The EU AI Act applies in four compliance phases, with deadlines running from February 2025 to August 2028.
Phase 1 banned prohibited AI practices and activated AI literacy obligations in February 2025. Phase 2 activated GPAI model obligations in August 2025.
Phase 3 brings transparency obligations for AI-generated content on 2 August 2026, with machine-readable watermarking for existing systems extended to 2 December 2026. Phase 4 covers high-risk system obligations. Standalone Annex III systems face a deadline of 2 December 2027. AI embedded in regulated products under Annex I faces 2 August 2028. Both dates are deferred under the Digital Omnibus, pending Official Journal publication.
This EU AI Act timeline covers every deadline with exact dates, the obligations each triggers, and who they affect. For context on the regulation’s scope and structure, see the complete guide to the EU AI Act.
How the EU AI Act Phases In
The EU AI Act implementation timeline rolls out in sequence, not all at once. The EU AI Act effective date was 1 August 2024, set under Article 113, Regulation (EU) 2024/1689. This is when the regulation entered into force and the compliance clock started. Prohibitions came next the eight banned AI practices under Article 5 took effect six months later. GPAI model obligations followed at the twelve-month mark.
High-risk system obligations come last, now restructured under the Digital Omnibus to December 2027 and August 2028. Remaining provisions transparency obligations, watermarking, and sandbox requirements fall across 2026 and 2027. Each phase builds on the last. The EU AI Act timeline table below maps every key date, the obligations it triggers, and who it affects.
EU AI Act Implementation Timeline
| Date | What Applies | Who Is Affected | Key Obligations |
|---|---|---|---|
| 1 August 2024 Entry into force Passed | EU AI Act effective date Enters into force (Article 113) |
All organisations operating AI systems in or targeting the EU | The regulation becomes binding EU law. No compliance obligations apply on this date. The phased application schedule starts here. |
| 2 February 2025 +6 months Passed | Prohibited AI practices banned Chapter II, Article 5 · AI literacy begins, Article 4 |
All providers and deployers of AI systems in the EU | Eight AI practices are immediately illegal under Article 5, including social scoring, predictive policing, and real-time biometric identification. AI literacy obligations begin for all providers and deployers. |
| 2 August 2025 +12 months Passed | GPAI obligations Tier 1 All general-purpose AI models Articles 51–56, Chapter V |
All GPAI model providers placing models on the EU market | Maintain technical documentation, provide downstream integration data, enforce EU copyright and TDM opt-outs, and publish a public training data summary. Open-source models are exempt from documentation rules only. |
| 2 August 2025 +12 months Passed | GPAI obligations Tier 2 Systemic risk models only Articles 51–56, Chapter V |
GPAI providers trained on compute exceeding 10²⁵ FLOPs, or models designated systemic risk by the Commission | All Tier 1 obligations apply. Additionally: conduct adversarial red-teaming, mitigate systemic risks, report incidents to the AI Office, and implement cybersecurity protections for model weights. Open-source exemptions are nullified above 10²⁵ FLOPs. Licences with commercial restrictions may also disqualify the exemption. |
| 2 August 2026 ~6 weeks away 6 Weeks | Article 50 transparency obligations AI-generated content disclosure |
Providers of AI systems that generate or manipulate content (text, image, audio, video) | Disclose AI interaction to users. Existing systems have until 2 December 2026 before machine-readable watermarking under Article 50(2) is enforced. |
| 2 December 2026 Confirmed future Pending OJ | Watermarking grace period ends New Article 5 prohibition active (NCII / CSAM ban) |
Providers of AI image and video generation systems | Article 50(2) watermarking becomes fully enforced for all systems. New Article 5 ban on AI-generated non-consensual intimate imagery and CSAM takes effect. Technical safeguards must be in place. |
| 2 August 2027 Confirmed future Future | AI regulatory sandboxes deadline Article 57 |
EU member state governments and national competent authorities | Member states must have AI regulatory sandboxes operational. Organisations may apply to participate for real-world testing, now extended to include Annex I high-risk systems. |
| 2 December 2027 Deferred (Digital Omnibus) Pending OJ | Annex III high-risk AI obligations Standalone systems, Article 6(2) |
Providers and deployers of standalone high-risk AI systems in biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, and justice | Complete conformity assessment, maintain technical documentation, implement human oversight, and register in the EU AI database before deployment. Pending Official Journal publication of the Digital Omnibus. |
| 2 August 2028 Deferred (Digital Omnibus) Pending OJ | Annex I high-risk AI obligations Product-integrated systems, Article 6(1) |
Providers of AI systems embedded in regulated products under Annex I including medical devices, machinery, vehicles, and civil aviation systems | All Annex III obligations apply. Sectoral duplication relief available where existing product safety legislation covers equivalent requirements. Machinery Regulation products are largely exempted. Pending Official Journal publication. |
All dates sourced from Article 113, Regulation (EU) 2024/1689 and official Commission documentation. Digital Omnibus dates remain pending Official Journal publication.
JAGGAER
JAI is JAGGAER’s Source-to-Pay AI, built on ISO 42001-certified governance.
JAI operates with GDPR-aligned EU data handling and a full audit trail across procurement workflows.
Phase 1 Prohibited Practices
The EU AI Act’s first obligations have been applicable since 2 February 2025. That deadline has passed, so these rules are live and enforceable today. Article 5 bans eight AI practices on the basis that they pose an unacceptable risk to fundamental rights.
This list covers social scoring, scraping of facial images from CCTV, and emotion recognition in workplaces and schools. It also bans manipulative or exploitative systems and most real-time remote biometric identification in public spaces.
2 February 2025 also triggered the Article 4 AI literacy duty. It applies to every provider and deployer regardless of the risk tier their systems fall into. According to Article 4, staff and contractors using AI on the organisation’s behalf must hold a sufficient level of understanding.
A further prohibition on AI that generates non-consensual intimate imagery and child sexual abuse material (CSAM) applies from 2 December 2026.
For the full list and risk tiers, see our guide to EU AI Act risk categories and prohibited practices.
Phase 2 GPAI Model Obligations
Obligations for general-purpose AI models have applied since 2 August 2025. The GPAI rules in Chapter V are live. The same milestone activated governance by the EU AI Office, national competent authorities, and penalties under Article 99.
Providers of GPAI models have four duties under Article 53. They must maintain technical documentation describing the model and its training. They must provide downstream deployers with the information and technical access needed to comply with their own obligations. They must have a policy to respect EU copyright law and TDM opt-outs. And they must publish a summary of the content used to train the model.
Providers whose models reached the market before 2 August 2025 have until 2 August 2027 to comply.
For the full breakdown, see our guide to EU AI Act rules for general-purpose AI models.
Phase 3 High-Risk Systems Compliance Deadline
The original date for complying with obligations for high-risk systems was 2 August 2026. But Digital Omnibus moved the deadline for standalone Annex III systems to 2 December 2027. This change is still pending formal adoption. Until it is published in the EU Official Journal, 2 August 2026 remains the binding date.
AI systems which can pose risks to safety, health and fundamental rights are tagged as high-risk systems. Various applications including AI systems in law enforcement, educational institutions, employment and border control management are classified as high-risk AI systems.
Providers of high-risk AI systems face heavy controls in the Act. They must
- Operate a risk management system across the system’s lifecycle
- Apply data governance standards to training and testing data
- Prepare full technical documentation and keep automatic logs
- Design the system for effective human oversight
Before the system reaches the market, the provider must complete a conformity assessment. They must then register the system in the EU database and affix the CE marking.
Deployer obligations for high-risk systems
Deployers carry separate duties. They must use the system in line with the provider’s instructions, assign competent human oversight and monitor operation. They must run a fundamental rights impact assessment in certain situations and keep logs.
JAGGAER
JAI manages Compliance and Oversight.
JAGGAER AI ensures human oversight, continuous monitoring and provides full audit logs — with security and compliance at its core.
For the full EU AI Act timeline across all phases, see the master table above.
For penalties and enforcement, see our guide to EU AI Act fines and enforcement.
Phase 4 Remaining Provisions through 2027 and Beyond
2 August 2027 is the final Article 113 deadline under the original regulation text. It applies to AI systems that are safety components of Annex I regulated products, where the product already requires third-party conformity assessment under its sector law.
The Digital Omnibus provisional agreement of 6–7 May 2026 proposes shifting Annex I embedded systems to 2 August 2028. That agreement is not formally adopted. Until it becomes law, 2 August 2027 is the legal deadline to plan against. Annex I covers 18 regulated product categories including medical devices, machinery, motor vehicles, in-vitro diagnostic devices, civil aviation equipment, and rail systems.
When Article 6(1) activates, full Chapter III Section 2 requirements apply: risk management (Article 9), technical documentation (Article 11), human oversight (Article 14), and accuracy and robustness (Article 15). These become part of your existing sector conformity assessment, not an addition to it.
Transitional provisions
Three transitional EU AI Act deadlines apply under Article 111. Check which one covers your system type.
