First prohibitions and general-purpose AI obligations

The first concrete obligations take effect six months after the regulation enters into force, on 2 February 2025. On that date the prohibitions on unacceptable AI practices become binding. These practices are considered a clear threat to safety and fundamental rights. They include government social-scoring systems, categorisation of people based on sensitive data without their knowledge, and emotion recognition in workplaces and schools. At the same time, providers of general-purpose AI models (GPAI) must begin maintaining technical documentation and publishing summaries of the data used to train their models.

High-risk systems and earlier exceptions

The main part of the regulation covering high-risk systems, such as applications in critical infrastructure, education or recruitment, applies after 36 months, on 2 August 2027. By that date companies must ensure their systems meet requirements on data quality, transparency, human oversight and cybersecurity. Two important exceptions have earlier deadlines. First, AI systems that are already part of regulated products, for example medical devices or avionics, fall under the AI Act from 2 August 2026. Second, tools for identification and categorisation of biometric data must also comply from August 2026.

Preparation guidance from CIAD audits

Although the main deadlines lie in the future, organisations should start preparation immediately because auditing and adapting systems is time-consuming. The first step is an inventory of all AI tools in use and their assignment to the risk categories defined by the European framework. A gap analysis must then reveal the differences between the current state and the regulation’s requirements. In practice, sufficient documentation on data provenance or algorithmic decision-making processes is often missing. Audits by the Czech Institute for AI and Data (CIAD) regularly confirm that companies which began mapping their systems a year in advance manage implementation without halting operations or facing last-minute crises.

Implications for organisations

For most companies there is no need to change operations immediately, but launching the preparation phase now is critical. If your organisation develops or deploys tools for employee selection, creditworthiness assessment or traffic management, you must plan for a full conformity process by August 2027. For systems using biometrics or those embedded in medical devices, the time reserve extends only to August 2026, which demands an immediate start on compliance work.

Frequently asked questions

Does the AI Act already apply in 2024?

The Regulation formally entered into force in August 2024, but most specific obligations for companies do not yet apply. Currently only deadlines for adopting implementing acts and codes of conduct are running, while the first real bans and obligations will not take effect until February 2025.

When must I comply with the rules for chatbots and large language models?

Obligations for providers of general-purpose AI models, which include large language models and content generators, took effect on 2 February 2025. From this date you must have technical documentation ready and inform users that they are interacting with a machine.

What happens if my system does not meet the requirements by 2027?

If you do not have your high-risk system in compliance with the Regulation after the transitional period expires, you face high fines and a ban on placing the product on the European market. Until then you have time to modify, certify and complete missing documentation according to the established standards.