Compliance CalendarEU AI Act

EU AI Act deadlines and compliance calendar

Track the staged AI Act application dates that matter for product, model, compliance, legal, security, and procurement owners.

Based on Article 113, Article 111, final Commission transparency guidance, GPAI guidance, and official AI Act source material; use it to assign owners and evidence before each date arrives.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 26, 2026
Sections
6

Structured answer sets in this page tree.

Primary sources
15

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 26, 2026
Overview

The next binding milestone is 27 July 2026, when Regulation (EU) 2026/1744 enters into force and AI Act Articles 102-110 begin to apply. The AI Act then applies generally from 2 August 2026, including most Article 50 transparency duties. Keep application dates, Article 111 transitions, binding amendments, Commission guidance, consultations, and voluntary codes in separate rows so teams know what is law, what supports compliance, and what still requires monitoring.

Section 1

Article 113 staged application dates to put on the calendar

is the binding anchor for the AI Act calendar. Regulation (EU) 2026/1744 amended it after publication in the Official Journal on 24 July 2026. The amendment enters into force on 27 July 2026, keeps the 2 August 2026 general application date, and replaces the earlier high-risk schedule for Chapter III Sections 1-3.

Use one calendar row per application date. Each row should identify the legal provision, affected systems or models, accountable owner, required evidence, and the internal readiness date that comes before the legal application date.

  • 1 August 2024: the Regulation entered into force, but entry into force did not make every operator duty immediately applicable.
  • 2 February 2025: Chapters I and II apply; calendar owners should cover AI literacy and prohibited-practice screening.
  • 2 August 2025: Chapter III Section 4, Chapter V, Chapter VII, Chapter XII, and Article 78 apply, except Article 101.
  • 2 August 2026: the Regulation applies as the main application date for obligations not covered by the specific exceptions.
  • 27 July 2026: Regulation (EU) 2026/1744 enters into force and Articles 102-110 apply.
  • 2 December 2026: the new Article 5(1) points (ba) and (bb), plus Article 5(1a) and (1b), apply.
  • 2 December 2027: Chapter III Sections 1-3 apply to high-risk systems classified under Article 6(2) and Annex III.
  • 2 August 2028: Chapter III Sections 1-3 apply to high-risk systems classified under Article 6(1) and Annex I.
  • Evidence to keep: source citation, affected chapter or article, system/model inventory slice, owner, readiness status, and approval date.
Section 2

2 February 2025: prohibited practices and AI literacy

The first operating deadline requires two active workstreams because Chapters I and II apply: an AI literacy owner for staff and other persons operating or using AI systems on the organisation's behalf, and a prohibited-practices owner for product and deployment screening.

The useful evidence is concrete: training audience, AI system context, role-specific literacy material, product-screening notes, and a release gate showing that prohibited-practice review happened before placing on the market, putting into service, or use.

  • AI literacy owner: legal/compliance sets the standard; product, engineering, support, and business owners identify who operates or uses each AI system.
  • Prohibited-practice owner: product and legal screen manipulation, exploitation of vulnerabilities, social scoring, certain biometric uses, and other Article 5 categories against the actual feature behavior.
  • Evidence: role-based literacy plan, attendance or completion records, product review notes, risk acceptance or rejection, and release-ticket links.
  • Reopen trigger: new AI feature, new user group, new deployment context, supplier model change, or expansion into workplace, education, law-enforcement, biometric, or vulnerable-person contexts.
Section 3

2 August 2025: GPAI, governance, confidentiality, and penalty chapters

The 2 August 2025 row should separate GPAI model-provider obligations from ordinary AI-system deployment work. brings Chapter V into application on this date, while Commission GPAI guidance states that GPAI provider obligations enter into application on 2 August 2025.

For organisations building on third-party GPAI models, the calendar should still assign a procurement and product owner. They need model documentation requests, downstream integration records, supplier contact points, and evidence that the product team knows whether the organisation is only deploying a model, integrating it into an AI system, or significantly modifying it.

  • GPAI provider owner: maintain model inventory, documentation status, copyright-policy evidence, public summary status, and systemic-risk notification review where relevant.
  • Downstream/product owner: record which GPAI model versions are integrated, what supplier documentation was received, and what product obligations depend on that model.
  • Compliance owner: track Chapter VII governance contacts, Article 78 confidentiality handling, and Chapter XII penalty exposure except Article 101 at this stage.
  • Procurement owner: add renewal triggers for model-provider documentation, material model changes, new model versions, and supplier non-response.
  • Evidence: model card or equivalent documentation, supplier correspondence, model version register, integration notes, and internal assessment of provider versus downstream-provider role.
Section 4

2026-2028: general application, enforcement, transitions, and changing high-risk dates

Use 2 August 2026 for the adopted Regulation's general application date, Article 50 transparency readiness, the start of Commission enforcement powers for GPAI provider obligations, and the Article 57 regulatory-sandbox deadline. These are different workstreams even though they share a date. The Commission published final Article 50 transparency guidelines on 20 July 2026; teams should use the final guidance for their last implementation review while treating the legal text as controlling.

