Skip to content

The EU AI Act timeline to put in your calendar

Regulation (EU) 2024/1689 applies in stages between February 2025 and August 2027. Here are the risk tiers, the provider and deployer split, the transparency duties for general-purpose models, and the fines.

By Alejandro Navarro — Managing Director Spain 8 min read
Desk calendar next to a pen, clips and scissors on a white surface, ready for dates to be marked
Four dates decide the work: 2 February 2025, 2 August 2025, 2 August 2026 and 2 August 2027. Photo: Leeloo The First / Pexels.
Contents

Updated 15 January 2026 — the first obligations are now in force and the Commission has proposed new dates for the high-risk rules.

Regulation (EU) 2024/1689 entered into force on 1 August 2024 and applies in stages. The prohibitions arrive on 2 February 2025, the rules for general-purpose models on 2 August 2025, the bulk of the regulation on 2 August 2026, and one class of high-risk systems on 2 August 2027. Most companies will be deployers, not providers.

Key takeaways

  • The regulation was published in the Official Journal on 12 July 2024 and applies from 2 August 2026, with the staggered exceptions listed in Article 113.
  • Obligations follow your role. A provider markets a system under its own name; a deployer uses one under its authority. Article 25 turns a deployer into a provider if it rebrands, substantially modifies or repurposes a high-risk system.
  • Article 50 applies to almost everyone: tell people they are interacting with AI, mark synthetic content in machine-readable form, and disclose deepfakes.
  • Fines reach €35,000,000 or 7% of worldwide annual turnover for prohibited practices, and €15,000,000 or 3% for most other breaches, whichever is higher.
  • Spain moved early: the AESIA supervisory agency got its statute in August 2023 and Real Decreto 817/2023 created a regulatory sandbox.

What the regulation is, and when each part applies

Regulation (EU) 2024/1689 is a product-safety style regulation applied to AI systems. It was adopted on 13 June 2024, published on 12 July 2024, and entered into force on the twentieth day after publication. It applies directly in Spain, with no transposition, which is a different situation from the accessibility rules that arrive through national law.

Timeline of the Article 113 dates, from entry into force on 1 August 2024 to the Article 6(1) systems on 2 August 2027
The prohibitions and the general-purpose model rules already apply; the high-risk block is the one still moving.

Article 113 sets the calendar. The general date is 2 August 2026. Chapters I and II — the definitions, the AI literacy duty in Article 4, and the prohibited practices in Article 5 — apply from 2 February 2025. The rules on notifying authorities, general-purpose AI models, governance, penalties and confidentiality apply from 2 August 2025, except Article 101. Article 6(1), which covers AI embedded as a safety component in regulated products, applies from 2 August 2027.

Two transitional rules matter for anything already running. Under Article 111, high-risk systems placed on the market before 2 August 2026 are only caught if their design changes significantly, while systems used by public authorities must comply by 2 August 2030. Providers of general-purpose models placed on the market before 2 August 2025 have until 2 August 2027.

Regulation (EU) 2024/1689 was published in the Official Journal on 12 July 2024 and applies from 2 August 2026. Article 113 brings the prohibitions forward to 2 February 2025, the general-purpose model rules to 2 August 2025, and delays Article 6(1) systems to 2 August 2027.

The risk tiers, and where most companies land

Article 5 bans a short list outright: manipulative or deceptive techniques that materially distort behavior, exploitation of vulnerabilities linked to age, disability or social and economic situation, social scoring, individual crime prediction based solely on profiling, untargeted scraping of facial images, emotion inference in workplaces and education, biometric categorization to infer protected characteristics, and real-time remote biometric identification in public spaces for law enforcement.

High risk has two routes. Article 6(1) covers AI that is a safety component of a product already regulated under the harmonization legislation in Annex I and subject to third-party conformity assessment. Article 6(2) covers the use cases in Annex III, including employment and worker management, access to essential services, creditworthiness, education and biometrics.

Article 6(3) offers a way out of Annex III, but a narrow one. A system escapes the classification only if it performs a narrow procedural task, improves the result of prior human work, detects deviations from decision patterns without replacing human assessment, or prepares an assessment. Any system that profiles natural persons stays high risk regardless.

Everything else falls into the transparency layer of Article 50 or into no specific obligation. A recommendation engine or an internal drafting assistant is usually in that last group, which does not mean the GDPR stops applying.

Provider or deployer: the distinction that decides your obligations

Article 3 defines a provider as whoever develops an AI system or general-purpose model, or has one developed, and places it on the market under its own name or trademark. A deployer uses a system under its own authority, outside personal non-professional activity. A company that licenses a tool and switches it on is a deployer.

The line moves. Under Article 25, a distributor, importer, deployer or third party becomes the provider of a high-risk system if it puts its own name or trademark on it, makes a substantial modification to it, or changes its intended purpose so that the system becomes high risk. Rebranding a supplier's model as your own product is not a marketing decision; it is a change of legal role.

This is the clause that catches integrators and agencies. Wrapping a general-purpose model in your own interface makes you a downstream provider, with documentation duties toward whoever integrates it next. Anyone who has taken a model from prototype to production will recognize that the paperwork follows the seams of the architecture.

What a deployer of a high-risk system must do

Article 26 is the operational core for buyers. Deployers must use the system according to the instructions, assign human oversight to people with the competence, training and authority to exercise it, and make sure input data under their control is relevant and sufficiently representative.

They must also monitor operation, keep automatically generated logs for at least six months, inform workers' representatives and affected workers before putting a high-risk system to work, and tell people when they are subject to one. Where a data protection impact assessment is required, the provider's information feeds it.

Article 27 adds a fundamental rights impact assessment for public bodies, private entities providing public services, and deployers of the credit and insurance pricing systems in Annex III. Article 4 requires providers and deployers to ensure a sufficient level of AI literacy among staff operating these systems.

