Logo

Artificial Intelligence

AI Act Timeline: What Applies Today (and What Waiting Could Cost You)

AI Act Timeline: What Applies Today (and What Waiting Could Cost You)

AI Act Timeline: Key Dates and Deadlines
AI Act Timeline: Key Dates and Deadlines

Faced with an AI Act implementation timeline stretching over several years, the temptation is obvious: wait for the dates to settle before acting.

That's a misreading. This regulatory calendar isn't just a checklist of deadlines. It's a progressive stress test of each organization's AI governance maturity, one milestone at a time.

This post helps you separate what's already in force from what's still subject to change, and what this time should be used to build, so you learn to apply this calendar to your own systems portfolio rather than simply endure it.

In a nutshell

  • The Digital Omnibus, formally adopted in June 2026, reshuffled part of the AI Act's timeline

  • The definitive prohibitions and the GPAI obligations are already in force, with no room for negotiation

  • August 2, 2026 remains the key date for the transparency obligations (Article 50), regardless of the high-risk deadline extension

  • High-risk systems now have until December 2, 2027 (Annex III) or August 2, 2028 (Annex I) to reach compliance

  • This extension does not excuse you from identifying the systems concerned within your IT estate right now

  • The right posture isn't to follow the calendar, but to build a governance model capable of absorbing it

ai act timeline

Reminder: what is the AI Act?

Regulation (EU) 2024/1689, better known as the AI Act, pursues a clear goal: protecting fundamental rights and people's safety without limiting Europe's capacity to innovate. It governs the development, market placement, and use of AI systems in Europe, and its provisions apply progressively, in successive waves. Much as GDPR once did for personal data, the AI Act imposes a new discipline - this time for AI systems.

How to Ensure Compliance with the AI Act

Download the guide

Which obligations are already in force?

Definitive prohibitions and the AI literacy obligation

Since February 2, 2025, a series of practices classified as "unacceptable risk" have been purely and simply banned across the European Union:

  • Social scoring by public authorities

  • Subliminal manipulation

  • Exploitation of cognitive vulnerabilities

  • Real-time biometric identification in public spaces

For most companies, this category doesn't directly touch their portfolio. It's still worth checking, though, as certain behavioral profiling or internal monitoring systems can come closer to this line than they first appear to.

That same date also brought the AI literacy obligation into force, and it's already producing effects. Every organization must ensure its staff have a sufficient level of understanding of the systems they use or deploy. In practical terms, for an IT department, this means having verified that no prohibited system is still active, and having launched at least a minimal training effort for teams.

Obligations for general-purpose AI model providers

Since August 2, 2025, providers of general-purpose AI (GPAI) models have been subject to strengthened transparency and governance obligations.

This date also shaped the regulation's institutional governance, with each member state designating the competent national authorities responsible for oversight.

For a deployer, this AI Act compliance deadline isn't an abstract check. It means making sure the model providers used within the organization (whether built in natively or consumed through a third-party API) meet these obligations, and formalizing that in contracts.

A trap to avoid: delegating your compliance

An IT department often holds several regulatory roles at once:

  • Provider, when it develops and markets its own AI tools

  • Deployer, when it integrates third-party solutions

  • Importer, when it redistributes internally models developed outside the EU

This overlap has a direct consequence: compliance cannot be delegated to your suppliers. Even when a solution is bought off the shelf, the organization remains responsible for how it's used - from risk classification to human oversight to documentation.

What does the August 2, 2026 deadline really change?

The Article 50 transparency obligations

From August 2, 2026, any user interacting with an AI system must be informed of it. In practice, this transparency obligation applies to every AI system: a customer service chatbot, an internal virtual assistant, a business conversational interface…

All of them must clearly communicate their artificial nature and identify themselves as AI, with no ambiguity for the end user. This is one of the pillars of the Commission's stated goal: trustworthy artificial intelligence.

August 2, 2026 is also the reference date for most of the regulation's general obligations - the date most organizations have flagged as the one to remember.

