The EU AI Act Timeline: What Applies When, and What To Do About It
The EU AI Act became law in 2024, but its obligations arrive in waves — and 2026 is the year the big one lands. If your company sells into Europe or runs AI on European users, here's the schedule that matters and the preparation order that actually works.
The phase-in that matters
Prohibited practices (social scoring, manipulative systems) have been banned since early 2025, alongside AI-literacy duties. Obligations for general-purpose AI models followed in mid-2025. The heaviest wave — the full requirements for high-risk AI systems, spanning risk management, data governance, technical documentation, human oversight, and post-market monitoring — takes effect through 2026 and into 2027. In other words: the runway is now measured in months, not years.
Are you actually in scope?
The Act reaches any provider placing AI systems on the EU market and any deployer using AI within the EU — headquarters location is irrelevant. The pivotal question is classification: high-risk categories include AI in hiring, credit, insurance pricing, education, critical infrastructure, and essential services. Many SaaS companies discover they're deployers of high-risk systems through a single HR-screening or credit-adjacent feature they barely remember shipping.
Prepare in this order
First, inventory: you cannot classify what you haven't listed — every model, every AI feature, every AI-powered vendor tool. Second, classify each against the Act's risk tiers and document the reasoning. Third, for anything plausibly high-risk, stand up the risk-management and human-oversight processes the Act describes. Fourth, wire post-market monitoring so incidents and complaints about AI behavior actually reach the people accountable for it.
If that sequence sounds like ISO 42001, that's not a coincidence — the standard operationalizes most of what the Act demands. Run one program, satisfy both. Compriska's AI Governance module was designed around exactly that overlap: one inventory, one risk methodology, evidence that serves the auditor and the regulator alike.