# Entry Into Force — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/entry-into-force-application-timeline
> Sources are cited per item. Verify against the official texts before relying on them.

This new topic is needed to specifically address the temporal aspects of when the AI Act and its various provisions enter into force and become applicable to different actors and systems.

## Overview

## Legal Framework

Article 113 of the AI Act establishes a staggered entry-into-force regime that creates distinct compliance deadlines for different categories of obligations. The regulation enters into force on the twentieth day following publication in the Official Journal of the European Union, but its substantive provisions become applicable on a phased schedule. Chapters I (General Provisions) and II (Prohibited AI Practices) apply from February 2, 2025. Chapter III Section 4 (Notifying Authorities), Chapter V (Governance), Chapter VII (Post-Market Monitoring), Chapter XII (Codes of Conduct), and Article 78 apply from August 2, 2025, with the exception of Article 101. The core classification obligation under Article 6(1) and its corresponding requirements apply from August 2, 2027. The general applicability date for remaining provisions is August 2, 2026.

This phased approach mirrors the GDPR model under Article 99, where the regulation entered into force on May 25, 2016, but became applicable two years later on May 25, 2018. During that transitional period, controllers were required to bring ongoing processing operations into compliance, though consent previously obtained under the Data Protection Directive did not need to be re-obtained.

## Key Developments

Dutch case law establishes clear principles on temporal application of new legislation. The WAMCA ruling clarifies that past events are not assessed under new law when a party could not have anticipated it, but conduct initiated before entry into force that continues afterward falls within the new regime — the party is deemed to have accepted exposure by continuing the behavior. The Woo jurisprudence reinforces this: where no transitional provisions are enacted, new legislation takes immediate effect and applies to all decisions rendered after the entry-into-force date, regardless of when the underlying request was filed. Courts have consistently applied this principle — a decision dated after entry into force is governed by the new legal framework even if the procedural history predates it.

The absence of transitional law means organizations cannot rely on pending procedures or pre-existing arrangements to defer compliance with newly applicable provisions.

## Practical Guidance

- **Map obligations to phased deadlines immediately**: Identify which AI Act provisions govern your systems and categorize compliance work against the three key dates — February 2, 2025 (prohibited practices), August 2, 2025 (governance and post-market monitoring), and August 2, 2026 (general applicability), with high-risk classification obligations under Article 6(1) extending to August 2, 2027.

- **Audit ongoing conduct against the continuation principle**: Under the WAMCA standard, AI systems deployed before a relevant entry-into-force date but continuing in operation afterward will be subject to the new regime. Document when each system was placed on the market and whether it remains in use.

- **Prepare for immediate application without transitional relief**: The Woo cases confirm that absent transitional provisions, new law applies to all decisions and actions taken after the applicability date. Do not assume pending assessments or pre-existing compliance frameworks will grandfather your operations.

- **Use the pre-applicability period substantively**: Following the GDPR model, the period between entry into force and applicability is intended for operational alignment, not mere awareness. Begin gap assessments, documentation, and governance restructuring now.

- **Reassess consent and lawful bases**: Where AI systems process personal data, verify that existing consent obtained under prior legal frameworks remains valid under current GDPR standards, as re-obtaining consent is not automatically required but adequacy must be confirmed.

## Legislation (full text of key provisions)

### Entry into force and application

*Source: AI Act, aiact-art-113-en, 2024-06-12 — https://overview.legal/posts/93679*

This Regulation shall enter into force on the twentieth day following that of its publication in the Official Journal of the European Union. It shall apply from 2 August 2026. However:

### Recital 95 — post remote biometric identification safeguards

*Source: AI Act, aiact-rec-95-en, 2024-06-12 — https://overview.legal/posts/93872*

Without prejudice to applicable Union law, in particular Regulation (EU) 2016/679 and Directive (EU) 2016/680, considering the intrusive nature of post-remote biometric identification systems, the use of post-remote biometric identification systems should be subject to safeguards. Post-remote biometric identification systems should always be used in a way that is proportionate, legitimate and strictly necessary, and thus targeted, in terms of the individuals to be identified, the location, temporal scope and based on a closed data set of legally acquired video footage. In any case, post-remote biometric identification systems should not be used in the framework of law enforcement to lead to indiscriminate surveillance. The conditions for post-remote biometric identification should in any case not provide a basis to circumvent the conditions of the prohibition and strict exceptions for real time remote biometric identification.

