The EU Artificial Intelligence Act, which governs the development and/or use of artificial intelligence (AI) in the EU, entered into force on 1 August 2024 after approval by the European Parliament.
In order to help preserve business continuity and give organizations a chance to adapt to the new regulations, it contains a series of rolling deadlines for rules about deepfakes, general-purpose AI models, AI regulatory sandboxes, systems categorized as especially high-risk and more.
When the AI Act entered into force, it gave multiple deadlines for companies to comply with various strictures based on the size of the company and the intended use of AI, among other factors. On 2 February 2025, the first of these AI regulation deadlines passed, imposing (among other rules, such as provisions for AI literacy) prohibitions on uses deemed “unacceptable risk” such as social scoring, mass data scraping to build facial recognition databases, emotion recognition and AI systems that use manipulative or deceptive techniques to harmfully distort a person’s behavior.
On 2 August 2025, the second rolling deadline passed. In addition to mandating that various AI governance bodies such as the EU’s Advisory Forum and AI Board must be set up, it applied the AI Act’s obligations for providers of general-purpose AI models on topics such as transparency in development and the handling of copyrighted materials, as well as additional requirements for systems deemed to have “systemic risk.” On 2 August 2026, the AI Act became generally applicable, most notably rules about transparency obligations for systems including chatbots, enforcement and measures to support innovation in EU member states.
There are still several deadlines to come, however, and they are subject to change. The AI Omnibus entered into force on 27 July 2026, amending the AI Act to simplify some rules for small and medium-sized enterprises (SMEs) and startups. It also shifted the timetable for rules about systems used in sensitive contexts including biometrics, critical infrastructure and law enforcement, as well as the timeline for rules on AI systems used in conjunction with other highly-regulated products such as toys or elevators. Additionally, it extended the deadline for member states to establish at least one national AI regulatory sandbox.
Following is a list of the remaining deadlines, per the amendments of the AI Omnibus, as well as the rules that will go into effect on each date:
Stay up to date on the most important—and intriguing—industry news on AI, automation, data, quantum, infrastructure and security with the Think Newsletter, delivered twice weekly.
On 2 December 2026, two new requirements imposed by the AI Omnibus will take effect: the prohibition of two particular AI uses, and the requirement of particular AI systems that reached the market before 2 August 2026 to ensure their outputs are machine-readable and detectable as AI.
Under the AI Act’s Article 5, as of 2 December 2026 the AI Act prohibits “the placing on the market, the putting into service or the use of an AI system that generates or manipulates realistic images, videos, audio or similar material of an identifiable natural person’s intimate parts, or of an identifiable natural person engaged in sexually explicit activities, without that person’s freely-given, specific, informed, unambiguous and explicit consent for that generation or manipulation,” as well as material that falls under EU legal definitions of child-abuse material.
The Act distinguishes between providers and deployers of AI systems for this prohibition: For providers, it is illegal to put a system on the market when making such material is the “intended purpose” of the system or a “reasonably foreseeable and reproducible outcome” and the system lacks reasonable safeguards.
For deployers, the prohibition applies when they use an AI system for the purpose of generating or manipulating the prohibited material. Accidental generation is outside the prohibition, but deliberate misuse, circumvention of safeguards or use of an otherwise lawful system for the prohibited purpose is covered.
Article 111(4) of the AI Act specifies that providers of older generative AI systems which create synthetic audio, images, video or text and were placed on the market before 2 August 2026 must make sure their AI-generated content and outputs are machine-readable and “detectable as artificially generated or manipulated.” The rule does not apply to systems that are used for tasks that help with “standard editing” or are authorized for law enforcement purposes.
This is a transitional deadline for older systems; systems marketed after 2 August 2026 were already subject to these requirements as of that date.
On 2 August 2027, two new strictures of the AI Act will take effect:
· Rolling compliance deadlines for “legacy” general-purpose AI (GPAI) models
· Member states must have access to an AI regulatory sandbox
The EU AI Act defines general-purpose AI models as “an AI model, including where such an AI model is trained with a large amount of data using self-supervision at scale, that displays significant generality and is capable of competently performing a wide range of distinct tasks regardless of the way the model is placed on the market and that can be integrated into a variety of downstream systems or applications.”
The EU AI Act creates separate rules for GPAI that include policies to respect EU copyright laws, as well as preparing and making publicly available detailed summaries of the content used to train the model. GPAI models are generally overseen by the EU’s AI Office, which provides a general-purpose AI code of practice that providers can follow to ease administrative overhead. If a GPAI model is classified as posing a systemic risk, providers will have additional obligations.
The 2 August 2027 deadline closes a two-year transition period for GPAI models put on the market before 2 August 2025. Providers must then comply with all applicable regulations under the AI Act. Models placed on the market after 2 August 2025 were already subject to these regulations.
As of 2 August 2027, each member state of the EU must have at least one operational AI regulatory sandbox.
The AI Act defines a regulatory sandbox as “a controlled environment that fosters innovation and facilitates the development, training, testing and validation of innovative AI systems for a limited time before their being placed on the market.” Providers remain subject to applicable data protection and product safety requirements in these settings, among other legal restrictions.
