnibus, pending Official Journal publication.

    This EU AI Act timeline covers every deadline with exact dates, the obligations each triggers, and who they affect. For context on the regulation’s scope and structure, see the complete guide to the EU AI Act.

    How the EU AI Act Phases In

    The EU AI Act implementation timeline rolls out in sequence, not all at once. The EU AI Act effective date was 1 August 2024, set under Article 113, Regulation (EU) 2024/1689. This is when the regulation entered into force and the compliance clock started. Prohibitions came next the eight banned AI practices under Article 5 took effect six months later. GPAI model obligations followed at the twelve-month mark.

    High-risk system obligations come last, now restructured under the Digital Omnibus to December 2027 and August 2028. Remaining provisions transparency obligations, watermarking, and sandbox requirements fall across 2026 and 2027. Each phase builds on the last. The EU AI Act timeline table below maps every key date, the obligations it triggers, and who it affects.

    EU AI Act Implementation Timeline

    Passed Already in force
    6 Weeks Imminent
    Pending OJ Agreed, awaiting Official Journal
    Future Confirmed future date
    Date What Applies Who Is Affected Key Obligations
    1 August 2024 Entry into force Passed EU AI Act effective date
    Enters into force (Article 113)
    All organisations operating AI systems in or targeting the EU The regulation becomes binding EU law. No compliance obligations apply on this date. The phased application schedule starts here.
    2 February 2025 +6 months Passed Prohibited AI practices banned
    Chapter II, Article 5 · AI literacy begins, Article 4
    All providers and deployers of AI systems in the EU Eight AI practices are immediately illegal under Article 5, including social scoring, predictive policing, and real-time biometric identification. AI literacy obligations begin for all providers and deployers.
    2 August 2025 +12 months Passed GPAI obligations Tier 1
    All general-purpose AI models
    Articles 51–56, Chapter V
    All GPAI model providers placing models on the EU market Maintain technical documentation, provide downstream integration data, enforce EU copyright and TDM opt-outs, and publish a public training data summary. Open-source models are exempt from documentation rules only.
    2 August 2025 +12 months Passed GPAI obligations Tier 2
    Systemic risk models only
    Articles 51–56, Chapter V
    GPAI providers trained on compute exceeding 10²⁵ FLOPs, or models designated systemic risk by the Commission All Tier 1 obligations apply. Additionally: conduct adversarial red-teaming, mitigate systemic risks, report incidents to the AI Office, and implement cybersecurity protections for model weights. Open-source exemptions are nullified above 10²⁵ FLOPs. Licences with commercial restrictions may also disqualify the exemption.
    2 August 2026 ~6 weeks away 6 Weeks Article 50 transparency obligations
    AI-generated content disclosure
    Providers of AI systems that generate or manipulate content (text, image, audio, video) Disclose AI interaction to users. Existing systems have until 2 December 2026 before machine-readable watermarking under Article 50(2) is enforced.
    2 December 2026 Confirmed future Pending OJ Watermarking grace period ends
    New Article 5 prohibition active (NCII / CSAM ban)
    Providers of AI image and video generation systems Article 50(2) watermarking becomes fully enforced for all systems. New Article 5 ban on AI-generated non-consensual intimate imagery and CSAM takes effect. Technical safeguards must be in place.
    2 August 2027 Confirmed future Future AI regulatory sandboxes deadline
    Article 57
    EU member state governments and national competent authorities Member states must have AI regulatory sandboxes operational. Organisations may apply to participate for real-world testing, now extended to include Annex I high-risk systems.
    2 December 2027 Deferred (Digital Omnibus) Pending OJ Annex III high-risk AI obligations
    Standalone systems, Article 6(2)
    Providers and deployers of standalone high-risk AI systems in biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, and justice Complete conformity assessment, maintain technical documentation, implement human oversight, and register in the EU AI database before deployment. Pending Official Journal publication of the Digital Omnibus.
    2 August 2028 Deferred (Digital Omnibus) Pending OJ Annex I high-risk AI obligations
    Product-integrated systems, Article 6(1)
    Providers of AI systems embedded in regulated products under Annex I including medical devices, machinery, vehicles, and civil aviation systems All Annex III obligations apply. Sectoral duplication relief available where existing product safety legislation covers equivalent requirements. Machinery Regulation products are largely exempted. Pending Official Journal publication.

    All dates sourced from Article 113, Regulation (EU) 2024/1689 and official Commission documentation. Digital Omnibus dates remain pending Official Journal publication.

    JAGGAER

    JAI operates with GDPR-aligned EU data handling and a full audit trail across procurement workflows.

    Phase 1 Prohibited Practices

    The EU AI Act’s first obligations have been applicable since 2 February 2025. That deadline has passed, so these rules are live and enforceable today. Article 5 bans eight AI practices on the basis that they pose an unacceptable risk to fundamental rights.

    This list covers social scoring, scraping of facial images from CCTV, and emotion recognition in workplaces and schools. It also bans manipulative or exploitative systems and most real-time remote biometric identification in public spaces.

