EU AI Act Historic Timeline, Updates & Developments

Contributors

Anas Baig

Product Marketing Manager at Securiti

Syed Tatheer Kazmi

Data Privacy Analyst

CIPP/Europe

This page is designed to provide important updates and detailed information about the EU AI Act. Here, you will find the latest developments, key changes, and significant milestones related to the Act, helping you stay informed about its progress and implications.

Article 6(1) and corresponding obligations come into effect.

2nd August 2027

The entire AI Act becomes applicable, except for Article 6(1) and corresponding obligations (High-Risk AI Systems category).

2nd August 2026

Chapters III Section 4 (Notifying bodies), Chapter V (General Purpose AI Models), Chapter VII (Governance), Article 78 (Confidentiality), and Articles 99 and 100 (Penalties) become applicable, excluding Article 101 (Fines for General Purpose AI Providers).

2nd August 2025

Chapters I (General Provisions) and II (Prohibited AI Systems) come into effect.

2nd February 2025

Upcoming developments

The AI Act comes into force.

1st August

The EU AI Act officially published and scheduled to come into effect 20 days later.

12th July

The European Council officially approves the AI Act, scheduling it for publication in the EU’s Official Journal.

21st May

The EU officially passes the AI Act, following the European Council performing its final checks.

13th March

The European Artificial Intelligence Office established to facilitate the implementation of the AI Act, particularly for general-purpose AI systems.

21st February

The Internal Market and Civil Liberties Committees approves the AI Act with a vote of 71-8 (7 abstentions).

13th February

Member states unanimously adopt the AI Act.

2nd February

Euractiv’s tech editor leaks the final version of the AI Act after it was shared with the Telecom Working Party for review.

22nd January

2024

The Parliament and the Council reaches a provisional agreement on the AI Act.

9th December

The European Commission, the Council, and the European Parliament reach a political agreement on the AI Act’s text, subject to final approval.

8th December

The Council of the EU releases a document with several proposed changes to the AI Act for trialogue discussions.

10th August

The European Council Presidency updated on the progress of trilogue negotiations concerning the AI Act.

3rd August

The European Commission's Executive President for a Europe Fit for the Digital Age announces the start of trilogue negotiations on the AI Act.

15th June

The European Parliament adopts its official position on the AI Act with 499 votes in favour, 28 against, and 93 abstentions.

14th June

The Internal Market and Consumer Protection and the Civil Liberties, Justice, and Home Affairs Committees vote on the draft AI Act.

11th May

The European Parliament agrees on a draft of the AI Act.

27th April

2023

The Council of the EU approves its common position on the AI Act.

6th December

The European Commission proposes several changes to national liability rules for AI to complement the AI Act.

28th September

The Committee on Legal Affairs (JURI) at the European Parliament adopts its opinion on the AI Act.

5th September

The Czech Presidency of the EU Council shares its discussion paper on the AI Act’s main priorities.

17th June

The French Presidency of the EU Council circulates its final compromise text on the AI Act before the Czech Presidency takes over.

15th June

The deadline for political groups in the European Parliament to submit amendments to the AI Act passes, with thousands of amendments submitted.

1st June

The French Presidency releases a proposal for regulating general-purpose AI systems.

13th May

MEPs Brando Benifei and Dragoș Tudorache publish their draft report on the AI Act.

20th April

The European Parliament adopts its position on the AI Act. The amendments include restricting AI usage for social scoring and remote biometric identification.

7th March

The Committee on Industry, Research, and Energy publishes its draft opinion on the AI Act.

3rd March

The Committee on Legal Affairs (JURI) publishes its amendments on the AI Act.

2nd March

The French Presidency of the Council circulates two compromise texts on user and provider obligations for high-risk AI systems. Another such text on harmonised standards, conformity assessments, and transparency obligations of certain AI systems was also shared.

3rd February

The European Commission presents a new Standardisation Strategy for the single market and global competitiveness.

2nd February

The lead committees of the European Parliament hold their first joint discussion on the AI Act proposal.

25th January

2022

The European Parliament’s internal market and civil liberties committees begin leading negotiations on the AI Act.

1st December

The EU Council’s rotating presidency shares a first compromise text on the AI Act with significant changes.

29th November

The European Parliament's Committee on Internal Market and Consumer Protection adopts a report on the AI Act, advocating a ban on biometric data for surveillance.

21st September

A study on biometric techniques from an ethical and legal perspective, commissioned by the European Parliament Policy Department for Citizens' Rights and Constitutional Affairs, is published.

6th August

The European Parliament Policy Department for Citizens’ Rights and Constitutional Affairs commissions and publishes a study on biometric techniques from an ethical and legal perspective.

6th August

The Slovenian EU Council Presidency hosts a virtual conference on AI regulation, ethics, and fundamental rights.

20th July

The European Parliament's Committee on Legal Affairs adopts a report endorsing stronger safeguards against mass surveillance and discrimination within AI.

1st June

The European Commission proposes a regulation of artificial intelligence in the EU.

