
The EU AI Act phases in over three years. Prohibitions and AI-literacy duties applied from 2 February 2025, general-purpose AI obligations from 2 August 2025, most high-risk system obligations arrive on 2 August 2026, and high-risk AI embedded in regulated products follows on 2 August 2027. This page tracks each wave and who it catches.
What applied in 2025?
Two waves are already in force. On 2 February 2025 the Act's prohibitions took effect, along with AI-literacy duties for organisations whose staff operate AI systems. On 2 August 2025 the obligations for general-purpose AI (GPAI) models followed.
For a Singapore company the 2025 waves matter in two ways. If you build on top of a general-purpose model, your upstream provider has been under GPAI obligations since August 2025, which changes what documentation you can demand from them. And the prohibitions apply to anyone in scope from day one; no risk-tiering softens that wave.
The AI-literacy duty is the sleeper of the February wave. It asks organisations to make sure the people operating AI systems understand enough to use them properly, which in practice means training records for staff who run AI-facing processes. Cheap to do, awkward to backfill.
Whether you are caught at all is a separate question, the Article 2 scope test, which our companion piece AI·07 walks through. This page assumes you have done that analysis and are now tracking dates.
If neither 2025 wave touched you, good. The next one is bigger, and it is the one Singapore software exporters are most likely to meet.
What lands on 2 August 2026?
The heavy wave. From 2 August 2026 the obligations for most high-risk systems, the ones listed in Annex III of the Act, apply, together with the transparency rules. This is the deadline that drives real engineering and documentation work: if a system you place on the EU market sits in an Annex III category, the compliance regime attached to it starts now, not at some comfortable future date.
What the high-risk regime asks for is the familiar governance stack: a risk management system, technical documentation, human oversight arrangements and conformity assessment before the system reaches the market. None of it is exotic. All of it takes longer than the quarter most teams budget, because the documentation has to describe the system you actually built rather than the one in the launch deck.
The transparency rules in the same wave are broader and lighter. Systems that interact with people or generate content pick up disclosure duties. Lighter, but not optional, and they catch far more Singapore companies than the high-risk category does.
Transparency duties sound trivial next to conformity assessment, and that is exactly why they get missed. A high-risk programme has an owner and a budget. A disclosure line in a chatbot has neither until someone assigns it.
What lands on 2 August 2027?
The final wave covers high-risk AI embedded in products already regulated under EU product law, machinery and medical devices among them. These systems got the longest runway because they sit inside existing conformity regimes with their own certification cycles.
If you export AI-enabled physical products to the EU, 2027 is your wave, and the runway is shorter than it looks. Product certification is slow. A device maker who starts the AI conformity work in mid-2027 has already missed the date in practical terms.
The 2027 wave is also where the Act's logic shows. A chatbot can be patched next sprint; a machine on a factory floor runs for a decade, so embedded AI got more time because the certification and recall economics of physical products are slower and costlier at every step. Component suppliers feel the wave secondhand: the product manufacturer holds the obligations, then pushes documentation demands down the supply chain to whoever built the AI component.
What should a non-EU company do per wave?
| Date | What applies | What to do |
|---|---|---|
| 2 February 2025 | Prohibitions; AI-literacy duties | Confirm nothing you operate touches a prohibited practice; brief the staff who run AI systems |
| 2 August 2025 | General-purpose AI model obligations | If you build on a GPAI model, collect the provider documentation now owed to you |
| 2 August 2026 | Annex III high-risk obligations; transparency rules | Classify every EU-facing system; start conformity work for anything high-risk; add disclosure where systems interact with people |
| 2 August 2027 | High-risk AI embedded in regulated products | Fold AI conformity into the existing product certification cycle early |
Work the table right to left. Start from the latest date that applies to you and count backwards through your own release and certification cycles to find the real internal deadline. For an Annex III system needing conformity work, the internal start date implied by 2 August 2026 was some time in 2025; for embedded products, the equivalent arithmetic for 2027 is worth doing this quarter.
Commission guidance keeps arriving between the waves, and some of it changes how the obligations read in practice. The 2025 waves arrived with interpretive guidance still maturing; expect the same around the 2026 wave. Treat the table as a living document; this page gets refreshed as guidance drops.
One habit is worth building regardless of wave: a written classification for each EU-facing system, dated, with the reasoning attached. Deadlines punish the undocumented far more than the merely late.
Zavior tracks each AI system in your inventory against the wave that catches it, so a 2027 obligation does not surface for the first time in a 2027 customer audit.
Frequently asked questions
Have the deadlines slipped?
The dates sit in the Regulation itself, not in guidance, so moving any of them takes an amendment to EU law rather than an administrative announcement. Check the Official Journal for the current text before relying on a date in this table.
What is a GPAI model?
A general-purpose AI model is trained for broad capability and usable across many different tasks; the large language models behind most commercial AI tools are the obvious members of the category. Obligations for GPAI models have applied since 2 August 2025.
Which fines attach to which wave?
The steepest penalties attach to the prohibited practices in force since February 2025; our companion piece AI·07 covers that ceiling of €35 million or 7% of global turnover. Other obligations carry lower maximum fines set out in the Regulation's own penalty article. Check the current figures there rather than assuming they scale evenly across waves.
Zavior · AI Governance
A deadline only bites once you know which of your systems it lands on. Zavior builds the inventory first, one row per AI system with its purpose and its risk classification, then maps each row to the wave that catches it, so 2 August 2026 arrives as a work plan rather than a scramble. Exporters usually find the count is smaller than feared and the classification harder than expected. Not sure the Act reaches you at all? The free AI Readiness Scan is the faster first answer.
Book a free 30-minute business assessment →This is general information, not legal advice.