    2 February 2025 also triggered the Article 4 AI literacy duty. It applies to every provider and deployer regardless of the risk tier their systems fall into. According to Article 4, staff and contractors using AI on the organisation’s behalf must hold a sufficient level of understanding.

    Enforcement timeline

    These banned AI systems cannot be placed on the EU market, put into service, or used. National market surveillance authorities are responsible for enforcement. Formal supervision applies from 2 August 2026. Penalties have been in force since August 2025. Breaches of Article 5 carry the heaviest fines in the regulation: up to €35 million or 7% of global annual turnover, whichever is higher.

    A further prohibition on AI that generates non-consensual intimate imagery and child sexual abuse material (CSAM) applies from 2 December 2026.

    For the full list and risk tiers, see our guide to EU AI Act risk categories and prohibited practices.

    Phase 2 GPAI Model Obligations

    Obligations for general-purpose AI models have applied since 2 August 2025. The GPAI rules in Chapter V are live. The same milestone activated governance by the EU AI Office, national competent authorities, and penalties under Article 99.

    Providers of GPAI models have four duties under Article 53. They must maintain technical documentation describing the model and its training. They must provide downstream deployers with the information and technical access needed to comply with their own obligations. They must have a policy to respect EU copyright law and TDM opt-outs. And they must publish a summary of the content used to train the model.

    Article 55 — Systemic risk models only

    Providers of GPAI models designated as posing systemic risk — those trained on compute exceeding 10²⁵ FLOPs, or models designated by the Commission — carry additional obligations under Article 55. These include model evaluations and adversarial testing, incident reporting to the AI Office, and cybersecurity measures to protect model weights. These obligations are separate from and additional to the Article 53 duties above. For the full breakdown, see our guide to EU AI Act rules for general-purpose AI models.

    Providers whose models reached the market before 2 August 2025 have until 2 August 2027 to comply.

    For the full breakdown, see our guide to EU AI Act rules for general-purpose AI models.

    Phase 3 High-Risk Systems Compliance Deadline

    The original date for complying with obligations for high-risk systems was 2 August 2026. But Digital Omnibus moved the deadline for standalone Annex III systems to 2 December 2027. This change is still pending formal adoption. Until it is published in the EU Official Journal, 2 August 2026 remains the binding date.

    AI systems which can pose risks to safety, health and fundamental rights are tagged as high-risk systems. Various applications including AI systems in law enforcement, educational institutions, employment and border control management are classified as high-risk AI systems.

    Providers of high-risk AI systems face heavy controls in the Act. They must

    • Operate a risk management system across the system’s lifecycle
    • Apply data governance standards to training and testing data
    • Prepare full technical documentation and keep automatic logs
    • Design the system for effective human oversight

    Before the system reaches the market, the provider must complete a conformity assessment. They must then register the system in the EU database and affix the CE marking.

    Deployer obligations for high-risk systems

    Deployers carry separate duties. They must use the system in line with the provider’s instructions, assign competent human oversight and monitor operation. They must run a fundamental rights impact assessment in certain situations and keep logs.

    JAGGAER

    JAGGAER AI ensures human oversight, continuous monitoring and provides full audit logs — with security and compliance at its core.

    For the full EU AI Act timeline across all phases, see the master table above.

    For penalties and enforcement, see our guide to EU AI Act fines and enforcement.

    Phase 4 Remaining Provisions through 2027 and Beyond

    Key facts

    • 2 August 2027: Article 6(1) activates: AI safety components across 18 Annex I product categories
    • 2 August 2027: GPAI grace period closes for models on market before 2 August 2025 (Article 111(3))
    • 31 December 2030: Annex X large-scale IT systems compliance deadline (Article 111(1))
    • 2 August 2030: Public authority deployers compliance deadline (Article 111(2))
    • Omnibus (provisional, not formally adopted): Annex I embedded systems proposed to shift to 2 August 2028

    2 August 2027 is the final Article 113 deadline under the original regulation text. It applies to AI systems that are safety components of Annex I regulated products, where the product already requires third-party conformity assessment under its sector law.

    The Digital Omnibus provisional agreement of 6–7 May 2026 proposes shifting Annex I embedded systems to 2 August 2028. That agreement is not formally adopted. Until it becomes law, 2 August 2027 is the legal deadline to plan against. Annex I covers 18 regulated product categories including medical devices, machinery, motor vehicles, in-vitro diagnostic devices, civil aviation equipment, and rail systems.

    When Article 6(1) activates, full Chapter III Section 2 requirements apply: risk management (Article 9), technical documentation (Article 11), human oversight (Article 14), and accuracy and robustness (Article 15). These become part of your existing sector conformity assessment, not an addition to it.

    Transitional provisions

    Three transitional EU AI Act deadlines apply under Article 111. Check which one covers your system type.

