TLDRocket
Sign in

AI Act Implementation: Timelines & Next steps

AI Act bentrz Covered by 2 sources

The EU's AI Act rollout has a real clock now, with rules phasing in from bans this year to full high-risk obligations by 2027. Miss a date and you're not compliant — simple as that.

Based on reporting by AI Act, bentrz — read the original for the full story.

Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error

Brussels loves a staggered rollout, and the AI Act is no exception. Six months after the law entered into force, the first hammer fell: outright bans on 'unacceptable risk' AI, the stuff nobody was seriously going to defend anyway, like social scoring systems. That was just the opening move.

The real test comes at the twelve-month mark, when rules for general-purpose AI models kick in and every member state is supposed to have named a competent authority to actually enforce this thing. Nine months in, codes of practice for GPAI providers are meant to be finalized — though anyone who has watched EU tech legislation before knows 'finalized' and 'settled' aren't always the same word. By eighteen months, the Commission is due to hand providers of high-risk systems a template for post-market monitoring, plus guidance on how to tell if your AI system even counts as high-risk in the first place.

The heavier obligations land later. Two years in, systems used in biometrics, hiring, education, law enforcement, and access to public services — the Annex III list — have to comply fully, and every country needs at least one working regulatory sandbox up and running, along with penalty rules that include real fines. Annex I high-risk systems, mostly products already subject to EU safety certification like medical devices or aviation equipment, get an extra year, until the 36-month mark. And some of the slowest-moving pieces, involving large-scale EU justice and security databases like the Schengen Information System, don't have to comply until the end of 2030.

Behind all these dates sits a quieter machine: delegated and implementing acts. The Commission keeps power for five years to redefine what counts as an AI system, adjust which use cases are high-risk, and set the threshold for when a general-purpose model becomes 'systemic' enough to warrant extra scrutiny. None of that is finished. It's being built as the clock runs, which means today's compliance map is really a snapshot of a law still being assembled in real time.

My take — AI-written commentary, not fact-checked reporting

What strikes me is how much of this 'landmark law' is actually still unwritten — delegated acts, codes of practice, guidelines with no fixed date at all. Calling it settled regulation right now is generous. I'd rather see fewer grand deadlines and more finished guidance before companies start building compliance programs around rules that might shift under them.

Read more about this at: AI Act

Related stories

The daily briefing

Every AI story that matters, in your inbox by 8am.

TLDRocket reads all relevant sources, removes duplicate coverage, and summarises the day in two minutes. Follow companies and topics for alerts, or get the briefing in Slack. Free, no spam, unsubscribe anytime.