EU AI Act Deadlines: Complete Timeline (2025-2027)
Complete timeline of EU AI Act enforcement deadlines from 2025 to 2027, including key compliance milestones for AI providers and deployers.
The EU AI Act (Regulation (EU) 2024/1689) entered into force on August 1, 2024, but its obligations are being enforced in phases through August 2027. Missing a deadline means your AI system could face fines of up to 35 million EUR or 7% of global annual turnover.
This timeline covers every enforcement milestone that matters for AI providers, deployers, importers, and distributors. Each date marks the point when specific obligations become legally enforceable — and when non-compliance becomes punishable.
Complete Enforcement Timeline
Entry Into Force
The EU AI Act is officially published and enters into force. The 24-month countdown to full enforcement begins. AI literacy obligations (Article 4) start applying to all operators.
Prohibited Practices Enforceable
Article 5 prohibited AI practices become enforceable. Social scoring, subliminal manipulation, exploitation of vulnerabilities, real-time remote biometric identification (with narrow exceptions), and emotion recognition in workplaces and schools are banned.
GPAI Obligations & Governance
General-purpose AI model obligations (Articles 51-56) become enforceable. GPAI providers must provide technical documentation, comply with EU copyright law, and publish training data summaries.
High-Risk AI System Obligations
All high-risk AI systems under Annex III must comply with Articles 6-49: risk management, data governance, technical documentation, record-keeping, transparency, human oversight, accuracy, robustness, and cybersecurity.
Full Enforcement for Annex I Systems
High-risk obligations extend to AI systems that are safety components of products covered by existing EU harmonised legislation listed in Annex I (e.g., medical devices, machinery, toys, aviation).
Who Is Affected
Providers
Organizations that develop or commission AI systems for placing on the EU market. Carry the heaviest compliance burden: risk management, technical documentation, conformity assessments, and post-market monitoring.
Deployers
Organizations that use AI systems under their authority. Must ensure human oversight, monitor operations, keep logs, inform affected persons, and conduct fundamental rights impact assessments.
Importers & Distributors
Organizations that bring AI systems into the EU market or make them available. Must verify that providers have completed conformity assessments and that proper CE marking and documentation exist.
GPAI Model Providers
Providers of general-purpose AI models (e.g., foundation models). Must provide technical documentation, comply with copyright rules, and publish training data summaries.
Non-Compliance Penalties
For violations of prohibited AI practices (Article 5).
For non-compliance with high-risk AI system obligations or GPAI requirements.
For providing incorrect, incomplete, or misleading information to authorities.
Frequently Asked Questions
Related Guides
How Scanara Helps
Scanara automates EU AI Act compliance from code to dossier. Connect your GitHub repos and get compliance reports in minutes.