EU AI Act Timeline: Key Compliance Deadlines Explained
The European Union AI Act officially entered into force on August 1, 2024, initiating a phased compliance implementation timeline that spans from 6 to 36 months. Key enforcement dates begin on February 2, 2025, with prohibitions on unacceptable-risk AI systems, followed by governance obligations for General-Purpose AI (GPAI) models on August 2, 2025. Obligations for standalone high-risk AI systems (Annex III) take effect on August 2, 2026, while embedded high-risk AI systems covered by existing EU sector harmonisation laws (Annex I) must comply by August 2, 2027. Organizations relying on or developing AI must map their systems to these statutory milestones immediately, utilizing management frameworks like ISO/IEC 42001 to ensure operational readiness.
Summary Timeline of EU AI Act Key Dates
Understanding the staggered rollout of the EU AI Act helps organizations allocate resources efficiently and avoid severe non-compliance penalties:
- August 1, 2024: EU AI Act officially enters into force.
- February 2, 2025 (6 Months): Enforcement begins for prohibited AI practices.
- August 2, 2025 (12 Months): Obligations for General-Purpose AI (GPAI) models, transparency rules, and national governance structures take effect.
- August 2, 2026 (24 Months): Full application of requirements for standalone high-risk AI systems (Annex III).
- August 2, 2027 (36 Months): Rules take effect for high-risk AI systems embedded in safety components governed by Annex I legislation (e.g., medical devices, automotive, civil aviation).
Breakdown of Statutory Compliance Phasing
Phase 1: Prohibited AI Practices (February 2025)
Systems deemed to pose an unacceptable threat to fundamental human rights are banned. This includes cognitive behavioral manipulation, untargeted scraping of facial images, emotion recognition in workplaces and educational institutions, social scoring systems, and predictive policing based purely on profiling.
Phase 2: General-Purpose AI Governance (August 2025)
Providers of GPAI models face transparency guidelines, technical documentation mandates, and copyright law compliance requirements. Systemic-risk GPAI models must undergo additional evaluations, adversarial testing (red-teaming), and cybersecurity safeguards enforced by the European AI Office.
Phase 3: High-Risk AI Systems under Annex III (August 2026)
Organizations deploying or manufacturing AI systems used in critical domains—such as critical infrastructure, education admissions, employment screening, essential public services, and law enforcement—must establish comprehensive risk management, data governance, continuous logging, and fundamental rights impact assessments (FRIA).
Phase 4: Embedded High-Risk Products (August 2027)
Products subject to third-party safety evaluations under broader EU product safety laws must integrate high-risk AI compliance procedures alongside traditional conformity assessments.
Why Waiting for Deadlines Is a Strategic Risk
While 2026 or 2027 may sound distant, establishing the operational capabilities necessary to demonstrate conformity takes significant lead time. Organizations must perform comprehensive AI inventories, classify risk profiles, set up continuous monitoring, and evaluate supply chain vendors well before statutory enforcement dates.
Furthermore, enterprise enterprise procurement teams are already inserting contractual requirements mirroring EU AI Act mandates into vendor negotiations. Waiting until final enforcement dates will limit market entry and increase operational friction.
Aligning ISO/IEC 42001 with the EU AI Act Timeline
ISO/IEC 42001 (Artificial Intelligence Management System) provides an ideal operational framework for meeting EU AI Act requirements systematically:
- Risk Management & Planning (Clause 6): Directly maps to the mandatory risk management systems required for high-risk AI providers under Article 9 of the EU AI Act.
- Impact Assessments (Control Domain A.5): Establishes structured assessments evaluating risks to individuals, groups, and society—directly supporting EU Fundamental Rights Impact Assessments (FRIA).
- Lifecycle Controls (Control Domain A.6): Ensures continuous design, testing, transparency, and logging mechanisms aligned with statutory post-market monitoring duties.
- Third-Party Relationships (Control Domain A.10): Streamlines oversight for vendors and supply chains supplying GPAI or sub-components.
By building an ISO/IEC 42001 management framework now, your organization can address EU AI Act deadlines as standard business processes rather than high-stress emergency projects.
Prepare Your Organization for AI Act Deadlines
To meet upcoming enforcement dates smoothly, follow these tactical steps:
- Build an AI Asset Inventory: Document all internally built and third-party AI models across your operational footprint.
- Classify Risk Tiers: Categorize every system against EU AI Act risk definitions (Unacceptable, High, Transparency/Limited, Minimal).
- Perform Gap Analyses: Measure current controls against ISO/IEC 42001 requirements to build a certification-ready baseline.
- Evaluate Readiness: Leverage specialized tools like DoAIRight's free readiness assessment to identify baseline gaps, refine control policies, and build an actionable compliance roadmap.
Frequently asked
When do EU AI Act fines and penalties begin to apply?
Penalties for prohibited AI practices begin on February 2, 2025 (up to €35M or 7% of global turnover). Penalties related to GPAI and standard obligations apply from August 2025 and August 2026 onward.
Is ISO/IEC 42001 mandatory for EU AI Act compliance?
ISO/IEC 42001 certification is not explicitly required by law, but implementing an ISO/IEC 42001 management system provides a recognized baseline that heavily aligns with harmonized EU standards.
Does the EU AI Act apply to non-EU companies?
Yes. The EU AI Act has extraterritorial reach. It applies to providers and deployers established outside the EU if the output produced by the AI system is intended for use within the EU market.
Does DoAIRight grant ISO/IEC 42001 certificates?
No. ISO/IEC 42001 certificates are issued exclusively by independent accredited certification bodies following formal human audits (per ISO/IEC 42006). DoAIRight provides tools and readiness assessments to help organizations prepare to pass certification audits.