Timeline RoadmapEU

EU AI Act Timeline and Phasing Roadmap

Use the timeline as a dated legal-status register for the AI Act's staged compliance deadlines.

For each milestone, record whether it comes from enacted law, a later political agreement, draft guidance, a consultation, or a voluntary code before assigning implementation work.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
5

Structured answer sets in this page tree.

Primary sources
13

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

The EU AI Act applies in stages. Prohibited practices and AI literacy already apply, general-purpose AI model obligations entered into application in 2025, and 2 August 2026 remains the general for provisions not assigned another date. Article 50 transparency duties also begin then, subject to the limited marking grace period for systems already on the market. Regulation (EU) 2026/1744, the Digital Omnibus on AI or , was published on 24 July 2026 and entered into force on 27 July 2026, including later high-risk and sandbox dates. This roadmap keeps each legal stage and source status visible before work is rescheduled.

Section 2

Already applicable: prohibited practices, AI literacy, and GPAI provider duties

Since 2 February 2025, Chapters I and II apply. Providers and deployers should therefore have an AI-literacy approach suited to the people operating or using their AI systems, and product or deployment review should stop or redesign uses that fall within Article 5 prohibited practices.

Since 2 August 2025, obligations for providers of general-purpose AI models have applied. A provider placing a model on the market after that date should already have the Article 53 documentation, downstream information, copyright policy, and public training-content summary workstream. Providers of models with systemic risk also need the Article 55 safety, evaluation, incident, and cybersecurity workstream.

  • Product and legal: maintain an Article 5 screen for releases, procurement, and changed uses.
  • People and system owners: document who needs AI literacy, what they need to understand, and why the training fits the system and affected persons.
  • model provider: maintain model scope, version, market-placement date, Article 53 evidence, systemic-risk assessment, and AI Office engagement.
  • Downstream provider: retain the model version and supplier information needed to understand capabilities, limits, and integration obligations.
  • Evidence: dated classification, owners, source, training record, provider documentation, copyright policy, public summary, and change trigger.
Section 3

2026 readiness: general application, Article 50, GPAI enforcement, and sandboxes

sets 2 August 2026 as the Regulation's general for provisions not assigned another date. Article 50 transparency obligations also apply from that date. They can require an AI-interaction notice, machine-readable marking of synthetic output, notices for emotion recognition or biometric categorisation, and disclosures for deepfakes or certain public-interest text, depending on the actor and use. A limited transition applies to Article 50(2): providers of systems placed on the market before 2 August 2026 have until 2 December 2026 to implement marking and detection. The Commission published final Article 50 guidelines on 20 July 2026, after the final voluntary transparency code was published on 10 June 2026.

The Commission's enforcement powers for provider obligations also enter into application on 2 August 2026. Regulation (EU) 2026/1744 amended Article 57 to require Member States to make at least one AI regulatory sandbox operational, individually or jointly, by 2 August 2027. A sandbox supports supervised development and testing; it does not waive prohibited-practice rules or automatically prove conformity.

  • Every system owner: confirm scope, role, risk route, applicable date, and evidence location.
  • Providers and deployers: identify each Article 50 trigger and approve the notice, marking, disclosure, exception analysis, timing, language, and accessibility treatment.
  • providers: prepare for Commission information requests, evaluation, monitoring, and enforcement from 2 August 2026.
  • Sandbox candidates: document the testing purpose, authority route, participant responsibilities, safeguards, exit criteria, and what remains necessary before market placement or use.
  • Evidence: status-labelled source, product decision, implementation artifact, approval, and reassessment trigger.
Section 4

2027 and 2028: transitions and amended high-risk dates

Article 111 gives providers of models placed on the market before 2 August 2025 until 2 August 2027 to comply.

Regulation (EU) 2026/1744 amended so Chapter III, Sections 1, 2, and 3 apply from 2 December 2027 for Annex III high-risk systems and 2 August 2028 for Article 6(1) and Annex I high-risk systems, except that Article 6(5) is not covered by those deferred dates. The amending Regulation was published on 24 July 2026 and entered into force on 27 July 2026.