Under Article 26 of Regulation (EU) 2024/1689, deployers of high-risk AI systems must assign human oversight to competent staff, keep automatically generated logs for at least six months, and inform workers' representatives before putting such a system into use at work.

Transparency for general-purpose models and generated content

Article 53 requires providers of general-purpose AI models to keep technical documentation, give integrators the information they need, apply a policy to comply with EU copyright law, and publish a sufficiently detailed summary of the content used for training. Models released under a free and open-source license are exempt from parts of this, never when they carry systemic risk.

Article 51 defines that systemic risk category. A model is presumed to have high-impact capabilities when the cumulative computation used for training exceeds 10^25 floating-point operations, and the Commission can adjust the threshold by delegated act.

Article 50 is the part almost every business touches. Systems that interact with people must make that clear unless it is obvious. Providers must mark synthetic audio, image, video and text in a machine-readable, detectable format. Deployers must disclose deepfakes, and must disclose AI-generated text published to inform the public on matters of public interest unless a human reviewed it and someone holds editorial responsibility.

Article 50 of the AI Act requires providers to mark synthetic audio, image, video and text in a machine-readable format, and deployers to disclose deepfakes and AI-generated text published to inform the public, unless it underwent human review and editorial control.

Penalties, and who pays them

Article 99 sets three bands. Breaching the Article 5 prohibitions carries fines up to €35,000,000 or 7% of total worldwide annual turnover for the preceding financial year, whichever is higher. Most other obligations, including the deployer duties, carry up to €15,000,000 or 3%. Supplying incorrect, incomplete or misleading information to authorities carries up to €7,500,000 or 1%.

Bar chart comparing the AI Act fine ceilings: 7% of worldwide turnover for prohibited practices against bands of 3% and 1%
For SMEs the rule inverts: the fine is capped at the lower of the percentage and the fixed amount.

For SMEs and start-ups each fine is capped at the lower of the percentage or the fixed amount, the opposite of the rule for large companies. Article 101 sets separate fines for providers of general-purpose models, up to €15,000,000 or 3%.

Spain has a head start on supervision. Real Decreto 729/2023 approved the statute of the Agencia Española de Supervisión de Inteligencia Artificial in August 2023, and Real Decreto 817/2023 created a controlled testing environment in November 2023 to trial compliance ahead of the European text.

What to do in the next twelve months

Start with an inventory, because you cannot classify what you have not listed. Every system that infers, recommends, scores, ranks or generates, built in-house or bought inside another product, with the business owner named next to it. Shadow use counts, and the tools that spread first were internal.

Classify each entry against Article 5, Annex III and Article 50, then look at contracts. Your supplier's obligations become your evidence, and a license signed today will still be running in August 2026. Ask in writing for technical documentation, the training-content summary and logging.

Then treat the rest as an operations change: assign oversight to named people, decide what is logged and for how long, and put AI literacy in the onboarding of anyone who touches these systems. This is an operations problem before it is a technology problem, which is where compliance programs usually fail. Companies funding tooling through public digitalization grants should check that the funded solution produces the evidence the regulation asks for.

What changed in this update

Two blocks are now in force: the Article 5 prohibitions and the Article 4 AI literacy duty since 2 February 2025, and the general-purpose model obligations since 2 August 2025. On 10 July 2025 the Commission published the General-Purpose AI Code of Practice, a voluntary instrument on transparency, copyright and safety that signatories can use to demonstrate compliance. On 19 November 2025 it proposed tying the high-risk rules to a decision confirming standards are available, with backstops of 2 December 2027 for Annex III and 2 August 2028 for Annex I. Until that proposal is adopted, the Article 113 dates stand, and so does the evidence AI buying decisions require.

FAQ

Does the AI Act apply to a company that only uses ChatGPT?

Yes, in a limited way. Using a general-purpose assistant makes the company a deployer, not a provider, so the heavy Chapter III obligations do not apply unless the use case is high risk. What does apply is Article 50 disclosure for generated content shown to the public and the Article 4 duty to ensure staff can use these systems competently.

When exactly do the high-risk obligations start?

For Annex III use cases, on 2 August 2026 under Article 113. For AI embedded as a safety component in products already regulated by EU harmonization legislation, on 2 August 2027. Systems already on the market before those dates are only caught if their design changes significantly, with a 2030 deadline for public authority use.

Can our agency become a provider without noticing?

Yes. Article 25 makes a deployer or third party the provider of a high-risk system when it puts its name or trademark on it, modifies it substantially, or changes its intended purpose. Building a client-facing product on top of a licensed model is the common route, and it transfers the provider obligations in Article 16.

What counts as a general-purpose model with systemic risk?

A model with high-impact capabilities, assessed with technical tools and benchmarks. Article 51 presumes those capabilities when the cumulative compute used for training exceeds 10^25 floating-point operations. Providers of such models cannot rely on the open-source exemption and take on additional obligations, with separate fines under Article 101.

The order that works is inventory, classification, contracts, then oversight. Teams that start by writing a policy usually find it does not match what is already deployed. Within six months the useful signal will be whether harmonized standards arrive on time, because complying in August 2026 depends more on those than on the text.

Share on

Related reading

Let's build what's next.

We create brands, products, and experiences that move your business forward.

Start a project
we are ONE

ONE News. What we build, and how it scales.

Sharp, practical insights on brand, technology and digital performance

Over 1000 subscribers

By subscribing, you agree to Onetouch's Terms of Use, and Privacy Policy.

Let’s start a new case of study together

01.

What do you need...

02.

Your budget is...

03.

Do you have a specific deadline?

04.

Attach a project brief if you’d like!

Attach a project brief if you’d like!

05.

About you...