Why this date shouldn't be confused with the high-risk extension

This is where the most common confusion arises. The extension that's been widely discussed since spring 2026 concerns exclusively the obligations relating to high-risk systems - not the Article 50 transparency obligations, which remain due on August 2, 2026, with no additional grace period.

An organization deploying chatbots or AI assistants therefore cannot rely on the high-risk extension to delay compliance on this specific point.

"The AI Act's timeline gives the illusion that you can follow it passively. In reality, every deadline does nothing more than reveal whether the groundwork (knowing precisely what's running in your IT estate) has been done or not."

- Fouzia Mahieddine, Smoteo co-founder

Why was the high-risk deadline pushed back?

Delayed harmonized standards behind the extension

The extension isn't a political retreat by the legislature: it's a technical consequence.

The obligations for high-risk systems rest on harmonized standards (risk management, data quality, documentation, human oversight) that the European standardization bodies (CEN and CENELEC) weren't able to deliver within the originally planned timeframe.

Without these standards, companies would not have known concretely what to do, nor how to demonstrate compliance to supervisory authorities. Entry into force on August 2, 2026 would therefore have created major legal uncertainty rather than a workable framework.

The definitive deadlines

The Digital Omnibus, formally adopted in June 2026, now sets two dates depending on the type of system:

  • December 2, 2027 for standalone high-risk systems (Annex III) - such as biometrics, critical infrastructure, education, employment, essential services, migration

  • August 2, 2028 for high-risk systems embedded in products already subject to other regulations (Annex I) - such as medical devices, machinery, lifts

The obligations that will apply on these dates remain the same as those already in force for other systems since August 2026: technical documentation, risk management, CE marking, registration in the European database, human oversight throughout the system's lifecycle. Only the calendar has changed, not the level of requirement.

"An extended deadline doesn't erase a governance shortfall. It only moves the moment when that shortfall becomes visible."

- Fouzia Mahieddine, Smoteo co-founder

Want a complete view of every AI Act deadline, obligation, and risk level, along with a detailed action plan? Download the full compliance guide.

Which systems in your portfolio fall under high risk?

The eight areas identified in Annex III

Annex III of the regulation lists eight areas in which certain AI uses are automatically classified as high risk. It isn't the technology itself that's targeted, but the context and purpose of its use:

  • Biometrics (identification and categorization of individuals)

  • Critical infrastructure (energy, water, transport, digital)

  • Education and vocational training

  • Employment, worker management, and access to self-employment

  • Access to essential public and private services (credit, insurance, social benefits)

  • Law enforcement

  • Migration, asylum, and border management

  • Administration of justice and democratic processes

The most common cases for your IT department

For an IT department, the most frequent cases are:

  • Automated resume screening, candidate scoring, and performance evaluation (HR and recruitment)

  • Bank or insurance credit scoring

  • AI-assisted medical diagnosis

  • School assessment involving AI components

  • Safety of critical infrastructure (energy, water, transport)

  • Border control and identity verification

The same system can be classified as high risk in one organization and not in another: it all depends on the deployment context and the activity it actually influences. An HR recommendation tool, for instance, can shift from one category to another depending on how it's used.

A trap to avoid: classifying the software rather than the use case

Many organizations make the same mistake the first time around: they try to classify a tool, when it's actually the use that needs to be classified.

The same system can therefore generate different classifications depending on the contexts in which it's deployed. If your ERP, ATS, or CRM includes scoring or decision-recommendation features, you are a deployer of those features and subject to the corresponding obligations, whether you're aware of it or not. Documenting why a system was classified in a given category, and by whom, is worth as much as the classification itself.

How to turn this timeline into an action plan

The real risk isn't the date - it's the lack of visibility onto your IT ecosystem

Every AI Governance Act deadline assumes a silent prerequisite: knowing exactly which IT systems and AI agents operate within your organization, on what data, with what level of autonomy, and under whose responsibility. Without this visibility, no date can be anticipated - it can only be endured.

