Most published AI Act calendars are copied from each other. While preparing this site we found three widely repeated deadlines that had already moved, which is the reason this page exists.
Nothing here is copied from another calendar. Every date below was read from the Regulation, and the provision is named next to it.
01What is the next deadline?
Next deadline
New Article 5 prohibition. The Article 5 provisions carved out of the February 2025 date start to apply, covering AI systems generating non-consensual intimate imagery and child sexual abuse material.
Source: Article 113(a). Verified 2026-09-13.
02What is the full timeline?
Twelve dates, in order. Status is relative to 2026-09-13, the day this page was last checked against the text.
| Date | What applies | Provision | Status |
|---|---|---|---|
| Entry into force | Article 113 | In force | |
| Prohibitions and AI literacy | Article 113(a) | In force | |
| GPAI, governance and penalties | Article 113(b) | In force | |
| Articles 102 to 110 | Article 113(d) | In force | |
| General application, Article 50 | Article 113 | In force | |
| New Article 5 prohibition | Article 113(a) | Pending | |
| Article 50(2) marking, legacy systems | Article 111(4) | Pending | |
| Legacy GPAI models | Article 111(3) | Pending | |
| High-risk, Annex III | Article 113(c) | Deferred | |
| High-risk, Annex I | Article 113(c) | Deferred | |
| Public authority deployments | Article 111(2) | Pending | |
| Annex X large-scale IT systems | Article 111(1) | Pending |
The detail behind each row, including what the obligation actually requires, is set out below in date order.
The Regulation enters into force, on the twentieth day after publication in the Official Journal. No substantive obligation applies yet.
Chapters I and II apply: the prohibited practices in Article 5 and the AI literacy duty in Article 4. Neither is scoped by risk classification, and neither has a size threshold.
Chapter V on general purpose AI models, Chapter VII on governance, Chapter XII on penalties except Article 101, Chapter III Section 4 and Article 78 all apply.
Articles 102 to 110 apply. These amend other Union instruments rather than creating duties for AI providers directly.
Routinely missing from published calendars because it creates no obligation of its own.
The general application date. In practice this is when the Article 50 transparency duties start to bite: interaction notices, machine-readable marking of synthetic output, emotion recognition notices and deepfake disclosure.
The Article 5 provisions carved out of the February 2025 date start to apply, covering AI systems generating non-consensual intimate imagery and child sexual abuse material.
Applies whether or not an organisation operates any high-risk system, because prohibitions are not scoped by risk tier.
Providers of systems generating synthetic audio, image, video or text that were placed on the market before 2 August 2026 must meet the machine-readable marking requirement of Article 50(2).
The transitional period covers the marking duty only. The deployer duties in Article 50(3) and 50(4) never had one.
Providers of general purpose AI models placed on the market before 2 August 2025 must have taken the steps needed to comply with the Regulation.
Chapter III Sections 1, 2 and 3 apply to standalone high-risk systems under Article 6(2) and Annex III: risk management, data governance, technical documentation, logging, human oversight, accuracy and robustness, conformity assessment.
Moved from 2 August 2026 by the amendment approved on 16 June 2026, a deferral of 16 months.
The same Chapter III obligations apply to AI embedded in products already regulated under Annex I, such as medical devices, lifts and radio equipment.
Moved from 2 August 2027 by the same amendment, a deferral of 12 months.
Providers and deployers of high-risk systems intended for use by public authorities, placed on the market before the relevant application date, must have taken the steps needed to comply.
Article 111(2) is written against 2 August 2026. We have not seen a consolidated text confirming whether that reference moved with the high-risk deferral, and we mark it as open rather than guess.
AI systems that are components of the large-scale IT systems listed in Annex X and were placed on the market before 2 August 2027 must be brought into compliance.
The longest deadline in the Regulation and the one most often absent from published timelines.
03Which dates have already moved?
Three, all on the same day. This is the part that makes older calendars wrong, and the reason a date without a verification date next to it is not worth much.
| Changed on | What | From | To |
|---|---|---|---|
| High-risk obligations for standalone Annex III systems | 2 August 2026 | 2 December 2027 | |
| High-risk obligations for AI embedded in Annex I regulated products | 2 August 2027 | 2 August 2028 | |
| Prohibition on AI generated non-consensual intimate imagery and child sexual abuse material | Did not exist | 2 December 2026 |
04What is commonly reported wrong?
Four things, in rough order of how often we see them.
- That high-risk obligations start on 2 August 2026. They were moved to 2 December 2027 for Annex III and 2 August 2028 for Annex I.
- That the whole Act was delayed. Only the high-risk dates moved. The prohibitions, the AI literacy duty, the general purpose AI duties and Article 50 transparency all apply on their original dates.
- That 2 December 2026 is only about marking. A new Article 5 prohibition carries the same date and applies regardless of risk classification.
- That the timetable ends in 2028. Article 111 runs to 2 August 2030 for public authority deployments and 31 December 2030 for Annex X systems.
05How is this maintained?
Every date is read from the operative text of the Regulation, never from another publication's calendar. Where a date rests on an amendment whose consolidated text we could not read directly, the row says so rather than presenting it as settled.
The page carries a verification date because that is the only thing that makes a compliance date usable. A date without one is a claim about the past.
If a date moves, the change log above gets a row and the briefings that relied on it get a correction note rather than a silent edit. Corrections and disputes: editor@theguardrailreport.com.
Reuse is welcome under CC BY 4.0. If this page saved you an afternoon, link to it rather than copying the table, because then your readers get the corrections too.
06References
- Regulation (EU) 2024/1689, Article 113, for the entry into force and the staged application dates in paragraphs (a) to (d). The link is the ELI, the permanent identifier published by the Union itself.
- Regulation (EU) 2024/1689, Article 111, for the transitional provisions covering legacy high-risk systems, general purpose AI models, synthetic content systems and Annex X large-scale IT systems.
- Regulation (EU) 2024/1689, Article 5, Article 50 and Article 6, for the substance of the obligations attached to each date.
- Amendment agreed provisionally on 7 May 2026 and approved by the European Parliament on 16 June 2026. Deferral dates confirmed against contemporaneous analyses; we have not read a consolidated official text and mark the affected rows accordingly.