AI + Deadlines

AI compliance deadlines: the EU Act, the UK, the US and Australia

Huceptron InsightsBy the Huceptron senior partners·5 min read

The AI Act does not arrive on one day. It arrives in stages across four years, and two of those stages are already behind us. The confusion in the market comes almost entirely from people reading a 2027 headline and concluding that nothing applies yet.

Things apply. Here is the calendar, and what each date actually turns on.

2 February 2025 - prohibitions, already in force

The banned practices took effect first. Social scoring by public authorities, exploitation of the vulnerabilities of specific groups, untargeted scraping of facial images to build recognition databases, and emotion inference in workplaces and educational settings outside narrow safety and medical exceptions.

There is no grace period left on these and no risk tier to assess. They are simply not allowed.

2 August 2025 - general-purpose AI models

Obligations on providers of general-purpose AI models began. For most Irish companies this is somebody else's duty - you are using the models, not placing them on the market - but it matters when you are choosing a vendor, because their documentation is what you will rely on.

2 August 2026 - transparency, and most of the rest

The date that quietly caught a lot of ordinary businesses. Article 50 transparency obligations began: people must be able to know when they are interacting with an AI system, and synthetic content must be marked in a machine-readable way.

If you run a support chatbot, generate marketing images, or publish AI-assisted text on matters of public interest, this one is yours and it started over a year ago. We have written about what it requires in practice.

One narrow easement: for systems already on the market before 2 August 2026, the machine-readable marking requirement runs to 2 December 2026.

2 December 2027 - high-risk systems in Annex III

This is the date that moved, and the movement is why so many people think the whole Act was delayed. It was not. The Annex III high-risk obligations - recruitment and worker management, education, credit and essential services, biometrics, law enforcement - were deferred to 2 December 2027 by the AI Digital Omnibus.

If you screen CVs with AI, this is your date. It sounds distant. It is one budget cycle away, and the work it implies - risk management system, data governance, logging, human oversight, technical documentation - is not a quarter's work.

2 August 2028 - high-risk embedded in regulated products

AI that is a safety component of a product already covered by EU product legislation - machinery, medical devices, lifts, toys. Deferred to 2 August 2028, on the sensible logic that these products already run long conformity cycles.

The UK, the United States and Australia: the dates that matter

None of these three has an AI act. All three have dates.

United Kingdom. 5 February 2026 - UK GDPR Articles 22A to 22D replaced Article 22 under the Data (Use and Access) Act 2025, removing the blanket ban on solely automated significant decisions and replacing it with a safeguards duty. 12 May 2026 - the ICO came under a statutory duty to produce a code of practice on AI and automated decision-making; the code itself has not been drafted, so expect it to land in 2027 or later. Beyond that there is no scheduled UK AI legislation. The May 2026 King’s Speech contained no AI bill.

United States. 1 January 2026 - Texas TRAIGA, California SB 53 on frontier models, California AB 2013 on training-data transparency, California SB 243 on companion chatbots, and Illinois HB 3773 on AI in employment all took effect on the same day. 2 August 2026 - California SB 942 content-provenance duties became operative. 1 January 2027 - Colorado’s replacement AI Act and New York’s RAISE Act. 1 January 2028 - the first mandatory independent third-party audits of large frontier developers under the Illinois AI Safety Measures Act, signed in July 2026. And running throughout, since July 2023: New York City’s annual bias audit for automated employment decision tools.

Australia. 15 June 2026 and December 2026 - mandatory requirements phase in under the Commonwealth policy for the responsible use of AI in government, including use-case registers and pre-deployment impact assessments. That is a public sector obligation, but it reaches suppliers through procurement. 30 November 2026 - the Joint Select Committee on AI reports. 10 December 2026 - Privacy Act APP 1.7 to 1.9 require privacy policies to disclose automated decision-making that could reasonably be expected to significantly affect a person. Early 2027 - mandatory Australian Standards for AI are expected to be introduced.

Put the three calendars beside the EU one and the shape is clear. The EU dates are the hard edges, because they attach penalties to named articles. The others are commencements of transparency and governance duties that assume you already know which of your systems make decisions about people. If you do not have that list, every one of these dates arrives as a surprise. We work to all four calendars, with representation in the United Kingdom, the United States and Australia.

What an Irish company should do with this calendar

Work backwards from December 2027, but do not start there. Start with what is already in force, because that is where exposure exists today rather than in eighteen months.

In order: confirm you are running nothing prohibited. Check whether Article 50 touches anything customer-facing. Establish AI literacy measures, which apply to everyone now. Then, and only then, work out whether anything you run falls into Annex III - and if it does, you have a genuine programme ahead of you and roughly a year to do it calmly.

The companies that will struggle in 2027 are the ones who read "December 2027" in 2026 and filed it.

One week. Then you know.
The AI audit week - what applies to you, where the gaps are, and what to do first
See what the week covers →