New AI Governance Report: Procurement & supply chain risk

Access now

Contents

EU AI Act Compliance Timeline: Key Dates for 2025-2027 by Risk Tier

Reading Time: 3 minutes
EU flag in front of Berlaymont building facade
Authors: 
Trilateral Research |
Date: 12 November 2025

The EU AI Act entered into force on 1 August 2024. Two critical deadlines have now passed: prohibited AI systems were banned in February 2025, and General-Purpose AI (GPAI) transparency requirements became mandatory in August 2025. If you haven't met these obligations, you're currently non-compliant and face enforcement action from national AI authorities, which are now fully operational.  

The next major deadline is August 2026 (less than 5 months away) for high-risk AI systems, followed by August 2027 for legacy systems integrated into regulated products. This article provides the complete implementation timeline, clarifies the risk-based tier system, and outlines what you must do now based on your compliance status. 

Not sure where your organisation stands? We can help you quickly assess your compliance position. Get in touch.  

Understanding and Classifying AI Risk Tiers

Clear definitions for immediate action

The AI Act defines four clear risk tiers, each with distinct regulatory obligations:

  1. Unacceptable Risk (Prohibited AI): These AI systems pose significant threats to fundamental rights, public safety, and democratic values. Examples include government-run social scoring, predictive policing, and real-time biometric identification in public spaces.
  2. High Risk: AI applications that significantly impact individual rights or safety fall under this category. Key examples include employment screening, financial credit scoring, medical diagnostics, education assessments, and critical infrastructure management.
  3. Limited Risk: Systems in this tier mainly require transparency measures to ensure users understand their interactions with AI. Chatbots and generative AI content tools are typical examples.
  4. Minimal Risk: Everyday AI applications such as spam filters and recommendation engines that pose minimal or no significant risk, requiring no specific compliance measures beyond voluntary best practices.

Promptly categorising your AI applications into these tiers is essential. It simplifies your compliance strategy and signals your commitment to responsible and ethical AI practices.

Detailed Timeline and Key Compliance Milestones

Updated compliance timeline as of March 2026

  • February 2025 (Passed):
    • Organisations were required to discontinue the use of all prohibited AI systems.
    • If your organisation has not yet completed comprehensive internal audits to document compliance, this should be prioritised urgently.
  • August 2025 (Passed):
    • General-Purpose AI (GPAI) providers must implement robust transparency and data governance measures, including clearly documented training datasets.
    • EU governance structures and national AI authorities become fully operational, significantly enhancing regulatory oversight.
  • August 2026:
    • Organisations deploying high-risk AI must comply with extensive requirements: detailed technical documentation, robust risk management, and effective human oversight mechanisms.
    • Formal conformity assessments by designated Notified Bodies become mandatory, leading to the CE marking of approved AI systems.

August 2026 is approaching fast. Our AI governance team can help you prepare for conformity assessments and CE marking. Talk to us

  • August 2027:
    • Full compliance deadline for AI integrated into regulated products, including medical devices, automotive safety systems, and industrial machinery.
    • GPAI models already in circulation before August 2025 must be fully updated to meet Act standards.

With August 2026 now less than 5 months away, organisations deploying high-risk AI should treat compliance preparation as an immediate priority, rather than a future project.

Comprehensive Readiness Checklist

Strategic actions for compliance as of March 2026

Loading…

Addressing these strategic actions immediately will not only ensure regulatory compliance but also position your organisation as a trusted leader in responsible AI.

Effective and proactive preparation is now critical. With the August 2026 deadline for high-risk AI systems approaching, organisations that act now will be better positioned for conformity assessments and better able to demonstrate responsible AI governance to regulators, clients, and partners. 

Organisations that proactively develop robust governance frameworks, rigorous risk management protocols, and comprehensive transparency measures will not only achieve compliance but also set the standard for ethical AI use, boosting stakeholder confidence and market credibility. 

If you’re looking for support on how to maintain compliance under the EU AI Act, whether by upskilling your team through AI training, managing AI risk, or governing your AI use, get in touch with our team.  

We can help you develop and deploy Responsible AI at scale with a deep understanding of your organisation’s goals and compliance requirements. 

Receive our latest articles

STRIAD AI Assurance

Cybersecurity

AI Governance & Compliance Services

AI Skills & Training Services

Related Articles

Responsible AI for Leaders

Practical insights and thought leadership to help you understand, govern, and grow with AI.