14 October 2025
EU AI Act: 2 August 2026 is closer than you think
Why every company and municipality must start now — even though the core rules apply from 2 August 2026.
The short version: The AI Act is already law. Prohibitions have applied since 2 February 2025. GPAI obligations kicked in on 2 August 2025. Most remaining duties apply from 2 August 2026 — with certain high-risk product rules stretching to 2027. There will be no pause. Start now.
Why the urgency?
- It’s in force. The Act entered into force 1 August 2024 with staged applicability over 24–36 months.
- No delay coming. After industry calls to slow down, the Commission confirmed no pause to the timeline.
- Guidance may arrive late. The Code of Practice for GPAI may not be ready until late 2025, shrinking your runway.
Timeline at a glance
- Prohibited practices: since 2 Feb 2025 (6 months post-entry).
- GPAI obligations: since 2 Aug 2025 (12 months).
- Most obligations: 2 Aug 2026 (24 months).
- Certain high-risk (embedded in regulated products): 2 Aug 2027 (36 months).
Who’s in scope?
Anyone building, procuring or deploying AI in the EU — companies and municipalities alike. Not just providers: deployers carry duties for risk management, data governance, oversight and logging.
Consequences of non-compliance
Fines up to €35m or 7% of global turnover for the most serious breaches; up to €15m or 3% for others; €7.5m or 1% for supplying incorrect information to authorities. Authorities can also order withdrawal of non-compliant AI from the market.
What to do this quarter
- Inventory AI use across departments (systems, vendors, GPT use).
- Risk classify (prohibited/limited/high/low) and assign owners per system.
- Secure the GPAI lane if you rely on models/services: documentation, supplier requirements, logging.
- Governance & auditability: decision flows, DPIA templates, audit trail (lineage, version signing).
- AI literacy (Art. 4): train roles that will govern, build and procure AI.
- Budget for 2026: procurement, tools, staffing, audit.
Municipalities: typical risk areas
Citizen services (chat/QA), CCTV/analytics, HR screening, school apps, procurement. Expect heightened requirements for traceability, data minimisation and human oversight.
Bottom line
The clock won’t stop. Guidance will be late. Waiting costs more than starting now. Start today — with inventory, governance and measurable compliance.
This article is for information only and does not constitute legal advice.