AI Act implementation and adoption timeline

The EU Artificial Intelligence Act, which governs the development and/or use of artificial intelligence (AI) in the EU, entered into force on 1 August 2024 after approval by the European Parliament.

In order to help preserve business continuity and give organizations a chance to adapt to the new regulations, it contains a series of rolling deadlines for rules about deepfakes, general-purpose AI models, AI regulatory sandboxes, systems categorized as especially high-risk and more.

When the AI Act entered into force, it gave multiple deadlines for companies to comply with various strictures based on the size of the company and the intended use of AI, among other factors. On 2 February 2025, the first of these AI regulation deadlines passed, imposing (among other rules, such as provisions for AI literacy) prohibitions on uses deemed “unacceptable risk” such as social scoring, mass data scraping to build facial recognition databases, emotion recognition and AI systems that use manipulative or deceptive techniques to harmfully distort a person’s behavior.

On 2 August 2025, the second rolling deadline passed. In addition to mandating that various AI governance bodies such as the EU’s Advisory Forum and AI Board must be set up, it applied the AI Act’s obligations for providers of general-purpose AI models on topics such as transparency in development and the handling of copyrighted materials, as well as additional requirements for systems deemed to have “systemic risk.” On 2 August 2026, the AI Act became generally applicable, most notably rules about transparency obligations for systems including chatbots, enforcement and measures to support innovation in EU member states.

There are still several deadlines to come, however, and they are subject to change. The AI Omnibus entered into force on 27 July 2026, amending the AI Act to simplify some rules for small and medium-sized enterprises (SMEs) and startups. It also shifted the timetable for rules about systems used in sensitive contexts including biometrics, critical infrastructure and law enforcement, as well as the timeline for rules on AI systems used in conjunction with other highly-regulated products such as toys or elevators. Additionally, it extended the deadline for member states to establish at least one national AI regulatory sandbox.

Following is a list of the remaining deadlines, per the amendments of the AI Omnibus, as well as the rules that will go into effect on each date:

2 December 2026

On 2 December 2026, two new requirements imposed by the AI Omnibus will take effect: the prohibition of two particular AI uses, and the requirement of particular AI systems that reached the market before 2 August 2026 to ensure their outputs are machine-readable and detectable as AI.

Prohibited AI practices

Under the AI Act’s Article 5, as of 2 December 2026 the AI Act prohibits “the placing on the market, the putting into service or the use of an AI system that generates or manipulates realistic images, videos, audio or similar material of an identifiable natural person’s intimate parts, or of an identifiable natural person engaged in sexually explicit activities, without that person’s freely-given, specific, informed, unambiguous and explicit consent for that generation or manipulation,” as well as material that falls under EU legal definitions of child-abuse material.

The Act distinguishes between providers and deployers of AI systems for this prohibition: For providers, it is illegal to put a system on the market when making such material is the “intended purpose” of the system or a “reasonably foreseeable and reproducible outcome” and the system lacks reasonable safeguards.

For deployers, the prohibition applies when they use an AI system for the purpose of generating or manipulating the prohibited material. Accidental generation is outside the prohibition, but deliberate misuse, circumvention of safeguards or use of an otherwise lawful system for the prohibited purpose is covered.

Readability and transparency rules

Article 111(4) of the AI Act specifies that providers of older generative AI systems which create synthetic audio, images, video or text and were placed on the market before 2 August 2026 must make sure their AI-generated content and outputs are machine-readable and “detectable as artificially generated or manipulated.” The rule does not apply to systems that are used for tasks that help with “standard editing” or are authorized for law enforcement purposes.

This is a transitional deadline for older systems; systems marketed after 2 August 2026 were already subject to these requirements as of that date.

2 August 2027

On 2 August 2027, two new strictures of the AI Act will take effect:

·       Rolling compliance deadlines for “legacy” general-purpose AI (GPAI) models

·       Member states must have access to an AI regulatory sandbox

Legacy GPAI

The EU AI Act defines general-purpose AI models as “an AI model, including where such an AI model is trained with a large amount of data using self-supervision at scale, that displays significant generality and is capable of competently performing a wide range of distinct tasks regardless of the way the model is placed on the market and that can be integrated into a variety of downstream systems or applications.”

The EU AI Act creates separate rules for GPAI that include policies to respect EU copyright laws, as well as preparing and making publicly available detailed summaries of the content used to train the model. GPAI models are generally overseen by the EU’s AI Office, which provides a general-purpose AI code of practice that providers can follow to ease administrative overhead. If a GPAI model is classified as posing a systemic risk, providers will have additional obligations.

The 2 August 2027 deadline closes a two-year transition period for GPAI models put on the market before 2 August 2025. Providers must then comply with all applicable regulations under the AI Act. Models placed on the market after 2 August 2025 were already subject to these regulations.

AI regulatory sandboxes

As of 2 August 2027, each member state of the EU must have at least one operational AI regulatory sandbox.

The AI Act defines a regulatory sandbox as “a controlled environment that fosters innovation and facilitates the development, training, testing and validation of innovative AI systems for a limited time before their being placed on the market.” Providers remain subject to applicable data protection and product safety requirements in these settings, among other legal restrictions.

Sandboxes must establish rules for:

·       Eligibility, selection and admission

·       Participation, monitoring and termination

·       What will be tested and developed in the sandbox

·       Exit reporting

·       Terms and conditions

·       Cooperation with national authorities

Additionally, by 2 August 2027 the European Commission must also adopt legislation identifying cases in which specific AI Act requirements or obligations for certain high-risk systems could be limited because existing legislation provides an “equivalent or higher level of protection.”

Think Keynotes

Win the enterprise AI race

Join Arvind Krishna to see how IBM is enabling AI-first enterprises through hybrid cloud and emerging quantum capabilities.