### Recital 178 — voluntary early compliance high-risk AI providers

*Source: AI Act, aiact-rec-178-en, 2024-06-12 — https://overview.legal/posts/94038*

Providers of high-risk AI systems are encouraged to start to comply, on a voluntary basis, with the relevant obligations of this Regulation already during the transitional period.

### Recital 179 — regulation phased application dates

*Source: AI Act, aiact-rec-179-en, 2024-06-12 — https://overview.legal/posts/94040*

This Regulation should apply from 2 August 2026. However, taking into account the unacceptable risk associated with the use of AI in certain ways, the prohibitions as well as the general provisions of this Regulation should already apply from 2 February 2025. While the full effect of those prohibitions follows with the establishment of the governance and enforcement of this Regulation, anticipating the application of the prohibitions is important to take account of unacceptable risks and to have an effect on other procedures, such as in civil law. Moreover, the infrastructure related to the governance and the conformity assessment system should be operational before 2 August 2026, therefore the provisions on notified bodies and governance structure should apply from 2 August 2025. Given the rapid pace of technological advancements and adoption of general-purpose AI models, obligations for providers of general-purpose AI models should apply from 2 August 2025. Codes of practice should be ready by 2 May 2025 in view of enabling providers to demonstrate compliance on time. The AI Office should ensure that classification rules and procedures are up to date in light of technological developments. In addition, Member States should lay down and notify to the Commission the rules on penalties, including administrative fines, and ensure that they are properly and effectively implemented by the date of application of this Regulation. Therefore the provisions on penalties should apply from 2 August 2025.

### Recital 111 — systemic risk classification methodology for general-purpose AI models

*Source: AI Act, aiact-rec-111-en, 2024-06-12 — https://overview.legal/posts/93904*

It is appropriate to establish a methodology for the classification of general-purpose AI models as general-purpose AI model with systemic risks. Since systemic risks result from particularly high capabilities, a general-purpose AI model should be considered to present systemic risks if it has high-impact capabilities, evaluated on the basis of appropriate technical tools and methodologies, or significant impact on the internal market due to its reach. High-impact capabilities in general-purpose AI models means capabilities that match or exceed the capabilities recorded in the most advanced general-purpose AI models. The full range of capabilities in a model could be better understood after its placing on the market or when deployers interact with the model. According to the state of the art at the time of entry into force of this Regulation, the cumulative amount of computation used for the training of the general-purpose AI model measured in floating point operations is one of the relevant approximations for model capabilities. The cumulative amount of computation used for training includes the computation used across the activities and methods that are intended to enhance the capabilities of the model prior to deployment, such as pre-training, synthetic data generation and fine-tuning. Therefore, an initial threshold of floating point operations should be set, which, if met by a general-purpose AI model, leads to a presumption that the model is a general-purpose AI model with systemic risks. This threshold should be adjusted over time to reflect technological and industrial changes, such as algorithmic improvements or increased hardware efficiency, and should be supplemented with benchmarks and indicators for model capability. To inform this, the AI Office should engage with the scientific community, industry, civil society and other experts. Thresholds, as well as tools and benchmarks for the assessment of high-impact capabilities, should be strong predictors of generality, its capabilities and associated systemic risk of general-purpose AI models, and could take into account the way the model will be placed on the market or the number of users it may affect. To complement this system, there should be a possibility for the Commission to take individual decisions designating a general-purpose AI model as a general-purpose AI model with systemic risk if it is found that such model has capabilities or an impact equivalent to those captured by the set threshold. That decision should be taken on the basis of an overall assessment of the criteria for the designation of a general-purpose AI model with systemic risk set out in an annex to this Regulation, such as quality or size of the training data set, number of business and end users, its input and output modalities, its level of autonomy and scalability, or the tools it has access to. Upon a reasoned request of a provider whose model has been designated as a general-purpose AI model with systemic risk, the Commission should take the request into account and may decide to reassess whether the general-purpose AI model can still be considered to present systemic risks.

