When does the EU AI Act take effect?
The EU AI Act (Regulation (EU) 2024/1689) entered into force on 1 August 2024, but its obligations apply in phases. The prohibited-practice rules and the AI literacy requirement applied from 2 February 2025; the general-purpose AI (GPAI) model obligations, the governance framework, and most penalty provisions applied from 2 August 2025; the main body of the Regulation, including the high-risk regime for Annex III systems, applies from 2 August 2026; and high-risk systems that are safety components of regulated products follow on 31 December 2030.
- •For an SME with a handful of AI systems, that staggering is the useful part. There is no single "compliance day". There is a sequence, and each stage asks something different of you.
The phased application dates, in order
1 August 2024 — entry into force
The Regulation became law. Nothing was immediately enforceable against providers or deployers, but the clock started on every subsequent date.
2 February 2025 — prohibitions and AI literacy
Two things began to apply. First, the list of prohibited AI practices in Art. 5 — including untargeted scraping of facial images to build recognition databases, emotion inference in the workplace and in education (with narrow safety and medical exceptions), social scoring, and certain manipulative or exploitative techniques. Second, the AI literacy obligation in Art. 4, which requires providers and deployers to take measures to ensure a sufficient level of AI literacy among staff and others operating AI systems on their behalf.
AI literacy is the one obligation that already bites for almost every organisation using AI, regardless of risk classification. It is also the cheapest to satisfy early: role-appropriate training, a record of who received it, and a short internal policy.
2 August 2025 — GPAI models, governance, penalties
Chapter V obligations for providers of general-purpose AI models applied from this date: technical documentation for the model, information to downstream providers, a copyright policy, and a sufficiently detailed summary of training content. Providers of GPAI models with systemic risk carry additional evaluation, risk-mitigation, incident-reporting, and cybersecurity duties.
The same date brought the notification and governance architecture into application, along with the penalty provisions — with the exception of the fines applicable to GPAI model providers, which the Regulation defers by a further year.
2 August 2026 — general application, including Annex III high-risk
This is the main date. From 2 August 2026 the Regulation applies generally, which brings in the high-risk requirements for the use cases listed in Annex III (employment and worker management, education, essential private and public services, credit scoring, certain biometrics, critical infrastructure, law enforcement, migration, and administration of justice), the corresponding provider and deployer duties, the registration requirements, and the transparency obligations in Art. 50 for chatbots, emotion-recognition and biometric-categorisation systems, deepfakes, and synthetic content.
2 August 2027 — product-embedded high-risk systems
High-risk classification under Art. 6(1) covers AI that is a safety component of a product — or is itself a product — falling under the EU harmonisation legislation listed in Annex I, where that product must undergo third-party conformity assessment. Machinery, medical devices, lifts, and toys sit here. Those obligations apply from 2 August 2027, giving manufacturers an extra year to align AI Act conformity assessment with their existing sectoral route.
The same date is the compliance deadline for GPAI models that were already placed on the market before 2 August 2025.
What is the deadline for high-risk AI systems?
There is no single high-risk deadline. Which date applies depends on why the system is high-risk.
- Annex III use cases (e.g. CV-screening, credit scoring, exam scoring, biometric identification): 2 August 2026.
- Safety components of products under Annex I harmonisation legislation requiring third-party conformity assessment: 2 August 2027.
- High-risk systems placed on the market or put into service before 2 August 2026: in general, only caught if their design changes significantly after that date.
- High-risk systems intended for use by public authorities that were already in service: the Regulation gives a longer runway, to 31 December 2030.
The legacy carve-out is often misread. It is a transitional provision, not an exemption in perpetuity: a significant change in design pulls the system back into scope, and the prohibitions and transparency obligations are not subject to it.
- •Note also Art. 6(3): a system falling within an Annex III area is not high-risk if it does not pose a significant risk of harm to health, safety, or fundamental rights — for instance because it performs a narrow procedural task or only improves the result of previously completed human activity. Relying on that derogation requires documenting the assessment before placing the system on the market, and registering it. The assessment is the work; the exemption is the outcome.
What changed with the 2026 Digital Omnibus?
In November 2025 the European Commission published a Digital Omnibus package — a set of proposals to simplify and align EU digital legislation, including targeted amendments to the AI Act. The most significant element for planning purposes is a proposal to postpone parts of the high-risk regime and to tie its application more closely to the actual availability of harmonised standards and supporting technical infrastructure, rather than to fixed calendar dates alone.
The critical point as a compliance matter: this is a legislative proposal. It must pass through the European Parliament and the Council before any date in the Regulation changes. Until an amending act is adopted and published in the Official Journal, the dates set out above remain the operative ones. Treat the Omnibus as a possible extension, not a granted one.
The proposal does not touch the prohibitions, which have applied since 2 February 2025, and it does not offer relief on AI literacy. Those parts of the timeline are settled.
Practically, an SME should plan to the current dates and treat any adopted delay as slack recovered. The alternative — pausing work on the expectation of a postponement that may be narrowed or dropped in trilogue — leaves you with a shorter runway and less negotiating room with suppliers.
Turning the timeline into a planning horizon
The deadlines describe when obligations apply. They say nothing about how long the underlying work takes. For most SMEs the long pole is not writing documentation — it is discovering what AI is actually in use, and getting evidence out of vendors who are themselves still assembling it.
A workable sequence
- Inventory first. List every AI system built, bought, or embedded in a SaaS product, with the business process it touches and who owns it. Without this, every later step is guesswork.
- Screen for prohibitions. These already apply. Emotion inference in workplace or educational settings is the one that most often surfaces unexpectedly, typically inside recruitment or monitoring tooling.
- Confirm your role per system. Provider, deployer, importer, or distributor — the obligations differ substantially, and the same organisation is frequently a provider for one system and a deployer for another.
- Classify. Prohibited, high-risk, limited-risk transparency, or minimal. Record the reasoning, including any Art. 6(3) derogation, and date it.
- Check the Art. 50 transparency items early. Disclosure that users are interacting with an AI system, and marking of synthetic content, are usually product changes with release cycles attached.
- Open supplier conversations at least twelve months before your applicable date. You need instructions for use, technical documentation, and conformity evidence from providers, and procurement cycles are slow.
- Build the recurring processes last, but build them. Post-market monitoring, serious incident reporting, and log retention are ongoing duties, not one-off deliverables.
Working backwards from 2 August 2026, an organisation starting an inventory in early 2026 with two or three Annex III systems and external suppliers is tight but feasible. Starting in mid-2026 is not.
The Veritome Help Center (help.veritome.eu) sets out how to run each of these steps as a repeatable workflow rather than a one-off project.
What happens after the deadlines
Enforcement sits with national market surveillance authorities designated by each Member State, with the AI Office overseeing GPAI models at Union level. Penalty ceilings are tiered: the highest band applies to breaches of the prohibitions, with lower bands for other obligations and for supplying incorrect or misleading information to authorities. The Regulation directs that penalties for SMEs and start-ups take into account their size and economic viability, and that proportionality is considered when setting the level of a fine.
- •That proportionality provision is not a reason to under-invest. It is a reason to be able to show your reasoning. An organisation that can produce a dated classification record, a training log, and a supplier evidence file is in a different position from one that cannot, even where the underlying conclusion turns out to need revision.