FinanceGadget
Guide

EU AI Act Enforcement Roadmap: Deadlines and Compliance Tiers

The short answer

The European Union Artificial Intelligence Act (Regulation EU 2024/1689) entered into force on 1 August 2024, but its obligations apply in phased enforcement waves through 2027. Prohibited AI practices became illegal on 2 February 2025. Rules for General Purpose AI (GPAI) models apply from 2 August 2025, while compliance requirements for High-Risk AI Systems (Annex III) take full effect on 2 August 2026. Organizations deploying AI in the EU must map their tools against these specific milestone dates.

The phased enforcement timeline (2025–2027)

To prevent market disruption, the European Parliament structured the EU AI Act with a 36-month transition period across four critical enforcement phases:

1. February 2, 2025 — Prohibited AI Practices (Article 5)

Enforcement begins for cognitive behavioural manipulation, social scoring systems, biometric categorization inferring sensitive attributes (race, political orientation, religion), and untargeted facial recognition database scraping. Organizations must immediately decommission any operational systems matching these categories.

2. May 2, 2025 & August 2, 2025 — General Purpose AI (GPAI) Governance (Chapter V)

Codes of Practice for General Purpose AI model providers take effect in May 2025. By 2 August 2025, providers of GPAI models (such as OpenAI, Anthropic, Google, and Meta) must satisfy transparency mandates, publish detailed training data summaries, adhere to EU copyright law, and disclose systemic risk evaluations for high-capacity models exceeding (10^{25}) FLOPs calculation thresholds.

3. August 2, 2026 — High-Risk AI Systems (Annex III)

Full enforcement takes effect for high-risk standalone AI applications across eight regulated domains:

  • HR, employee selection, and resume screening algorithms
  • Financial credit scoring and loan eligibility evaluations
  • Critical infrastructure management (energy, transport, water)
  • Education admissions and vocational scoring
  • Law enforcement and judicial risk assessments

Deployers of Annex III systems must conduct a Data Protection Impact Assessment (DPIA), establish continuous Risk Management Systems (Article 9), log all operational events automatically (Article 12), and provide human oversight controls (Article 14).

4. August 2, 2027 — Embedded High-Risk Systems (Annex I)

Obligations extend to AI components integrated into safety-regulated physical products governed by existing EU harmonization legislation (e.g., medical devices, aviation, automotive safety, and industrial machinery).

Risk classification breakdown

EU AI Act Risk Pyramid:

   /\     PROHIBITED (Social scoring, biometric categorization)
  /  \    Enforcement: 2 Feb 2025
 /    \   -------------------------------------------------
/ HIGH \  HIGH RISK (HR, Credit Scoring, Infrastructure)
/--------\ Enforcement: 2 Aug 2026 (Annex III) / 2 Aug 2027 (Annex I)
/ GENERAL \ GENERAL PURPOSE AI (LLM APIs, Coding Assistants)
/----------\ Enforcement: 2 Aug 2025
/  MINIMAL  \ MINIMAL RISK (Spam filters, inventory search)
/------------\ Voluntary Code of Conduct

Specific obligations for enterprise deployers vs providers

A common point of confusion for security teams is distinguishing between a Provider (who builds or fine-tunes the foundation model) and a Deployer (the company integrating an AI API or software into internal business processes).

Deployer Responsibilities under Article 26:

  1. Follow Instructions of Use: Deploy AI tools in strict accordance with the provider’s technical documentation and governance parameters.
  2. Assign Qualified Human Oversight: Ensure human supervisors possess the technical competence, authority, and training to override automated AI outputs.
  3. Monitor Operations & Incidents: Continuously track system behavior for bias, unexpected outputs, or security vulnerabilities. Report serious incidents to the national supervisory authority immediately.
  4. Transparency Disclosures: Under Article 50, deployers must explicitly inform natural persons when they are interacting with an AI system or exposed to AI-generated synthetic content.

Steps to achieve compliance today

To ensure your organization meets upcoming enforcement deadlines without interrupting operational workflows:

  1. Inventory All AI Assets: Maintain a centralized software register of all commercial AI tools, IDE extensions, internal chatbots, and third-party APIs used across departments.
  2. Run a Risk Tier Assessment: Classify each system using our interactive EU AI Act & Security Compliance Classifier.
  3. Enforce Vendor DPA Terms: Ensure all cloud model vendors sign standard Data Processing Addendums containing explicit sub-processor transparency clauses. Review our Judgement Framework for AI Providers for step-by-step guidance.
Advertisement