Chapter 2 of 11
Timelines and Thresholds: When Your Obligations Start to Bite
Deadlines in the EU AI Act are staggered and easy to misunderstand—this module turns the timeline into a practical calendar so you know exactly what is expected of your business in 2025, 2026, 2027 and beyond.
Orienting Yourself: How the AI Act Timeline Works
Why the Timeline Matters
The AI Act is already in force, but most duties are staggered over several years. To plan projects and budgets, you need to know exactly when each set of rules starts to bite.
Force vs Application
Entry into force (Aug 1, 2024) made the AI Act valid law. Entry into application is when concrete obligations start. The Act uses different application dates for different topics.
Multiple Clocks
You must track several clocks: a short one for prohibited practices, a medium one for general rules (around Aug 2, 2026), and longer ones for high-risk AI and GPAI models.
Your Goal in This Module
By the end, you should be able to turn the legal timeline into a project calendar: what your organization must do now, in 2026–2027, and in the following years.
Phase 1: Early Dates and Prohibited Practices
Unacceptable-Risk AI
The AI Act bans certain AI uses outright. These include manipulative systems, harmful exploitation of vulnerabilities, some social scoring, and most real-time remote biometric ID in public spaces.
Early Application
These prohibitions kicked in about 6 months after entry into force, around February 2025. By July 2026 they are long active: you cannot rely on any grace period here.
Impact on Projects
Any AI project that might fall into a prohibited category must be stopped or redesigned. This is true even if the rest of the AI Act obligations have not yet fully applied.
Vendor Considerations
If you sell AI systems, you must ensure you are not marketing prohibited systems into the EU. Claims like "for research only" do not bypass a prohibition on unacceptable-risk AI.
Phase 2: The General Application Date – August 2, 2026
General Application Date
Around August 2, 2026, many of the AI Act’s general rules start to apply. This is when the Act becomes part of everyday compliance for most organizations using AI.
Who Is Affected
Providers and deployers of non-high-risk AI must start complying with transparency and governance duties. AI literacy expectations begin to matter in practice.
New Expectations
You must classify your AI systems, add user-facing transparency (like AI interaction notices and some content labels), and have basic AI governance structures in place.
Planning for August 2026
Treat August 2, 2026 as a key deadline: by then you should know your AI inventory, risk levels, and have policies and staff training started, even if high-risk rules apply later.
Phase 3: High-Risk AI – Later Application and Grace Periods
What Is High-Risk AI?
High-risk AI covers sensitive areas like critical infrastructure, education, employment, essential services, law enforcement, migration, and justice. These systems face the toughest rules.
Later Application
High-risk rules apply later than August 2026, roughly around mid‑2027 and beyond, with detailed dates and transition periods defined in the Act.
Heavier Obligations
High-risk systems need risk management, quality data, technical documentation, logging, human oversight, and strong robustness and cybersecurity controls.
Use the Grace Period Wisely
Extra time does not mean you can wait. Use 2025–2027 to map high-risk systems, plan redesigns, and bake AI Act compliance into procurement and development roadmaps.
Phase 4: GPAI Models and Foundation Models
What Is GPAI?
General-purpose AI (GPAI) models are broad, flexible models like large language or vision models that can be adapted to many tasks and integrated into many systems.
GPAI Obligations
The AI Act requires GPAI providers to document data sources, manage risks, and provide technical info. Extra duties apply to very large, systemic-risk models.
Timeline Nuance
GPAI rules kick in after standards and codes of practice are developed. They apply earlier than some high-risk details but later than the bans on prohibited practices.
Downstream Users
If you use GPAI via APIs, focus on whether your use becomes high-risk and on contracts that guarantee you get enough info from the GPAI provider to stay compliant.
Map Your Organization’s AI to the Timeline
Use this thought exercise to connect the AI Act timeline to concrete systems.
Task 1: List your AI systems
Write down 3–5 AI systems your (real or hypothetical) organization uses or plans to use. For each, note:
- Name (e.g. "Customer support chatbot")
- Purpose (e.g. "Answer customer questions")
- Who provides it (in-house, vendor, cloud API)
Task 2: Classify by risk and type
For each system, decide:
- Could it be prohibited? (Yes/No)
- Is it likely high-risk under the AI Act? (Yes/No/Unsure)
- Does it rely on a GPAI model (like a general LLM or vision model)? (Yes/No/Unsure)
If you are unsure, that is fine. The goal is to practice thinking in categories.
Task 3: Assign a primary deadline
For each system, assign the earliest relevant deadline:
- If it might be prohibited: Already applicable (since ~Feb 2025).
- If not prohibited but used in the EU: General rules (around Aug 2, 2026).
- If clearly high-risk: High-risk deadlines (mid‑2027 and beyond).
- If GPAI provider: GPAI-specific deadlines after standards and codes of practice.
