October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run ScanOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

EU AI Act Published in Official Journal: What the Deadlines Mean

The EU AI Act’s Official Journal publication started a staggered timetable—not an immediate blanket compliance deadline. Here’s what applies and what companies should check.
From TheFinanceBase Team6 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The EU published its Artificial Intelligence Act, Regulation (EU) 2024/1689, in the Official Journal on July 12, 2024. That publication started a staggered legal timetable: the regulation entered into force on August 1, 2024, but different obligations apply on different dates. As of August 18, 2026, later simplification measures have also changed parts of the timetable, so the original 2024 dates are not a universal guide to current deadlines.

What Official Journal publication changed

Publication made the adopted regulation’s text official and started the 20-day period before it entered into force. The EU AI Act is a regulation, not a directive: its provisions apply directly across member states when their respective application dates arrive. National authorities still have roles in implementation and enforcement. Read Regulation (EU) 2024/1689 in the Official Journal.

Three milestones are easy to confuse: publication, entry into force and application. Entry into force made the Act part of EU law; it did not make every requirement immediately applicable. The Act instead set different dates for different provisions and system categories.

How the deadlines fit together

The dates below distinguish the original timetable from the current implementation picture. The first five dates are the Act’s original milestones. The Commission’s current implementation materials reflect later simplification measures affecting some high-risk-system deadlines; check the live timeline for the relevant system and transition rule.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Milestone Date What it means
Official Journal publication July 12, 2024 The adopted legal text was formally published.
Entry into force August 1, 2024 The regulation became part of EU law; most obligations did not all apply on this date.
First provisions applied February 2, 2025 Under the original timetable, definitions, AI-literacy provisions and prohibitions on specified practices began to apply.
GPAI and governance provisions August 2, 2025 Under the original timetable, general-purpose AI (GPAI) and governance provisions began to apply.
General application date in the original Act August 2, 2026 Most remaining provisions were originally scheduled to apply, subject to category-specific transitions and later changes.
Longer transitions for specified systems Some dates fall in 2027 or 2028 Special rules apply to certain product-related, legacy and other categories. The current Commission timeline sets out dates by category.

For the current status, consult the Commission’s AI regulatory framework overview and its implementation timeline. A date that has passed does not necessarily mean every organization has the same obligation: the system’s use, market status and applicable transition rule matter.

Who and what the Act regulates

The Act classifies AI chiefly by risk and use, not by whether a product is marketed as “AI.” It imposes different duties on providers, deployers and other operators; one organization may hold more than one role. Buying a system from a vendor does not automatically transfer the buyer’s responsibilities.

  • Prohibited practices: specified uses are banned, subject to the precise definitions and exceptions in the law.
  • High-risk systems: generally permitted, but subject to extensive requirements and oversight.
  • Transparency-sensitive systems: certain uses trigger disclosure or information duties.
  • Minimal-risk systems: generally face no mandatory AI Act requirements beyond other applicable laws, though voluntary codes may apply.
  • General-purpose AI models: a separate framework applies to model providers, with additional requirements for models presenting systemic risk.

High-risk classification can arise through two main routes: AI that is a safety component of, or itself a product covered by, specified EU product-safety legislation in Annex I; and standalone systems used in sensitive areas listed in Annex III, such as employment, education, essential services, law enforcement, migration, justice and democratic processes. The use case is central: the same technology may be treated differently in different contexts. The regulation’s articles and annexes set the legal definitions and exceptions; the Commission’s Annex I reference covers product legislation.

Practices the Act prohibits

Article 5 is not a blanket ban on “dangerous AI” or facial recognition. It prohibits specifically defined practices, including certain manipulative or deceptive techniques that materially distort behavior, exploitation of vulnerabilities linked to age, disability or particular social or economic circumstances, and certain forms of social scoring. It also restricts specified predictive criminal-risk systems, biometric categorization and emotion recognition, as well as real-time remote biometric identification in publicly accessible spaces, subject to narrow law-enforcement exceptions. The exact scope depends on Article 5’s wording and conditions.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What high-risk compliance can involve

Providers of high-risk systems may have to establish risk management and quality-management processes; govern data; prepare technical documentation and logs; provide instructions and transparency; enable human oversight; meet accuracy, robustness and cybersecurity requirements; complete conformity assessment and registration steps; and monitor systems after they reach the market. The specific duties depend on the system and the provider’s role.

