What Happened
The European Commission has outlined its responsibilities under the EU AI Act. This document lists 28 tasks, such as establishing notified body registries and creating a database of high-risk AI systems. However, none of these tasks come with a specific deadline for completion.
The tasks are divided into three activation dates. Some begin on 02 February 2025 under Article 113(a), others on 02 August 2025 under Article 113(b), and the rest on 02 August 2026 under the general rule of Article 113. These dates indicate when the Commission's obligations start, not when they must be completed. Your team is left with a regulatory framework that lacks an implementation schedule.
Timeline
02 February 2025: Article 113(a) tasks begin. The Commission starts promoting AI literacy tools and receiving notifications on real-time biometric identification authorizations from Member States.
02 August 2025: Article 113(b) tasks begin. The Commission starts receiving notified body registrations, establishing the AI Board secretariat, forming the advisory forum, and creating the scientific panel.
02 August 2026: General Article 113 tasks begin. The Commission starts building the EU database of high-risk AI systems, facilitating regulatory sandbox access, and developing the single information platform.
Present day: Your compliance team faces a regulatory structure where the Commission's duties have start dates but no delivery deadlines.
Missing Controls
This isn't a typical failure but a structural gap in the regulation. The AI Act sets governance requirements without implementation milestones. Three control areas lack definition:
Conformity assessment infrastructure: Articles 30-38 require notified bodies to assess high-risk AI systems before market placement. The Commission has no deadline to authorize these bodies. Your team can't submit Technical Documentation (Annex IV) for third-party assessment if the infrastructure isn't ready.
Registration and transparency systems: Article 49 requires providers to register high-risk AI systems in the EU database before market placement. Article 71 tasks the Commission with building this database. It must be operational by 02 August 2026, but there's no deadline for completing specifications, conducting audits, or ensuring compliance with Directive (EU) 2019/882.
Guidance and support mechanisms: Articles 57 and 62 require the Commission to support regulatory sandboxes and maintain an information platform. Your team needs this guidance to interpret requirements. The Commission must start these tasks by 02 August 2026 but faces no completion deadline.
What the Relevant Standard Requires
The EU AI Act itself creates this gap. Article 113 sets application dates without delivery obligations. Compare this to provider-side requirements:
Article 16: High-risk AI system providers must establish a Quality Management System ensuring compliance. There's no ambiguity about timing or deliverables.
Article 49: Providers must register high-risk AI systems in the EU database before market placement, even if the database isn't ready.
Article 60: Providers must draft an EU declaration of conformity for each high-risk AI system and keep it available for 10 years. This requirement stands regardless of Commission readiness.
ISO/IEC 42001:2023 offers a contrast. Clause 6.1 requires organizations to plan actions to address AI risks and integrate them into processes. Clause 9.1 requires organizations to determine what needs monitoring and when. The standard assumes you'll define your own timelines based on risk assessment.
The AI Act inverts this model. It defines what the Commission must do but not when. Your organization must comply with requirements that depend on infrastructure the Commission may deliver on an undefined schedule.
Lessons and Action Items for Your Team
Use the Commission's start dates as your planning deadlines. If a task activates on 02 August 2025, have your internal processes ready by then. Don't wait for the Commission to finish building infrastructure before documenting your approach.
Prepare your conformity assessment documentation now. Article 43 requires providers to demonstrate conformity before market placement. Draft your Technical Documentation (Annex IV) using the template in Annex IV. Map your system against requirements in Article 9 (Risk Management System), Article 10 (Data and Data Governance), and Article 15 (Accuracy, Robustness, and Cybersecurity). When notified bodies are authorized, you'll be ready.
Create a shadow database for internal AI systems. Article 71 specifies the information required for EU database registration. Set up your own registry with these fields. When the EU database goes live, you'll migrate existing records rather than starting from scratch.
Document your risk classification decisions with explicit Article 6 references. Article 6(3) allows you to show your AI system isn't high-risk despite matching an Annex III use case. Article 6(4) requires registration even for systems you've determined aren't high-risk. Document these determinations now, including the specific Annex III category, distinguishing factors, and supporting evidence. If the Commission later issues guidance contradicting your approach, you'll have a clear baseline for revision.
Develop a regulatory sandbox strategy independent of Commission support. Article 57 envisions Commission-supported sandboxes, but Article 57(1) permits Member States to establish their own. Identify which Member State sandbox aligns with your plans. Contact the national competent authority directly. Don't wait for the Commission's coordination platform.
Assign ownership for each Commission-dependent process. Create a matrix: Commission task in column one, your dependent process in column two, assigned owner in column three, fallback approach in column four. For example: Commission task is "establish EU database." Your dependent process is "register high-risk systems." Assigned owner is your AI governance lead. Fallback approach is "maintain internal registry and monitor Commission progress quarterly."
The AI Act's missing timelines create a planning problem, not a compliance excuse. Your obligations remain fixed. The Commission's delivery schedule doesn't change what you must demonstrate about your AI systems. Build your governance framework as if the infrastructure already exists. When the Commission delivers, you'll integrate rather than scramble.



