EU AI Act: The Complete Timeline and What It Means for Your Business

The EU AI Act is the European Union's legal framework regulating the development, deployment, and use of AI systems, and it applies to any organisation whose AI touches EU markets, regardless of where that organisation is based. This landmark legislation will profoundly impact every organization developing, deploying, or using AI systems within EU markets. With implementation rolling out in phases from 2024 to 2031, organizations face a complex compliance journey with critical deadlines requiring immediate attention.
This article breaks down the complete timeline and practical implications for businesses at each stage, providing a strategic roadmap for AI compliance over the next six years.
The Bottom Line for Business Leaders
First prohibitions come into force February 2025 - certain AI applications will be outright banned
GPAI model compliance required by August 2025 - affects foundation model providers and deployers
Full compliance mandatory by August 2026 - all high-risk AI systems must meet requirements
Compliance grace period ending 2027-2030 - depending on system type and deployment date
Organizations that plan strategically can turn AI compliance from a burden into a competitive advantage. This article provides the implementation timeline, business implications, and strategic recommendations to navigate the regulatory landscape successfully.
Phase 1: Foundation Setting (2024-2025)
Key Dates and Implications
July 12, 2024: Official Publication
The AI Act was published in the Official Journal of the European Union
Business Impact: While no requirements apply yet, this starts the clock on all future compliance deadlines
Action Required: Begin compliance readiness assessment and gap analysis
August 1, 2024: Official Entry into Force
The AI Act officially entered into force, though requirements phase in gradually
Business Impact: Organizations should begin preparation for upcoming obligations
Action Required: Form cross-functional AI governance team and begin inventorying AI systems
November 2, 2024: Member State Authority Designation
EU member states must identify authorities responsible for fundamental rights protection
Business Impact: Clarity on which authorities will enforce compliance in each jurisdiction
Action Required: Track authority designations in countries where you operate
February 2, 2025: Prohibitions Apply
First legal requirements take effect: prohibitions on certain AI systems and AI literacy initiatives
Business Impact: Organizations must immediately cease any prohibited AI practices
Action Required: Audit all AI systems against prohibition criteria; implement AI literacy programs
May 2, 2025: Codes of Practice Ready
Industry codes of practice must be finalized
Business Impact: Practical guidelines for implementation become available
Action Required: Participate in industry bodies developing these codes; prepare for adoption
August 2, 2025: GPAI and Governance Framework
Requirements for general-purpose AI models, governance structures, and penalties take effect
Business Impact: Major foundation model providers face compliance obligations; substantial penalties possible
Action Required: Implement governance structures; assess GPAI models against requirements
Phase 2: Main Implementation (2026-2027)
Key Dates and Implications
February 2, 2026: Implementation Guidelines
The Commission will provide practical implementation guidelines
Business Impact: Greater clarity on compliance expectations
Action Required: Review guidelines and adjust compliance strategies accordingly
August 2, 2026: Full Application
The majority of the AI Act's requirements come into force
Business Impact: All organizations using high-risk AI systems must be fully compliant
Action Required: Complete implementation of compliance measures for all AI systems
August 2, 2027: Classification Requirements
Article 6(1) requirements for system classification take effect
Business Impact: All AI systems must be properly classified according to risk categories
Action Required: Implement formal classification processes for all AI systems
Phase 3: Long-term Compliance (2028-2031)
Key Dates and Implications
August 2, 2028: First Major Evaluation
Commission evaluates the AI Office functioning and voluntary codes of conduct
Business Impact: Potential adjustments to compliance requirements based on findings
Action Required: Participate in feedback processes; prepare for potential regulatory changes
August 2, 2029: Comprehensive Review
First comprehensive evaluation and review of the regulation
Business Impact: Potential amendments to address implementation challenges
Action Required: Document compliance challenges to inform the review process
August 2, 2030 - December 31, 2030: Final Deadlines
Last compliance deadlines for public authority systems and large-scale IT systems
