The AI Act does not have one single start date. Its rules apply in phases. Regulation (EU) 2026/1744 is now in force and fixes the dates that were previously under debate: 2 December 2027 for the core obligations covering Annex III systems and 2 August 2028 for the core obligations covering Annex I systems.
For compliance planning, separate duties that already apply, the general application date of 2 August 2026, the limited Article 50(2) transition for certain existing systems, and the later high-risk dates. This is the binding timeline, not a provisional planning scenario.
Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744 is the governing law. The high-risk dates moved, but there is no pause button for Article 4 measures, Article 50 transparency, governance or evidence.
The short version
Work with three tracks
Already active: prohibited AI practices and AI literacy.
2026: general application, transparency duties, national supervision setup and operational preparation.
2027 and 2028: fixed application dates for the core high-risk obligations, depending on the type of AI system.
If you remember one thing: a delay for high-risk obligations does not delay preparation. It mostly shifts the moment when full compliance becomes enforceable. Inventory, role allocation, vendor assurance, data quality, logging and governance need to be in place before that.
Deadlines already in force
1 August 2024: entry into force
The AI Act entered into force on 1 August 2024. That does not mean every obligation applied immediately, but it did make the Act part of the EU legal framework. From that date, the phased application period started running.
2 February 2025: prohibited practices and AI literacy
Since 2 February 2025, Chapters I and II apply. In practical terms, this means two things.
First, prohibited AI practices are active. These include certain forms of manipulative AI, social scoring, untargeted scraping of facial images for biometric databases and prohibited emotion recognition in work and education settings.
Second, Article 4 on AI literacy applies. Providers and deployers must take proportionate measures supporting the development of AI literacy for staff and other persons dealing with AI systems on their behalf. The measures should reflect knowledge, experience, education, context and the people affected, but the law does not require a guaranteed individual level.
This is therefore not a future topic. For organizations that provide or use AI systems, AI literacy should already be part of the core compliance file. For training evidence and team competence, LearnWize is the logical next step.
2 August 2025: GPAI, governance and penalties
Since 2 August 2025, rules on general-purpose AI models, parts of the governance architecture and penalty provisions have applied. This mainly affects providers of GPAI models, but organizations procuring or integrating such models should include this in vendor assurance.
An organization relying on large language models, image models or other GPAI systems should be able to explain which provider is used, what documentation is available and which obligations have been passed through contractually.
2026: the operational year
2 August 2026: general application and Article 50
Under Article 113, the AI Act has generally applied since 2 August 2026, with the earlier exceptions above and the later date for certain product-related high-risk systems.
Under the amended law, this is the date on which many operational duties become relevant, including Article 50 transparency, market surveillance and national powers. The core obligations for Annex III high-risk systems follow on 2 December 2027.
For organizations, 2026 is not a waiting year. It is the year to set up AI inventory, classification, roles, procurement clauses, publication rules, human oversight measures and documentation processes.
Inventory AI systems
Map all AI systems: internal, procured, embedded in software, used by teams and offered to customers or citizens. Do not start with legal qualification. Start with actual use.
Classify risk and role
For each system, determine whether you are provider, deployer, importer, distributor or product manufacturer. Then determine whether the system is prohibited, high-risk, limited-risk or low-risk.
Organize evidence
Make sure you can prove decisions: why a system does or does not fall under Annex III, which source data is used, who provides oversight and which vendor documentation is available.
2 December 2026: limited Article 50(2) transition
Article 50 has applied since 2 August 2026. Regulation (EU) 2026/1744 gives providers of synthetic-content systems already on the market before that date until 2 December 2026 for the machine-readable marking duty in Article 50(2). This is a narrow transition, not a general postponement of Article 50.
For teams using content generation, chatbots, voicebots, image generation or public communication, Article 50 should not be treated as a late-stage detail. Transparency needs to become part of product design, publication workflow and vendor selection.