## Guidance

### Statement 3/2024 on data protection authorities’ role in the Artificial Intelligence Act framework

*Source: EDPB, statement-32024-on-data-protection-authorities-role-in-the-en, 2024-07-16 — https://overview.legal/posts/125732 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/statement-32024-on-data-protection-authorities-role-in-the_en*

Final 1 Statement 3/2024 on data protection authorities’ role in the Artificial Intelligence Act framework Adopted on 16 July 2024 The European Data Protection Board has adopted the following statement: 1 BACKGROUND AND PURPO SE OF THIS STATEMENT 1. On 12 July 2024, Regulation (EU) 2024/1689 laying down harmonised rules on a rtificial i ntelligence (Artificial Intelligence Act, hereinafter the “ AI Act ”) and amending certain Union Legislative Acts was published in the Official Journal 1 . 2.…

### Report on stakeholder event on processing of personal data to target or deliver political advertisements

*Source: EDPB, report-on-stakeholder-event-on-processing-of-personal-data-en, 2026-03-27 — https://overview.legal/posts/125684 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/report-on-stakeholder-event-on-processing-of-personal-data_en*

Report on stakeholder event on processing of personal data to target or deliver political advertisements 27 March 2026 1. Background The EDPB organised an online stakeholder event on 27 March 2026 to collect stakeholders’ input on processing of personal data to target or deliver political advertisements. The objective was to engage with stakeholders at an early stage of drafting the EDPB Guidelines on the processing of personal data to target or deliver political advertisements (Chapter III of…

### Contribution of the EDPB to the European Commission’s evaluation of the Data Protection Law Enforcement Directive (LED) under Article 62

*Source: EDPB, contribution-of-the-edpb-to-the-european-commissions-en, 2021-12-14 — https://overview.legal/posts/125973 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/contribution-of-the-edpb-to-the-european-commissions_en*

Adopted Contribution of the EDPB to the European Commission’s evaluation of the Data Protection Law Enforcement Directive ( LED ) under Article 62 Adopted on 14 December 2021 2 3 The European Data Protection Board Having regard to Articles 51(1)(a)(b) and (h) of the Directive ( EU ) 2016/680 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal da ta by competent authorities for the purposes of the…

## Enforcement decisions

### EDPS finds Commission infringed purpose limitation and data transfer rules in Microsoft

*Source: EDPS, 2024-03-08 — https://overview.legal/posts/125645 — original: https://gdprhub.eu/index.php?title=EDPS_-_2021-0518*