    • GPAI providers whose models were on market before 2 August 2025 must comply by 2 August 2027
    • Annex X large-scale IT system components placed on market before 2 August 2027 have until 31 December 2030
    • Public authority deployers have until 2 August 2030

    Regulatory sandboxes

    National regulatory sandboxes have been operational since 2 August 2026 under Article 57(1). Providers following the sandbox plan in good faith will not face administrative fines during testing. SMEs and startups get sandbox access free of charge under Article 58(3).

    Obligations by Actor Type

    The table below maps obligations by role in the supply chain. Confirm your system’s deadline under Phase 3 or Phase 4, then use your actor column. All four actor types apply from the same baseline dates: 2 August 2026 for Annex III systems and 2 August 2027 for Annex I systems. Public authority deployers have until 2 August 2030 under Article 111(2). If your business is outside the EU but places AI systems on the EU market, the same obligations apply. See how the EU AI Act applies to non-EU businesses.

    Obligation Providers Deployers Importers / Distributors
    Technical documentation Prepare and maintain before market placement Receive and apply from provider Verify present before supplying
    Conformity assessment Complete before placement. Self-assessment (Annex III) or notified body (Annex I Section A) Verify completed; verify CE marking present
    Human oversight Design system so natural persons can monitor, override, or stop it Assign oversight to named, competent natural persons
    Registration in EU database Register before market placement Public authority deployers only. Verify registration before use.
    Transparency to affected persons Inform persons subject to system decisions where required by law
    Post-market monitoring Establish and execute monitoring plan Monitor operation. Notify provider of risks without undue delay.
    Role shift trigger Baseline role Any actor becomes a provider by: (a) re-labelling the system, (b) making a substantial modification, or (c) changing intended purpose so a non-high-risk system becomes high-risk Same as Deployers
    Applies from Annex III: 2 Aug 2026.
    Annex I: 2 Aug 2027.
    Annex III: 2 Aug 2026.
    Annex I: 2 Aug 2027.
    Public authorities: 2 Aug 2030.
    Annex III: 2 Aug 2026.
    Annex I: 2 Aug 2027.

    JAGGAER

    JAGGAER AI is built according to workflows, thresholds and compliance obligations to ensure that procurement AI holds up to deadlines.

    FAQ

    The EU AI Act applies in 4 phases: prohibited practices from 2 February 2025, GPAI obligations from 2 August 2025, general applicability from 2 August 2026, and Annex I product-embedded system obligations from 2 August 2027. Transitional provisions under Article 111 extend specific deadlines to 2030.

    The EU AI Act effective date was 1 August 2024, when it entered into force 20 days after publication in the Official Journal of the EU on 12 July 2024. Compliance obligations applied progressively from 2 February 2025.

    High-risk AI system obligations apply from 2 August 2026 for Annex III systems under the current binding legal deadline. The Digital Omnibus proposes deferring this to 2 December 2027, but that change is pending Official Journal publication. Annex I product-embedded systems apply from 2 August 2027 (proposed deferral to 2 August 2028). Both dates are sourced from Article 113, Regulation (EU) 2024/1689.

    GPAI model obligations under Chapter V of Regulation (EU) 2024/1689 came into force on 2 August 2025. Models on market before that date must comply by 2 August 2027 under Article 111(3).

    The 8 categories of prohibited AI practices listed in Article 5 of Regulation (EU) 2024/1689 became enforceable on 2 February 2025, six months after the regulation entered into force.

    There is no single implementation date. The EU AI Act effective date was 1 August 2024, but the last Article 113 deadline is 2 August 2027. Transitional provisions under Article 111 extend specific deadlines to 31 December 2030.

    Yes. The EU AI Act applies in 4 phases between 2 February 2025 and 2 August 2027 under Article 113, with Article 111 transitional provisions extending specific deadlines to 2030.

    Deployer obligations under Article 26 apply from 2 August 2026 for Annex III systems and 2 August 2027 for Annex I systems. Public authority deployers have until 2 August 2030 under Article 111(2).

    EU AI Act enforcement began on 2 February 2025 for prohibited practices. GPAI enforcement by the EU AI Office started 2 August 2025. High-risk system enforcement begins from 2 August 2026 under Article 113.

    The EU AI Act fully applies from 2 August 2027 under Article 113. Public authority deployers must comply by 2 August 2030 and Annex X IT system components by 31 December 2030 under Article 111.

    Next Steps

    Talk to a procurement expert.

    Tell us your challenge. We will show you exactly where JAGGAER One fits into your current setup — with specifics, not a generic demo.

    • Direct or indirect?
      We handle both — on one platform.
    • Already have an ERP?
      JAGGAER Link connects to 1,000+ systems, no rip-and-replace.
    • Need to show ROI fast?
      We define outcomes and KPIs before you sign.
    • Vertical-specific?
      Manufacturing, higher ed, public sector — configured, not customized.

    Related Articles

    Copyright © 2026 JAGGAER – All Rights Reserved

    JAGGAER and the JAGGAER logo are registered trademarks of JAGGAER, LLC. All other registered trademarks, trademarks, and service marks are the property of their respective owners.