Europe's artificial intelligence rulebook does not arrive in one stroke. It phases in over four years, with obligations landing on providers, deployers and regulators at different moments between August 2024 and August 2028. For any business building or using AI systems - including those in gaming, betting and financial services, where automated decision-making already shapes credit checks, fraud detection, personalisation and risk profiling - this staggered rollout is the practical roadmap that determines when compliance work becomes mandatory rather than optional.
A calendar built for gradual compliance
The AI Act entered into force on 1 August 2024, but most substantive duties were deferred. From 2 February 2025, the general provisions took hold: definitions, AI literacy requirements and, notably, an outright ban on certain uses judged unacceptable, such as manipulative or exploitative AI systems. Six months later, on 2 August 2025, the rules for general-purpose AI models became applicable, alongside a requirement for Member States to designate national competent authorities and for EU-level bodies - the AI Board, a Scientific Panel and an Advisory Forum - to be operational. This is the point at which governance infrastructure, rather than just legal text, starts to exist.
The most consequential date so far is 2 August 2026. That is when the bulk of the Act's provisions come into force, transparency obligations under Article 50 begin applying, and enforcement formally starts at both national and EU level for prohibitions, general-purpose AI rules and literacy requirements. Businesses that treated earlier deadlines as distant will find enforcement risk becomes concrete from this point onward.
Deepfakes, synthetic content and a widening scope
From 2 December 2026, additional prohibitions take effect, specifically targeting AI systems used to generate non-consensual sexual deepfakes and child sexual abuse material. This matters well beyond any single sector: synthetic media generation touches marketing, entertainment platforms and advertising ecosystems, including those adjacent to online gaming and betting, where AI-generated promotional content or personalised marketing material is increasingly common. The same date introduces a transitional deadline for providers of AI systems - including general-purpose AI systems - that generate synthetic content and were already on the market before August 2026, giving them time to align with Article 50(2)'s labelling and disclosure requirements.
A further practical milestone falls on 2 August 2027: every Member State should have at least one AI regulatory sandbox operating, giving smaller providers a controlled environment to test compliance before full enforcement bites.
High-risk systems: the final and most demanding phase
The rules with the greatest bearing on consumer-facing sectors arrive last. From 2 December 2027, obligations for high-risk AI systems listed in Annex III become applicable - a category covering uses such as biometric identification, credit scoring, employment screening and other decisions with significant impact on individuals' rights or access to services. Systems used for player risk profiling or automated affordability checks in regulated gambling markets could fall within adjacent scrutiny, depending on how national regulators interpret overlapping obligations. Finally, by 2 August 2028, rules for high-risk AI embedded in regulated products covered by Annex I - think medical devices, machinery and other product-safety regimes - complete the rollout.
Several of these later-stage provisions have been amended through the Digital Omnibus on AI, reflecting Brussels' recognition that a single rigid timeline risked outpacing the practical readiness of both regulators and industry. For operators in data-intensive, consumer-facing sectors, the lesson is straightforward: compliance planning cannot wait for the final deadline. Governance structures, documentation and risk classification work need to begin well before enforcement actually starts.