The European AI Act is the first broad AI law in the world. It entered into force on 1 August 2024, but the obligations apply in phases. That is good news: you have time — but only if you start now with an overview.
– days until 2 August 2026 — AI Act high-risk obligations
The timeline in outline
- 2 February 2025 — the prohibited AI practices (such as social scoring and certain forms of manipulation) apply, and the duty of AI literacy (Article 4): everyone working with AI must understand enough about it.
- 2 August 2025 — obligations for providers of general-purpose AI models, and the governance/enforcement structure.
- 2 August 2026 — the bulk of the obligations for high-risk AI (the Annex III uses, such as AI in recruitment, education, credit and public services).
- 2 August 2027 — high-risk AI embedded in regulated products (Annex I) reaches its deadline.
Always check the exact dates and scope against the official text — the phasing has nuances per category.
The first question is always the same
Which obligation applies to you depends on two things: your role (do you develop AI, or use it — possibly via a supplier?) and the risk category of the use. But before you get there, you must know: which AI do we actually use? AI often enters unnoticed via existing software. An inventory is therefore step zero.
What you can do now
- Make an inventory of your AI and algorithm uses, including what comes in via suppliers.
- Arrange AI literacy: policy and training, evidenced (this already applies).
- Classify your uses and determine which fall under high risk — that is where the core of the work lies.
The bottom line
The AI Act is no reason to stand still, but it is a reason to get an overview. Whoever now puts the inventory and the literacy in order has the rest arranged well in time.
This article is general information, not legal or organisational advice for your specific situation.