Task 4: Pick one system and plan actions
Choose the system with the earliest deadline and answer:
- What do you need to know or document this year to be safe?
- Do you depend on a vendor to meet your obligations? If yes, what contract changes or questions do you need?
- What AI literacy training do the users of this system need before they rely on its outputs?
Write short bullet points. The goal is not perfection, but to build the habit of aligning AI projects with regulatory dates.
Case Study: A Mid-Sized Bank Planning 2025–2028
Bank Scenario Overview
A mid-sized EU bank uses: 1) a customer chatbot, 2) credit scoring AI, 3) HR screening AI, and 4) an internal GPAI assistant. Each falls under different parts of the AI Act.
Risk Classification
Chatbot: limited-risk. Credit scoring and HR screening: likely high-risk. GPAI assistant: downstream use of a GPAI model via a vendor.
Timeline Mapping
Chatbot and GPAI assistant: focus on transparency and governance by Aug 2, 2026. High-risk systems: prepare for heavier obligations around mid‑2027 and beyond.
Project Calendar
2025–mid‑2026: inventory, notices, training, gap analysis. Aug 2026–2027: implement high-risk controls. 2028+: continuous monitoring and updates as guidance evolves.
Check Your Understanding: Timelines and Priorities
Answer this question to test your grasp of the AI Act timeline.
Your company operates a non-high-risk customer service chatbot in the EU and is piloting a high-risk AI system for credit scoring. It does not develop its own GPAI models. Which statement best describes your **earliest** urgent compliance focus as of July 2026?
- Focus first on high-risk credit scoring obligations, because all high-risk rules already fully apply before August 2026.
- Focus first on ensuring the chatbot meets transparency and governance requirements by around August 2, 2026, while planning high-risk credit scoring compliance over the following years.
- You can safely wait until all high-risk deadlines in 2027–2028 before doing anything, because the AI Act only applies to high-risk systems.
- Immediately stop using the chatbot because all AI systems are treated as prohibited practices after August 2, 2026.
Show Answer
Answer: B) Focus first on ensuring the chatbot meets transparency and governance requirements by around August 2, 2026, while planning high-risk credit scoring compliance over the following years.
The general application date around August 2, 2026 makes transparency and governance for non-high-risk systems (like the chatbot) an urgent priority. High-risk obligations apply later, with transitional periods, so you should start planning for the credit scoring system now but do not need full compliance before August 2026. The AI Act has been in force since 2024 and covers more than high-risk systems, but it does not treat all AI as prohibited.
Review: Key Timeline Terms
Use these flashcards to reinforce the core concepts about timing and thresholds.
- Entry into force
- The date a law becomes legally valid. For the EU AI Act, this was August 1, 2024, when it started existing as binding EU law, even though many obligations applied later.
- Entry into application
- The date when specific obligations of a law start to apply in practice. For the AI Act, many general rules apply around August 2, 2026, with other parts applying earlier or later.
- Prohibited (unacceptable-risk) AI practices
- Certain AI uses banned outright, such as manipulative systems, some social scoring by public authorities, and most real-time remote biometric ID in public spaces. These bans started applying around February 2025.
- High-risk AI system
- An AI system used in sensitive contexts like critical infrastructure, education, employment, essential services, law enforcement, migration, or justice. It faces strict obligations that apply later and with transitional periods.
- General-purpose AI (GPAI) model
- A broad, flexible AI model (such as a large language model) that can perform many tasks and be integrated into many systems. The AI Act sets baseline and enhanced duties for GPAI providers, with timelines linked to future standards.
- AI literacy
- The knowledge and skills people need to understand and use AI systems responsibly. Under the AI Act, organizations are expected to improve AI literacy of staff, especially as general rules apply from August 2026 onward.
- Transitional arrangements
- Grace periods that let existing AI systems, especially high-risk ones, continue operating for a limited time while they are adapted to meet new requirements. They do not apply to prohibited practices.
Key Terms
- AI literacy
- The ability of individuals to understand what AI systems do, their limits, and how to use them responsibly.
- Entry into force
- The moment a law becomes legally valid and binding at a high level. For the EU AI Act, this was August 1, 2024.
- High-risk AI system
- An AI system used in sensitive domains like critical infrastructure, education, employment, essential services, law enforcement, migration, or justice, subject to strict obligations.
- Entry into application
- The moment when specific obligations in a law start to apply in practice, often at different dates for different sections.
- Transitional arrangements
- Time-limited periods allowing existing AI systems to keep operating while being brought into compliance with new legal requirements.
- General-purpose AI (GPAI) model
- A broad, flexible AI model that can serve many purposes and be integrated into many downstream systems, such as large language models.
- Prohibited practices (unacceptable-risk AI)
- AI uses that the AI Act bans outright, such as certain manipulative systems, some social scoring, and most real-time remote biometric identification in public spaces.