The Cost of Waiting: Key AI Act Deadlines Companies Can No Longer Ignore.

Published: Updated: 10 min read
The Cost of Waiting: Key AI Act Deadlines Companies Can No Longer Ignore.

Regarding the AI Act, many companies still view it much as they viewed the GDPR in its early days: they follow the news, hear about deadlines, but somehow the whole issue still seems distant. Yet the European Artificial Intelligence Regulation is not a future piece of legislation. The first obligations have already come into force, and it is now becoming clear that the next two years will primarily be a question of corporate governance and compliance rather than technology.

For many organisations, moreover, the real challenge is not AI use itself, but simply being aware of where, how and in what form they use — or could use — artificial intelligence. In most companies, AI entered daily operations long ago; it simply was not necessarily called that. A CV-screening tool in HR, a customer service chatbot, a client-scoring solution or even a Copilot integration can be just as much an AI compliance issue as a custom-built model.

The EU AI Act entered into force in August 2024, but its rules are becoming applicable gradually. This is why many still feel that “there is time”. They are partly right — but only partly.

The first truly important date was February 2025. From then on, certain AI practices became prohibited, and from the same date the so-called AI literacy requirement — meaning the knowledge necessary for the conscious and responsible use of artificial intelligence — became mandatory for organisations and individuals using AI systems. This may sound like a harmless requirement at first, yet it can have serious organisational consequences. The regulation essentially expects employees who use or oversee AI systems to have adequate knowledge of how those systems operate and what risks they pose.

Many companies encountered for the first time that the AI Act is not merely a technological regulation affecting developers. It will no longer be sufficient to say that “IT handles this”. Compliance is gradually spreading to HR, legal and compliance functions, and even internal training.

Meanwhile, it is also becoming clear that one of the greatest misunderstandings surrounding the AI Act concerns derogations, or transitional exemptions. Many organisations heard that longer transition periods apply to systems already in operation and concluded that they had nothing to do with their existing AI solutions. The situation, however, is far more complex.

A so-called “grandfathering” mechanism does indeed exist, meaning that certain high-risk AI systems already in use may temporarily be exempt from full compliance obligations. However, this applies only as long as the system does not change materially. This is where one of the greatest legal interpretation challenges begins. For example, if a company has been using an AI-based CV-screening system since 2025 and it was deployed before the relevant AI Act obligations became applicable, it may temporarily fall under the grandfathering rules. If it is later enhanced with features such as video interview analysis or automatic assessment of candidates’ personality traits, that may qualify as a significant change and could terminate the exemption.

What exactly does “significant change” mean? A new model? Retraining? A new scoring logic? An extension of a Copilot feature? In many cases, there is still no entirely clear answer.

At many large enterprises, this has already become a separate governance question: who may authorise modifications to AI systems? In many organisations, AI developments are being brought under the same change-management processes previously applied to critical IT systems.

The next significant milestone was 2 August 2025, when the requirements for general-purpose AI models — General Purpose AI, or GPAI — entered into force. Examples include models underlying services such as ChatGPT, Gemini, Claude and Copilot. For providers placing a GPAI model on the market after 2 August 2025, the new requirements, including security testing and systemic risk assessment where applicable, became immediately relevant.

Providers of GPAI models already on the market were granted a transitional period for the main requirements until 2 August 2027. Transparency and content-identification obligations, such as the labelling of content generated by ChatGPT-like models, apply according to the relevant implementation timeline.

This distinction matters because the transitional exemption is not necessarily complete and does not remove every obligation.

Most companies are affected not as model developers but as users or integrators. For them, the main questions are which provider supplies the AI solution, what risks its use entails, who is responsible for it and how the organisation can keep its use under documented control. These issues become key elements of vendor governance.

For most organisations, however, August 2026 will be the real turning point. From then on, the rules for high-risk AI systems become broadly applicable. This may directly affect HR, financial scoring, client assessment, healthcare solutions and certain compliance systems.

At that point, we are no longer talking about a few administrative obligations. The regulation effectively demands a comprehensive AI governance framework: documentation, human oversight, continuous monitoring, risk management and auditability. Failure to comply may result not only in substantial fines — potentially amounting to tens of millions of euros — but, in extreme cases, also in restrictions on or prohibition of the use of the AI system concerned.

In recent months, many European companies have begun to realise that the AI Act is much closer to corporate governance than to classical technology regulation. It is not merely about “what AI we use”, but also about how well the organisation can control its own digital decision-making mechanisms.

Perhaps this is why the situation is so reminiscent of the early days of GDPR. Then too, many thought that the time for compliance was still far away. Suddenly, organisations realised that the real question was not whether they needed to address it, but how late they had started. Organisations are increasingly treating AI in the same way they previously treated GDPR or information security — as an independent compliance area.

Something very similar is now happening with AI. Let us therefore look at the most important AI Act deadlines and transitional rules.

Key AI Act Deadlines

  • Prohibited AI practices — 2 February 2025: certain AI solutions have been prohibited since this date; there is no general transitional exemption.
  • AI literacy — 2 February 2025: organisations must ensure an adequate level of AI knowledge among the people who use or oversee AI systems.
  • General-purpose AI models — 2 August 2025: the GPAI framework became applicable, subject to transitional rules for models already on the market.
  • High-risk AI systems — 2 August 2026: the main compliance framework becomes applicable, while certain existing systems may remain subject to transitional arrangements.
  • AI systems embedded in regulated products — 2 August 2027: compliance must be assessed together with the relevant sectoral product-safety rules.
  • Certain public-sector high-risk systems — 2 August 2030: qualifying existing systems benefit from a longer transitional period.