21st April

2021

Join Our Newsletter

Get all the latest information, law updates and more delivered to your inbox


Share

More Stories that May Interest You
Videos
View More
Rehan Jalil, Veeam on Agent Commander : theCUBE + NYSE Wired: Cyber Security Leaders
Following Veeam’s acquisition of Securiti, the launch of Agent Commander marks an important step toward helping enterprises adopt AI agents with greater confidence. In...
View More
Mitigating OWASP Top 10 for LLM Applications 2025
Generative AI (GenAI) has transformed how enterprises operate, scale, and grow. There’s an AI application for every purpose, from increasing employee productivity to streamlining...
View More
Top 6 DSPM Use Cases
With the advent of Generative AI (GenAI), data has become more dynamic. New data is generated faster than ever, transmitted to various systems, applications,...
View More
Colorado Privacy Act (CPA)
What is the Colorado Privacy Act? The CPA is a comprehensive privacy law signed on July 7, 2021. It established new standards for personal...
View More
Securiti for Copilot in SaaS
Accelerate Copilot Adoption Securely & Confidently Organizations are eager to adopt Microsoft 365 Copilot for increased productivity and efficiency. However, security concerns like data...
View More
Top 10 Considerations for Safely Using Unstructured Data with GenAI
A staggering 90% of an organization's data is unstructured. This data is rapidly being used to fuel GenAI applications like chatbots and AI search....
View More
Gencore AI: Building Safe, Enterprise-grade AI Systems in Minutes
As enterprises adopt generative AI, data and AI teams face numerous hurdles: securely connecting unstructured and structured data sources, maintaining proper controls and governance,...
View More
Navigating CPRA: Key Insights for Businesses
What is CPRA? The California Privacy Rights Act (CPRA) is California's state legislation aimed at protecting residents' digital privacy. It became effective on January...
View More
Navigating the Shift: Transitioning to PCI DSS v4.0
What is PCI DSS? PCI DSS (Payment Card Industry Data Security Standard) is a set of security standards to ensure safe processing, storage, and...
View More
Securing Data+AI : Playbook for Trust, Risk, and Security Management (TRiSM)
AI's growing security risks have 48% of global CISOs alarmed. Join this keynote to learn about a practical playbook for enabling AI Trust, Risk,...

Spotlight Talks

Spotlight 59:11
Data Controls for AI: Findings from the 2026 GigaOm DSPM Research
Watch Now View
Spotlight 1:02:06
Consent by proxy: When AI agents start deciding for us
Watch Now View
Spotlight 1:00:41
Future-Proofing for the Privacy Professional
Watch Now View
Spotlight 50:52
From Data to Deployment: Safeguarding Enterprise AI with Security and Governance
Watch Now View
Spotlight 11:29
Not Hype — Dye & Durham’s Analytics Head Shows What AI at Work Really Looks Like
Not Hype — Dye & Durham’s Analytics Head Shows What AI at Work Really Looks Like
Watch Now View
Spotlight 11:18
Rewiring Real Estate Finance — How Walker & Dunlop Is Giving Its $135B Portfolio a Data-First Refresh
Watch Now View
Spotlight
Choosing the Right DSPM: An Industry Analyst’s Perspective
Watch Now View
Spotlight 13:38
Accelerating Miracles — How Sanofi is Embedding AI to Significantly Reduce Drug Development Timelines
Sanofi Thumbnail
Watch Now View
Spotlight 10:35
There’s Been a Material Shift in the Data Center of Gravity
Watch Now View
Spotlight 14:21
AI Governance Is Much More than Technology Risk Mitigation
AI Governance Is Much More than Technology Risk Mitigation
Watch Now View
Latest
Australia’s Office of AI: Why Annual Audits Miss What Your AI Can Reach View More
Australia’s Office of AI: Why Annual Audits Miss What Your AI Can Reach
Picture this: a fictional but entirely plausible scenario. An Australian financial institution's AI systems spend six months accessing a customer data repository nobody has...
View More
A Complete DSPM Needs Classification and Context
Classification is one of the core functions a DSPM program handles, and it usually runs in tandem with discovery, since together they form the...
View More
What Is Enterprise AI Security? A Beginner’s Guide
Learn what enterprise AI security is, why it matters, the key risks organizations face, and how to protect AI systems, agents, models, data, and...
View More
What is Data Transparency? Why it Matters for the Modern Enterprise
Learn what data transparency is, why it matters, and how organizations can improve visibility, accountability, governance, trust, and responsible data use.
View More
Privacy RFP Buyer’s Guide: 120+ Questions to Evaluate Privacy Automation Platforms
Download the Privacy RFP Buyer’s Guide with 120+ practical questions to evaluate privacy automation platforms across compliance, security, integrations, governance, and scalability.
View More
Green-Light AI, Not Data Exposure
Learn the five critical data-layer controls enterprises need to prevent sensitive data exposure and enable secure, scalable AI agent adoption.
The Toxic Combination Problem in DataAI Risks View More
The Toxic Combination Problem in DataAI Risks
Discover how siloed security alerts create hidden toxic risk combinations and how correlated context helps reduce alert fatigue and uncover compound risks faster.
The Cloud Storage Bill Nobody Reads View More
The Cloud Storage Bill Nobody Reads
Hidden cloud storage costs add up fast. Learn how redundant, obsolete, and trivial data drives unnecessary spend, expands risk, and why automated data minimization...
View More
Take the Data Risk Out of AI
Learn how to prepare enterprise data for safe Gemini Enterprise adoption with upstream governance, sensitive data discovery, and pre-index policy controls.
View More
Navigating HITRUST: A Guide to Certification
Securiti's eBook is a practical guide to HITRUST certification, covering everything from choosing i1 vs r2 and scope systems to managing CAPs & planning...
What's
New