EU AI Act Timeline: What AI Vendors and Developers Must Track Through 2026
The EU AI Act's staged implementation has already introduced AI literacy, prohibited-use and GPAI milestones. The next major enforcement date is August 2026.
The EU AI Act is not a single regulatory switch that turned on in 2025. Its requirements are being applied in stages, creating distinct deadlines for AI vendors, model providers, developers and organizations deploying AI systems in Europe. The first rules took effect on 2 February 2025, while a second major milestone on 2 August 2025 brought governance provisions and obligations for providers of general-purpose AI models into application.
That phased approach matters for companies building or using AI tooling. Consumer assistants, industrial applications and internal software may rely on general-purpose AI models, but the compliance timeline depends on the role an organization plays and the type of system involved. The next major date is 2 August 2026, when the AI Act's enforcement powers and most high-risk AI requirements are scheduled to become fully applicable.
The EU AI Act rollout is phased, not blanket
The European Union has structured the AI Act around a risk-based framework and a staged implementation schedule. According to the EU AI Act implementation timeline published by the AI Act Service Desk, 2 February 2025 marked the application of the Act's general provisions, including definitions and AI literacy, alongside prohibitions on unacceptable-risk AI uses.
Six months later, on 2 August 2025, the governance framework began applying. Crucially for the current AI market, this phase also brought obligations for providers of general-purpose AI, commonly abbreviated as GPAI, models into application. These are models with broad capabilities that can support many different downstream applications.
| Implementation milestone | Date | Verified scope |
|---|---|---|
| First rules apply | 2 February 2025 | General provisions, including definitions and AI literacy, plus prohibitions for unacceptable-risk uses |
| GPAI and governance phase | 2 August 2025 | Governance framework and obligations for providers of general-purpose AI models |
| Major enforcement milestone | 2 August 2026 | Enforcement powers and the majority of high-risk AI requirements are scheduled to become fully applicable |
| Later high-risk timelines | 2027 to 2028 timeframes | Further phased requirements for Annex III high-risk systems and products embedded with AI |
The distinction between these dates is essential. A company cannot reasonably reduce its AI Act planning to a single claim that the regulation either is, or is not, in force. Parts of the framework already apply, while other provisions are scheduled for later implementation.
Why the GPAI milestone changes the compliance conversation
The August 2025 milestone puts particular attention on the organizations providing general-purpose AI models. This is relevant beyond the model developers themselves because many AI products and workflows are built on, or otherwise leverage, such models. For software teams, the regulatory question is therefore not limited to whether they train a foundation model. It also concerns how their product relates to the model provider, how it is deployed, and whether its intended use moves it into a more tightly regulated category.
The verified timeline does not make every AI application high risk, nor does it establish identical obligations for every business that uses AI. Instead, it shows why teams need a clear view of their position in the AI supply chain and of the systems they are placing into use.
For organizations operating in Europe, the practical governance priorities supported by the rollout include:
- AI literacy, which entered into application with the first wave of rules in February 2025.
- Use-case assessment, particularly to identify prohibited unacceptable-risk uses and systems that may be subject to later high-risk requirements.
- Provider and model mapping, since GPAI provider obligations began applying in August 2025.
- Forward planning for 2026 and beyond, rather than treating the 2025 milestones as the end of implementation.
What vendors and developers should prepare for next
The 2 August 2026 date is the central near-term milestone for many organizations. The European Commission's phased schedule places the AI Act's enforcement powers and the majority of high-risk requirements at that point. Further timing remains relevant for Annex III high-risk systems and products that include AI, with later phases cited for 2027 and 2028.
That schedule makes governance an operational issue rather than a policy exercise reserved for legal teams. Product leaders need to understand the intended use of a system. Engineering teams need clarity on which models and components are involved. Procurement and deployment decisions need to account for the provider relationships behind AI capabilities. These are practical questions that become more important as the framework expands.
Companies should also avoid two unhelpful assumptions. The first is that the arrival of GPAI obligations means every tool using a general-purpose model faces the same requirements. The second is that later high-risk milestones mean current obligations can be ignored. The verified timeline supports neither conclusion. The Act is already applying in defined areas, while additional requirements are still approaching.
Organizations assessing AI systems, model dependencies and internal governance can work with Scalevise on AI architecture, workflow automation and implementation planning that connects technical delivery with operational controls.
Frequently Asked Questions
When did the first EU AI Act rules start applying?
The first wave started on 2 February 2025. It applied general provisions, including definitions and AI literacy, as well as prohibitions for unacceptable-risk AI uses.
When did obligations for general-purpose AI model providers begin?
Obligations for providers of general-purpose AI models began applying on 2 August 2025, alongside the AI Act's governance framework.
Does the EU AI Act fully apply to every AI system already?
No. The Act is rolling out in stages. Enforcement powers and most high-risk AI requirements are scheduled to become fully applicable on 2 August 2026, with further high-risk timelines extending into 2027 and 2028.
Why should companies using third-party AI models track the GPAI rules?
Many AI tools rely on or leverage general-purpose AI models. Companies need to understand their role in the AI supply chain, their system's intended use and the implementation dates that may apply to them.
Conclusion
The EU AI Act's 2025 milestones established that AI governance in Europe is already a live operational concern, especially for unacceptable-risk uses, AI literacy and general-purpose AI model providers. For vendors and developers, the key task is to treat the regulation as a staged program: address the rules already in application, map AI dependencies and prepare for the major high-risk and enforcement milestone scheduled for August 2026.