This is precisely what the timeline reveals, deadline after deadline: it's less a question of legal compliance than one of governance. Organizations that start now build this visibility progressively. Those that wait for the next deadline will have to reconstruct it under time pressure, in a rush. And this can't be improvised.

Why a one-off audit isn't enough to hold up over time

Even a rigorous AI audit produces a snapshot at a single point in time. Yet the AI Act's timeline stretches over several years, with systems that evolve, new uses that emerge, and teams that deploy tools without always reporting back to the IT department.

A registry frozen in a spreadsheet, or an audit carried out six months earlier, no longer reflects the reality of your IT estate. The visibility needed to navigate this calendar isn't therefore a state you reach once, but a capability you maintain continuously - something most traditional governance tools, designed for one-off checkpoints, simply don't allow.

What does that look like with Smoteo?

This is exactly the gap Smoteo closes:

  • The usage registry continuously centralizes every active AI system and initiative by department, along with their application context, owners, and qualified risk level. It's updated in real time rather than reconstructed at each deadline.

  • The AI Value Stream Map visually maps where these agents operate across your business and IT ecosystem: which domains they cover, which data they consume, which business capabilities they touch.

You end up with a documentation base that's directly usable against AI Act requirements, and that remains valid no matter how the calendar evolves next. Organizations that use Smoteo to structure themselves this way cut their pre-production non-compliance risk by 30%.

Take the lead on the AI Act timeline rather than just following it

The AI Act's timeline will likely keep evolving: new clarifications will come, standards will be published, some dates may still shift.

An organization that has built visibility into its IT estate rides out these adjustments without disruption. The question, then, isn't knowing the next date. It's knowing whether your organization would be ready, whatever date is set.

To go further, download the full AI Act compliance guide, with the details of every deadline, the four risk levels, and a seven-step action plan.

Practical Guide

How to Ensure Compliance with the AI Act

Deadline schedule, risk levels, and a comprehensive checklist to keep your project on track

Faced with an AI Act implementation timeline stretching over several years, the temptation is obvious: wait for the dates to settle before acting.

That's a misreading. This regulatory calendar isn't just a checklist of deadlines. It's a progressive stress test of each organization's AI governance maturity, one milestone at a time.

This post helps you separate what's already in force from what's still subject to change, and what this time should be used to build, so you learn to apply this calendar to your own systems portfolio rather than simply endure it.

In a nutshell

  • The Digital Omnibus, formally adopted in June 2026, reshuffled part of the AI Act's timeline

  • The definitive prohibitions and the GPAI obligations are already in force, with no room for negotiation

  • August 2, 2026 remains the key date for the transparency obligations (Article 50), regardless of the high-risk deadline extension

  • High-risk systems now have until December 2, 2027 (Annex III) or August 2, 2028 (Annex I) to reach compliance

  • This extension does not excuse you from identifying the systems concerned within your IT estate right now

  • The right posture isn't to follow the calendar, but to build a governance model capable of absorbing it

ai act timeline

Reminder: what is the AI Act?

Regulation (EU) 2024/1689, better known as the AI Act, pursues a clear goal: protecting fundamental rights and people's safety without limiting Europe's capacity to innovate. It governs the development, market placement, and use of AI systems in Europe, and its provisions apply progressively, in successive waves. Much as GDPR once did for personal data, the AI Act imposes a new discipline - this time for AI systems.

How to Ensure Compliance with the AI Act

Download the guide

Which obligations are already in force?

Definitive prohibitions and the AI literacy obligation

Since February 2, 2025, a series of practices classified as "unacceptable risk" have been purely and simply banned across the European Union:

  • Social scoring by public authorities

  • Subliminal manipulation

  • Exploitation of cognitive vulnerabilities

  • Real-time biometric identification in public spaces

For most companies, this category doesn't directly touch their portfolio. It's still worth checking, though, as certain behavioral profiling or internal monitoring systems can come closer to this line than they first appear to.