Facts — Following an investigation in 2019-2020, the EDPS issued recommendations and the Commission modified the ILA. The EDPS investigated whether these modifications were sufficient to bring processing in compliance with data protection requirements and found infringements. Data accessed by Microsoft include identity and contact data of users (when signing on to the service and when checking the licenses), data generated by the users while using the software and data generated by Microsoft based on the usage of the software. The EDPS found that the processing presents significant risks as it monitors the behaviour of users, combines datasets and uses artificial intelligence. Reference date is the 12th May 2021, the date when the investigation was launched. Some measures were taken meanwhile by the Commission, which were taken into account in the recommendations issued. Holding — The EDPS found infringements with regards to purpose limitation, transfers to a third country and further, unathorised disclosure of personal data. Purpose limitation: The EDPS found that it was not sufficiently defined in the International License Agreement (ILA) which types of personal data are to be processed for which purposes. Instead, there was only a list of purposes stating that Microsoft uses these data for: troubleshooting billing remunerating Microsoft staff, internal reporting and business modelling, financial reporting following the use of the system for own reasons (analytics) to improve the service security risk management protection of intellectual property These stated purposes were considered to be too vague and general pursuant to the Art 29 WP. The Commission and Microsoft could not demonstrate that all these data were necessary and that a less intrusive collection of data would be insufficient to achieve the purposes cited. In addition, some of these purposes were actually not in the interest of the Commission but for purposes of individual to Microsoft (like remuneration of their personnel). In this case, the processor acts as controller; thus, these purposes and the data used for this purposes should have been precisely defined. Also, if data were used for purposes other than for which they were collected, the compatibility of these new purposes with the original ones should have been assessed. As a processor, Microsoft should have processed the personal data on documented instructions by the Commission. This was not ensured as the Commission did not issue sufficiently clear documented instructions to Microsoft. For example, though the Commission gave instructions for analytics and improvement of the service, these instructions were not sufficiently detailed and precise and did not exclusively concern uses of data for the purposes of the controller. Some instructions were given orally, but this was not enabled by the ILA and the oral instructions were not documented. The Commission did not assess whether it is necessary and proportionate to transmit data to Microsoft Ireland and its sub-processors. Further details of this infringement are given under the part on further unauthorised disclosure or personal data. Transfer to third countries : The Commission transferred personal data to Microsoft, a company established in the US. This raises questions about adequacy for such transfers to a third country. After the reference date, the Commission adopted the Transatlantic Data Privacy Framework (TDPF), which is an adequacy decision in respect of recipients in the US who register under this framework. The EDPS found that even when the software and data storage is property of Microsoft, it is directly transferred to these subcontractors and cannot therefore be covered by the TDPF to Microsoft US and onward transfer from Microsoft US to other subcontractors under SCCs. The EDPS found that in was not clearly specified in the ILA what types of personal data can be transferred to which recipients in which third country. The Commission also did not appraise the transfers and therefore could not determine whether any supplementary measures are necessary. In addition, the Commission should have performed a data transfer impact assessment and (as there are no SCCs applicable by EUIs as exporters) should have submitted the DPAs with these processors or subprocessors in third countries to the EDPS for approval. Because it failed to do this, the Commission did not implement effective supplementary measures for these transfers. Another issue was that the “EU storage guarantee” offered by Microsoft did not cover all types of data. Some data may be accessible to recipients in third countries. The “EU Data Boundary” also has numerous exceptions and exclusions which cover customer data, service generated data, diagnostic data and professional services data. Further unauthorised disclosure or personal data: A specific reference was made to Article 9 Regulation (EU) 2018/1725, which concerns transmission of personal data by EU institutions to recipients established in the EU. According to the EDPS, this article is also applicable to transmission of personal data to processors of EUIs. Therefore all transmission of personal data should be in the public interest and if the data subject’s legitimate interests may be prejudiced, the controller has to weigh the competing interests and establish that it is proportionate to transmit the personal data. The purpose of management and functioning of the Commission, use of products the staff is familiar with etc. was not found to be the purpose of processing of the personal data by MS. As long as the purposes are not specified, specific and explicit, it is not possible to do this balancing. In addition, the EDPS found that the Commission did not ensure that transfers take place “solely to allow tasks within the competence of the controller to be carried out”. The EDPS determined that organisational and contractual measures to restrict/prevent access of third country authorities were not sufficient, and that further technical measures are thus necessary. The EDPS also found that the organisational measures applied are only limiting transfers but does not ensure that transfers are protected. Further, the encryption is only found to be an adequate measure if the controller is in control of the encryption key. In this case, customers control the keys, but Microsoft has access to the encryption key, and thus, even when law does not oblige it to decrypt the data on an authority request, it may do it voluntarily. Also, the ILA does not detail encryption of data other than “customer data”, i.e. diagnostic data, service generated data or professional services data. The contract also enabled the processor not to notify the Commission about a request of disclosure also when EU or Member State law did not prohibit this notification and enabled recipients in third countries not to notify requests for disclosure also when the law prohibiting it did not constitute a necessary and proportionate measure in a democratic society respecting the essence of the fundamental rights and freedoms recognised by the Charter.