  • Existing provider: identify every model placed on the market before 2 August 2025 and close Article 53 and, where relevant, Article 55 evidence before 2 August 2027.
  • Annex III owner: classify the intended purpose and exact Annex III area, then plan against the 2 December 2027 date in amended .
  • Product-regulatory owner: map Annex I product legislation, third-party assessment routes, and the 2 August 2028 date in amended .
  • Legal monitoring: retain Regulation (EU) 2026/1744, its Official Journal publication and entry-into-force dates, and the decision that reconciles old and new dates.
  • Do not postpone Article 5, AI literacy, , or Article 50 work because the high-risk dates were amended.
Section 5

Minimum fields for an auditable AI Act roadmap

One row should let a reviewer understand the date without opening every linked document. Store the legal status and affected actor beside the action and evidence, then give one person responsibility for monitoring changes.

Review the row whenever a system changes intended purpose, model, market, operator role, affected group, integration, or risk classification, and whenever the controlling legal or guidance source changes status.

Keep chronology and applicability separate. A milestone can occur on a known date without creating an operator deadline, while one legal can create different work for providers, deployers, importers, distributors, product manufacturers, model providers, public authorities, and Member States.

Should a political agreement replace the adopted AI Act date in our compliance calendar?

Not by itself. Keep the adopted-law date and add the political-agreement date as a separate status-labelled development. Replace the legal baseline only after verifying the formally adopted text, its Official Journal publication, entry into force, and the provision it amends.

Does following a voluntary code of practice change the date of the underlying AI Act obligation?

No. A code may provide a recognised way to demonstrate compliance, but the legal duty and its come from the AI Act or later binding legislation. Record code participation separately from legal applicability.

What should happen when an official source gives only a publication month?

Store the precision as month-only. If the visual timeline requires a day for positioning, explain that the first day is a display convention and do not describe it as the verified publication day.

  • Milestone name, date, date precision, jurisdiction, and status: enacted law, political agreement, draft, consultation, final guidance, or voluntary code.
  • Controlling article or official source, short explanation, affected actor, affected system or model, and transition population.
  • Required action, accountable owner, internal readiness date, dependency, and release or deployment gate.
  • Evidence link, reviewer, approval date, unresolved interpretation, and next source-monitoring date.
  • Reassessment triggers for product, model, supplier, role, purpose, geography, guidance, standards, and legal amendments.
Recommended next step

Track legal status, owners, actions, and evidence together

Use the visual timeline for chronology, then maintain one roadmap row per milestone with its legal status, affected systems and actors, internal readiness date, evidence, and change-monitoring owner.

Primary sources

References and citations

ai-act-service-desk.ec.europa.eu
Referenced sections
  • Article 4 requires providers and deployers to take measures, to their best extent, to ensure sufficient AI literacy for staff and other persons operating or using AI systems on their behalf.
"a sufficient level of AI literacy"
digital-strategy.ec.europa.eu
Referenced sections
  • Commission list of implementation guidelines planned across high-risk classification and duties, transparency, incidents, FRIA, value-chain responsibilities, post-market monitoring, and SME simplification.
"support compliance with the rules"
digital-strategy.ec.europa.eu
Referenced sections
  • This source reports the revised high-risk dates and states that the classification guidelines remain draft; the targeted consultation closed on 23 July 2026 and final Commission adoption remains pending.
"Following the political agreement on the AI Omnibus"
digital-strategy.ec.europa.eu
Referenced sections
  • The Commission roadmap identifies planned 2026 guidance on high-risk classification, transparency, serious incidents, FRIA, value-chain responsibilities, substantial modification, post-market monitoring, and simplified SME quality-management elements.
"clear and practical instructions on how to apply the AI Act"
digital-strategy.ec.europa.eu
Referenced sections
  • Official page for the final voluntary code supporting Article 50 marking and labelling duties, including its 10 June 2026 publication and sign-up context.
"transparency of AI-generated content"
eur-lex.europa.eu
Referenced sections
  • Articles 50 and 113 support the transparency application date and general application baseline; Regulation (EU) 2026/1744 amends the sandbox deadline and adds the Article 50(2) transition.
"Transparency obligations for providers and deployers of certain AI systems"
eur-lex.europa.eu
Referenced sections
  • Article 113 is the adopted-law baseline for entry into force and staged application; Article 111 provides transition rules for systems and GPAI models already on the market or in use.
"It shall apply from 2 August 2026"
eur-lex.europa.eu
Referenced sections
  • Primary legal text for the original application-date baseline, transitions, AI literacy, prohibited practices, transparency, high-risk systems, GPAI models, and operator duties, read with Regulation (EU) 2026/1744 for amended dates.
"Entry into force and application"
Related guides

