EU AI Act: The world's first horizontal AI regulation
Regulation (EU) 2024/1689 regulates AI systems on a risk basis — from prohibited practices, through obligations for general-purpose AI, to a high-risk regime with a phased timeline running to 2027/2028. An EU "Digital Omnibus" package was still in the legislative process as of this writing.
Risk-based regulation with a phased application timeline.
Regulation (EU) 2024/1689 (the "AI Act") classifies AI systems by risk level: prohibited practices (Art. 5), high-risk AI (incl. Annex III), general-purpose AI (GPAI) models with their own obligations, and AI systems with limited risk (transparency duties). As a regulation, it applies directly in all member states.
Unlike DORA or GDPR, the AI Act does not become fully applicable on a single date but in several phases spread over multiple years — from the first prohibitions in February 2025 to the last high-risk obligations, which depending on classification only take effect in 2027.
Important note as of this writing: in May/June 2026 the EU politically agreed a "Digital Omnibus" simplification package intended to postpone several deadlines. At the time this page was published, that package had not yet been published as a legal act in the Official Journal and was therefore not yet in force — until then, the original deadlines in Art. 113 of the regulation remain authoritative.
Key deadlines
Prohibited practices (Art. 5) and AI literacy (Art. 4)
First application phase per Art. 113(a): prohibitions on unacceptable AI practices, plus the duty to ensure AI literacy among staff.
Obligations for general-purpose AI (GPAI)
Chapter V (GPAI models), governance rules, and the penalty regime become applicable (Art. 113(b)).
General application begins, incl. high-risk Annex III
Art. 113(c): the regulation's general application date, including high-risk obligations for use cases listed in Annex III (Art. 6(2)). This is the deadline currently set out in the regulation's text.
High-risk classification of product-embedded AI (Art. 6(1))
For AI systems that are safety components of products already regulated (Annex I, sectoral product legislation), a longer transition period applies, until 02.08.2027.
Proposed deadline postponement (incl. Annex III → Dec. 2027)
Political agreement between the Council and Parliament on 07.05.2026, European Parliament approval 16.06.2026, Council approval 29.06.2026 — signature and publication in the Official Journal were still pending as of this page's publication. Only after that will the postponed deadlines become legally binding.
What the EU AI Act actually requires.
Prohibited practices (Art. 5)
Including social scoring, certain real-time biometric identification in public spaces, and manipulative AI techniques have been prohibited since 02.02.2025.
AI literacy (Art. 4)
Providers and deployers must ensure their staff have a sufficient level of AI literacy — applicable since 02.02.2025.
Obligations for GPAI models
Technical documentation, transparency duties, and for models with systemic risk, additional risk-assessment and reporting obligations.
High-risk AI obligations
Conformity assessment, risk-management system, technical documentation per Annex IV, fundamental rights impact assessment, and post-market monitoring per Art. 72 — application date staggered by classification.
A register that keeps pace with the timeline.
The ReportAct EU AI Act Framework Pack maintains an AI system register with AI-assisted risk categorisation per Art. 6–7 and Annex III, documents conformity assessments and fundamental rights impact assessments, and seals the Annex IV technical documentation as provable evidence.
Because the application date of individual obligations can keep shifting through delegated acts and — currently — the Digital Omnibus process, ReportAct keeps the deadline status of each obligation current in the Framework Pack rather than assuming a single fixed date.
Cross-mapping to DORA avoids double-capturing ICT risk assessments for AI systems used by financial entities.
Product/positioning statement, not legal advice.
Read the originals
ReportAct is not a consultancy. This page does not constitute legal advice. The deadlines listed here reflect the regulation's text (Art. 113) as of this page's publication date. The "Digital Omnibus" package may change these deadlines once in force — check the current status directly on EUR-Lex and with the European AI Office before relying on it for binding decisions. Our Terms of Service apply.
An AI register that keeps up with the regulation.
Start right away with your AI system register — including risk categorisation and Annex IV documentation.