Regulation (EU) 2026/1744 now makes 2 December 2027 the Chapter III Sections 1-3 application date for Annex III high-risk systems and 2 August 2028 the corresponding date for Article 6(1) systems. The separate 2 August 2027 transition applies to GPAI models placed on the market before 2 August 2025.

  • 2 August 2026: confirm general applicability, Article 50 interaction notices, synthetic-content marking, deployer disclosures, GPAI enforcement readiness, and any sandbox participation as separate rows.
  • Article 50 evidence: map each system to the applicable provider or deployer duty, document any exception, retain the approved notice or disclosure, and record how machine-readable marking is implemented where required.
  • 2 December 2026: complete the Article 111(4) transition for provider-side synthetic-output marking and detection for covered systems placed on the market before 2 August 2026, and apply the new Article 5 prohibitions.
  • 2 August 2027: close transition work for GPAI models placed on the market before 2 August 2025.
  • 2 December 2027 and 2 August 2028: complete the relevant Chapter III Sections 1-3 work for Annex III and Article 6(1) high-risk systems respectively.
  • High-risk owner: map the exact Annex I product route or Annex III use case, technical documentation, conformity route, registration, monitoring, and deployer dependencies.
  • Reopen trigger: formal amendment, final guidance, substantial modification, intended-purpose change, new model, new product route, or new deployment context.
Section 5

Article 111 transitional provisions to track separately

Article 111 creates specific transitional treatment for large-scale IT systems, pre-2 August 2026 high-risk systems, public-authority high-risk systems, and GPAI models placed on the market before 2 August 2025. It does not grant a general grace period to every AI system.

Keep these rows separate from . The owner must determine both when a chapter applies and whether an already-placed system or model is covered by a transition, has changed, is intended for public-authority use, or has a later compliance deadline.

  • Large-scale IT systems in Annex X: systems placed on the market or put into service before 2 August 2027 must be brought into compliance by 31 December 2030.
  • Other high-risk AI systems whose type and model were first placed on the market or put into service before the Chapter III date that applies under : Article 111 applies the Regulation only if, from that date, the systems are subject to significant design changes.
  • Synthetic-content systems placed on the market before 2 August 2026: providers must take the necessary steps to comply with Article 50(2) by 2 December 2026.
  • High-risk AI systems intended for use by public authorities: providers and deployers must take necessary steps to comply by 2 August 2030.
  • GPAI models placed on the market before 2 August 2025: providers must take the necessary steps to comply by 2 August 2027.
  • Evidence: first placing-on-market or putting-into-service date, change-control record, public-authority use flag, GPAI model market date, and owner sign-off on the applicable transition row.
Section 6

Owner and evidence planning fields for each calendar row

Tie each calendar row to a system or model inventory view so product and compliance teams can see which obligations are approaching, which evidence is missing, and who can unblock the work.

Do not validate unsupported future guidance dates in the calendar. If a date is not in the cited source material, leave it out and track the dependency as a watch item rather than a legal milestone. Commission evaluation and reporting dates under Article 112 are also watch items, not direct operator compliance deadlines.

Set an internal readiness date for each binding milestone. The internal date should allow time for role and classification review, implementation, evidence approval, supplier follow-up, and release gating; it is an organisation's planning control, not a legal extension or a substitute for the application date.

  • Calendar row fields: date, source article or guidance page, affected chapter or obligation set, systems/models in scope, owner, evidence owner, readiness status, and next review trigger.
  • System/model fields: provider, deployer, importer, distributor, downstream provider, GPAI provider, public-authority use, Annex I product route, Annex III category, and significant-change status.
  • Evidence fields: source URL, source quote, inventory export, role assessment, risk classification, supplier documentation, training record, conformity evidence, registration evidence, and approval record.
  • Owner fields: legal interpretation, product behavior, engineering controls, security evidence, privacy review, procurement supplier file, quality/conformity assessment, operations monitoring, and executive escalation.
  • Watch items: Commission guidance, harmonised standards, supplier model changes, product redesign, new deployment context, and authority requests; do not turn watch items into dated obligations without source support.
Primary sources

