Ob­jec­tives, tar­get group and ap­pli­ca­tion time­line

The objectives of the AI Act are to promote the development and use of trustworthy AI in the EU, enable innovation and minimise risks, while safeguarding health, safety and fundamental rights. The AI Act is addressed to companies, public authorities and organisations that deploy or develop AI.

Objectives

The AI Act has several key objectives:

  • Safety and protection: the AI Act aims to protect people from the possible risks of AI applications, in particular where health, safety and fundamental rights such as democracy, the rule of law and environmental protection could be affected.
  • Boosting innovation: the AI Act creates a favourable environment for the development and use of AI in Europe.
  • Uniform rules: the AI Act lays down a uniform legal framework for the whole of the EU internal market, enabling companies across Europe to operate under the same conditions.
  • Trust: the AI Act provides for clear rules, transparency and responsibility aimed at strengthening trust in AI technologies.

The AI Act creates clear rules for operators along the AI value chain. It defines binding requirements for certain AI applications and increases transparency and safety in the use of AI technology. At the same time, the AI Act makes sure that the administrative and financial burden on companies, especially SMEs, is kept to a minimum.

Target group

The rules apply to all companies, public authorities, organisations and other operators deploying or placing on the market AI systems. The decisive factor is not where a company is located but whether an AI system is placed on the market or put into service in the EU and whether the AI system’s outputs have an impact on people in the EU (Art. 2 AI Act).

The AI Act applies to these operators

  • Provider and product manufacturer: They develop or have an AI system/GPAI model developed. They place it on the market under their own name or trademark or put it into service.
  • Deployer: They are based in the EU. They use or integrate AI systems into their work processes.
  • Importer: They are located or established in the Union. They bring AI systems from third-country suppliers to the EU market. The AI systems they import bear the name or trademark of the company in the third country.
  • Distributor: They make an AI system available on the Union market.
  • Authorised representative: They are located or established in the Union. They have a written mandate from the provider of an AI system or GPAI model in a third country to comply with EU regulations on the provider’s behalf.

More information on operators within the meaning of the AI Act can be found here.

These operators are subject to requirements including:

  • the risk-based categorisation of AI systems,
  • documentation obligations and proof of conformity,
  • transparency obligations to show users that they are interacting with an AI system,
  • safety and risk management requirements, in particular for high-risk AI applications,
  • surveillance by the national supervisory authorities.
The AI Act does not apply to deployers using AI systems for private purposes only. In addition, the rules do not apply to AI systems developed for the sole purpose of research and development or designed and used for military or defence purposes.

Application timeline

Since the Regulation (EU) 2026/1744 amending Regulations (EU) 2024/1689, (EU) 2018/1139 and (EU) 2023/1230 as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI - AI Omnibus Act) came into force on July 27, 2026, some of the deadlines set out in the AI Regulation have been postponed. The relevant entries in the timeline below are marked accordingly.

2 February 2025

AI literacy: providers and deployers of AI systems must take steps to support the development of their staff’s AI skills.
Prohibited practices: the AI Act defines eight practices that may no longer be applied.

2 August 2025

2 July 2026

  • The amending provisions in Art. 102 to 110 shall apply (Art. 1(40)(c) of the AI Omnibus Act).

2 August 2026

  • Transparency requirements apply to providers and deployers of certain AI systems.
  • Member States must have implemented rules on penalties.
  • All the other requirements of the AI Act not explicitly listed become applicable.

2 December 2026

  • The prohibited practices newly introduced by the AI Omnibus Act now apply (Art. 1(40)(a) AI Omnibus Act).

2 August 2027

  • At least one operational AI regulatory sandbox must be established at national level (Art. 1(22)(a) AI Omnibus Act).
  • Rules for general-purpose AI models deployed before August 2025 become applicable.

2 December 2027

  • Rules apply to high-risk AI systems in accordance with Annex III of the AI Act. (Art. 1(40)(b) of the AI Omnibus Act).

2 August 2028

  • Rules apply to high-risk AI systems in accordance with Annex I of the AI Act. (Art. 1(40)(b) of the AI Omnibus Act).

Transitional arrangements

  • Providers of AI systems, including general-purpose AI systems that generate synthetic audio, image, video or text content, which were placed on the market before 2 August 2026, shall take the necessary measures to comply with Art. 50(2) by 2 December 2026.
  • AI systems that are components of large-scale EU IT systems in the fields of freedom, security and law that have been placed on the market or put into service before 2 August 2027 and established by EU legislation, such as the Schengen Information System, must comply with the requirements of the AI Act by 31 December 2030.
  • Deployers of high-risk AI systems that have been placed on the market or put into servicebefore 2 December 2027 must only comply with the AI Act if the systems are subject to significant changes in their designs.
  • Providers and deployers of high-risk AI systems that are intended to be used by public authorities must ensure compliance with all the requirements and obligations laid down in the AI Act by 2 August 2030.

Guidelines and Codes of Practice

In addition to the timetable for the application of the AI Act, the Act also sets out a timetable for the publication of guidelines and codes of practice.

The AI Act includes various guidelines and codes of practice designed to facilitate compliance with the regulations. Some of these guidelines must be finalised by specific deadlines, whilst others may be published at unspecified times.

Guidelines

Classification of high-risk AI systems

These guidelines on the classification of AI systems under Article 6 include practical examples of high-risk and non-high-risk use cases. Article 6(5) requires the Commission to submit guidelines on practical implementation by February 2, 2026.

Reporting obligation

The Commission has presented guidelines to facilitate providers’ compliance with the reporting obligation in the event of serious incidents. Art. 73(7) of the AI Regulation stipulates that the Commission must publish such guidelines by 2 August 2025.

Further Guidelines

Six further guidelines which the Commission must draw up to promote practical implementation are listed in Art. 96(1). A seventh has been added by Art. 1(36)(b) of the AI Omnibus Act

In drawing up these guidelines, the Commission must take particular account of the needs of small and medium-sized enterprises, including start-ups, local authorities and the sectors most affected.

Topic

Status

application of the requirements and obligations referred to in Art. 8 to 15 and in Art. 25No announcements have been made
prohibited practices referred to in Art. 5On 4 February 2025, the Commission published the Guidelines on prohibited AI practices, as defined by the AI Act
practical implementation of the provisions related to substantial modificationNo announcements have been made
practical implementation of transparency obligations laid down in Art. 50Guidelines on transparency obligations for providers and deployers of certain AI systems were published on 20 July 2026.
detailed information on the relationship of this Regulation with the Union harmonisation legislation listed in Annex I, as well as with other relevant Union law, including as regards consistency in their enforcementNo announcements have been made

application of the definition of an AI system as set out in Art. 3, point (1)

 

On 6 February 2025, the Commission published guidelines on the AI system definition
Practical implementation of Art. 8(2), Art. 9(10) and Art. 17(3) in accordance with the principles of complementarity and proportionality, with a view to avoiding duplication of effort and minimising the additional burden involved in complying with the requirements of the AI Act and the Union’s harmonisation legislation (Annex I, Section A) To be published by 1 August 2027

Codes of Practice

Art. 56 of the Regulation deals with the development of codes of practice at Union level. Codes of practice are voluntary instruments drawn up by independent experts. They are intended to help market participants comply with the obligations set out in the AI Act.

On 10 July 2025, the first code of practice, the 'General-Purpose AI Code of Practice', was published. Further information can be found here.
On 10 June 2026, the second code of practice, the 'Code of Practice on marking and labelling of AI-generated content', was published.

Further information can be found here.

Mastodon