2027: high-risk AI becomes concrete
2 December 2027: Annex III high-risk systems under the amended law
Regulation (EU) 2026/1744 fixes 2 December 2027 for the core obligations covering high-risk AI systems in Annex III areas such as biometrics, critical infrastructure, education, employment, access to essential services, law enforcement, migration and administration of justice.
That gives organizations more time, but mainly for better implementation. An HR system ranking applicants, a credit scoring system or a municipal system selecting citizens for interventions still needs serious governance.
Use 2027 as the maturity deadline, not as the starting point.
2028: product chains and sector regimes
2 August 2028: Annex I product and safety systems under the amended law
For high-risk AI systems embedded in products or covered by Annex I sectoral EU safety legislation, Regulation (EU) 2026/1744 fixes the core application date at 2 August 2028.
This matters for providers in healthcare, industry, mobility, toys, radio equipment and other regulated product chains. The key question is not only whether the AI system complies with the AI Act. It is also how AI compliance fits into existing CE marking, technical documentation, risk assessment and post-market monitoring.
What about existing systems?
The AI Act contains transition rules for systems already placed on the market or put into service.
Article 111 contains transition rules for systems already placed on the market or put into service. The exact treatment depends on the system category, its applicable date and whether it undergoes a significant change. Record the original market date and every material change, then verify the route against the amended text.
For providers of GPAI models placed on the market before 2 August 2025, the necessary steps to comply must be taken by 2 August 2027.
The practical lesson: legacy systems still need to be labelled in your AI register. Otherwise, you will not know later which systems fall under a transition rule, which systems have been significantly modified and which systems become fully subject to new obligations.
Dutch supervision timeline
The Dutch consultation on the AI Act implementation law closed on 1 June 2026. That national law does not change the substance of the AI Act, but it determines who supervises in the Netherlands, how authorities cooperate and where organizations can expect questions or information requests.
For Dutch organizations, this matters because AI Act enforcement will not only happen in Brussels. Sectoral regulators such as AFM, DNB, IGJ, the Dutch Labour Inspectorate and the Dutch DPA are likely to play important practical roles. See also the analysis of the Dutch AI Act implementation law consultation.
Practical planning by quarter
Now to summer 2026
- Update your AI register.
- Remove or block prohibited practices.
- Document AI literacy by role and risk profile.
- Classify the most important AI systems.
- Set up vendor assurance for GPAI and critical suppliers.
- Create a baseline policy for AI transparency and AI-generated content.
Summer to end 2026
- Operationalize Article 50 transparency.
- Make sure chatbot, voicebot and content workflows can handle labels and disclosure.
- Link AI systems to owners, controls and evidence.
- Incorporate the Dutch supervision structure once finalized.
- Align the roadmap with Regulation (EU) 2026/1744 and record the applicable date per system.
2027
- Build out high-risk files: risk management, data governance, logging, technical documentation, human oversight and conformity assessment.
- Carry out FRIAs where Article 27 applies.
- Formalize procurement and supplier arrangements.
- Test whether oversight and escalation processes work in practice.
2028
- Integrate AI Act compliance into sectoral product and safety regimes.
- Align post-market monitoring, incident processes and technical documentation at product level.
- Make AI changes part of change management, not isolated legal review.
The mistake to avoid
The biggest mistake is thinking the AI Act only becomes relevant at the last formal deadline. That is not how this law works. The deadlines mark the moment when obligations become applicable or enforceable. Before then, the organization must already know which AI systems exist, who is responsible, what risks exist and what evidence is available.
Organizations that wait until the final date build compliance under pressure. Organizations that start now use any additional time to implement better.
Frequently asked questions
The most important questions and answers about AI Act deadlines.
Sources
Newsletter
Every Tuesday, the AI Act week ahead in 5 minutes
A practical briefing on deadlines, new guidance and enforcement, so you know what matters this week. No spam and you can unsubscribe in one click.
Practical and short · No spam · One-click unsubscribe