Deployers also have operational responsibilities. Depending on the system and use, they may need to follow provider instructions, assign competent human oversight, monitor operation, keep required logs, conduct workplace or fundamental-rights assessments, inform affected people or employees, report incidents and use data lawfully. A vendor’s documentation and contract can help establish a workable division of tasks, but they do not erase the deployer’s own duties.

Separate duties for general-purpose AI providers

The Act’s GPAI framework applies to providers of general-purpose models, rather than treating every business that uses a model as its provider. Depending on the model and role, provider obligations include technical documentation, information for downstream providers, a copyright-compliance policy and a sufficiently detailed summary of training content. Providers of models with systemic risk face additional duties such as evaluation, adversarial testing, systemic-risk assessment, serious-incident reporting and cybersecurity measures.

A company that develops or places a general-purpose model on the market, one that fine-tunes or integrates another provider’s model, and a business that deploys an AI application can occupy different legal positions. The Act also includes exceptions and conditions, including for some open-source models; open-source status is not a universal exemption.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Transparency rules businesses should check

Some covered interactions and outputs require people to be told that AI is involved or that content has been artificially generated or manipulated. Relevant scenarios include certain chatbot interactions, synthetic audio, image, video or text, deepfakes, and uses of emotion-recognition or biometric-categorization systems. These are not blanket requirements for every chatbot or AI-generated item: applicability depends on the provision, system, actor and circumstances.

Can the Act affect a company outside the EU?

Yes, in circumstances tied to the EU market or use. The regulation can apply to non-EU organizations whose systems or outputs are placed on the EU market, put into service in the EU, or used in the EU in circumstances covered by the Act. It can also affect organizations in a supply chain involving an EU provider, deployer, importer or distributor. A company’s lack of an EU subsidiary does not, by itself, settle whether the Act applies.

How to start an organization’s compliance work

  1. Build an AI inventory. Include internal and customer-facing tools, AI embedded in purchased software, contractor and vendor models, and features enabled by default in enterprise products.
  2. Identify each legal role. Determine whether the organization acts as provider, deployer, importer, distributor, product manufacturer, GPAI provider or downstream integrator. An organization may have multiple roles. Placing a system under its own name, substantially modifying it or changing its intended purpose can affect its classification and responsibilities.
  3. Classify each use case. Check whether it falls within a prohibited practice, a high-risk category, transparency-sensitive rules, minimal-risk treatment or GPAI obligations. Do not classify from the model name alone.
  4. Map EU connections. Check customers, employees, affected people, intended markets, output use and cross-border vendor arrangements.
  5. Review vendor contracts and evidence. Establish who supplies technical documentation and logs, handles incident reporting, completes conformity-assessment work, and communicates material model updates or modifications.
  6. Set governance and controls. Name an accountable owner and establish approval, risk assessment, human oversight, monitoring, escalation and record-retention processes.
  7. Check notices and disclosures. Review chatbot notices, synthetic-content or deepfake disclosures, user-facing explanations, and employee or affected-person notices where applicable.
  8. Assess related legal regimes. Review GDPR, the Digital Services Act, product-safety, cybersecurity, employment, discrimination, consumer-protection and sector-specific rules. AI Act compliance does not replace these laws.

Being an SME does not create a blanket exemption. The Act’s requirements depend on activity and system, though proportionality, guidance, support measures and regulatory sandboxes may be relevant. Likewise, “already in use” does not automatically mean a system is grandfathered: check transition provisions, significant changes, new intended purposes, market placement, regulated-product status and any rules for large-scale EU information systems.

Penalties and enforcement

The Act establishes tiered maximum administrative fines. For certain prohibited-practice violations, the ceiling is up to €35 million or 7% of worldwide annual turnover, whichever is higher. For certain other obligations, it is up to €15 million or 3%; for supplying incorrect, incomplete or misleading information in relevant contexts, it is up to €7.5 million or 1%. The applicable ceiling depends on the infringement and the regulation’s rules. Enforcement responsibilities differ by category and involve national authorities and EU-level governance.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Governance software can help organize inventories, workflows, evidence and monitoring, but it does not itself determine legal classification, perform all technical testing or satisfy conformity assessment. The compliance work remains an organizational and legal responsibility.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase09 OCT 267 minMortgage Escrow FAQs: Taxes, Insurance, Shortages, and Refunds
  2. The Money DeskBlogTheFinanceBase09 OCT 265 minHow Mortgage Escrow Accounts Work and What Homeowners Pay For
  3. The Money DeskBlogTheFinanceBase09 OCT 265 minHow to Read a Stock Chart, Volume and Market-Cap Data
Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.