The AI Act's staggered rollout creates a compliance timeline unlike any regulation you've managed before. Most frameworks give you one deadline and a clear scope. The AI Act gives you six major checkpoints over four years, each triggering different obligations for different system types.
Here's what changed and what your team needs to do about it.
Understanding the Timeline
The AI Act entered into force with a phased implementation schedule spanning 6 to 36 months. Unlike GDPR's single compliance date, this regulation activates in waves: prohibited practices first, then General-Purpose AI Model obligations, followed by high-risk systems by category and sector. The final wave affects large-scale IT systems in EU justice and security domains by 2030.
This structure complicates planning. You can't build one compliance program and be done. Your AI System Impact Assessment process for biometric systems needs to be ready 12 months before your assessment process for safety components in regulated products.
Five Critical Checkpoints
February 2025 (6 months): Prohibited AI Practices take effect (Article 113). If you're deploying social scoring systems, real-time biometric identification in public spaces (with narrow exceptions), or emotion recognition in workplaces and schools, you're out of compliance now. Your legal team should have already mapped your portfolio against Article 5's prohibited list. If you haven't done this review, it's overdue.
May 2025 (9 months): General-Purpose AI Code of Practice finalized (Article 113). If you're a foundation model provider or you've built custom models that meet the general-purpose definition under Article 3, this code sets your transparency and documentation baseline. The AI Office is drafting these codes now. You need someone monitoring the consultation process and flagging requirements that will change your model documentation, systemic risk assessments, or copyright compliance approach.
August 2025 (12 months): General-Purpose AI Model rules apply (Article 113). This is when Code of Practice obligations become enforceable. If you're providing models to downstream deployers, your Technical Documentation (Annex IV) and Instructions for Use must be ready. If you're using foundation models from external providers, verify their compliance documentation before this date. You don't want to discover in September that your vendor hasn't prepared the disclosures you need for your own high-risk system documentation.
February 2026 (24 months): High-risk systems in Annex III sectors come into scope (Article 111). This covers AI in biometrics, critical infrastructure, education, employment, essential services, law enforcement, immigration, and justice. If you're deploying in these areas, you need conformity assessment processes, Technical Documentation, risk management systems, Post-Market Monitoring plans, and quality management documentation ready. Member states must also have operational AI regulatory sandboxes live by this date (Article 57). If you're building novel high-risk systems, engaging with a sandbox now gives you regulatory feedback before the compliance deadline.
August 2026 (36 months): High-risk AI as safety components in regulated products (Article 113). This phase captures AI systems embedded in products already subject to EU conformity assessment, medical devices, machinery, toys, aviation equipment. If your AI controls or influences a safety function in these products, you're now managing dual compliance: the existing product regulation plus AI Act requirements. Your conformity assessment body needs to understand both frameworks.
December 2030: Large-scale IT systems in freedom, security, and justice domains (Article 111). This covers systems like the Schengen Information System and other EU-wide databases. If you're a contractor or technology provider for these systems, you have the longest runway, but also the most complex integration requirements, since these systems involve multiple member states and existing legal frameworks.
Implications for Your Compliance Program
You can't treat the AI Act as a single-phase project. Your compliance roadmap needs to be phased by system type, sector, and risk category.
Start by inventorying your AI systems and tagging each one with its applicable deadline. A chatbot providing customer service information has different timing than a resume screening tool (employment, 24 months) or a diagnostic support model in a medical device (36 months).
For each deadline, work backward to identify dependencies. Conformity assessment for high-risk systems requires Technical Documentation, which requires a functioning quality management system, which requires defined AI lifecycle processes. If you're aiming for the 24-month checkpoint, you need your quality management framework operational at least six months earlier to generate the evidence your documentation will reference.
Member state guidance will lag the regulation. Article 6 says the Commission will publish practical guidance on high-risk determination by 18 months after entry into force, six months before Annex III obligations apply. Don't wait for that guidance to start your risk classification work. Build your initial framework now using the criteria in Article 6 and Annex III, then update it when official guidance arrives.
Action Items by Priority
This quarter:
- Complete your AI system inventory and map each system to its compliance deadline.
- Identify systems that may fall under prohibited practices and conduct legal review.
- If you provide or use General-Purpose AI Models, assign someone to track Code of Practice consultations.
Before May 2025:
- For foundation model providers: draft Technical Documentation templates aligned with Annex XI requirements.
- For model deployers: audit your vendor contracts to confirm they'll provide required GPAI documentation.
- Establish your AI System Impact Assessment process framework, even if full implementation isn't required yet.
Before August 2025:
- General-Purpose AI Model providers must have documentation and transparency measures operational.
- Deployers of GPAI models should verify vendor compliance and document your due diligence.
Before February 2026:
- High-risk system providers in Annex III sectors: complete Technical Documentation, implement risk management and quality management systems, establish Post-Market Monitoring processes.
- Consider AI regulatory sandbox participation if you're testing novel high-risk applications.
- Finalize conformity assessment approach (internal or notified body).
Before August 2026:
- If you embed AI in regulated products, integrate AI Act requirements into existing product conformity processes.
- Update safety documentation and Instructions for Use to cover AI-specific risks.



