EU AI Act - the dates that drive your 2026 plan
The phased applicability of the EU AI Act through 2026-2027 in one calendar, plus what each milestone means for the work on your desk.
The calendar
| Date | What applies | Action |
|---|---|---|
| 2 Feb 2025 | Prohibited practices (Art. 5) - social scoring, untargeted facial-recognition scraping, emotion recognition in workplace / education, real-time biometric ID in public spaces (narrow exceptions). AI literacy (Art. 4) for staff. | Review use cases against Art. 5; remove prohibited ones. Roll out AI literacy training. |
| 2 Aug 2025 | GPAI model obligations (Arts 53-55). Codes of Practice in force. Governance, notified bodies, penalties framework operational. | If you train or substantially fine-tune a GPAI model, publish technical documentation and a summary of training data. Deployers: confirm your provider has done this. |
| 2 Aug 2026 | Most high-risk system obligations (Arts 6-49 except Annex II). Transparency for limited-risk systems (Art. 50) - AI-generated content disclosure, chatbot identification, deepfake labelling. | Operationalise Art. 14 human oversight, Art. 10 data governance, Art. 15 accuracy/robustness/cybersecurity for in-scope systems. Add AI-content disclosure to product UX. |
| 2 Aug 2027 | High-risk systems covered by Annex II (product safety legislation: medical devices, toys, machinery, lifts, etc.) - full obligations. | Align AI conformity work with existing CE-marking processes. |
| 31 Dec 2030 | High-risk systems that are components of large-scale IT systems listed in Annex X - full obligations. | Largely for public-sector systems; map exposure. |
What "high-risk" means in practice
Annex III high-risk categories most likely to affect typical enterprises:
- Recruitment, evaluation, promotion, termination (HR).
- Access to and enjoyment of essential private services (credit, insurance pricing).
- Educational access and assessment.
- Critical infrastructure operation.
- Law enforcement, migration, justice (public sector).
If you operate in any of these, your AI is presumed high-risk unless you can show a narrow Annex III(2) exception applies - with documented rationale.
What to put in the board pack
- Which of your AI systems are prohibited, high-risk, limited-risk, minimal.
- The Aug 2026 readiness plan with named owners.
- The provider/deployer split for each system (Arts 16 vs 26).
Do this Monday
- Tag every system in your AI inventory with its EU AI Act class.
- Add the four dates above to your compliance calendar with 90-day pre-warnings.
- For Aug 2026, draft the Art. 50 transparency UX text now - review cycles take longer than the build.
Reviewer hot-buttons
- A written classification per system, not "we think we are not high-risk".
- A plan dated against the Aug 2026 milestone with engineering hours allocated.
- Art. 50 disclosure visible in the actual product, not just the policy.