Scope - What This Guide Covers
This guide outlines the compliance dates set by the European Parliament for the EU AI Act, focusing on high-risk AI systems and those under EU sectoral safety legislation. You'll find requirement breakdowns, implementation guidance for cross-border deployments, and a quick-reference table for easy access.
We cover the December 2027 and August 2028 application dates, watermarking deadlines, and the new ban on non-consensual intimate imagery systems. This is for teams needing to align regulatory timelines with internal sprint cycles and resource planning.
Key Concepts and Definitions
High-Risk AI Systems: These are systems listed in Annex III of the EU AI Act or those under EU product safety legislation requiring third-party conformity assessment. They include AI used in critical infrastructure, employment, law enforcement, and migration management.
Systems Covered by EU Sectoral Safety Legislation: AI systems under existing product safety frameworks like machinery, medical devices, and aviation. The EU AI Act adds requirements to these established regimes.
Watermarking: Technical measures that identify AI-generated content, particularly synthetic media. This applies to systems generating or manipulating image, audio, or video content.
Prohibited AI Practices: Uses of AI banned under Article 5, including social scoring by public authorities, real-time biometric identification in public spaces (with narrow exceptions), and systems creating non-consensual intimate imagery.
Requirements Breakdown
December 2, 2027: High-Risk Systems
If you're deploying a high-risk AI system, your compliance obligations start on this date. This includes:
- Technical Documentation (Annex IV): Detailed records of your system's design, development, and validation.
- Risk Management System: Continuous identification and mitigation processes throughout the system lifecycle.
- Data Governance: Quality criteria for training, validation, and testing datasets.
- Transparency Obligations: User-facing information requirements and logging capabilities.
- Human Oversight Measures: Interfaces and protocols enabling meaningful human intervention.
- Accuracy, Robustness, and Cybersecurity Standards: Performance benchmarks and security controls.
The delay in this date allows time for harmonized standards development and guidance from the AI Office. However, don't delay preparation. Your technical documentation and validation evidence take months to assemble properly.
August 2, 2028: Sectoral Safety Legislation Systems
Systems already regulated under EU product safety frameworks get an additional eight months. This acknowledges the dual compliance burdens: existing sectoral requirements plus new AI-specific obligations.
The Parliament suggests that AI Act obligations can be "less stringent" for products already regulated under sectoral laws. Watch the trilogue negotiations closely. If adopted, this could mean streamlined conformity assessment procedures for medical devices or machinery with AI components.
November 2, 2026: Watermarking Compliance
Providers of systems generating or manipulating synthetic content must implement watermarking by this date. This deadline is before the high-risk system dates, creating a staggered compliance burden.
Your watermarking approach must survive compression, resizing, and format conversion while remaining machine-detectable. Test against common social media platform transformations.
Immediate Effect: Non-Consensual Intimate Imagery Ban
The prohibition on systems creating or manipulating sexually explicit images of identifiable people without consent took effect with the AI Act's entry into force. The Parliament explicitly names "nudifier" systems, closing any interpretive loopholes.
The exception for "systems with effective safeguards" requires documentation proving your controls prevent misuse. Age verification, consent mechanisms, and abuse detection are compliance requirements.
Implementation Guidance
Build Your Compliance Timeline Backward
Start from December 2, 2027, and work backward. If you're deploying a high-risk system:
18 months out (June 2026): Complete your risk tiering assessment and Annex III classification analysis. Document your reasoning. Market surveillance authorities will scrutinize self-classification decisions.
12 months out (December 2026): Finalize Technical Documentation (Annex IV). Your documentation must trace from business requirements through dataset composition to validation results. Missing links in this chain create audit findings.
6 months out (June 2027): Conduct third-party conformity assessment if required. Don't assume notified bodies have immediate availability. Some sectors face assessment backlogs.
3 months out (September 2027): Complete EU database registration and CE marking processes. Budget time for back-and-forth with the AI Office on registration completeness.
Resource Planning for Dual Compliance
If you're subject to both EU AI Act requirements and existing sectoral legislation, your compliance team faces overlapping documentation burdens. Consider these resource multipliers:
For medical device AI: You're already maintaining technical files under the Medical Devices Regulation. The AI Act's Technical Documentation (Annex IV) overlaps substantially but not completely. Budget for gap analysis and documentation reconciliation.
For machinery incorporating AI: The Machinery Regulation's risk assessment requirements align with AI Act risk management, but the AI Act adds dataset governance and bias testing obligations. Plan for expanded validation protocols.
Transatlantic Cooperation
US companies already cooperate with EU enforcement mechanisms on data portability and interoperability. This cooperation model suggests practical pathways for AI governance alignment.
If you're managing AI deployments across US and EU jurisdictions, look for shared compliance building blocks. Risk tiering frameworks, model validation evidence, and bias testing protocols often satisfy requirements in both jurisdictions with minimal modification.
Common Pitfalls
Assuming "Simplification" Means Relaxed Requirements: The Parliament adopted the simplification proposal with 569 votes in favor, 45 against, and 23 abstentions. The delays provide implementation time, not compliance relief. Your obligations remain substantive.
Treating Sectoral Legislation as a Compliance Shield: While the Parliament suggests less stringent AI Act obligations for systems already regulated under sectoral laws, this doesn't create blanket exemptions. You still face AI-specific requirements around transparency, data governance, and human oversight.
Underestimating Documentation Effort: Technical Documentation (Annex IV) requires traceability from requirements through deployment. Teams accustomed to lightweight documentation practices face a compliance gap. Start building documentation habits now, not in 2027.
Ignoring the Watermarking Deadline: November 2, 2026, arrives before the high-risk system dates. If you're generating synthetic media, watermarking compliance can't wait for your broader AI Act implementation program.
Misreading the Prohibited Practices Exception: "Effective safeguards" for intimate imagery systems requires documented, tested controls. A terms-of-service prohibition isn't sufficient. You need technical controls with audit trails.
Quick Reference Table
| Requirement | Compliance Date | Applies To | Key Actions |
|---|---|---|---|
| High-Risk System Obligations | December 2, 2027 | Annex III systems and AI in product safety legislation requiring third-party assessment | Technical Documentation (Annex IV), risk management system, data governance, transparency measures, human oversight, conformity assessment |
| Sectoral Safety Legislation Systems | August 2, 2028 | AI systems covered by EU product safety frameworks (machinery, medical devices, aviation) | Same as high-risk obligations, potentially with streamlined procedures (pending trilogue) |
| Watermarking | November 2, 2026 | Systems generating or manipulating image, audio, or video content | Implement machine-detectable watermarks surviving common transformations |
| Non-Consensual Intimate Imagery Ban | Effective immediately | Systems creating or manipulating sexually explicit images of identifiable people | Implement documented safeguards: consent mechanisms, age verification, abuse detection |
| EU Database Registration | Before deployment (system-specific) | High-risk systems before market placement | Complete registration with AI Office, obtain registration confirmation |
| General-Purpose AI Model Transparency | August 2, 2025 (already in effect) | General-Purpose AI Model providers | Technical documentation, training data summaries, EU copyright compliance |
Your compliance calendar should account for harmonized standards publication timelines. The AI Office will release implementation guidance between now and December 2027. Monitor the Official Journal for technical specifications that clarify ambiguous requirements.
The Parliament's fixed dates eliminate regulatory uncertainty about "when" compliance begins. Your focus shifts to "how", building validation evidence, documentation trails, and governance processes that survive market surveillance scrutiny.