2 December 2027

On 2 December 2027, rules for high-risk systems in the AI Act’s Annex III come into effect.

This deadline was originally 2 August 2026 but was postponed by the AI Omnibus. Annex III concerns special rules for high-risk systems involved with:

·       Biometrics

·       Critical infrastructure including critical digital infrastructure, road traffic, or supply of water, gas, heating or electricity

·       Education and vocational training

·       Employment and the management of workers

·       Essential private and public services including healthcare services, insurance, consumer credit and emergency calls

·       Law enforcement

·       Migration, asylum and border control

·       Administration of justice and democratic processes

On 2 December 2027, providers of systems that fall under Annex III will be required to implement:

Risk-management systems

Providers must establish, implement and document a risk-management system throughout the high-risk AI system’s lifecycle. It must identify, analyze and evaluate risks arising from the system’s intended use and any “reasonably foreseeable misuse,” while adopting appropriate risk-management measures.

Data controls and governance

The datasets used by high-risk systems for training are subject to quality and governance requirements for:

·       Data collection

·       Detecting and mitigating bias

·       Relevance and representativeness

·       Appropriate statistical properties

·       Consideration of the particular setting in which the system will be used

Technical documentation

Providers must prepare technical documentation that shows how the system complies with the AI Act, as well as giving authorities the necessary information to inspect their systems for compliance.

Automatic logging

Under Chapter III, Section 2, Article 12 of the AI Act, high-risk AI systems must “technically allow for the automatic recording of events (logs) over the lifetime of the system.”

The systems must provide traceable logs that track system operation and situations that could create risks as defined by the AI Act.

Transparency requirements and instructions for deployers

The Act states that “High-risk AI systems shall be designed and developed in such a way as to ensure that their operation is sufficiently transparent to enable deployers to interpret a system’s output and use it appropriately.”

This includes instructions for use and descriptive information about:

·       The system’s intended purpose

·       Its capabilities and performance

·       Known limitations

·       Any circumstances that could affect performance

·       Human oversight

·       Maintenance, monitoring and logging

Human oversight

High-risk AI systems “shall be designed and developed in such a way, including with appropriate human-machine interface tools, that they can be effectively overseen by natural persons during the period in which they are in use.”

Oversight measures should be scaled according to the “risks, level of autonomy and context of use” of the high-risk AI system, and should enable those conducting oversight to understand the system’s capabilities and limitations, detect automation bias, interpret outputs, discard, override or reverse an output if they deem it necessary, or intervene in or stop the system when necessary.

Accuracy and cybersecurity

The Act mandates that providers of high-risk systems should design and develop those systems to establish accuracy metrics and achieve resilience against both “errors, faults or inconsistencies” and attempts by third parties to exploit vulnerabilities in the system.

In addition to these requirements for systems, providers and operators will be required to provide:

Quality-management systems

Providers must establish a quality-management system that ensures compliance with policies relevant to the system by monitoring design and development, testing, data management, risk management, post-market monitoring, incident reporting and corrective action.

Conformity assessment and registration

Before placing a system on the market, providers must register them and complete a conformity assessment based on the characteristics of the system and applicable provisions.

Post-market monitoring

Providers must demonstrate the capability to monitor their system once it is on the market and take appropriate corrective action if it goes out of compliance, which could include correcting the system, withdrawing it, disabling it or recalling it.

Serious-incident reporting

Providers must report qualifying “serious incidents,” which are events that directly or indirectly lead to at least one of the following four outcomes:

·       death or serious damage to health

·       serious and irreversible disruption of the management and operation of critical infrastructure

·       infringements of obligations under Union law intended to protect fundamental rights

·       serious damage to property or the environment

Deployers are subject to a separate set of obligations, including following instructions for use, providing human oversight, monitoring systems, retaining logs and taking specified action when risks or serious incidents are identified. Additional obligations may apply depending on the deployer and use case.

2 August 2028

On 2 August 2028, the relevant high-risk requirements become applicable to AI systems classified as high-risk under Article 6(1). An AI system falls within this category when both of the following conditions are met:

·       It is intended as a safety component of a product covered by the Union harmonization legislation listed in Section A of Annex I, or it is itself such a product.

·       The covered product is required by that legislation to undergo a third-party conformity assessment before being placed on the market or put into service.

Examples of products that fall under this risk category include certain kinds of toys and elevators. Machinery is subject to a distinct sectoral approach under Section B of Annex I. Regulation (EU) 2023/1230 must incorporate corresponding AI-related health and safety requirements through delegated acts applying by 2 August 2028.

Under Article 2(13) of the AI Act as amended by the AI Omnibus, some requirements for high-risk systems may be limited by delegated acts of the European Commission if existing regulations provide an “equivalent or higher level of protection” to the AI Act. Under an additional provision, certain machinery and transportation-related products that are already covered by sectoral legislation receive special treatment through regulators in that sector.

Derek Robertson

Staff Writer

IBM Think

Related solutions
Governance, risk and compliance (GRC) services 

Explore how IBM’s GRC services provide organizations with key capabilities across people, process and technology.

    Discover IBM GRC services
    Data security and protection solutions

    Protect data across multiple environments, meet privacy regulations and simplify operational complexity.

      Explore data security solutions
      IBM® OpenPages®

      Simplify data governance, risk management and regulatory compliance with IBM OpenPages—a highly scalable, AI-powered and unified GRC platform.

        Explore IBM OpenPages
        Take the next step

        Automate and manage your GRC tools. IBM Active Governance Services (AGS) integrates key cybersecurity and organizational data points into a centralized solution across cloud, on-premises and hybrid environments.

        1. Explore GRC services
        2. Explore data security solutions