The interactive tool needs JavaScript. Below is the full set it draws from, with the date each takes effect and the source behind it, so you can work out which reach you yourself.
2 February 2025
Prohibited practices and AI literacy
Certain AI practices are banned outright, and staff who deal with AI systems must have sufficient AI literacy for their role. Both have applied since 2 February 2025.
- Confirmation that no in-scope system performs a prohibited practice - social scoring, untargeted facial image scraping, emotion inference in workplaces or education, and certain biometric categorisation
- Evidence that staff involved in operating or using AI have appropriate AI literacy for their role
Source: European Commission, Shaping Europe's digital future · verified 2026-08-25
2 August 2026
Article 50 transparency obligations
People must be told when they are interacting with an AI system, and synthetic audio, image, video or text must be marked in a machine-readable way. In force since 2 August 2026.
- Clear disclosure at the point a person begins interacting with an AI system
- Machine-readable marking of synthetic content, and visible disclosure of deep fakes
- Disclosure where AI-generated text is published on matters of public interest
Source: European Commission, Shaping Europe's digital future · verified 2026-08-25
2 December 2027
Annex III high-risk system obligations
The full high-risk regime: risk management, data governance, technical documentation, logging, human oversight, accuracy and robustness, plus registration and post-market monitoring.
- A documented risk management system operating across the whole lifecycle
- Data governance covering training, validation and testing data
- Technical documentation and automatically generated logs
- Human oversight designed in, with the authority to intervene or stop
- Registration in the EU database before placing on the market
- Post-market monitoring and serious incident reporting
Source: European Commission, Shaping Europe's digital future · verified 2026-08-25
2 August 2028
High-risk obligations for AI inside regulated products
Where AI is a safety component of a product already covered by EU product safety law, the high-risk requirements apply through the existing conformity assessment for that product.
- The high-risk requirements met within the product's existing conformity assessment
- Notified body involvement where the underlying product legislation requires it
- Technical documentation integrated with the product's existing file
Source: European Commission, Shaping Europe's digital future · verified 2026-08-25
2 August 2025
General-purpose AI model obligations
Providers of general-purpose AI models must maintain technical documentation, publish a sufficiently detailed summary of training content, and have a copyright policy. In force since 2 August 2025.
- Technical documentation for the model, kept current
- Information and documentation for downstream providers who build on it
- A policy to comply with EU copyright law
- A sufficiently detailed public summary of the content used for training
Source: European Commission, Shaping Europe's digital future · verified 2026-08-25
2 December 2027
Deployer duties for high-risk systems
Deployers of high-risk AI carry their own obligations, separate from the provider's. This is the set most often missed, because organisations assume buying a compliant system makes them compliant.
- Use the system in line with its instructions for use
- Assign human oversight to people with the competence, training and authority to exercise it
- Ensure input data is relevant and sufficiently representative for the intended purpose
- Keep the automatically generated logs
- Inform workers' representatives before putting a high-risk system into use in the workplace
- Where the deployer is a public body or provides essential services, complete a fundamental rights impact assessment
Source: European Commission, Shaping Europe's digital future · verified 2026-08-25