Explore more topics

Are industry AI use cases high-risk under EU AI Act Annex III?
FAQ answer on when an industry AI use case falls under EU AI Act Annex III, how Article 6 classification works, when Article 6(3) can support a non-high-risk conclusion, and what evidence providers should keep.
EU AI Act AI System Classification Edge Cases FAQ
Answers for EU AI Act edge cases: AI system definition, inference versus simple rules, GPAI models, embedded products, territorial scope, roles, and classification evidence.
EU AI Act Applicability and Roles: Scope, Actor Map, and Evidence
Determine whether the EU AI Act applies to an AI system or GPAI model, map provider, deployer, importer, distributor, and product manufacturer roles, and record evidence for classification.
EU AI Act applicability test: scope, role, and risk classification
Stepwise EU AI Act applicability test for AI-system status, exclusions, territorial scope, operator role, prohibited uses, high-risk systems, GPAI models, transparency duties, and evidence records.
EU AI Act Article 5 Prohibited AI Practices Screening Guide
Screen AI systems against EU AI Act Article 5, including manipulation, social scoring, biometrics, law enforcement, and the new prohibited-content category.
EU AI Act Article 50 transparency disclosures FAQ
Article 50 FAQ for EU AI Act transparency duties covering chatbot notices, synthetic content marking, biometric and emotion notices, deepfakes, public-interest text, timing, accessibility, and exceptions.
EU AI Act Article 50 transparency, labeling, and user disclosures
Source-backed guide to EU AI Act Article 50 duties for user interaction notices, synthetic content marking, deepfake labels, emotion recognition notices, biometric categorisation notices, and related high-risk AI instructions for use.
EU AI Act Article 73 serious incident FAQ
FAQ on EU AI Act serious incident handling for high-risk AI systems, including Article 73 reporting, deployer escalation, corrective action, and GPAI systemic-risk distinctions.
EU AI Act Compliance Checklist by Risk Class
A practical EU AI Act checklist for classifying AI systems, assigning operator roles, screening prohibited practices, and collecting evidence for high-risk, GPAI, transparency, monitoring, and incident duties.
EU AI Act Compliance Program: roles, high-risk evidence, GPAI and incidents
Build an EU AI Act compliance program around provider, deployer, importer, distributor, high-risk, GPAI, transparency, monitoring, and incident evidence duties.
EU AI Act conformity assessment and notified bodies for high-risk AI
Source-backed guide to EU AI Act high-risk AI conformity assessment routes, provider evidence, EU declaration of conformity, CE marking, and notified body involvement.
EU AI Act deadlines and compliance calendar | Article 113 dates
EU AI Act compliance calendar for Regulation (EU) 2026/1744, Article 113 dates, Article 111 transitions, GPAI enforcement, Article 50, and high-risk systems.
EU AI Act FAQ: scope, roles, high-risk AI, GPAI, FRIA, and dates
Source-backed EU AI Act FAQ covering scope, roles, risk classification, GPAI, transparency, AI literacy, rights and complaints, sandboxes, authorities, SME provisions, and current legal status.
EU AI Act FRIA FAQ: Article 27 Scope, Contents, and Notification
Source-backed FAQ on when Article 27 requires a fundamental rights impact assessment, which deployers are covered, what the FRIA must contain, and how it relates to DPIAs and registration.
EU AI Act FRIA for high-risk AI systems: Article 27 scope and evidence
Source-backed guide to EU AI Act Article 27 fundamental rights impact assessments: who must run a FRIA, Article 6(2) triggers, Annex III carveouts, DPIA overlap, notification, and registration evidence.
EU AI Act GPAI and Systemic-Risk Duties: Article 53 and 55 FAQ
FAQ on EU AI Act duties for general-purpose AI model providers, including Article 53 documentation, copyright and training-summary duties, Article 55 systemic-risk duties, serious incidents, cybersecurity, and staged enforcement.
EU AI Act GPAI evidence pack checklist for Article 53 and 55
