The EU AI Act Compliance Calendar for Enterprise AI Teams
On August 2, 2026, the EU AI Act reached one of the most important dates in its implementation calendar.
Yet the deadline many enterprise teams had spent months preparing for had already changed.
A Just six days earlier, on July 27, the EU AI Omnibus entered into force and extended the compliance timeline for high-risk AI systems. Annex III high-risk rules now apply from December 2, 2027 while high-risk AI embedded in regulated products under Annex I moves to August 2, 2028.
At the same time, important transparency provisions became applicable on August 2, 2026 and enforcement responsibilities expanded across the European AI Office and national authorities.
For enterprise AI teams, that changes the planning question.
The useful question today is: which EU AI Act requirements already apply to our systems, what should be operational now and what must be ready before the next compliance date?
The EU AI Act does not operate through one universal deadline. Different obligations apply according to the type of AI involved, the organisation's role in the AI value chain and the risk classification of the system.
An enterprise may simultaneously operate a customer chatbot subject to transparency requirements, use a general-purpose AI model governed by GPAI rules and develop an employment screening application that could fall into a high-risk category.
This means one enterprise can have several compliance tracks running at the same time.
GPAI obligations have applied since August 2025. Transparency requirements became applicable in August 2026. Annex III high-risk requirements apply from December 2027 while Annex I product-related requirements follow in August 2028.
For engineering, security, data governance, product and legal teams, the EU AI Act compliance timeline therefore needs to become an operational calendar rather than a single regulatory deadline.
Here are the key dates enterprise AI teams should have on their calendars.
February 2, 2025: Prohibited AI Practices Took Effect
The first major EU AI Act deadline has already passed.
The initial prohibited AI practices became applicable on February 2, 2025. These include practices such as harmful AI-based manipulation, social scoring, certain forms of biometric categorisation, untargeted facial image scraping and specified uses of emotion recognition.
AI literacy provisions also originally entered into application during this phase. However, the 2026 AI Omnibus subsequently replaced the previous company AI-literacy requirement with non-binding encouragement, with the European Commission and Member States taking a stronger role in promoting AI literacy.
For enterprises, the practical priority is maintaining visibility into how AI is being used across the organisation.
An approved enterprise AI platform may be reviewed by security and legal teams while an experimental HR tool, browser-based AI service or department-level automation could escape the same process.
This visibility provides the foundation for identifying prohibited uses and determining which systems require further regulatory assessment.
August 2, 2025: GPAI Obligations Became Applicable
The EU AI Act's rules for GPAI models became applicable on August 2, 2025.
Providers are subject to requirements involving areas such as technical documentation, copyright compliance and information about model training content. Providers of GPAI models with systemic risk face additional obligations around risk assessment and mitigation.
Most enterprises will consume GPAI models rather than train frontier models themselves. Their compliance work still requires understanding the model supply chain.
This becomes especially important when enterprises compare multiple model providers. Our guide to Frontier AI Models: OpenAI vs Claude vs Gemini (2026) explores the broader enterprise considerations behind those model choices.
GPAI compliance therefore intersects with architecture and procurement decisions long before an application reaches regulatory review.
August 2, 2026: Transparency Requirements Are Now Applicable
Article 50 transparency obligations became applicable on August 2, 2026.
The rules address situations including direct interaction with certain AI systems and the identification or labelling of specific AI-generated or manipulated content.
Providers of relevant generative AI systems must ensure outputs can be marked in a machine-readable format where Article 50 requires it. Deployers also face disclosure requirements for areas such as deepfakes, emotion recognition, biometric categorisation and certain AI-generated text published to inform the public on matters of public interest.
The European Commission published dedicated Article 50 transparency guidelines in July 2026 to clarify how these requirements apply to providers and deployers.
For enterprise teams, this creates an immediate review point.
Consider a customer-support chatbot that clearly tells a user they are interacting with AI. Its responses may later be copied into a knowledge base, transformed into customer communications or republished through another channel. If the workflow removes required disclosures or technical markings along the way, a compliant interface alone may not be enough.
Transparency needs to work across the production pipeline, not only in the original interface.
December 2, 2026: Another Prohibited AI Practice Takes Effect
December 2, 2026 adds another prohibited practice covering specified non-consensual sexually explicit AI-generated content and child sexual abuse material.
This is particularly relevant to enterprises providing generative image, video or content creation systems, which should review safeguards and content controls before the date.
December 2, 2027: Annex III High-Risk AI Requirements Apply
This is the deadline that changed most significantly in 2026.
