Timeline · AI, management, cybersecurity and data

The rules already have dates.

Artificial intelligence no longer operates in a regulatory vacuum. But not everything carries the same weight: some dates relate to applicable laws, others to technical standards, others to voluntary frameworks and others to acts already adopted with deferred application.

How to read this timeline

Each milestone indicates what came into effect, what was published or what was scheduled. A filled dot marks a milestone that has already occurred. A hollow dot marks a scheduled future date. The status anticipated is reserved for dates that still require regulatory confirmation.

17 past
7 scheduled
0 anticipated
Milestone types

Not all dates impose obligations in the same way.

Applicable law

Legal obligation in force or with an application date.

Technical standard

Standard published by a standards body; it may be certifiable or serve as technical guidance.

Voluntary framework

Reference guidance with no direct legal obligation.

Certification transition

Date relevant to certified organisations or certification bodies.

Adopted regulation

Adopted legislative act, with entry into force or application according to its timetable.

Official guidance

Public position of an authority or agency; provides guidance without always constituting a legal obligation.

  1. 20181 milestone

    • 25 May 2018 European Union Applicable law

      The GDPR becomes applicable

      The General Data Protection Regulation sets the European baseline for personal data processing. It matters for AI because no serious system can be governed without governing the data it uses, generates, infers or transforms.

      Official source →
  2. 20221 milestone

    • 25 Oct 2022 ISO/IEC Technical standard

      ISO/IEC 27001:2022

      The current edition of the international standard for information security management systems is published. Its relevance to AI is direct: without security, access control, traceability and risk management, governance remains incomplete.

      Official source →
  3. 20233 milestones

    • 26 Jan 2023 United States · NIST Voluntary framework

      AI Risk Management Framework 1.0

      NIST publishes a voluntary framework for managing artificial intelligence risks. It is neither a law nor a certifiable standard, but it has become an international reference for structuring risks, trust, bias, security, transparency and oversight.

      Official source →
    • 24 Sep 2023 European Union Applicable law

      Data Governance Act applicable

      The focus is not on banning AI, but on structuring data availability, reuse and governance. For AI, this matters because models are not governed solely through the algorithm: they are also governed through the data architecture that feeds them.

      Official source →
    • 18 Dec 2023 ISO/IEC Technical standard

      ISO/IEC 42001:2023

      First international AI management system standard

      ISO/IEC 42001 establishes requirements for creating, implementing, maintaining and improving an artificial intelligence management system. It marks the shift from general ethical discussion to auditable governance: policies, objectives, responsibilities, risks, monitoring, improvement and evidence.

      Official source →
  4. 20244 milestones

    • 1 Aug 2024 European Union Entry into force

      The AI Act enters into force

      From this point, the phased application timetable begins. The discussion shifts from whether there will be AI regulation to which provisions apply, when they apply and what evidence each organisation will need to demonstrate.

      Official source →
    • 27 Sep 2024 Argentina · AAIP Official guidance

      Argentine guidance on responsible AI and data protection

      AAIP publishes guidance for public and private entities on transparency and personal data protection in the use of artificial intelligence. It is not an AI law, but it anticipates criteria for algorithmic transparency, impact assessment and the lifecycle.

      Official source →
    • 17 Oct 2024 European Union Applicable law

      NIS2 transposition deadline

      Member States were required to transpose the NIS2 Directive. Its effects may extend to Latin American supply chains when they work with clients, parent companies or services linked to the European market.

      Official source →
    • 10 Dec 2024 European Union Entry into force

      Cyber Resilience Act enters into force

      The European cybersecurity framework for products with digital elements enters into force. The core obligation does not apply immediately, but the clock starts ticking for manufacturers, developers and suppliers of digital products.

      Official source →
  5. 20257 milestones

    • 17 Jan 2025 European Union Applicable law

      DORA starts to apply

      Digital operational resilience ceases to be an isolated good practice in the European financial sector and becomes part of the regulatory system: ICT risks, incidents, continuity, testing, critical third parties and supervision.

      Official source →
    • 2 Feb 2025 European Union Partial legal application

      AI Act

      Prohibited practices and AI literacy

      The prohibitions on unacceptable-risk practices and obligations related to AI literacy start to apply. Before scaling up AI, an organisation must know which uses it cannot accept and which minimum capabilities it needs to govern it.

      Official source →
    • 28 May 2025 ISO/IEC Technical standard

      ISO/IEC 42005:2025

      AI system impact assessment

      The standard provides guidance on conducting impact assessments of artificial intelligence systems. It complements ISO/IEC 42001 by bringing governance down to a concrete question: what foreseeable effects an AI system may produce and how they are documented throughout its life cycle.

      Official source →
    • 10 Jul 2025 European Union Voluntary tool

      Code of practice for general-purpose models

      The Code of Practice for general-purpose AI models is published. It is voluntary, but relevant: it offers a practical route to demonstrating compliance with AI Act obligations on transparency, copyright, safety and models with systemic risk.

