Guide · Data Protection

EU AI Act compliance timeline: a roadmap for your company

Prohibitions and AI literacy in force, GPAI rules applying, and the high-risk regime from 2 December 2027: a step-by-step compliance timeline for your company.

09 June 20264 dk okumaBy Mehmet Köksal · Data Protection
Köksal Attorney Partnership — data, artificial intelligence, cybersecurity and legal tech work
Summary · At a glance
  • Prohibited practices and AI literacy have been in force since February 2025.
  • GPAI (general-purpose model) rules started to apply in August 2025.
  • The main obligations of the high-risk regime come into effect in August 2026.
  • Turkish systems whose output is used in the EU may also fall within scope.

Reading the timeline correctly

The AI Act enters into force not on a single date but in waves. Since February 2025, applications posing unacceptable risk have been prohibited, and companies have an obligation to build competence (AI literacy) among staff who work with AI. In August 2025, transparency and copyright rules for general-purpose AI models (GPAI) began to apply. The main wave has moved to 2 December 2027: under the Digital Omnibus, the quality management, technical documentation, record-keeping and human oversight obligations for standalone Annex III high-risk systems apply from 2 December 2027. The dates for prohibited practices (2 February 2025) and general-purpose AI (2 August 2025) are unchanged.

Practical guidance

The first step is an inventory: which AI systems are used in the company, for what purpose, and in whose role? The classification and obligation map is built on this inventory.

Let us put your AI Act preparation on a timeline

We set up the inventory, risk classification, and policy suite within a single framework aligned with KVKK/GDPR.

AI compliance & governance

Role first, then risk

Your set of obligations is determined by two questions: what is your role in the system (provider, deployer or importer) and what is the system’s risk class? The same company may hold different roles across different systems: a provider for a product it develops itself, a deployer for an HR tool it purchases. Compliance work carried out without mapping out this matrix hangs in the air.

Scope seen from Türkiye

The Regulation is broad in territorial terms: providers/deployers of systems placed on the EU market and of systems whose output is used in the EU may fall within scope even if they are established in a third country. Turkish companies that sell SaaS to the EU, produce analytical output for EU clients, or ship products with embedded software to the EU market are affected through this gateway; in certain cases an authorised representative in the EU is required.

What to do before 2026

1) System inventory and role/class determination; 2) a prohibition screen (particularly uses touching on biometrics, scoring and emotion recognition); 3) a usage policy, human-approval thresholds and a record-keeping regime; 4) adding AI compliance commitments to procurement contracts; 5) planning technical-documentation preparation for high-risk candidates; 6) documenting the training programme. This sequence spreads the cost across the waves and leaves an audit-ready trail.

Intersection with KVKK/GDPR

AI systems often process personal data: the rules on automated decision-making, profiling, and data minimisation apply independently of the AI Act. The most efficient approach is to combine the two compliance streams within a single governance framework.

Sanctions: a tiered penalty architecture

The Regulation’s penalty framework has three tiers: for prohibited practices, administrative fines of up to EUR 35 million or 7% of total worldwide annual turnover; for other breaches of obligations, up to EUR 15 million / 3%; and for supplying misleading information to the authorities, up to EUR 7.5 million / 1%. For SMEs, the rates are adapted more favourably. As in the GDPR experience, this architecture creates the expectation of tiered but deterrent enforcement — particularly for uses that have skipped the prohibition screen. We track current enforcement developments in our AI Act radar entry.

A quick assessment by use case

Customer-service chatbot: limited risk; a transparency notice and management of liability for incorrect information are sufficient — for the liability structure, apply the human-approval thresholds model from our Artificial Intelligence focus area. CV-screening and promotion tools: a high-risk candidate; deployer obligations plus employment law and KVKK’s limits on automated decision-making come into play together. Credit scoring: high risk; a double framework with financial regulation. Generative content tools: GPAI transparency plus copyright and data-leakage policies. AI embedded in a product: a combined assessment with product safety legislation from 2 August 2028. In every scenario the first question is the same: what is your role, and where is the output used?

The Köksal approach

Our AI compliance & governance service sets up the inventory, classification, and policy set within a single framework together with KVKK/GDPR compliance. As a team that uses AI in our own workflows, we write the rules to fit technical reality; for legal departments, our legal tech roadmap is the twin of this guide.

Conclusion

The cost of falling behind on the AI Act is commercial before it is a penalty risk: EU clients have begun to ask their suppliers for a declaration of compliance. Starting today with an inventory turns the 2026 wave into routine — and turns artificial intelligence from a risk into a competitive advantage.

This content is for general information purposes only and does not constitute legal advice. Please get in touch with our team for an assessment relating to your specific situation.
Mehmet Köksal

Author

Mehmet Köksal

Founder and Managing Partner

Combining legal practice with academic work since 1987, Prof. Dr. iur. Mehmet Köksal advises on corporate and commercial law, contracts, employment, foreign direct investment, ESG and supply-chain due diligence, dispute resolution, consumer law and family law.

Related Areas of Work

Explore this publication together with the relevant services, practice areas, focus areas, sectors and desks.

Services

Areas of work directly connected to this publication.

See all

Practice Areas

The legal disciplines the topic sits within.

See all

Focus Areas

Focus areas assessed together according to the client's needs.

See all

Sectors

The sectors this topic touches most often.

See all

Regional Desks

Regional desks that follow the matter with a cross-border or specialist focus.

See all

For prohibited practices, up to €35 million or 7% of global turnover; for other breaches, progressively lower caps are provided.

As a rule, it is a user (deployer); but offering the system under its own brand or substantially modifying it can trigger provider obligations.

No; this is general information. Contact our team for your systems.

Knowledge Centre

Let us put your AI Act preparation on a timeline

We set up the inventory, risk classification, and policy suite within a single framework aligned with KVKK/GDPR.