## Recent developments

### The 2022 annual report of the CNIL

*Source: CNIL, 2023-05-23 — https://overview.legal/posts/6201 — original: https://www.cnil.fr/en/2022-annual-report-cnil#entry-5292*

The publication of its activity report enables the CNIL to report on its actions with regard to its four major missions: inform and protect the general public, accompany and advise professionals and public authorities, anticipate and innovate to build the digital of tomorrow, and finally monitor and sanction breaches of the General Data Protection Regulation (GDPR) and the French law.
 



 


Download the 2022 annual report (in French)
Informing and protecting
The actions carried out this year

## Literature

### Italy’s Artificial Intelligence Act and Global AI Governance: The EU Model’s Practice and Prospects

*Source: Law and Economy, 2026-02-25 — https://overview.legal/posts/132619 — original: https://doi.org/10.63593/le.2788-7049.2026.03.004*

The Italian Artificial Intelligence Act, enacted on September 17, 2025, represents the first comprehensive national implementation of the European Union’s AI Act. This study examines the Italian legislation through the theoretical lens of multi-level governance, analyzing its dual function as both a “bridging legislation” that translates EU framework into domestic practice and a site of significant regulatory innovation. Through detailed textual analysis and case studies, particularly in healthc

### Use of Artificial Intelligence Tools by Law Enforcement Services in Light of the Artificial Intelligence Act

*Source: Zeszyt Prawniczy UAM, 2025-12-22 — https://overview.legal/posts/132565 — original: https://doi.org/10.14746/zpuam.2025.15.4*

Celem artykułu jest wskazanie przestępstw, w przypadku których służby państwowe mogą korzystać z systemów zdalnej identyfikacji biometrycznej w czasie rzeczywistym w przestrzeni publicznej. Zostanie to uczynione przez analizę przesłanek umożliwiających posługiwanie się tą technologią oraz przyrównanie ich do czynów zabronionych przez polski kodeks karny. Rezultatem powyższego jest stworzenie katalogu przestępstw, odnośnie do których służby mogą zastosować system zdalnej identyfikacji biometryczn

### A Comparative Analysis of the EU AI Act and the Colorado AI Act: Regulatory Approaches to Artificial Intelligence Governance

*Source: International Journal of Computer Applications, 2024-09-26 — https://overview.legal/posts/132613 — original: https://doi.org/10.5120/ijca2024923954*

International Journal of Computer Applications (0975 – 8887) Volume 186 – No. 38 , September 2024 23 A Comparative Analysis of the EU AI Act and the Colorado AI Act: Regulatory Approaches to Artificial Intelligence Governance Mayur Jariwala School of Computer and Information Sciences, University of the Cumberlands, Williamsburg, KY, USA ABSTRACT This comparative study examines the EU AI Act and the Colorado AI Act, focusing on their regulatory approaches to artificial intelligence. The EU AI Act provides a comprehensive framework with a risk - based classification, emphasizing transparency, accountability, and the protection of fundamental rights across diverse sectors. It aims to set a global benchmark for AI governance, influencing international standards. The Colorado AI Act targets high - risk AI systems, prioritizing consumer protection, fairness, and the prevention of algorithmic discrimination. It mandates detailed documentation, ri sk management, and transparency measures to ensure ethical AI deployment. This analysis explores the impacts of each act on innovation, industry practices, and consumer protection, as well as their potential global influence. The findings highlig

## Related topics

- **Artificial Intelligence** — https://overview.legal/topics/ai
  AI systems and their implications for data protection
- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons
- **Supervision** — https://overview.legal/topics/toezicht
  Oversight and enforcement by supervisory authorities
- **AI Value Chain Actors and Roles** — https://overview.legal/topics/ai-value-chain-actors
  The content focuses on responsibilities distributed across different actors in the AI value chain. A dedicated topic for understanding the various actors, their
- **Monitoring** — https://overview.legal/topics/monitoring
  Systematic observation and tracking of individuals
- **Public Authority** — https://overview.legal/topics/overheid
  Government bodies and their data processing activities

---
Generated by overview.legal · https://overview.legal/topics/entry-into-force-application-timeline · 2026-08-22
