EU AI Act compliance deadlines and duties
Regulation (EU) 2024/1689 has been in force since 1 August 2024 and applies to providers and deployers placing AI systems on the Union market, putting them into service in the Union, or using outputs in the Union. The law adds requirements on top of sector rules and excludes areas such as military, defence, national security, purely personal non-professional use, and some research or open-source systems.
The framework sorts systems into unacceptable, high, limited and minimal risk. Article 5 bans practices including manipulative techniques causing significant harm, social scoring, untargeted facial-image scraping, certain emotion recognition uses, biometric categorisation of sensitive attributes and real-time remote biometric identification for law enforcement except in narrow cases.
High-risk systems are covered through Annex I product law or Annex III domains such as biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, and justice and democratic processes. Providers face duties around risk management, data governance, documentation, logging, human oversight, accuracy, cybersecurity, conformity assessment, EU database registration, post-market monitoring and incident reporting. Deployers must follow instructions, assign trained human oversight, monitor use, retain logs where controlled and notify affected people in specified cases.
Key dates include Article 50 transparency duties from 2 August 2026, Annex III high-risk obligations from 2 December 2027, and Annex I product-embedded AI obligations from 2 August 2028. Penalties range up to €35 million or 7 % for prohibited practices and up to €15 million or 3 % for many obligation breaches.