EU AI Act — the dates that drive your 2026 plan

The phased applicability of the EU AI Act through 2026–2027 in one calendar, plus what each milestone means for the work on your desk.

The calendar

Date What applies Action
2 Feb 2025 Prohibited practices (Art. 5) — social scoring, untargeted facial-recognition scraping, emotion recognition in workplace / education, real-time biometric ID in public spaces (narrow exceptions). AI literacy (Art. 4) for staff. Review use cases against Art. 5; remove prohibited ones. Roll out AI literacy training.
2 Aug 2025 GPAI model obligations (Arts 53–55). Codes of Practice in force. Governance, notified bodies, penalties framework operational. If you train or substantially fine-tune a GPAI model, publish technical documentation and a summary of training data. Deployers: confirm your provider has done this.
2 Aug 2026 Most high-risk system obligations (Arts 6–49 except Annex II). Transparency for limited-risk systems (Art. 50) — AI-generated content disclosure, chatbot identification, deepfake labelling. Operationalise Art. 14 human oversight, Art. 10 data governance, Art. 15 accuracy/robustness/cybersecurity for in-scope systems. Add AI-content disclosure to product UX.
2 Aug 2027 High-risk systems covered by Annex II (product safety legislation: medical devices, toys, machinery, lifts, etc.) — full obligations. Align AI conformity work with existing CE-marking processes.
31 Dec 2030 High-risk systems that are components of large-scale IT systems listed in Annex X — full obligations. Largely for public-sector systems; map exposure.

What "high-risk" means in practice

Annex III high-risk categories most likely to affect typical enterprises:

  • Recruitment, evaluation, promotion, termination (HR).
  • Access to and enjoyment of essential private services (credit, insurance pricing).
  • Educational access and assessment.
  • Critical infrastructure operation.
  • Law enforcement, migration, justice (public sector).

If you operate in any of these, your AI is presumed high-risk unless you can show a narrow Annex III(2) exception applies — with documented rationale.

What to put in the board pack

  • Which of your AI systems are prohibited, high-risk, limited-risk, minimal.
  • The Aug 2026 readiness plan with named owners.
  • The provider/deployer split for each system (Arts 16 vs 26).

Do this Monday

  1. Tag every system in your AI inventory with its EU AI Act class.
  2. Add the four dates above to your compliance calendar with 90-day pre-warnings.
  3. For Aug 2026, draft the Art. 50 transparency UX text now — review cycles take longer than the build.

Reviewer hot-buttons

  • A written classification per system, not "we think we are not high-risk".
  • A plan dated against the Aug 2026 milestone with engineering hours allocated.
  • Art. 50 disclosure visible in the actual product, not just the policy.