02 Feb 2025
Article 5 prohibited AI practices are now illegal in the EU. Fines up to €35M or 7% of global turnover. In effect now.
02 Aug 2025
General-Purpose AI model obligations apply. GPAI providers must produce technical documentation, comply with copyright rules, and publish training data summaries. In effect now.
16 June 2026
The European Parliament granted final approval to amendments delaying high-risk obligations. Council adoption and Official Journal publication are expected by 02 August 2026; until then the current Act remains law. Treat this as added time to complete compliance work, not a relaxation of the obligations.
02 DEC 2026
Watermarking obligations take effect for AI systems placed on the market before 02 August 2026. Nudifier applications become a prohibited AI system. General transparency duties under Article 50 continue to apply.
02 Dec 2027 — Standalone high-risk systems
Obligations for standalone high-risk AI systems in the Annex III categories (employment, education, credit scoring, critical infrastructure, law enforcement, and similar) take effect. Articles 9, 10, 12, 13, 14, 26, 27, and 49 apply here. This 16-month delay from the original 02 Aug 2026 deadline covers most agentic AI in regulated functions.
02 Aug 2028
High-risk AI rules extend to AI embedded in regulated products — medical devices, machinery, toys, vehicles. If you deploy AI in physical products, this date applies to you.
| Article | What It Requires | Owner | Evidence You Need |
|---|---|---|---|
| Art. 9 | Continuous risk management across the full AI lifecycle | Provider | Vendor's risk management documentation — request in writing |
| Art. 10 | Data quality, governance, and regional handling controls for training data | Provider / Deployer if fine-tuning | Vendor's data governance documentation; your own data handling records if you fine-tune |
| Art. 12 | System must technically allow automatic logging over its lifetime | Provider | Vendor confirmation that logging is technically enabled |
| Art. 13 | Provider must supply transparency documentation on capabilities and limits | Provider | Vendor's transparency disclosure — should come with the product |
| Art. 14 | Human oversight mechanisms must be in place | Deployer | Your internal records: assigned oversight roles and training completed |
| Art. 26 | Monitor the system, retain logs 6 months, report incidents | Deployer | Activity logs, incident reports, oversight assignment records |
| Art. 27 | Fundamental rights impact assessment before deploying certain high-risk AI systems | Deployer (where applicable) | Completed FRIA documentation — required for public bodies and certain high-risk use cases |
| Art. 49 | Register in EU database before deployment | Provider + Deployer | EU database registration confirmation and your system inventory |
🔎
📋
🕐
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
These cookies are used for managing login functionality on this website.
Google Tag Manager simplifies the management of marketing tags on your website without code changes.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
Clarity is a web analytics service that tracks and reports website traffic.
Service URL: clarity.microsoft.com (opens in a new window)