When Can an Existing AI System Remain Under a Transitional Exemption?

One of the most important elements of the AI Act is the so-called “grandfathering” rule, or transitional exemption. Put simply, this means that certain AI systems already in operation may temporarily be exempt from some of the new obligations. However, this applies only as long as the system does not change materially.

An existing AI system can typically remain under the transitional rules if:

  • it was already operating before the relevant deadline;
  • its purpose does not change;
  • it does not receive new, higher-risk functionality;
  • no significant retraining takes place;
  • there is no material functional expansion.

What Can Terminate the Transitional Exemption?

One of the most important concepts in the AI Act is “significant change”. Although its precise interpretation is still developing, the following changes are more likely to trigger new compliance obligations.

Changes More Likely to Be Significant

  • introduction of a new AI model or model architecture;
  • retraining with a new dataset;
  • rewriting the scoring logic;
  • introducing a new automated decision-making function;
  • introducing a new HR profiling function.

Changes Less Likely to Be Significant on Their Own

  • a security update;
  • minor optimisation;
  • a bug fix;
  • a user-interface modification;
  • an infrastructure update.

The Public Sector Was Granted a Longer Period

One of the lesser-known elements of the AI Act is that the European Union provides a longer transitional period for certain high-risk AI systems used by public authorities. Under Article 113 in conjunction with the relevant transitional provisions, certain qualifying public-sector systems may have until 2 August 2030 to achieve full compliance. The applicability of this longer period depends on the system’s status and whether it was already placed on the market or put into service before the relevant cut-off date.

The rationale is primarily practical. Replacing or transforming state and public-administration systems is generally far slower and more complex than changing systems used by market players. In many cases, these systems involve multi-year development cycles, large databases and critical infrastructure whose operation cannot be transformed overnight.

The longer transitional period may particularly affect systems that perform decision-support or assessment functions in public administration. These may include:

  • administrative decision-support systems;
  • certain automated client-assessment or scoring solutions;
  • systems analysing eligibility for social benefits or public support;
  • certain law-enforcement or regulatory AI tools.

The European Union is thereby acknowledging that transforming public-sector digital systems is not only a technological issue, but also an operational and societal one. A malfunctioning state AI system may pose more than a business risk: it can directly affect citizens’ rights, services and public-administration decisions.

Summary of Key Deadlines and Actions

  • 2 February 2025 — Prohibited AI practices and AI literacy: identify and discontinue prohibited uses, and ensure relevant personnel receive adequate training and guidance.
  • 2 August 2025 — New GPAI models: apply the relevant GPAI obligations, including transparency requirements and, where applicable, systemic-risk controls.
  • 2 August 2026 — High-risk AI systems: establish the full compliance framework, including documentation, risk management, human oversight, monitoring and auditability.
  • 2 August 2027 — Existing GPAI models and certain product-related systems: complete the applicable transitional compliance work and coordinate AI Act obligations with sectoral regulation.
  • 2 August 2030 — Certain existing public-sector systems: complete the longer transitional compliance programme where the statutory conditions are met.

Omnibus Package and Possible New Deadlines

Based on the agreement referenced in the article and the EU digital regulatory package known as OMNIBUS VII — Digital Omnibus, some deadlines and implementation expectations may change. Organisations should therefore verify the final adopted legal text before relying on any proposed date.

AI Inventory

  • Scope: all levels of AI use;
  • Requirement: list all AI systems in use in an internal document and keep the inventory up to date;
  • Indicative deadline in the article: 2 August 2026.

Chatbot and Voicebot AI Labelling

  • Scope: transparency obligations under Article 50;
  • Requirement: provide a clear and clearly visible disclosure that users are interacting with an AI system;
  • Indicative deadline in the article: 2 August 2026.

Labelling of Generative AI Content

  • Scope: transparency obligations under Article 50;
  • Requirement: use appropriate labels and technical metadata, such as machine-readable provenance information or watermarking where applicable;
  • Indicative deadline in the article: 2 December 2026.

AI Literacy Training for Employees

  • Scope: all relevant AI use under Article 4;
  • Requirement: support the continuous development of employees’ AI competence and awareness;
  • Timeline: ongoing.

Audit of Non-Consensual Deepfake Content

  • Scope: prohibited or otherwise unlawful content, depending on the use case;
  • Requirement: identify, prevent and remove prohibited uses;
  • Indicative deadline in the article: 2 December 2026.

HR Screening AI Risk-Management Plan

  • Scope: high-risk employment and worker-management systems under Annex III;
  • Requirement: establish risk management, documentation and, where applicable, a data-protection impact assessment;
  • Indicative deadline in the article: 2 December 2027.

Credit-Scoring AI Compliance Package

  • Scope: high-risk systems under Annex III where the statutory classification criteria are met;
  • Requirement: implement the full compliance framework, including effective human oversight;
  • Indicative deadline in the article: 2 December 2027.

AI Functions in Medical Devices and Industrial Machinery

  • Scope: high-risk systems connected to regulated products under Annex I;
  • Requirement: assess the overlap between sectoral product regulation and the AI Act;
  • Indicative deadline in the article: 2 December 2028.

Try the AI Act risk classifier

Find out in 5 minutes which risk category your AI system falls into — free, 100% private, with a detailed PDF result.

Start the assessment
H
Pallos Gabriella
Harvey's · AI & compliance team
Experts in AI Act compliance, testing and security audits. Reach out any time with questions.
LinkedIn

Harvey's newsletter

Stay up to date with our AI Act content

One practical monthly summary on EU AI Act compliance — no spam, unsubscribe any time.

← Back to the blog