References and citations

digital-strategy.ec.europa.eu
Referenced sections
  • Commission policy page used for implementation context, risk categories, high-risk provider workflow, and transition support through the AI Pact and Service Desk.
"risk-based rules for AI developers and deployers"
digital-strategy.ec.europa.eu
Referenced sections
  • Commission announcement confirming publication of the final transparency guidelines on 20 July 2026 and the 2 August 2026 application date for Article 50 obligations.
"which start to apply on 2 August 2026"
digital-strategy.ec.europa.eu
Referenced sections
  • Non-binding Commission guidance explains the Annex III and product-integrated high-risk dates and identifies the classification guidance as draft pending final adoption.
eur-lex.europa.eu
Referenced sections
  • Primary legal text used for cited calendar rows, AI Act roles, staged dates, transition provisions, and high-risk classification.
"binding in its entirety and directly applicable"
eur-lex.europa.eu
Referenced sections
  • Primary legal text for transition rows covering existing high-risk AI systems, Annex X large-scale IT systems, public-authority use, and pre-2 August 2025 GPAI models.
"AI systems already placed on the market"
eur-lex.europa.eu
Referenced sections
  • Primary legal text confirming the 2 August 2025 application of Chapter V and related chapters listed in Article 113.
"Chapter V, Chapter VII and Chapter XII"
eur-lex.europa.eu
Referenced sections
  • Primary legal text for Article 113 staged application dates, Article 111 transition provisions, Article 4 AI literacy, Article 5 prohibited practices, and Article 6(1) high-risk classification.
"Entry into force and application"
eur-lex.europa.eu
Referenced sections
  • Original legal text used for the AI literacy duty that began to apply with Chapter I on 2 February 2025 and was replaced on 27 July 2026.
"ensure, to their best extent, a sufficient level of AI literacy"
Related guides

Explore more topics

Are industry AI use cases high-risk under EU AI Act Annex III?
FAQ answer on when an industry AI use case falls under EU AI Act Annex III, how Article 6 classification works, when Article 6(3) can support a non-high-risk conclusion, and what evidence providers should keep.
EU AI Act AI System Classification Edge Cases FAQ
Answers for EU AI Act edge cases: AI system definition, inference versus simple rules, GPAI models, embedded products, territorial scope, roles, and classification evidence.
EU AI Act Applicability and Roles: Scope, Actor Map, and Evidence
Determine whether the EU AI Act applies to an AI system or GPAI model, map provider, deployer, importer, distributor, and product manufacturer roles, and record evidence for classification.
EU AI Act applicability test: scope, role, and risk classification
Stepwise EU AI Act applicability test for AI-system status, exclusions, territorial scope, operator role, prohibited uses, high-risk systems, GPAI models, transparency duties, and evidence records.
EU AI Act Article 5 Prohibited AI Practices Screening Guide
Screen AI systems against EU AI Act Article 5, including manipulation, social scoring, biometrics, law enforcement, and the new prohibited-content category.
EU AI Act Article 50 transparency disclosures FAQ
Article 50 FAQ for EU AI Act transparency duties covering chatbot notices, synthetic content marking, biometric and emotion notices, deepfakes, public-interest text, timing, accessibility, and exceptions.
EU AI Act Article 50 transparency, labeling, and user disclosures
Source-backed guide to EU AI Act Article 50 duties for user interaction notices, synthetic content marking, deepfake labels, emotion recognition notices, biometric categorisation notices, and related high-risk AI instructions for use.
EU AI Act Article 73 serious incident FAQ
FAQ on EU AI Act serious incident handling for high-risk AI systems, including Article 73 reporting, deployer escalation, corrective action, and GPAI systemic-risk distinctions.
EU AI Act Compliance Checklist by Risk Class
A practical EU AI Act checklist for classifying AI systems, assigning operator roles, screening prohibited practices, and collecting evidence for high-risk, GPAI, transparency, monitoring, and incident duties.
EU AI Act Compliance Program: roles, high-risk evidence, GPAI and incidents
Build an EU AI Act compliance program around provider, deployer, importer, distributor, high-risk, GPAI, transparency, monitoring, and incident evidence duties.
EU AI Act conformity assessment and notified bodies for high-risk AI
Source-backed guide to EU AI Act high-risk AI conformity assessment routes, provider evidence, EU declaration of conformity, CE marking, and notified body involvement.
EU AI Act FAQ: scope, roles, high-risk AI, GPAI, FRIA, and dates
Source-backed EU AI Act FAQ covering scope, roles, risk classification, GPAI, transparency, AI literacy, rights and complaints, sandboxes, authorities, SME provisions, and current legal status.
EU AI Act FRIA FAQ: Article 27 Scope, Contents, and Notification
Source-backed FAQ on when Article 27 requires a fundamental rights impact assessment, which deployers are covered, what the FRIA must contain, and how it relates to DPIAs and registration.
EU AI Act FRIA for high-risk AI systems: Article 27 scope and evidence
Source-backed guide to EU AI Act Article 27 fundamental rights impact assessments: who must run a FRIA, Article 6(2) triggers, Annex III carveouts, DPIA overlap, notification, and registration evidence.
EU AI Act GPAI and Systemic-Risk Duties: Article 53 and 55 FAQ
FAQ on EU AI Act duties for general-purpose AI model providers, including Article 53 documentation, copyright and training-summary duties, Article 55 systemic-risk duties, serious incidents, cybersecurity, and staged enforcement.
EU AI Act GPAI evidence pack checklist for Article 53 and 55
Build a source-backed evidence pack for EU AI Act GPAI model obligations: technical documentation, downstream information, copyright policy, training-content summary, and systemic-risk records where applicable.
EU AI Act GPAI Provider Obligations: Articles 53 and 55
Source-backed guide to EU AI Act duties for general-purpose AI model providers: Article 53 documentation, copyright policy, training-content summary, downstream information, and Article 55 systemic-risk controls.
EU AI Act High-Risk AI Requirements: Articles 8-16 and 26
Map the EU AI Act requirements for high-risk AI systems: risk management, data governance, technical documentation, logs, transparency, human oversight, accuracy, robustness, cybersecurity, and deployer duties.
EU AI Act high-risk AI use cases by industry | Article 6 and Annex III guide
Industry-by-industry guide to EU AI Act high-risk classification under Article 6, Annex III, Annex I product safety routes, exclusions, and provider/deployer boundaries.
EU AI Act high-risk conformity assessment route selector
Select the EU AI Act Article 43 conformity assessment route for a high-risk AI system, including Annex I product legislation, Annex III categories, notified body triggers, standards, declaration, CE marking, registration, and evidence.
EU AI Act high-risk requirements checklist: Articles 8-15
Checklist for EU AI Act high-risk AI system requirements in Articles 8-15: risk management, data governance, documentation, logs, transparency, human oversight, accuracy, robustness, and cybersecurity.
EU AI Act penalties and fines: Article 99 tiers and GPAI exposure
EU AI Act penalties explained: Article 99 fine tiers, prohibited-practice exposure, incorrect information, SME caps, Member State rules, and GPAI model fines.
EU AI Act post-market monitoring and serious incident reporting
Source-backed guide to EU AI Act Articles 72 and 73 for high-risk AI: monitoring plans, serious incident reporting, deployer escalation, corrective action, and GPAI distinctions.
EU AI Act post-market monitoring FAQ for high-risk AI systems
Answer to how providers and deployers should handle EU AI Act post-market monitoring for high-risk AI systems under Article 72, with serious-incident, log, corrective-action, and lifecycle-change triggers.
EU AI Act provider vs deployer role boundaries: Article 3 and Article 25 FAQ
FAQ on EU AI Act provider, deployer, operator, importer, distributor, authorised representative, product manufacturer, downstream provider, and GPAI model provider boundaries.
EU AI Act risk classification intake workflow
A source-based intake structure for classifying EU AI Act scope, prohibited practices, high-risk routes, Annex III use cases, GPAI model status, roles, and reassessment triggers.
EU AI Act serious incident reporting triage workflow: Article 73 and Article 55
Triage EU AI Act serious incidents by definition, actor, reporting route, deadline, deployer escalation, corrective action, and separate GPAI systemic-risk reporting.
EU AI Act Technical Documentation and Provider Evidence Templates
Build AI Act evidence templates for high-risk AI providers: Article 11 technical documentation, Annex IV fields, quality management, conformity, CE marking, registration, logs, and post-market monitoring.
EU AI Act technical documentation FAQ | Article 11 and Annex IV
What Article 11 and Annex IV require in high-risk AI technical documentation: system identity, intended purpose, architecture, data, testing, oversight, cybersecurity, conformity, and post-market monitoring.
EU AI Act Timeline Roadmap: Dates, Legal Status, Owners, and Evidence
Turn EU AI Act milestones into an implementation roadmap by separating enacted dates, political agreements, draft guidance, consultations, and voluntary codes, then assigning actions and evidence.
EU AI Act vs ISO/IEC 42001: legal duties, controls, and evidence limits
Compare the EU AI Act and ISO/IEC 42001:2023, including legal status, Article 17 quality management, high-risk duties, GPAI, evidence reuse, and assurance limits.
EU AI Act vs NIST AI RMF: legal duties, risk controls, and evidence boundaries
Compare the EU AI Act with NIST AI RMF 1.0 across legal status, GOVERN-MAP-MEASURE-MANAGE, high-risk duties, GPAI, evidence reuse, and revision limits.
FAQ: EU AI Act conformity assessment procedures and notified body selection
cited FAQ on EU AI Act Article 43 conformity assessment routes, Annex VI internal control, Annex VII notified-body review, CE marking, declarations, and registration.