      Official source →
    • 2 Aug 2025 European Union Partial legal application

      AI Act

      Governance and general-purpose models

      Obligations related to AI Act governance and general-purpose AI models become applicable. Providers can no longer rely solely on general statements: they must demonstrate documentation, traceability, information for integrators and risk management where applicable.

      Official source →
    • 12 Sep 2025 European Union Applicable law

      Data Act becomes applicable

      The Data Act affects the data economy: access, use, sharing, portability and rules for data generated by connected products and related services. For AI, data access and governance become a structural part of compliance.

      Official source →
    • 31 Oct 2025 IAF · Certification Certification transition

      Operational close of the transition to ISO/IEC 27001:2022

      The three-year transition from ISO/IEC 27001:2013 to ISO/IEC 27001:2022 within the accredited certification scheme ends. The critical point was not to change the certificate, but to demonstrate a real transition: gaps, SoA, risks and control effectiveness.

      Official source →
  6. 20264 milestones

    • 29 Jun 2026 European Union Adopted regulation

      AI Omnibus

      Final approval to adjust the AI Act timeline

      The Council of the EU gave the final green light to the Digital Omnibus on AI. The text simplifies certain AI Act rules and sets new dates for high-risk systems, transparency of AI-generated content, new prohibitions and coordination with sectoral legislation.

      Official source →
    • 2 Aug 2026 European Union Applicable law

      AI Act

      General application, with exceptions and a revised timeline

      The AI Act reaches its general application date. Some obligations already applied, others start now and others are deferred under the revised AI Omnibus timeline. The date must be read precisely, not as the entire framework taking effect at once.

      Official source →
    • 11 Sep 2026 European Union Scheduled legal obligation

      Cyber Resilience Act

      Reporting obligations

      Reporting obligations related to actively exploited vulnerabilities and significant incidents affecting products with digital elements start to apply.

      Official source →
    • 2 Dec 2026 European Union Scheduled legal obligation

      Transparency of AI-generated content

      The revised timeline sets this date as the new deadline for transparency solutions for AI-generated content. This matters for organisations that produce, integrate or distribute synthetic content: text, images, audio, video or systems that interact with people.

      Official source →
  7. 20273 milestones

    • 2 Aug 2027 European Union Expected institutional date

      AI regulatory sandboxes

      The revised timeline postpones until this date the deadline for competent authorities to establish AI regulatory sandboxes at national level. Without available testing environments, guidance and standards, demonstrating compliance becomes more difficult.

      Official source →
    • 2 Dec 2027 European Union Scheduled legal obligation

      AI Act

      High-risk systems by use case

      Under the revised timeline, obligations for AI systems classified as high-risk by use case apply from this date, including areas such as biometrics, critical infrastructure, education, employment, migration, border control and law enforcement.

      Official source →
    • 11 Dec 2027 European Union Applicable law

      Cyber Resilience Act

      Main application

      The main obligations of the Cyber Resilience Act for products with digital elements start to apply. This affects manufacturers, developers, importers and distributors placing digital products on the European market.

      Official source →
  8. 20281 milestone

    • 2 Aug 2028 European Union Scheduled legal obligation

      AI Act

      High-risk AI embedded in regulated products

      Under the revised timeline, obligations for high-risk AI systems embedded in products subject to sectoral safety regulation apply from this date. This affects manufacturers and technical supply chains where AI forms part of regulated products.

      Official source →
Technical interpretation

What this timeline demonstrates.

Regulation does not arrive all at once. It arrives in layers.

First, data was brought into order. Then cybersecurity was strengthened. Next came operational resilience. Now artificial intelligence is starting to demand management, evidence, documentation and accountability.

The mistake would be to look at each standard or regulation separately. The correct interpretation is systemic: data, security, resilience, AI, suppliers, traceability and evidence form part of the same conversation on organisational governance.

Scope

Technical guidance with a declared scope.

This timeline organises dates based on official or institutional sources and does not constitute legal advice. Dates related to the AI Omnibus reflect the final approval announced by the Council of the EU on 29 June 2026 and must always be checked against the applicable text in force.

Text in force Applicable jurisdiction Competent authority Organisation’s role Type of AI system Data processed Users or affected parties Value chain Available evidence

Instrument factsheet

Scope
24 published milestones
Sources
Official or institutional documents: EUR-Lex, European Commission, Council of the EU, ISO, NIST, AAIP and IAF. Each milestone links to its verifiable source.
Inclusion criteria
A milestone is included when it has a confirmed or scheduled date, a verifiable official source and a direct effect on the management, certification or governance of AI, data and cybersecurity. Unconfirmed dates are published as expected dates until sufficient official sourcing is available.
What it does not do
It does not constitute legal advice or replace reading the regulatory text in force for a specific decision.
Part of the tools index →
WhatsApp G-CERTI