The EU AI Act timeline for public institutions
The EU AI Act is the first comprehensive law governing artificial intelligence, and it applies in phases. For public institutions, it turns AI adoption from an informal experiment into something that must be documented, supervised and traceable. Here is the timeline — and what each stage means for public-sector work.
Why the AI Act matters for the public sector
Public administrations sit squarely inside the AI Act's scope. Many of the use cases they are most interested in — processing documents, supporting decisions, handling correspondence and citizen data — can fall into the Act's high-risk category, which carries the heaviest obligations. The law does not ban this work. It requires that AI is deployed with risk assessment, human oversight, logging and clear accountability.
That is a shift in how AI is adopted, not whether it is. Institutions can no longer scale AI through consumer tools and individual experiments. They need a controlled path from testing to production — which is precisely the gap generic AI tools leave open.
The timeline at a glance
The AI Act enters into force
The Regulation is adopted and the clock starts. Its obligations then apply in stages rather than all at once.
Prohibited practices & AI literacy
Bans on unacceptable-risk AI take effect, and organisations must ensure staff working with AI have adequate AI literacy. For institutions, this is the first concrete duty — and it already applies today.
General-purpose AI (GPAI) & governance
Transparency and governance obligations for general-purpose AI models begin, alongside the supervisory structures that enforce the Act.
High-risk obligations — the original date
Under the original schedule, most rules apply from this date, including obligations for high-risk systems: risk management, data governance, logging, human oversight and registration. A proposed deferral (below) may move parts of this later.
High-risk (Annex III), under the Digital Omnibus
A 2025–2026 "Digital Omnibus" package proposes deferring high-risk obligations for Annex III use cases — including biometrics, critical infrastructure, education, employment, and migration — to this date. Treat as expected, subject to final EU decisions.
High-risk AI embedded in regulated products
Obligations for high-risk AI embedded in products already regulated under EU law (Annex I) apply on the longest transition, per the proposed revisions.
Dates reflect the Regulation and the proposed Digital Omnibus revisions as understood in mid-2026. The AI Act's exact application dates remain subject to official EU guidance and may be adjusted.
What public institutions can do now
- Build AI literacy. The February 2025 duty already applies. Make sure the people using AI understand what it can and cannot do, and where human judgement is required.
- Keep a human in control. AI should prepare, draft and suggest; an authorised employee reviews, decides and approves. This is both good practice and central to high-risk compliance.
- Insist on traceability. Answers and actions should be linked to approved sources, and system activity should be logged, so decisions can be explained and audited.
- Choose deployable, controllable tools. Data control, model governance and flexible deployment — European cloud, on-premise or disconnected — make the documented, risk-aware posture the Act expects achievable.
How Splot approaches it
Splot is built for public work under exactly these conditions. Every answer can be linked to approved sources; people stay accountable for decisions; and the platform is designed to be deployed where the institution needs it. Rather than adding AI on top of an ungoverned process, Splot brings meetings, documents and knowledge into one environment where governance is part of the design.
Talk to us about governed AI adoption
Sources: European Commission — Regulatory framework on AI; reporting on the EU "Digital Omnibus" proposed deferral of high-risk obligations (2025–2026). This article is general information, not legal advice.