Build a source-backed evidence pack for EU AI Act GPAI model obligations: technical documentation, downstream information, copyright policy, training-content summary, and systemic-risk records where applicable.
EU AI Act GPAI Provider Obligations: Articles 53 and 55
Source-backed guide to EU AI Act duties for general-purpose AI model providers: Article 53 documentation, copyright policy, training-content summary, downstream information, and Article 55 systemic-risk controls.
EU AI Act High-Risk AI Requirements: Articles 8-16 and 26
Map the EU AI Act requirements for high-risk AI systems: risk management, data governance, technical documentation, logs, transparency, human oversight, accuracy, robustness, cybersecurity, and deployer duties.
EU AI Act high-risk AI use cases by industry | Article 6 and Annex III guide
Industry-by-industry guide to EU AI Act high-risk classification under Article 6, Annex III, Annex I product safety routes, exclusions, and provider/deployer boundaries.
EU AI Act high-risk conformity assessment route selector
Select the EU AI Act Article 43 conformity assessment route for a high-risk AI system, including Annex I product legislation, Annex III categories, notified body triggers, standards, declaration, CE marking, registration, and evidence.
EU AI Act high-risk requirements checklist: Articles 8-15
Checklist for EU AI Act high-risk AI system requirements in Articles 8-15: risk management, data governance, documentation, logs, transparency, human oversight, accuracy, robustness, and cybersecurity.
EU AI Act penalties and fines: Article 99 tiers and GPAI exposure
EU AI Act penalties explained: Article 99 fine tiers, prohibited-practice exposure, incorrect information, SME caps, Member State rules, and GPAI model fines.
EU AI Act post-market monitoring and serious incident reporting
Source-backed guide to EU AI Act Articles 72 and 73 for high-risk AI: monitoring plans, serious incident reporting, deployer escalation, corrective action, and GPAI distinctions.
EU AI Act post-market monitoring FAQ for high-risk AI systems
Answer to how providers and deployers should handle EU AI Act post-market monitoring for high-risk AI systems under Article 72, with serious-incident, log, corrective-action, and lifecycle-change triggers.
EU AI Act provider vs deployer role boundaries: Article 3 and Article 25 FAQ
FAQ on EU AI Act provider, deployer, operator, importer, distributor, authorised representative, product manufacturer, downstream provider, and GPAI model provider boundaries.
EU AI Act risk classification intake workflow
A source-based intake structure for classifying EU AI Act scope, prohibited practices, high-risk routes, Annex III use cases, GPAI model status, roles, and reassessment triggers.
EU AI Act serious incident reporting triage workflow: Article 73 and Article 55
Triage EU AI Act serious incidents by definition, actor, reporting route, deadline, deployer escalation, corrective action, and separate GPAI systemic-risk reporting.
EU AI Act Technical Documentation and Provider Evidence Templates
Build AI Act evidence templates for high-risk AI providers: Article 11 technical documentation, Annex IV fields, quality management, conformity, CE marking, registration, logs, and post-market monitoring.
EU AI Act technical documentation FAQ | Article 11 and Annex IV
What Article 11 and Annex IV require in high-risk AI technical documentation: system identity, intended purpose, architecture, data, testing, oversight, cybersecurity, conformity, and post-market monitoring.
EU AI Act vs ISO/IEC 42001: legal duties, controls, and evidence limits
Compare the EU AI Act and ISO/IEC 42001:2023, including legal status, Article 17 quality management, high-risk duties, GPAI, evidence reuse, and assurance limits.
EU AI Act vs NIST AI RMF: legal duties, risk controls, and evidence boundaries
Compare the EU AI Act with NIST AI RMF 1.0 across legal status, GOVERN-MAP-MEASURE-MANAGE, high-risk duties, GPAI, evidence reuse, and revision limits.
FAQ: EU AI Act conformity assessment procedures and notified body selection
cited FAQ on EU AI Act Article 43 conformity assessment routes, Annex VI internal control, Annex VII notified-body review, CE marking, declarations, and registration.