
The EU AI Act, Regulation (EU) 2024/1689, published in the Official Journal on 12 July 2024, covers AI systems placed on the EU market, put into service within it, or producing outputs used inside it.
Knowing that the Act covers your use of AI is only the starting point. What it actually demands, and when those requirements apply, is where the picture becomes more complicated.
The Act does not impose one set of obligations on every AI system. Different rules can apply to the same system at the same time: the Article 5 prohibitions on unacceptable-risk practices, the Article 6 high-risk rules linked to Annexes I and III, the Article 50 transparency requirements for specific uses, and the Chapter V rules for general-purpose AI models. That becomes easier to see when you follow a system through a real use case. Take a large language model used inside a recruitment platform as an example. Depending on how it is built and deployed, the same system could fall under all four sets of rules at once. The obligations do not simply travel with the technology: the provider who built the system and the deployer who puts it into use can have different responsibilities. Buying or integrating the technology does not transfer those obligations from one party to the other.
What this means in practice is that the Act does not arrive all at once. Different obligations have come into force at different points, and some are already applying today.
The first major set of rules took effect on 2 February 2025. That includes the Article 5 prohibitions and the AI literacy requirement, as Baker McKenzie's product risk analysis confirms. The prohibited practices include social scoring by public authorities, real-time remote biometric identification in public spaces subject to narrow exceptions, and AI systems designed to exploit people's psychological vulnerabilities in ways that can distort their behaviour. Where one of these practices is involved, the prohibition applies outright. This part of the Act is already law.
The next milestone came on 2 August 2025, when the rules for general-purpose AI models began to apply. The high-risk rules come later. For most systems covered by Article 6 and Annex III — including AI used in areas such as employment, education, credit and critical infrastructure — the requirements apply from December 2027. For high-risk AI embedded in products already covered by EU product-safety legislation, the deadline extends to August 2028, according to the European Commission's regulatory framework.
The dates for 2027 and 2028 can easily give the wrong impression. They are deadlines for having the relevant requirements in place, not dates on which companies should start thinking about them.
There is a fair amount to do before then. Conformity assessments, technical documentation, human oversight arrangements and EU database registration can all take time. And one of the things companies might reasonably have expected to make that work easier is still unfinished. The harmonised standards intended to provide a clearer route to compliance were due in August 2025, but CEN and CENELEC did not meet that deadline. The standards that were meant to make compliance easier are still not finished. The European Commission's FAQ confirms that the work is still under way. In other words, waiting for the standards to be finished before starting will only leave you with less time to prepare.
There are a few boundaries worth keeping in mind, too. The Act excludes AI developed and used exclusively for military purposes or for national security. But that does not mean that anything connected to defence is automatically outside the Act. A system developed for a defence contractor but then sold commercially, for example, can fall back within its scope. The same can happen with tools that have both military and commercial uses.
Another boundary sits much closer to the technology itself. The Act does not regulate everything that happens to involve the word “AI”. Article 3(1) defines an AI system in terms of a machine-based system that infers from inputs how to generate outputs such as predictions, recommendations or decisions. A piece of automation that simply follows fixed, pre-programmed rules therefore does not meet that definition. As AI systems become more sophisticated, the line may become harder to draw. For now, though, it is an important distinction.
So where does that leave a company trying to work out what actually applies to it? A useful starting point is to look at what the company is doing with the system. Are you the provider, the deployer, or both? From there, look at the type of system and the obligations attached to it: prohibited practices, high-risk systems under Annex I or Annex III, Article 50 transparency requirements, or systems that carry no mandatory obligations under the Act. The one-page summary of the EU AI Act's structure is a useful place to map this out, while the steps due before the August deadlines go further into what that preparation actually involves.
The picture, then, is fairly straightforward. The Act is broad, but its requirements do not all arrive at once. Some are already enforceable. Others come later. The later dates give companies more time to prepare, not a reason to put the work off. By the time those deadlines arrive, the organisations that started early will be checking what remains to be done. Those that waited may be starting from the beginning.