Business Impact: Complete closure of transition periods
Action Required: Ensure all legacy systems are compliant
Strategic Preparation: A Three-Layer Approach
To navigate this complex timeline effectively, organizations should implement VerityAI's Three-Layer Trust Architecture:
Layer 1: Governance Foundation (Immediate Priority)
Establish AI inventory and classification system
Create cross-functional AI governance committee
Develop comprehensive documentation system
Implement training and awareness programs
Layer 2: Technical Compliance (Secondary Priority)
Implement technical controls for high-risk systems
Establish testing protocols for bias, explainability, and robustness
Create post-deployment monitoring systems
Develop incident response procedures
Layer 3: Continuous Validation (Ongoing)
Implement regular compliance auditing
Create feedback loops from users and stakeholders
Establish regulatory change monitoring
Develop continuous improvement processes
Sector-Specific Considerations
Financial Services
Focus on bias detection in credit scoring models
Implement enhanced transparency for algorithmic trading systems
Establish robust model governance frameworks
Prioritize documentation of decision-making processes
Healthcare
Implement rigorous testing for diagnostic systems
Establish clear human oversight for treatment recommendations
Create comprehensive documentation for medical AI tools
Develop specialized validation for patient-facing systems
Manufacturing
Focus on safety validation for autonomous systems
Implement robust testing for predictive maintenance models
Establish clear human control mechanisms
Develop comprehensive documentation for operational AI
Public Sector
Prioritize transparency in citizen-facing systems
Implement robust fairness testing across demographics
Establish clear human oversight for consequential decisions
Develop comprehensive appeal mechanisms
Conclusion: From Compliance Burden to Strategic Advantage
While the EU AI Act timeline presents significant compliance challenges, organizations that approach it strategically can transform regulatory requirements into business advantages:
Trust Differentiation: Demonstrable compliance becomes a competitive differentiator
Risk Reduction: Systematic governance reduces operational and reputational risks
Innovation Guidance: Clear boundaries enable focused, responsible innovation
Market Access: Compliance ensures continued access to EU markets
Operational Improvement: Governance requirements often drive operational excellence
By understanding the timeline and implications of the EU AI Act and implementing a structured compliance approach, organizations can navigate the regulatory landscape confidently while building trust with customers, stakeholders, and regulators.
For an assessment of your organization's AI compliance readiness, sign up to VerityAI and get a comprehensive evaluation against our AI governance framework.
If you want support with this, VerityAI offers board-level AI governance.
Frequently asked questions
What is the EU AI Act?
The EU AI Act is the European Union's law governing how AI systems can be developed, sold, and used across EU markets. It sorts AI systems into risk categories and sets different obligations for each, with the strictest rules applying to high-risk uses such as employment, credit, and law enforcement.
Does the EU AI Act apply to businesses outside the EU?
Yes. The Act applies extraterritorially, so any organisation whose AI system is placed on the EU market, or whose output is used within the EU, falls within scope even if the organisation itself is based elsewhere. This mirrors the approach taken by GDPR.
What happens if a business doesn't comply with the EU AI Act?
Non-compliance carries financial penalties and creates broader risk in the form of restricted market access, reputational damage, and legal exposure. The scale of the penalty depends on the nature of the breach and the category of AI system involved.
When do businesses need to be fully compliant with the EU AI Act?
Compliance phases in gradually rather than landing on a single date, with different obligations taking effect for prohibited practices, general-purpose AI models, and high-risk systems at different points. Organisations need to track which phase applies to their specific AI systems rather than assuming one deadline covers everything.

Sotiris Spyrou
Sotiris Spyrou is the founder of VerityAI, a Responsible AI advisory for boards and AI-deploying businesses. With 27 years across agencies, global in-house roles, and the C-suite, he advises leaders on AI governance and risk, and on answer-engine visibility engineered without the dark patterns the rest of the industry is getting penalised for. He is the author of TRANSFORM, AI Moats, and Ethical AI.
Founder at VerityAI
Areas of Expertise: