Timeline

The EU AI Act deadlines

The EU AI Act does not apply all at once, but in clearly defined stages. Two important obligations are already in force today — and the next major deadline is approaching faster than many realise.

The EU AI Act timeline

The EU legislator gave the EU AI Act a staggered entry into force, a deliberate choice to give companies time to adapt. Those who wait until all deadlines have passed, however, will have waited too long. The timeline below shows which obligations apply from when:

  • 1 August 2024: The EU AI Act (Regulation (EU) 2024/1689) enters into force and is directly applicable in all member states as an EU Regulation, without national implementing legislation. The transitional periods for most obligations begin to run.
  • 2 February 2025: Prohibited AI practices under Article 5 are banned with immediate effect. At the same time, the AI literacy obligation under Article 4 applies: companies must ensure that all individuals who use AI professionally have sufficient AI knowledge.
  • 2 August 2025: Obligations for GPAI models (General Purpose AI) take effect. In parallel, the governance structure becomes applicable: the EU AI Office, national market surveillance authorities and the penalty provisions become enforceable.
  • 2 August 2026: The majority of the provisions for high-risk AI systems become applicable. This is the central date for companies that deploy or develop AI in sensitive areas such as recruitment, credit scoring or critical infrastructure.
  • 2 August 2027: The last transitional periods expire, for certain high-risk AI systems used as a safety component in already-regulated products (e.g. medical devices, machinery).

What applies today?

When the EU AI Act entered into force on 1 August 2024, the clock started running. Since 2 February 2025, the first hard obligations have applied, for virtually every company that uses AI professionally.

Prohibited practices (Art. 5): Certain AI applications have since been fully banned. These include systems that manipulate people without their knowledge, social scoring by government authorities and uncontrolled real-time biometric mass matching in public spaces. Anyone operating or developing such systems has been acting unlawfully since February 2025.

AI literacy obligation (Art. 4): Alongside this, Article 4 requires providers and deployers to ensure that all persons deployed have an appropriate level of AI knowledge. This obligation explicitly covers deployers too, i.e. companies that use finished AI products such as chatbots, analysis tools or AI-powered recruitment software without developing them themselves. The vast majority of all companies fall into exactly this category.

The AI literacy obligation under Art. 4 has applied since 2 February 2025, regardless of company size and the risk class of the AI in use. Companies that have not yet trained their employees should do so now. Proof of documented training is the most important compliance instrument.

What comes next?

The next major deadline is 2 August 2026. From that date, the core provisions of the EU AI Act for high-risk AI systems become fully applicable, and with them the associated fine provisions. Companies that cannot produce solid compliance evidence by then risk substantial penalties.

What counts as high-risk? The EU AI Act defines specific areas of application in Annex III: AI in recruitment and HR management, in educational and vocational training institutions, in credit scoring, in critical infrastructure and in law enforcement. AI systems that prepare or influence decisions about access to essential public or private services can also be classified as high-risk.

For high-risk systems, from August 2026, the requirements include, among others: a documented risk management system, technical documentation, human oversight and a quality management system — as well as proof of sufficient AI literacy of the persons deployed. The risk-based approach and the four risk classes are explained on our EU AI Act overview page.

Sanctions already possible: The EU AI Act's penalty provisions have been applicable since 2 August 2025. Infringements of prohibited practices carry fines of up to €35 million or 7 % of global annual turnover. Violations of the AI literacy obligation and other deployer obligations can be sanctioned with up to €15 million or 3 %. All details on the fines page.

What companies should do and by when

  • Immediately: create an AI inventory: Where does your company use AI systems, and which risk class do those applications belong to?
  • Immediately (if not already done): organise AI literacy training for all employees who use AI professionally, and document participation in a verifiable manner. authorities can request proof.
  • By August 2026: for high-risk AI, verify and ensure that risk management, technical documentation and human oversight are in place and demonstrable in accordance with the EU AI Act's requirements.
  • Ongoing: when introducing new AI tools and GPAI models, assess their risk class and any transparency obligations before putting them into production use.
  • Ongoing: keep training records safely and refresh them regularly. AI is evolving fast, and the law expects up-to-date knowledge.

Frequently asked questions about the deadlines

The AI literacy obligation already applies, but what exactly does that mean?

Article 4 of the EU AI Act requires providers and deployers to ensure that all persons who use or supervise AI have sufficient AI knowledge. The law deliberately defines the content in a technology-neutral way. It is not about all employees being able to code. It is about them understanding how the systems in use work, what risks they carry and when human intervention is needed. A structured EU AI Act training course is the most direct way to meet and document this obligation. More details are explained on the Art. 4: AI literacy obligation page.

We only use simple AI tools. Does this really affect us?

Yes. The AI literacy obligation under Article 4 applies regardless of whether a company develops AI or "merely" uses it. Anyone who professionally uses an AI chatbot, an AI-powered translation tool or automated analysis software is a deployer within the meaning of the EU AI Act and therefore bound by the obligation. The risk class of the AI in use determines the scope of further obligations. But the literacy obligation applies to all. Further answers can be found on our FAQ page.

Train your team now Understand the AI literacy obligation

This overview is based on the official application timeline of Regulation (EU) 2024/1689 and does not constitute legal advice.