Under the updated EU AI Act implementation timeline, rules for Annex III high-risk AI systems apply from December 2, 2027. Relevant areas include biometrics, critical infrastructure, education, employment, migration, asylum and border control.
Requirements include risk management, appropriate data governance, logging, technical documentation, human oversight, robustness, cybersecurity and accuracy.
Consider an enterprise recruitment platform.
A model may rank applicants, generate candidate scores and recommend interview shortlists. Compliance cannot be demonstrated through model accuracy alone.
Teams need traceability around the data used, model versions, intended purpose, operating limits, human intervention and production performance.
For example, if the underlying model changes after deployment, the organisation should be able to determine what changed, which evaluations were performed and whether the system continues to operate within its intended parameters.
This makes evaluation and observability an important part of the compliance architecture.
The December 2027 extension gives enterprises additional implementation time. More importantly, it creates an opportunity to build controls into the AI lifecycle while systems are still evolving rather than adding them immediately before a regulatory deadline.
Our EU AI Act Compliance Checklist: Everything Enterprises Need to Know Before 2027 provides a broader view of the requirements enterprises should assess while preparing their governance programmes.
August 2, 2028: High-Risk AI Embedded in Regulated Products
The AI Omnibus moved these requirements to August 2, 2028.
The category can include AI integrated into regulated physical products such as machinery and other products governed by EU product safety legislation.
The longer runway reflects the additional compliance complexity created when AI requirements intersect with existing product regulation and conformity processes.

These regulatory dates should then be translated into internal engineering milestones.
Waiting for the legal deadline leaves little room for architecture changes, documentation gaps or controls that need to be redesigned after systems are already in production.
What Enterprise AI Teams Should Put on Their Internal Calendar
Now: Inventory and Classify AI Systems
Start with system discovery.
Identify production AI systems and record their owner, business purpose, model provider, deployment environment, user population and decision impact.
Then assign a preliminary risk classification. Employment systems, credit-related applications, biometric systems and AI used in other sensitive areas deserve early attention because they may fall within the high-risk framework.
Treat this inventory as a working system record rather than a one-time spreadsheet. A model replacement, new data source or additional application access can change how an AI system operates and potentially affect its regulatory profile.
Q4 2026: Close Transparency and Prohibited-Practice Gaps
Review customer-facing chatbots, generative AI workflows and AI-generated content against transparency requirements that are already applicable.
Test the actual production journey rather than checking only interface designs. Verify that disclosures appear where required and that relevant machine-readable marking is not lost as content moves between systems or channels.
Teams should also prepare for the additional prohibited practice taking effect in December 2026 by reviewing safeguards, acceptable-use controls and escalation mechanisms where relevant.
2027: Build Documentation, Logging and Oversight
For systems that may fall within Annex III, establish risk management, technical documentation, logging, human oversight, evaluation records, data lineage, access controls and production monitoring.
Vendor relationships also need scrutiny. Enterprises increasingly build applications on external models, agent platforms and managed AI services. Responsibility can change according to how a system is developed, modified and marketed.
That makes build-versus-buy decisions a governance issue as well as an architecture decision. Build vs Buy: AI Agent Platforms Compared (2026) looks at those enterprise platform decisions in greater detail.
Before December 2027: Test High-Risk Readiness
Teams responsible for Annex III systems should move from creating controls to proving that those controls work.
- Can the organisation reproduce evaluation evidence for a deployed model?
- Can it trace significant changes to data, models and system behaviour?
- Are human-oversight mechanisms actually usable in production?
- Can monitoring identify when a system begins operating outside its intended parameters?
The objective is to ensure that evidence exists to demonstrate how systems were designed, evaluated, deployed and monitored.
Engineering teams developing autonomous workflows should establish these controls while systems are being designed. Our guide on How to Build an AI Agent for Your Business covers the architecture considerations involved in moving AI agents toward production.
2028: Complete Annex I Product Compliance Where Applicable
Organisations developing AI embedded in regulated products should integrate AI governance with existing product safety, quality assurance and conformity processes ahead of the August 2028 deadline.
By this stage, AI compliance should not operate as a parallel programme. It should become part of the processes already used to design, test, approve and monitor regulated products.
The goal is not simply to reach each regulatory date. EU AI Act compliance for enterprises requires a living calendar that keeps system ownership, risk classification, documentation and monitoring aligned as AI systems evolve.
FAQ
EU AI Act Readiness Starts Before the Deadline
Prepare your AI systems with the right controls, documentation and monitoring before key compliance dates arrive.