- GPAI providers whose models were on market before 2 August 2025 must comply by 2 August 2027
- Annex X large-scale IT system components placed on market before 2 August 2027 have until 31 December 2030
- Public authority deployers have until 2 August 2030
Obligations by Actor Type
The table below maps obligations by role in the supply chain. Confirm your system’s deadline under Phase 3 or Phase 4, then use your actor column. All four actor types apply from the same baseline dates: 2 August 2026 for Annex III systems and 2 August 2027 for Annex I systems. Public authority deployers have until 2 August 2030 under Article 111(2). If your business is outside the EU but places AI systems on the EU market, the same obligations apply. See how the EU AI Act applies to non-EU businesses.
| Obligation | Providers | Deployers | Importers / Distributors |
|---|---|---|---|
| Technical documentation | ✅ Prepare and maintain before market placement | ✅ Receive and apply from provider | ✅ Verify present before supplying |
| Conformity assessment | ✅ Complete before placement. Self-assessment (Annex III) or notified body (Annex I Section A) | ✗ | ✅ Verify completed; verify CE marking present |
| Human oversight | ✅ Design system so natural persons can monitor, override, or stop it | ✅ Assign oversight to named, competent natural persons | ✗ |
| Registration in EU database | ✅ Register before market placement | ✅ Public authority deployers only. Verify registration before use. | ✗ |
| Transparency to affected persons | ✗ | ✅ Inform persons subject to system decisions where required by law | ✗ |
| Post-market monitoring | ✅ Establish and execute monitoring plan | ✅ Monitor operation. Notify provider of risks without undue delay. | ✗ |
| Role shift trigger | Baseline role | Any actor becomes a provider by: (a) re-labelling the system, (b) making a substantial modification, or (c) changing intended purpose so a non-high-risk system becomes high-risk | Same as Deployers |
| Applies from | Annex III: 2 Aug 2026. Annex I: 2 Aug 2027. |
Annex III: 2 Aug 2026. Annex I: 2 Aug 2027. Public authorities: 2 Aug 2030. |
Annex III: 2 Aug 2026. Annex I: 2 Aug 2027. |
JAGGAER
JAI tracks and logs procurement AI activity against compliance thresholds and deadline milestones.
JAGGAER AI is built according to workflows, thresholds and compliance obligations to ensure that procurement AI holds up to deadlines.
FAQ
The EU AI Act applies in 4 phases: prohibited practices from 2 February 2025, GPAI obligations from 2 August 2025, general applicability from 2 August 2026, and Annex I product-embedded system obligations from 2 August 2027. Transitional provisions under Article 111 extend specific deadlines to 2030.
The EU AI Act effective date was 1 August 2024, when it entered into force 20 days after publication in the Official Journal of the EU on 12 July 2024. Compliance obligations applied progressively from 2 February 2025.
High-risk AI system obligations apply from 2 August 2026 for Annex III systems under the current binding legal deadline. The Digital Omnibus proposes deferring this to 2 December 2027, but that change is pending Official Journal publication. Annex I product-embedded systems apply from 2 August 2027 (proposed deferral to 2 August 2028). Both dates are sourced from Article 113, Regulation (EU) 2024/1689.
GPAI model obligations under Chapter V of Regulation (EU) 2024/1689 came into force on 2 August 2025. Models on market before that date must comply by 2 August 2027 under Article 111(3).
The 8 categories of prohibited AI practices listed in Article 5 of Regulation (EU) 2024/1689 became enforceable on 2 February 2025, six months after the regulation entered into force.
There is no single implementation date. The EU AI Act effective date was 1 August 2024, but the last Article 113 deadline is 2 August 2027. Transitional provisions under Article 111 extend specific deadlines to 31 December 2030.
Yes. The EU AI Act applies in 4 phases between 2 February 2025 and 2 August 2027 under Article 113, with Article 111 transitional provisions extending specific deadlines to 2030.
Deployer obligations under Article 26 apply from 2 August 2026 for Annex III systems and 2 August 2027 for Annex I systems. Public authority deployers have until 2 August 2030 under Article 111(2).
EU AI Act enforcement began on 2 February 2025 for prohibited practices. GPAI enforcement by the EU AI Office started 2 August 2025. High-risk system enforcement begins from 2 August 2026 under Article 113.
The EU AI Act fully applies from 2 August 2027 under Article 113. Public authority deployers must comply by 2 August 2030 and Annex X IT system components by 31 December 2030 under Article 111.
Next Steps
Talk to a procurement expert.
Tell us your challenge. We will show you exactly where JAGGAER One fits into your current setup — with specifics, not a generic demo.
- Direct or indirect?
We handle both — on one platform. - Already have an ERP?
JAGGAER Link connects to 1,000+ systems, no rip-and-replace. - Need to show ROI fast?
We define outcomes and KPIs before you sign. - Vertical-specific?
Manufacturing, higher ed, public sector — configured, not customized.



