The clock: when each obligation bites

Lesson 5 of 5 in The EU AI Act at a Glance: Purpose, Scope, and the Risk Pyramid.

"Is the AI Act in force?" is the wrong question — it entered into force on 1 August 2024. The right question is "which obligations apply to my system today?", because the Act switches on in stages, and those stages were themselves amended after adoption.

The original design was simple: prohibitions and AI literacy first (2 February 2025 — six months in), the GPAI chapter plus governance and penalties next (2 August 2025), general application at the two-year mark (2 August 2026), and the Annex I embedded-products route last. Then came the Digital Omnibus: a Commission simplification package that, among other changes, pushed the high-risk application dates back — Annex III systems to 2 December 2027 and Annex I systems to 2 August 2028 — and set the synthetic-content transparency compliance deadline at 2 December 2026.

The EU AI Act application timeline

  • 2021-04-21European Commission proposes the AI Act:

    The first comprehensive horizontal AI law: product-safety architecture, risk tiers, prohibited practices. Three years of negotiation begin.

  • 2023-12-08AI Act trilogue deal:

    After a 36-hour final negotiation — GPAI rules and biometric carve-outs the sticking points — Parliament, Council, and Commission agree the text.

  • 2024-08-01EU AI Act enters into force:

    Regulation (EU) 2024/1689 begins its phased application: prohibitions Feb 2025, GPAI Aug 2025, general application Aug 2026, high-risk tiers thereafter.

  • 2025-02-02AI Act prohibitions + AI literacy apply:

    The eight Art 5 bans (social scoring, workplace emotion recognition, untargeted face scraping…) become enforceable, alongside the Art 4 AI-literacy duty.

  • 2025-07-10EU GPAI Code of Practice published:

    Three chapters — transparency, copyright, safety & security — the practical compliance route for general-purpose model providers ahead of the August deadline.

  • 2025-08-02AI Act GPAI rules, governance, and penalties apply:

    Model-provider duties (Art 53), systemic-risk obligations (Art 55), the AI Office’s supervisory powers, and the penalty regime all go live.

  • 2025-11-19Digital Omnibus proposes AI Act simplification:

    The Commission’s package defers high-risk application dates — Annex III to 2 Dec 2027, Annex I to 2 Aug 2028 — among wider changes. Final adopted details: check current status.

  • 2026-08-02AI Act general application:

    The Act’s main body applies — transparency duties, governance structures, sandboxes operational in every Member State. High-risk tiers follow on the deferred schedule.

  • 2026-12-02Synthetic-content marking compliance deadline:

    Art 50(2) machine-readable marking and detectability duties for AI-generated content become enforceable (per the Omnibus schedule).

  • 2027-12-02High-risk rules apply — Annex III systems:

    The full Arts 8–15 + conformity-assessment stack becomes enforceable for use-case-based high-risk AI (hiring, credit, education, policing…). Deferred from Aug 2026 by the Omnibus.

  • 2027-08-02Legacy GPAI models must comply:

    Models placed on the market before August 2025 reach their compliance deadline for the Art 53/55 duties.

  • 2028-08-02High-risk rules apply — Annex I products:

    AI embedded in regulated products (machinery, medical devices, vehicles…) reaches full AI Act enforceability, aligned with sectoral conformity regimes.

The dates that matter (post-Omnibus) — commit the bold rows to memory
DateWhat switches onWhy it matters

1 Aug 2024

Entry into force

Clock starts; nothing yet enforceable

2 Feb 2025

Prohibitions (Art 5) + AI literacy (Art 4)

The bans and the training duty came first — already live

2 Aug 2025

GPAI chapter (Arts 51–56), governance bodies, penalties framework

Model providers’ duties began; AI Office supervision live

2 Aug 2026

General application of the Act

The default date for everything not given its own date

2 Dec 2026

Synthetic-content transparency compliance deadline (Art 50 marking)

Machine-readable marking of AI content must be in place

2 Aug 2027

Legacy GPAI models (on the market before 2 Aug 2025) must comply

The grace period for pre-existing foundation models ends

2 Dec 2027

Annex III high-risk obligations apply (Omnibus deferral)

The big one for most companies: employment, credit, education systems

2 Aug 2028

Annex I high-risk obligations apply (Omnibus deferral)

AI embedded in regulated products: machinery, medical devices…

End of 2030

Outer grandfathering horizon (Art 111), incl. large-scale EU IT systems

Legacy public-sector systems’ final deadline

Two grandfathering rules complete the picture. Legacy GPAI models — on the market before 2 August 2025 — get until 2 August 2027 to comply. Legacy high-risk systems placed on the market before their application date are caught only when they undergo a significant change in design — except systems used by public authorities, which must comply regardless, and large-scale EU IT systems (think border databases), which have until the end of 2030 (Art 111).

The strategic reading: the EU sequenced the Act to ban the worst first, discipline the model layer second, and give the compliance-heavy high-risk regime the longest runway — then extended that runway when standards and guidance ran late. Every module that follows sits somewhere on this clock; when you learn an obligation, always ask when it bites, not just what it says.

Tool: Regulatory Time Machine — Scrub the 2024–2030 timeline yourself: pin a system and watch which obligations switch on at each date, with the Omnibus toggle on and off.

Interactive checkpoint quiz (1 questions) — open this page in a browser to take it.