The EU AI Act by the calendar: every date that actually applies to you
The most common AI Act mistake I see is treating it as a single switch that flips on one day. It doesn't. It phases in over years, and only a slice of the timeline touches any one company. Here's the calendar that matters — and what to have ready before each date.
Already in force: prohibited practices
The Act's bans on a short list of unacceptable practices — things like manipulative subliminal techniques and certain social-scoring and biometric uses — came into effect first, back in early 2025. For most mid-market companies these simply don't apply, but the action item is real: confirm, in writing, that none of your systems fall into a prohibited category. It's a five-minute check that closes a very expensive door.
2 August 2026: the machinery starts
This is when the Act's core enforcement architecture — the AI Office at EU level and national authorities — is operational, and the bulk of obligations begin their run-in. Practically, it marks the point where "we'll deal with it later" stops being a strategy. If the EU is in your market, this is the moment to have an inventory of your AI systems and a first read on your risk tier.
2 December 2026: Article 50 transparency — the near one
This is the deadline most mid-market companies actually feel first. Article 50 transparency obligations apply in full: you must tell people when they're interacting with an AI system, mark AI-generated or manipulated content in a machine-readable way, and label deepfakes. If you run a customer chatbot or generate synthetic media, this is your date. The good news is that it's largely a disclosure-and-labelling exercise, not a full conformity assessment — but it's concrete, and it's close.
2 December 2027 and 2 August 2028: high-risk
The heavy obligations for high-risk systems (the Annex III use cases — think hiring, credit, essential services) phase in later: standalone high-risk systems around 2 December 2027, and high-risk AI embedded in already-regulated products around 2 August 2028. This is more runway than the headlines suggest — but the work (risk management system, data governance, technical documentation, human oversight, conformity assessment) is substantial, so "later" is not "ignore."
The number behind the urgency
Why bother ahead of the deadline? Because the penalties are tiered to be taken seriously: up to €35M or 7% of global turnover for prohibited-practice breaches, €15M or 3% for most other obligation breaches, and €7.5M or 1% for supplying incorrect information (Art. 99). For a mid-sized company, the percentage line, not the euro line, is usually the frightening one. That's honest urgency — the law set the dates, not a marketing team.
Educational orientation, not legal advice. EU AI Act dates current as of September 2026; confirm your obligations for your specific systems. For binding interpretation, consult qualified counsel.