The clock: when each obligation bites
Lesson 5 of 5 in The EU AI Act at a Glance: Purpose, Scope, and the Risk Pyramid.
"Is the AI Act in force?" is the wrong question — it entered into force on 1 August 2024. The right question is "which obligations apply to my system today?", because the Act switches on in stages, and those stages were themselves amended after adoption.
The original design was simple: prohibitions and AI literacy first (2 February 2025 — six months in), the GPAI chapter plus governance and penalties next (2 August 2025), general application at the two-year mark (2 August 2026), and the Annex I embedded-products route last. Then came the Digital Omnibus: a Commission simplification package that, among other changes, pushed the high-risk application dates back — Annex III systems to 2 December 2027 and Annex I systems to 2 August 2028 — and set the synthetic-content transparency compliance deadline at 2 December 2026.
The EU AI Act application timeline
- 2021-04-21 — European Commission proposes the AI Act:
The first comprehensive horizontal AI law: product-safety architecture, risk tiers, prohibited practices. Three years of negotiation begin.
- 2023-12-08 — AI Act trilogue deal:
After a 36-hour final negotiation — GPAI rules and biometric carve-outs the sticking points — Parliament, Council, and Commission agree the text.
- 2024-08-01 — EU AI Act enters into force:
Regulation (EU) 2024/1689 begins its phased application: prohibitions Feb 2025, GPAI Aug 2025, general application Aug 2026, high-risk tiers thereafter.
- 2025-02-02 — AI Act prohibitions + AI literacy apply:
The eight Art 5 bans (social scoring, workplace emotion recognition, untargeted face scraping…) become enforceable, alongside the Art 4 AI-literacy duty.
- 2025-07-10 — EU GPAI Code of Practice published:
Three chapters — transparency, copyright, safety & security — the practical compliance route for general-purpose model providers ahead of the August deadline.
- 2025-08-02 — AI Act GPAI rules, governance, and penalties apply:
Model-provider duties (Art 53), systemic-risk obligations (Art 55), the AI Office’s supervisory powers, and the penalty regime all go live.
- 2025-11-19 — Digital Omnibus proposes AI Act simplification:
The Commission’s package defers high-risk application dates — Annex III to 2 Dec 2027, Annex I to 2 Aug 2028 — among wider changes. Final adopted details: check current status.
- 2026-08-02 — AI Act general application:
The Act’s main body applies — transparency duties, governance structures, sandboxes operational in every Member State. High-risk tiers follow on the deferred schedule.
- 2026-12-02 — Synthetic-content marking compliance deadline:
Art 50(2) machine-readable marking and detectability duties for AI-generated content become enforceable (per the Omnibus schedule).
- 2027-12-02 — High-risk rules apply — Annex III systems:
The full Arts 8–15 + conformity-assessment stack becomes enforceable for use-case-based high-risk AI (hiring, credit, education, policing…). Deferred from Aug 2026 by the Omnibus.
- 2027-08-02 — Legacy GPAI models must comply:
Models placed on the market before August 2025 reach their compliance deadline for the Art 53/55 duties.
- 2028-08-02 — High-risk rules apply — Annex I products:
AI embedded in regulated products (machinery, medical devices, vehicles…) reaches full AI Act enforceability, aligned with sectoral conformity regimes.
| Date | What switches on | Why it matters |
|---|---|---|
1 Aug 2024 | Entry into force | Clock starts; nothing yet enforceable |
2 Feb 2025 | Prohibitions (Art 5) + AI literacy (Art 4) | The bans and the training duty came first — already live |
2 Aug 2025 | GPAI chapter (Arts 51–56), governance bodies, penalties framework | Model providers’ duties began; AI Office supervision live |
2 Aug 2026 | General application of the Act | The default date for everything not given its own date |
2 Dec 2026 | Synthetic-content transparency compliance deadline (Art 50 marking) | Machine-readable marking of AI content must be in place |
2 Aug 2027 | Legacy GPAI models (on the market before 2 Aug 2025) must comply | The grace period for pre-existing foundation models ends |
2 Dec 2027 | Annex III high-risk obligations apply (Omnibus deferral) | The big one for most companies: employment, credit, education systems |
2 Aug 2028 | Annex I high-risk obligations apply (Omnibus deferral) | AI embedded in regulated products: machinery, medical devices… |
End of 2030 | Outer grandfathering horizon (Art 111), incl. large-scale EU IT systems | Legacy public-sector systems’ final deadline |
Two grandfathering rules complete the picture. Legacy GPAI models — on the market before 2 August 2025 — get until 2 August 2027 to comply. Legacy high-risk systems placed on the market before their application date are caught only when they undergo a significant change in design — except systems used by public authorities, which must comply regardless, and large-scale EU IT systems (think border databases), which have until the end of 2030 (Art 111).
The strategic reading: the EU sequenced the Act to ban the worst first, discipline the model layer second, and give the compliance-heavy high-risk regime the longest runway — then extended that runway when standards and guidance ran late. Every module that follows sits somewhere on this clock; when you learn an obligation, always ask when it bites, not just what it says.
Tool: Regulatory Time Machine — Scrub the 2024–2030 timeline yourself: pin a system and watch which obligations switch on at each date, with the Omnibus toggle on and off.
Interactive checkpoint quiz (1 questions) — open this page in a browser to take it.