That same date also brought the AI literacy obligation into force, and it's already producing effects. Every organization must ensure its staff have a sufficient level of understanding of the systems they use or deploy. In practical terms, for an IT department, this means having verified that no prohibited system is still active, and having launched at least a minimal training effort for teams.

Obligations for general-purpose AI model providers

Since August 2, 2025, providers of general-purpose AI (GPAI) models have been subject to strengthened transparency and governance obligations.

This date also shaped the regulation's institutional governance, with each member state designating the competent national authorities responsible for oversight.

For a deployer, this AI Act compliance deadline isn't an abstract check. It means making sure the model providers used within the organization (whether built in natively or consumed through a third-party API) meet these obligations, and formalizing that in contracts.

A trap to avoid: delegating your compliance

An IT department often holds several regulatory roles at once:

  • Provider, when it develops and markets its own AI tools

  • Deployer, when it integrates third-party solutions

  • Importer, when it redistributes internally models developed outside the EU

This overlap has a direct consequence: compliance cannot be delegated to your suppliers. Even when a solution is bought off the shelf, the organization remains responsible for how it's used - from risk classification to human oversight to documentation.

What does the August 2, 2026 deadline really change?

The Article 50 transparency obligations

From August 2, 2026, any user interacting with an AI system must be informed of it. In practice, this transparency obligation applies to every AI system: a customer service chatbot, an internal virtual assistant, a business conversational interface…

All of them must clearly communicate their artificial nature and identify themselves as AI, with no ambiguity for the end user. This is one of the pillars of the Commission's stated goal: trustworthy artificial intelligence.

August 2, 2026 is also the reference date for most of the regulation's general obligations - the date most organizations have flagged as the one to remember.

Why this date shouldn't be confused with the high-risk extension

This is where the most common confusion arises. The extension that's been widely discussed since spring 2026 concerns exclusively the obligations relating to high-risk systems - not the Article 50 transparency obligations, which remain due on August 2, 2026, with no additional grace period.

An organization deploying chatbots or AI assistants therefore cannot rely on the high-risk extension to delay compliance on this specific point.

"The AI Act's timeline gives the illusion that you can follow it passively. In reality, every deadline does nothing more than reveal whether the groundwork (knowing precisely what's running in your IT estate) has been done or not."

- Fouzia Mahieddine, Smoteo co-founder

Why was the high-risk deadline pushed back?

Delayed harmonized standards behind the extension

The extension isn't a political retreat by the legislature: it's a technical consequence.

The obligations for high-risk systems rest on harmonized standards (risk management, data quality, documentation, human oversight) that the European standardization bodies (CEN and CENELEC) weren't able to deliver within the originally planned timeframe.

Without these standards, companies would not have known concretely what to do, nor how to demonstrate compliance to supervisory authorities. Entry into force on August 2, 2026 would therefore have created major legal uncertainty rather than a workable framework.

The definitive deadlines

The Digital Omnibus, formally adopted in June 2026, now sets two dates depending on the type of system:

  • December 2, 2027 for standalone high-risk systems (Annex III) - such as biometrics, critical infrastructure, education, employment, essential services, migration

  • August 2, 2028 for high-risk systems embedded in products already subject to other regulations (Annex I) - such as medical devices, machinery, lifts

The obligations that will apply on these dates remain the same as those already in force for other systems since August 2026: technical documentation, risk management, CE marking, registration in the European database, human oversight throughout the system's lifecycle. Only the calendar has changed, not the level of requirement.

"An extended deadline doesn't erase a governance shortfall. It only moves the moment when that shortfall becomes visible."

- Fouzia Mahieddine, Smoteo co-founder

Want a complete view of every AI Act deadline, obligation, and risk level, along with a detailed action plan? Download the full compliance guide.

Which systems in your portfolio fall under high risk?

