Several provisions have already come into force, marking the beginning of the compliance journey. The next major milestone arrives on 2 August 2026, when the requirements governing high-risk AI systems become applicable. As a result, organizations now have a limited window to assess their AI portfolios, strengthen governance frameworks, and prepare for the stricter compliance obligations that lie ahead.
Key EU AI Act Compliance Milestones
The EU AI Act has moved beyond policy discussions and is now shaping real-world operations. Organizations must prepare for several important deadlines that will introduce new compliance requirements across the AI lifecycle.
Critical Dates to Remember:
Organizations must comply with transparency requirements for applicable AI systems, ensuring users are appropriately informed when interacting with AI.
Most standalone high-risk AI systems will become subject to extensive compliance obligations, including risk management, documentation, human oversight, and monitoring requirements.
High-risk AI systems embedded within already regulated products, such as medical devices, machinery, and vehicles, must fully comply with the EU AI Act.
What is the EU AI Act Timeline?
The EU AI Act is being implemented gradually rather than taking effect on a single date. Regulation (EU) 2024/1689 introduces a phased compliance schedule between 2024 and 2027, with each milestone activating new obligations for organizations that develop, deploy, or use AI systems within the European Union.
The regulation officially entered into force on 1 August 2024, but enforcement follows a staged approach to give organizations and regulators sufficient time to prepare.
Key EU AI Act Deadlines
1 August 2024 – Regulation Enters into Force
The EU AI Act formally became law, establishing the world's first comprehensive framework for regulating artificial intelligence. What this means:
- The legal framework is officially in place.
- Organizations should begin assessing their AI landscape.
- No major obligations were yet enforceable.
2 February 2025 – Prohibited AI Practices and AI Literacy
The first substantive requirements became applicable, making this a significant compliance milestone.
Organizations must now:
- Avoid deploying prohibited AI practices under Article 5.
- Ensure employees and AI operators possess adequate AI literacy under Article 4.
Examples of prohibited practices include:
- Social scoring systems.
- Untargeted scraping of facial images.
- Manipulative or exploitative AI systems.
- Certain emotion-recognition technologies in workplaces and educational settings.
Violations at this stage can result in penalties of up to €35 million or 7% of global annual turnover, whichever is higher.
2 August 2025 – General-Purpose AI (GPAI) Rules
The second phase introduced obligations for providers of general-purpose AI models, such as large language models and foundation models.
Key requirements include:
- Technical documentation and transparency measures.
- Compliance with copyright obligations.
- Additional safeguards for systemic-risk AI models.
This milestone also activated the broader governance and enforcement framework, including the establishment of the EU AI Office.
2 August 2026 – High-Risk AI Obligations
For many organizations, this is the most critical deadline.
From August 2026, high-risk AI systems listed under Annex III must comply with extensive regulatory requirements.
High-risk sectors include:
Organizations operating in these areas will need to implement:
- Risk management systems.
- Human oversight mechanisms.
- Data governance controls.
- Transparency and documentation processes.
- Post-market monitoring procedures.
2 August 2027 – AI Embedded in Regulated Products
An additional transition period applies to AI systems integrated into products already regulated under EU product safety legislation.
Examples include:
- Medical devices
- Machinery
- Vehicles
- Toys
- Aviation products
Manufacturers must ensure that these AI-enabled products meet both existing product safety requirements and the new AI Act obligations.
Does the EU AI Act Apply to Non-EU Companies?
Yes. The Act has an extraterritorial scope similar to GDPR.
Organizations located outside the EU may still be subject to the regulation if:
- They place AI systems on the EU market.
- Their AI outputs are used within the European Union.
- They provide AI-enabled services to European customers.
As a result, many global organizations will need to assess and prepare for compliance, regardless of where they are headquartered.
How Organizations Can Prepare
To strengthen readiness ahead of upcoming deadlines, organizations should focus on five immediate actions:
With the high-risk obligations taking effect in August 2026, organizations that begin preparations early will be in a much stronger position to meet regulatory expectations and minimize compliance risks.
Digital Transformation in Hotel Technology:
World BI is hosting the Digital Transformation in Hotel Technology Conference, where hospitality experts will discuss digital transformation strategies, AI adoption, smart hotel technologies, and the implications of the EU AI Act for the industry. For more information, click here.