The timeline you should already have on your compliance Gantt chart
**August 1 2024 — entry into force.** Regulation (EU) 2024/1689 was published in the Official Journal on July 12 2024 and entered into force twenty days later, on August 1 2024. From that date, the clock started ticking on every staged obligation in the Act. No compliance was immediately due — but every internal program and every supplier contract executed after that date should already reference the Act by name. The consolidated text is at https://eur-lex.europa.eu/eli/reg/2024/1689/oj and the Commission's policy hub at https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai.
**February 2 2025 — prohibitions and AI literacy duties bit.** Article 5 prohibitions on unacceptable-risk AI — social scoring by public authorities, manipulative subliminal techniques, exploitation of vulnerabilities, untargeted scraping of facial images, emotion recognition in workplace and education contexts, biometric categorization for protected characteristics, and real-time remote biometric identification in publicly accessible spaces (with narrow law-enforcement exceptions) — became enforceable. Article 4 AI literacy obligations on providers and deployers also took effect: organizations using AI must ensure staff have a sufficient level of AI literacy to operate and oversee the systems. This sixteen months into enforcement, you should already have an AI literacy program documented.
**August 2 2025 — GPAI obligations and the governance regime.** The European AI Office at DG CNECT formally took over its exclusive competence for general-purpose AI on this date. GPAI providers — foundation model labs — became subject to transparency obligations, copyright policy obligations, and (for systemic-risk models above 10^25 FLOPs of training compute) additional adversarial testing, incident reporting, and cybersecurity obligations. The voluntary General-Purpose AI Code of Practice at https://digital-strategy.ec.europa.eu/en/library/general-purpose-ai-code-practice was published as the safe-harbor pathway. Member states' national notification regimes and the AI Board structure were also operational by this date.
**August 2 2026 — high-risk Annex III systems (the big one).** This is six weeks from publication of this guide. Every AI system listed in Annex III — biometric identification and categorization, critical infrastructure management, education and vocational training, employment and worker management, access to essential private and public services and benefits (including credit scoring and life/health insurance pricing), law enforcement use, migration/asylum/border control, and administration of justice/democratic processes — must be fully compliant. That means risk management system (Article 9), data governance (Article 10), technical documentation (Article 11), automatic logging (Article 12), transparency to deployers (Article 13), human oversight (Article 14), accuracy/robustness/cybersecurity (Article 15), conformity assessment, CE marking, and registration in the EU database (Article 49). If you are an HR tech vendor, credit scoring fintech, ed-tech grading vendor, or biometric vendor — this is your deadline.
**August 2 2027 — high-risk Annex I systems and full applicability.** AI systems that act as safety components in products already covered by the EU's New Legislative Framework — Medical Device Regulation, Machinery Regulation, Toy Safety Directive, Lifts Directive, Civil Aviation, Automotive Type-Approval, Marine Equipment Directive, Radio Equipment Directive — must be conformity-assessed under the integrated AI Act + sectoral regime. The longer runway exists because these products are already subject to mature third-party notified-body assessment, and the Commission gave industry an extra year to integrate AI Act obligations into existing technical files. Use the extra time — medical device technical files take six to eighteen months to refresh.
**Ongoing — post-market monitoring, incident reporting, and renewals.** From the moment each system is on the market, providers run Article 72 post-market monitoring plans and Article 73 serious incident reporting on a continuous basis. Article 16 places ongoing duties on providers; Article 26 on deployers. Substantial modifications to high-risk systems trigger a fresh conformity assessment. Treat the August deadlines as the start of compliance, not the end — the Act runs as a living regime, like GDPR, not a one-shot certification.