The eight areas identified in Annex III

Annex III of the regulation lists eight areas in which certain AI uses are automatically classified as high risk. It isn't the technology itself that's targeted, but the context and purpose of its use:

  • Biometrics (identification and categorization of individuals)

  • Critical infrastructure (energy, water, transport, digital)

  • Education and vocational training

  • Employment, worker management, and access to self-employment

  • Access to essential public and private services (credit, insurance, social benefits)

  • Law enforcement

  • Migration, asylum, and border management

  • Administration of justice and democratic processes

The most common cases for your IT department

For an IT department, the most frequent cases are:

  • Automated resume screening, candidate scoring, and performance evaluation (HR and recruitment)

  • Bank or insurance credit scoring

  • AI-assisted medical diagnosis

  • School assessment involving AI components

  • Safety of critical infrastructure (energy, water, transport)

  • Border control and identity verification

The same system can be classified as high risk in one organization and not in another: it all depends on the deployment context and the activity it actually influences. An HR recommendation tool, for instance, can shift from one category to another depending on how it's used.

A trap to avoid: classifying the software rather than the use case

Many organizations make the same mistake the first time around: they try to classify a tool, when it's actually the use that needs to be classified.

The same system can therefore generate different classifications depending on the contexts in which it's deployed. If your ERP, ATS, or CRM includes scoring or decision-recommendation features, you are a deployer of those features and subject to the corresponding obligations, whether you're aware of it or not. Documenting why a system was classified in a given category, and by whom, is worth as much as the classification itself.

How to turn this timeline into an action plan

The real risk isn't the date - it's the lack of visibility onto your IT ecosystem

Every AI Governance Act deadline assumes a silent prerequisite: knowing exactly which IT systems and AI agents operate within your organization, on what data, with what level of autonomy, and under whose responsibility. Without this visibility, no date can be anticipated - it can only be endured.

This is precisely what the timeline reveals, deadline after deadline: it's less a question of legal compliance than one of governance. Organizations that start now build this visibility progressively. Those that wait for the next deadline will have to reconstruct it under time pressure, in a rush. And this can't be improvised.

Why a one-off audit isn't enough to hold up over time

Even a rigorous AI audit produces a snapshot at a single point in time. Yet the AI Act's timeline stretches over several years, with systems that evolve, new uses that emerge, and teams that deploy tools without always reporting back to the IT department.

A registry frozen in a spreadsheet, or an audit carried out six months earlier, no longer reflects the reality of your IT estate. The visibility needed to navigate this calendar isn't therefore a state you reach once, but a capability you maintain continuously - something most traditional governance tools, designed for one-off checkpoints, simply don't allow.

What does that look like with Smoteo?

This is exactly the gap Smoteo closes:

  • The usage registry continuously centralizes every active AI system and initiative by department, along with their application context, owners, and qualified risk level. It's updated in real time rather than reconstructed at each deadline.

  • The AI Value Stream Map visually maps where these agents operate across your business and IT ecosystem: which domains they cover, which data they consume, which business capabilities they touch.

You end up with a documentation base that's directly usable against AI Act requirements, and that remains valid no matter how the calendar evolves next. Organizations that use Smoteo to structure themselves this way cut their pre-production non-compliance risk by 30%.

Take the lead on the AI Act timeline rather than just following it

The AI Act's timeline will likely keep evolving: new clarifications will come, standards will be published, some dates may still shift.

An organization that has built visibility into its IT estate rides out these adjustments without disruption. The question, then, isn't knowing the next date. It's knowing whether your organization would be ready, whatever date is set.

To go further, download the full AI Act compliance guide, with the details of every deadline, the four risk levels, and a seven-step action plan.

Practical Guide

How to Ensure Compliance with the AI Act

About the Author

About the Author

Focus on What Matters

Everyone Drives Change, Smoteo Connects the Dots

Whatever your role - CIO, Architect, PMO, or Product Owner - we've got your back

Everyone Drives Change, Smoteo Connects the Dots

Whatever your role - CIO, Architect, PMO, or Product Owner - we've got your back