NEWVenvera speaks your language: the full platform, in English, German, Spanish, Bulgarian and Arabic.See what’s new
EU AI Act Compliance Timeline: How Long It Takes
Learn

EU AI Act Compliance Timeline: How Long It Takes

·Alexander Sverdlov

For most companies, EU AI Act compliance takes weeks rather than years, because most companies are deployers of AI systems that are not high risk. For a provider of a high risk system it takes 9 to 18 months from a standing start, and longer if a notified body sits in the path. The range is that wide because Regulation (EU) 2024/1689 does not impose one obligation on one kind of company. It assigns duties by role and by risk class, and the timeline follows the same logic: the first month decides which track you are on, and the track decides the calendar.

The date to plan against also changed this summer. Regulation (EU) 2026/1744, adopted on 8 July 2026 and published on 24 July 2026, moved the high risk obligations in Chapter III from 2 August 2026 to 2 December 2027 for Annex III systems and 2 August 2028 for Annex I products. What did not move is the general application date of 2 August 2026, which has now passed, and the 2 December 2026 date by which existing generative systems must mark their output.

PhaseTypical durationWhat gates it
Inventory every AI system2 to 6 weeksFinding the AI that arrived through procurement rather than engineering. The list is always longer than the engineering team thinks.
Classify and assign roles2 to 4 weeksArticle 6 and Annex III for risk class. Article 3 and Article 25 for whether you are the provider or the deployer of each system.
Literacy, transparency and deployer duties1 to 3 monthsArticle 4, Article 50 and Article 26. Mostly training, disclosure copy and contract work with your AI suppliers.
High risk provider build6 to 12 monthsArticles 9 to 17: risk management, data governance, technical documentation, logging, human oversight and a quality management system. Engineering capacity decides this phase.
Conformity assessment and registration1 to 4 monthsThe Article 43 route and Article 49 registration. Internal control closes fast, a notified body queue does not.
Five phases of an EU AI Act compliance programme, from inventory and classification through literacy and transparency to the high risk build and conformity assessment

How long does EU AI Act compliance take?

Three timelines, not one, and which one you are on is decided in the first month.

If you use AI but nothing you run is high risk, the obligations are Article 4 AI literacy and, where you deploy chatbots or generative systems, the Article 50 transparency duties. That is training, disclosure copy and a check on how generated output is marked. Weeks.

If you deploy a high risk system that someone else provides, a CV screening tool or a credit scoring model for example, Article 26 applies: use the system in accordance with its instructions for use, assign human oversight to people with the competence, training and authority to exercise it, and keep the logs. One to three months, and much of that time is spent waiting for information the provider has to give you.

If you provide a high risk system, Articles 9 to 17 apply: a risk management system, data governance, technical documentation to Annex IV, logging, human oversight design, accuracy and robustness, and a quality management system, followed by conformity assessment and registration. Nine to eighteen months, dominated by the engineering.

A quick test of where you sit: can you list every AI system in the business, say which Annex III point each one falls under if any, and name whose name is on it? If any of those is a shrug, the inventory phase is where your time goes first.

Typical duration of each EU AI Act track, showing the high risk provider build under Articles 9 to 17 consuming six to twelve months

What decides whether it takes weeks or 18 months?

Four things, in descending order of impact.

1. Your role for each system

Provider or deployer is the first fork. Article 25 moves the line: put your name or trademark on a high risk system, substantially modify one, or change a system's intended purpose so that it becomes high risk, and you are its provider with the full Chapter III build ahead of you. Firms that fine tune a bought model for a regulated use case are the usual casualty. Our guide to provider versus deployer under the EU AI Act walks the test.

2. Whether any system is high risk at all

Article 6(2) with Annex III is the standalone use case list: biometrics, critical infrastructure, education, employment, access to essential services including credit scoring and insurance pricing, law enforcement, migration and justice. Article 6(1) with Annex I is AI acting as a safety component of a product already covered by Union harmonisation legislation. The classification decides your date, 2 December 2027 or 2 August 2028, as well as your workload. The paragraph by paragraph test is in our guide to Article 6 and the Annex III high risk list.

3. The conformity assessment route

Article 43 is where the calendar can stretch. For high risk systems in points 2 to 8 of Annex III, providers follow the conformity assessment procedure based on internal control in Annex VI, which does not involve a notified body. For point 1, biometrics, a provider that has applied harmonised standards may choose between internal control and a notified body, and must use the Annex VII notified body route where harmonised standards do not exist and no common specifications are available. Annex I products follow the conformity procedure of their own sectoral legislation, with the AI Act requirements folded in. Notified bodies already designated under that legislation have until 28 January 2028 to apply for designation under the AI Act, so capacity for Annex I products is still being assembled.

4. What you already run

Risk management, record keeping, incident handling and governance built for ISO 27001, DORA or ISO 42001 transfer into Articles 9, 12 and 17. What does not transfer is the Annex IV technical file, the Article 49 registration in the EU database, and the Article 50 marking of generated output. Our guide to ISO 42001 versus the EU AI Act sets out the overlap.

Which EU AI Act date binds each class of system: 2026 for the general application date and generative output, 2027 for Annex III high risk and 2028 for Annex I high risk

Which deadline should you plan against?

Three dates matter, and the first has already passed.

2 August 2026 is the general application date in Article 113. Anything not expressly deferred applies from then, including Article 50 transparency. The Article 4 literacy duty and the Article 5 prohibitions have applied since 2 February 2025. If you are reading this in September 2026 and have neither, that is the work to do this month, not next year.

