The AI Act is often discussed as if it were one deadline. It isn't, it's a staircase. The regulation entered into force on 1 August 2024, and its obligations switch on in phases over several years. If your organisation uses AI (in AI Act terms, if you're a deployer), here is the staircase in plain language.

The phased timeline

DateWhat starts applyingWho feels it
1 Aug 2024Regulation enters into forceEveryone (clock starts)
2 Feb 2025Prohibited practices banned; AI-literacy duty (Art. 4)All providers & deployers
2 Aug 2025General-purpose AI (GPAI) model obligations; governance & penalties frameworkModel providers, primarily
2 Aug 2026The bulk of the Act, including high-risk systems (Annex III) and the Art. 50 transparency dutiesProviders & deployers broadly
2 Aug 2027High-risk rules for AI embedded in regulated products (Art. 6(1))Product manufacturers

What you should already be doing

Two obligations have applied to essentially every organisation using AI since February 2025:

  • Avoiding prohibited practices. The banned list (manipulative techniques, social scoring, most emotion recognition in workplaces, and similar) applies regardless of company size or sector.
  • AI literacy (Article 4). Staff who operate or use AI systems must have a sufficient level of AI literacy. This is a real, current obligation, and one of the easiest to evidence with a training module and a record of completion.

What lands on 2 August 2026

The big one. From this date the high-risk regime applies to Annex III use cases, think employment and HR screening, credit scoring, essential services, education, and most public-sector decision support. Deployers of high-risk systems get concrete duties: use the system per its instructions, ensure human oversight, keep logs, feed incidents back to the provider, and in some cases run a fundamental-rights impact assessment (FRIA).

Alongside it, the Article 50 transparency duties apply: people must be told when they're interacting with an AI system, and AI-generated content must be disclosed in a machine-readable way where required.

A common misconception: “we only use an internal chatbot, so the AI Act isn't about us.” Mostly true for the high-risk regime, an internal drafting assistant is normally not Annex III, but the AI-literacy duty, the prohibited-practices ban and (from Aug 2026) the transparency rules still apply to you.

Where self-hosting changes the picture

The AI Act doesn't care where your servers are, obligations follow the use case, not the hosting model. What self-hosting does change is how much of the evidence chain you control. When the model runs on your hardware, you can pin the exact model version you assessed, produce your own logs without waiting on a vendor, and answer "what does the system actually do with inputs" from first-hand knowledge rather than a sub-processor list. That's why Kaldryn ships the deployer tooling, transparency banner, AI-literacy module, FRIA/DPIA templates and an immutable audit log, in the box.

Sensible next steps

  1. Inventory your AI use and sort it: prohibited (stop), high-risk (prepare for Aug 2026), limited-risk (transparency), minimal (document and move on).
  2. Stand up AI-literacy training now if you haven't, it's already due.
  3. For anything potentially high-risk, assign an owner for the deployer duties and start the FRIA groundwork this year.