How to read the timeline without confusing entry into force with application
Regulation (EU) 2024/1689, known as the Artificial Intelligence Act or AI Act, did not become fully applicable on the day it entered into force. The text establishes a phased timetable: some provisions began to apply before others, and certain rules have later dates. Therefore, saying that “the law is already in force” does not, by itself, establish which specific obligations apply to an organisation on a given date. The useful question is which provision applies, to whom, and from when. Source: Regulation (EU) 2024/1689.
It is useful to distinguish three concepts. Entry into force indicates when the Regulation became part of the applicable legal order; the date of application indicates when particular rules take effect; and actual compliance also depends on whether the entity and system fall within the scope of those rules. The Commission announced that the Regulation entered into force on 1 August 2024, but that date should not be presented as the simultaneous start of all obligations. Source: European Commission.
This guide summarises general milestones and offers a method for identifying the overlap with privacy rules. It does not determine whether a particular system is high-risk, whether a company must meet a specific obligation, or whether a data processing activity is lawful. Those answers require reviewing the actual use, the parties involved and the applicable text, as well as any relevant sector-specific legislation. The dates below come from the timetable set out in the Regulation; decisions about a particular case should be based on the legal text, not just an informational summary.
Timeline: general milestones in the AI Act
The Regulation was published in the Official Journal of the European Union on 12 July 2024 and entered into force on 1 August that year, twenty days after publication. However, Article 113 set different time limits for different parts. The timetable is particularly important because obligations do not all take effect at once: reading only the entry-into-force date leads to an incomplete interpretation. Source: Regulation (EU) 2024/1689.
The Commission identifies 2 February 2025 as the date when the general provisions and prohibitions on certain AI practices began to apply. On 2 August 2025, obligations for providers of general-purpose AI models, among others, began to apply. These dates refer to different categories of rules: they do not mean that every AI system is subject to the same requirements from those days. Source: Commission FAQs; Source: Commission guidelines on general-purpose AI models.
As a general rule, the Regulation will apply from 2 August 2026. The timetable itself provides for a later exception for certain obligations relating to high-risk systems integrated into regulated products: their application date is 2 August 2027. The 2027 date should not be extended to all high-risk systems, nor should it be assumed that the general 2026 date eliminates earlier deadlines. To check a specific obligation, read the relevant article and its transitional provisions. Source: Regulation (EU) 2024/1689.
Which framework regulates what: the AI Act and GDPR
The AI Act establishes a framework for the placing on the market, putting into service and use of artificial intelligence systems in the European Union, with rules that vary according to risk and each participant’s role. The GDPR, by contrast, regulates the processing of personal data. If an AI system processes information that identifies or could identify a person, both frameworks may be relevant. The presence of AI does not automatically make all data personal data; what matters is the context and whether the information relates to an identified or identifiable person. Source: AI Act.
The relationship is not one of substitution. Meeting the applicable AI Act obligations does not, by itself, demonstrate that there is an appropriate legal basis for processing data, that GDPR transparency duties have been met, or that security and data-minimisation measures are sufficient. Conversely, GDPR compliance does not automatically demonstrate compliance with the AI Act’s specific requirements. These are separate checks that may overlap within the same project.
Nor should it be concluded that an assessment required under one framework replaces the assessment required under the other. For certain high-risk systems, the AI Act includes risk-management obligations and a fundamental-rights impact assessment; the GDPR may require a data protection impact assessment when processing is likely to result in a high risk to people’s rights and freedoms. Their purposes and conditions are not interchangeable, even though a coordinated analysis may help avoid duplication and inconsistency. What is required in a particular case depends on the use and the applicable legal criteria. Source: AI Act.
A system does not have just one responsible party
The AI Act allocates functions among different actors, such as providers and deployers, and obligations depend on the role assumed and the type of system. In data protection, responsibilities are determined by the functions entities perform in relation to processing—for example, who decides its purposes and means. It is not safe to assume that the tool provider will always be responsible for everything, or that a business customer will always have the same role in every operation. The relationship must be analysed activity by activity. Source: AI Act.
A practical review can begin with these questions:
- What system is being used, and for what specific purpose? Is an organisation developing, offering or integrating a system, or using a third-party system?
- What information does it receive, produce or retain? Does it include personal data or allow results to be linked to individuals?
- Who determines the purposes and means of processing, and who decides how the system is used in practice?
- Which AI Act category and obligations apply to the system and each organisation’s role?
- Which GDPR requirements apply to the processing, independently of the AI obligations? Is a data protection impact assessment needed? Sources: AI Act; Commission FAQs.
What to check before drawing conclusions for users or organisations
For an organisation, the timetable is a starting point for organising work, not an automatic to-do list that is identical for everyone. First, take stock of actual uses, including functions integrated into third-party products or services; then document the data and decisions involved. With that information, it is possible to check whether the system falls within the Regulation’s scope, what role each entity plays, and which date is relevant to the identified provisions. Classification should not be based solely on a tool’s commercial name or on its use of machine-learning techniques.
In parallel, the controller should examine the processing of personal data under the GDPR. Depending on the circumstances, this may involve analysing the purpose, legal basis, transparency, data limitation, retention, security and people’s rights. This is not a list of obligations that takes effect in full in every case: each requirement depends on the processing and its circumstances. If an impact assessment is considered necessary, it must follow the GDPR criteria and should not be treated as a formality that can be replaced by generic AI-system documentation.
For readers and affected people, a label such as “AI Act compliant” does not, by itself, reveal what data is used, on what legal basis, for how long, or how to exercise rights. It is reasonable to seek information about the specific service, who offers it and what process is available for raising questions or complaints. An organisation’s general explanations may provide guidance, but do not by themselves prove that every particular use complies with both frameworks. The competent authorities and legal texts are more appropriate references for resolving specific legal questions.
Limits of this timeline and conclusion
The dates summarised here describe the general timetable in Regulation (EU) 2024/1689; they are not an opinion on an entity, system or data processing activity. Obligations may depend on the system’s classification, the organisation’s role, applicable exceptions and rules governing particular products or sectors. In addition, Commission guidance may help interpret and apply the framework, but it should not be confused with the legislation itself. In case of a discrepancy, consult the relevant legal provision and consider the full legal context.
The safest conclusion is simple: the AI Act applies in stages, and data protection remains a separate check whenever personal data is processed. A well-used timeline helps identify what to review and when; it does not allow anyone to infer, without further information, that a system is lawful, prohibited or already compliant. The next step is to connect the legal timetable with a precise description of the system, its participants and the data processing it actually performs.
The available research does not substantiate subsequent changes to the legal text that alter the general dates stated here. This guide is limited to the milestones in the cited sources and does not replace legal advice or an individual assessment. The Commission’s guidelines and FAQs provide operational context, while the Regulation published on EUR-Lex is the primary reference for checking articles, exceptions and dates.