Sandboxes must establish rules for:
· Eligibility, selection and admission
· Participation, monitoring and termination
· What will be tested and developed in the sandbox
· Exit reporting
· Terms and conditions
· Cooperation with national authorities
Additionally, by 2 August 2027 the European Commission must also adopt legislation identifying cases in which specific AI Act requirements or obligations for certain high-risk systems could be limited because existing legislation provides an “equivalent or higher level of protection.”
On 2 December 2027, rules for high-risk systems in the AI Act’s Annex III come into effect.
This deadline was originally 2 August 2026 but was postponed by the AI Omnibus. Annex III concerns special rules for high-risk systems involved with:
· Biometrics
· Critical infrastructure including critical digital infrastructure, road traffic, or supply of water, gas, heating or electricity
· Education and vocational training
· Employment and the management of workers
· Essential private and public services including healthcare services, insurance, consumer credit and emergency calls
· Law enforcement
· Migration, asylum and border control
· Administration of justice and democratic processes
On 2 December 2027, providers of systems that fall under Annex III will be required to implement:
Providers must establish, implement and document a risk-management system throughout the high-risk AI system’s lifecycle. It must identify, analyze and evaluate risks arising from the system’s intended use and any “reasonably foreseeable misuse,” while adopting appropriate risk-management measures.
The datasets used by high-risk systems for training are subject to quality and governance requirements for:
· Data collection
· Detecting and mitigating bias
· Relevance and representativeness
· Appropriate statistical properties
· Consideration of the particular setting in which the system will be used
Providers must prepare technical documentation that shows how the system complies with the AI Act, as well as giving authorities the necessary information to inspect their systems for compliance.
Under Chapter III, Section 2, Article 12 of the AI Act, high-risk AI systems must “technically allow for the automatic recording of events (logs) over the lifetime of the system.”
The systems must provide traceable logs that track system operation and situations that could create risks as defined by the AI Act.
The Act states that “High-risk AI systems shall be designed and developed in such a way as to ensure that their operation is sufficiently transparent to enable deployers to interpret a system’s output and use it appropriately.”
This includes instructions for use and descriptive information about:
· The system’s intended purpose
· Its capabilities and performance
· Known limitations
· Any circumstances that could affect performance
· Human oversight
· Maintenance, monitoring and logging
High-risk AI systems “shall be designed and developed in such a way, including with appropriate human-machine interface tools, that they can be effectively overseen by natural persons during the period in which they are in use.”
Oversight measures should be scaled according to the “risks, level of autonomy and context of use” of the high-risk AI system, and should enable those conducting oversight to understand the system’s capabilities and limitations, detect automation bias, interpret outputs, discard, override or reverse an output if they deem it necessary, or intervene in or stop the system when necessary.
The Act mandates that providers of high-risk systems should design and develop those systems to establish accuracy metrics and achieve resilience against both “errors, faults or inconsistencies” and attempts by third parties to exploit vulnerabilities in the system.
In addition to these requirements for systems, providers and operators will be required to provide:
Providers must establish a quality-management system that ensures compliance with policies relevant to the system by monitoring design and development, testing, data management, risk management, post-market monitoring, incident reporting and corrective action.
Before placing a system on the market, providers must register them and complete a conformity assessment based on the characteristics of the system and applicable provisions.
Providers must demonstrate the capability to monitor their system once it is on the market and take appropriate corrective action if it goes out of compliance, which could include correcting the system, withdrawing it, disabling it or recalling it.
Providers must report qualifying “serious incidents,” which are events that directly or indirectly lead to at least one of the following four outcomes:
· death or serious damage to health
· serious and irreversible disruption of the management and operation of critical infrastructure
· infringements of obligations under Union law intended to protect fundamental rights
· serious damage to property or the environment
Deployers are subject to a separate set of obligations, including following instructions for use, providing human oversight, monitoring systems, retaining logs and taking specified action when risks or serious incidents are identified. Additional obligations may apply depending on the deployer and use case.
On 2 August 2028, the relevant high-risk requirements become applicable to AI systems classified as high-risk under Article 6(1). An AI system falls within this category when both of the following conditions are met:
· It is intended as a safety component of a product covered by the Union harmonization legislation listed in Section A of Annex I, or it is itself such a product.
· The covered product is required by that legislation to undergo a third-party conformity assessment before being placed on the market or put into service.
Examples of products that fall under this risk category include certain kinds of toys and elevators. Machinery is subject to a distinct sectoral approach under Section B of Annex I. Regulation (EU) 2023/1230 must incorporate corresponding AI-related health and safety requirements through delegated acts applying by 2 August 2028.
Under Article 2(13) of the AI Act as amended by the AI Omnibus, some requirements for high-risk systems may be limited by delegated acts of the European Commission if existing regulations provide an “equivalent or higher level of protection” to the AI Act. Under an additional provision, certain machinery and transportation-related products that are already covered by sectoral legislation receive special treatment through regulators in that sector.