2 December 2026 is the nearest live date. Under the new Article 111(4), providers of systems generating synthetic audio, image, video or text that were on the market before 2 August 2026 must comply with the Article 50(2) machine readable marking duty by then. The two prohibitions inserted in 2026, Article 5(1) points (ba) and (bb) together with paragraphs (1a) and (1b), apply from the same day.

2 December 2027 and 2 August 2028 are the high risk dates, for Annex III and Annex I respectively. They are flat calendar dates. Earlier drafts of the simplification package tied the delay to the availability of harmonised standards; the adopted text does not. The full table, including the transitional dates in Article 111, is in our guide to every EU AI Act deadline.

Two transitional rules move the date for systems that already exist. Under Article 111(2) as replaced, a high risk system placed on the market before Chapter III applies is caught only if its design is significantly changed after that date, with a backstop of 2 August 2030 for systems intended to be used by public authorities. Under Article 111(3), general purpose AI models on the market before 2 August 2025 have until 2 August 2027.

Counting back from 2 December 2027 gives a provider starting today fifteen months. Against a 9 to 18 month programme that is enough for a firm with a secure development lifecycle already in place, and not enough for one without.

What the other results get wrong

Four errors recur in the published guidance.

The first is quoting a single number. Six to twelve months describes a provider of one high risk system with a competent engineering team. It says nothing about the deployer down the road, whose programme is weeks, and it flatters the provider whose product needs a notified body.

The second is treating August 2026 as postponed. Only Chapter III Sections 1, 2 and 3 moved. The general application date held, Article 50 applies, and the Article 4 and Article 5 duties have applied for over a year.

The third is planning around a conditional trigger. Guidance written against the proposal describes a deferral that would end when standards became available. The Regulation as adopted sets dates, not conditions.

The fourth is describing the work as documentation. The Annex IV technical file is an output. The months go on the risk management system, the data governance and the logging that make the file true.

EU AI Act readiness dashboard showing AI systems inventoried, systems classified under Article 6, Article 50 disclosures in place and high risk systems without a technical file
Venvera EU AI Act dashboard with the AI system inventory and risk classification for each system

What can you do in the next 30 days?

Fill this in for your own estate. Any row you cannot complete is your first project.

QuestionYour answerWhy it matters
How many AI systems do you use, including the AI inside tools you bought for something else?Without an inventory there is no timeline, only a guess.
For each system, are you the provider or the deployer?Article 25 moves the line. Getting this wrong is the most expensive misclassification available.
Does any system fall under Annex III or Annex I?This sets your date: 2 December 2027 or 2 August 2028.
Do you deploy chatbots or systems that generate content?Article 50 has applied since 2 August 2026. Existing generative systems must mark output by 2 December 2026.
Can you show the Article 4 literacy measures you have taken?In force since 2 February 2025. The amended text asks for measures that support literacy, not a guaranteed level.

If you want a baseline before committing to a plan, run a free compliance check. It will not size the engineering work, but it will show which of the five rows you are going to struggle with, and our EU AI Act compliance software holds the inventory, the classification and the technical file in one place once you start.

The bottom line on EU AI Act timing: plan back from December 2027 but act on the August 2026 duties now

Frequently asked questions

Has the 2 August 2026 deadline been cancelled?

No. It is the general application date in Article 113 and it has passed. What moved to 2 December 2027 and 2 August 2028 is the high risk regime in Chapter III Sections 1, 2 and 3.

We are an SME. Does that shorten the timeline?

Not the dates. It lightens the artefacts. Article 11(1) lets SMEs, start-ups and small mid-caps use a simplified technical documentation form that notified bodies must accept, Article 17(2) makes the quality management system proportionate to your size, and Article 99(6) caps fines at the lower of the amount and the percentage rather than the higher.

Does a notified body always add months?

Only where one is required. Annex III points 2 to 8 self assess under Annex VI. Point 1 needs a notified body only where harmonised standards do not exist or were not fully applied. Annex I products follow their sectoral route, which may already involve one.

Our high risk system is already on the market. Do we start again?

Not unless its design changes significantly after Chapter III applies. Article 111(2) grandfathers existing systems on that condition, and the recitals of the 2026 amendment confirm that the grace period attaches to the type and model rather than to each unit. Systems intended for public authorities must comply by 2 August 2030 regardless.

What happens if we miss the date?

Article 99(4) covers provider and deployer obligations at up to 15 million euros or 3% of total worldwide annual turnover, whichever is higher. The three tiers, and the SME rule that inverts them, are in our guide to EU AI Act penalties and fines.

Primary sources

Dates and obligations are taken from Regulation (EU) 2024/1689 (Articles 4, 6, 9 to 17, 25, 26, 43, 49, 50, 99, 111 and 113, with Annexes I, III, IV, VI and VII) as amended by Regulation (EU) 2026/1744, which replaced Article 4, Article 43(3) and Article 111(2), added Article 111(4), and rewrote the third paragraph of Article 113. Durations are planning estimates from implementation work, not figures from the Regulation. Confirm the current consolidated text before relying on a date.

Alexander Sverdlov

Alexander Sverdlov

CEO & Founder

Alexander is the founder of Venvera and a 20+ year veteran of European cybersecurity and compliance. He has led security and risk programmes for regulated financial institutions, fintechs and SaaS companies operating under DORA, NIS2, GDPR, ISO 27001 and the EU AI Act. Before Venvera, he founded Atlant Security, an offensive security consultancy that ran penetration tests, red-team exercises and ISO 27001 readiness programmes for clients across the EU and the Middle East. He writes on the cross-framework realities of running modern compliance: how to map one control to many obligations, where the spreadsheets fall apart, and what regulators are actually asking for once the auditor sits down.

More articles by Alexander

CONTINUE READING