Applicable law
Legal obligation in force or with an application date.
Artificial intelligence no longer operates in a regulatory vacuum. But not everything carries the same weight: some dates relate to applicable laws, others to technical standards, others to voluntary frameworks and others to acts already adopted with deferred application.
Each milestone indicates what came into effect, what was published or what was scheduled. A filled dot marks a milestone that has already occurred. A hollow dot marks a scheduled future date. The status anticipated is reserved for dates that still require regulatory confirmation.
Legal obligation in force or with an application date.
Standard published by a standards body; it may be certifiable or serve as technical guidance.
Reference guidance with no direct legal obligation.
Date relevant to certified organisations or certification bodies.
Adopted legislative act, with entry into force or application according to its timetable.
Public position of an authority or agency; provides guidance without always constituting a legal obligation.
Showing 24 of 24 milestones
The General Data Protection Regulation sets the European baseline for personal data processing. It matters for AI because no serious system can be governed without governing the data it uses, generates, infers or transforms.
Official source →The current edition of the international standard for information security management systems is published. Its relevance to AI is direct: without security, access control, traceability and risk management, governance remains incomplete.
Official source →NIST publishes a voluntary framework for managing artificial intelligence risks. It is neither a law nor a certifiable standard, but it has become an international reference for structuring risks, trust, bias, security, transparency and oversight.
Official source →The focus is not on banning AI, but on structuring data availability, reuse and governance. For AI, this matters because models are not governed solely through the algorithm: they are also governed through the data architecture that feeds them.
Official source →First international AI management system standard
ISO/IEC 42001 establishes requirements for creating, implementing, maintaining and improving an artificial intelligence management system. It marks the shift from general ethical discussion to auditable governance: policies, objectives, responsibilities, risks, monitoring, improvement and evidence.
Official source →From this point, the phased application timetable begins. The discussion shifts from whether there will be AI regulation to which provisions apply, when they apply and what evidence each organisation will need to demonstrate.
Official source →AAIP publishes guidance for public and private entities on transparency and personal data protection in the use of artificial intelligence. It is not an AI law, but it anticipates criteria for algorithmic transparency, impact assessment and the lifecycle.
Official source →Member States were required to transpose the NIS2 Directive. Its effects may extend to Latin American supply chains when they work with clients, parent companies or services linked to the European market.
Official source →The European cybersecurity framework for products with digital elements enters into force. The core obligation does not apply immediately, but the clock starts ticking for manufacturers, developers and suppliers of digital products.
Official source →Digital operational resilience ceases to be an isolated good practice in the European financial sector and becomes part of the regulatory system: ICT risks, incidents, continuity, testing, critical third parties and supervision.
Official source →Prohibited practices and AI literacy
The prohibitions on unacceptable-risk practices and obligations related to AI literacy start to apply. Before scaling up AI, an organisation must know which uses it cannot accept and which minimum capabilities it needs to govern it.
Official source →AI system impact assessment
The standard provides guidance on conducting impact assessments of artificial intelligence systems. It complements ISO/IEC 42001 by bringing governance down to a concrete question: what foreseeable effects an AI system may produce and how they are documented throughout its life cycle.
Official source →The Code of Practice for general-purpose AI models is published. It is voluntary, but relevant: it offers a practical route to demonstrating compliance with AI Act obligations on transparency, copyright, safety and models with systemic risk.
Official source →Governance and general-purpose models
Obligations related to AI Act governance and general-purpose AI models become applicable. Providers can no longer rely solely on general statements: they must demonstrate documentation, traceability, information for integrators and risk management where applicable.
Official source →The Data Act affects the data economy: access, use, sharing, portability and rules for data generated by connected products and related services. For AI, data access and governance become a structural part of compliance.
Official source →The three-year transition from ISO/IEC 27001:2013 to ISO/IEC 27001:2022 within the accredited certification scheme ends. The critical point was not to change the certificate, but to demonstrate a real transition: gaps, SoA, risks and control effectiveness.
Official source →Final approval to adjust the AI Act timeline
The Council of the EU gave the final green light to the Digital Omnibus on AI. The text simplifies certain AI Act rules and sets new dates for high-risk systems, transparency of AI-generated content, new prohibitions and coordination with sectoral legislation.
Official source →General application, with exceptions and a revised timeline
The AI Act reaches its general application date. Some obligations already applied, others start now and others are deferred under the revised AI Omnibus timeline. The date must be read precisely, not as the entire framework taking effect at once.
Official source →Reporting obligations
Reporting obligations related to actively exploited vulnerabilities and significant incidents affecting products with digital elements start to apply.
Official source →The revised timeline sets this date as the new deadline for transparency solutions for AI-generated content. This matters for organisations that produce, integrate or distribute synthetic content: text, images, audio, video or systems that interact with people.
Official source →The revised timeline postpones until this date the deadline for competent authorities to establish AI regulatory sandboxes at national level. Without available testing environments, guidance and standards, demonstrating compliance becomes more difficult.
Official source →High-risk systems by use case
Under the revised timeline, obligations for AI systems classified as high-risk by use case apply from this date, including areas such as biometrics, critical infrastructure, education, employment, migration, border control and law enforcement.
Official source →Main application
The main obligations of the Cyber Resilience Act for products with digital elements start to apply. This affects manufacturers, developers, importers and distributors placing digital products on the European market.
Official source →High-risk AI embedded in regulated products
Under the revised timeline, obligations for high-risk AI systems embedded in products subject to sectoral safety regulation apply from this date. This affects manufacturers and technical supply chains where AI forms part of regulated products.
Official source →Regulation does not arrive all at once. It arrives in layers.
First, data was brought into order. Then cybersecurity was strengthened. Next came operational resilience. Now artificial intelligence is starting to demand management, evidence, documentation and accountability.
The mistake would be to look at each standard or regulation separately. The correct interpretation is systemic: data, security, resilience, AI, suppliers, traceability and evidence form part of the same conversation on organisational governance.
This timeline organises dates based on official or institutional sources and does not constitute legal advice. Dates related to the AI Omnibus reflect the final approval announced by the Council of the EU on 29 June 2026 and must always be checked against the applicable text in force.