EU AI Act Timeline
An engineering-oriented timeline of the EU AI Act: the statutory milestones (entry into force, prohibitions, GPAI obligations, high-risk rules) and what each one asks a builder to produce — model cards, logging, risk documentation, human-oversight design. Filter by your system type to see which obligations land and when. This is a plain-language planning aid for engineers, not legal advice, and it flags where proposed changes (the Digital Omnibus) may move dates that are not yet settled.
Pick a system type above to see the artifact checklist it implies.
The EU AI Act lands on engineers as a set of deliverables with deadlines, and the useful way to read it is a timeline mapped to artifacts rather than a wall of legal text. The statutory milestones are fixed points: the Act entered into force on 1 August 2024; prohibited practices and AI-literacy duties applied from 2 February 2025; obligations for general-purpose AI models plus the governance and penalty framework applied from 2 August 2025; and the bulk of the Act — high-risk systems under Annex III — applies from 2 August 2026, with high-risk systems built into already-regulated products following in 2027.
What turns those dates into a plan is attaching the work each one implies. A high-risk classification is not an abstract label — it means a documented risk-management process, data-governance records, technical documentation, automatic logging of events, designed-in human oversight, and evidence of accuracy and robustness. General-purpose-model duties mean model documentation and training-data transparency. This tool lets you filter by your system type and shows which of those artifact sets applies and by when, so compliance reads as a backlog with due dates instead of a last-minute scramble.
The honest caveat runs through it: this is a plain-language engineering planning aid, not legal advice, and it can lag amendments. In particular, after the Act passed the Commission floated simplification proposals — discussed broadly as the Digital Omnibus — that could defer or reshape some obligations, high-risk timelines especially. Those are proposals, not settled law, so the timeline marks where dates have been debated and reminds you to confirm anything decision-critical against the official text and your compliance team before you rely on it.
How it works
- Statutory milestones: in-force, prohibitions, GPAI, high-risk.
- Each date mapped to engineering artifacts it requires.
- Filter by system type (GPAI, high-risk, limited, minimal).
- Flags proposed Digital Omnibus changes — not yet settled law.
Frequently asked questions
Is this legal advice?
No — it is an engineering planning aid. It translates the EU AI Act’s published milestones into the artifacts a builder typically has to produce (documentation, logging, oversight design, transparency notices) so you can plan work against dates. It is a plain-language summary, it can be incomplete or lag amendments, and it is no substitute for your legal and compliance teams. Confirm anything that drives a real decision against the official text and current guidance.
What are the main statutory dates?
The Act entered into force on 1 August 2024. Prohibited practices and AI-literacy duties applied from 2 February 2025. Obligations for general-purpose AI models and the governance/penalty framework applied from 2 August 2025. The bulk of the Act — including requirements for high-risk systems under Annex III — applies from 2 August 2026, with high-risk systems embedded in already-regulated products following on 2 August 2027. This tool lays those out and attaches the engineering work each implies.
What is the “Digital Omnibus” caveat?
After the Act passed, the Commission floated simplification proposals (referred to broadly as the Digital Omnibus) that could defer or adjust some obligations — high-risk timelines in particular. As a proposal it is not settled law and the dates could move. The timeline marks where such changes have been discussed so you do not treat a proposed deferral as a done deal, and so you know which dates to re-check before relying on them.
How do I map obligations to engineering work?
That is the point of the tool. High-risk obligations, for example, translate into concrete deliverables: a risk-management process, data-governance records, technical documentation, automatic event logging, human-oversight controls, and accuracy/robustness evidence. GPAI-model duties translate into model documentation and training-data transparency. Filter by your system type and the timeline shows which artifact set applies and by when, so compliance becomes a backlog rather than a panic.