EU AI Act Enforcement Timeline 2025–2028: What Professional Services Firms Need to Know Now
The EU AI Act is no longer a future concern. It is already partially in force, its deadlines are shifting, and the legal landscape surrounding artificial intelligence in Europe is generating precedents that will affect how professional services businesses operate globally. If you have not yet mapped
EU AI Act Enforcement Timeline 2025–2028: What Professional Services Firms Need to Know Now
The EU AI Act is no longer a future concern. It is already partially in force, its deadlines are shifting, and the legal landscape surrounding artificial intelligence in Europe is generating precedents that will affect how professional services businesses operate globally. If you have not yet mapped your AI use against the Act's requirements, the window for orderly compliance is narrowing.
This briefing sets out the key enforcement milestones, the litigation developments shaping legal risk, and the practical implications for accountants, solicitors, HR consultancies, and marketing agencies — wherever in the world they operate.
The Enforcement Timeline: What Applies and When
The EU AI Act entered into force in August 2024, but its obligations are rolling out in phases. Understanding which deadline applies to which type of AI system is the first step in any compliance programme.
February 2025 brought the Act's prohibited practices into effect, alongside obligations around AI literacy. Businesses using AI systems that fall into prohibited categories — manipulation, social scoring, certain biometric applications — should have ceased those practices already. AI literacy requirements mean organisations must ensure staff who deploy or oversee AI systems have an appropriate level of understanding. This is not aspirational guidance; it is a legal obligation.
2 August 2025 marks the application of rules for General-Purpose AI (GPAI) models and the governance structures underpinning them. GPAI includes the large language models many professional services firms use daily — tools that generate documents, analyse data, or communicate with clients. From this date, providers of GPAI models must comply with transparency obligations, and the governance architecture of the Act, including the role of national competent authorities, becomes fully operational.
2 August 2026 is the date by which Member States must have established at least one AI regulatory sandbox, providing a structured environment for businesses to test compliant AI development. Critically, this is also when the European Commission's enforcement powers over GPAI models become active. The Commission will, from this date, be able to levy significant fines against GPAI providers for non-compliance. For professional services firms that deploy GPAI-based tools in client-facing or decision-influencing contexts, this changes the risk profile of your technology vendors overnight.
2 December 2026 sees new prohibitions apply specifically targeting AI systems that generate non-consensual sexual deepfakes and child sexual abuse material. Separately, the updated Product Liability Directive (PLD) becomes applicable from the same month, establishing strict liability as the primary legal route for harm caused by AI-enabled products, following the European Commission's withdrawal of the standalone AI Liability Directive in February 2025.
2 December 2027 is the revised deadline for stand-alone high-risk AI systems listed under Annex III of the Act. Following the Digital Omnibus Package agreed in May 2026, this represents a sixteen-month extension from the original August 2026 date. Annex III covers AI systems used in employment decisions, access to essential services, credit scoring, and education — areas directly relevant to HR consultancies, accountancy firms, and financial advisers.
2 August 2028 is the final deadline in this sequence, applying to AI systems embedded as safety components in already-regulated products under Annex I. Firms operating in sectors that intersect with regulated product categories should take note of this extended transition period.
Why International Businesses Cannot Ignore This
The EU AI Act applies to any organisation that places AI systems on the EU market or whose AI outputs affect people within the EU. A marketing agency in Dubai running AI-generated campaigns for European clients, a Canadian HR consultancy using algorithmic screening tools for EU-based roles, a US law firm deploying AI contract review for European matters — all fall within scope.
This extraterritorial reach mirrors the logic of the GDPR and demands the same response: understand your obligations, document your systems, and do not assume geographic distance provides legal insulation.
GDPR Enforcement: A Cautious but Active Landscape
Two recent cases illustrate the current state of GDPR enforcement as it intersects with AI.
In March 2026, the Court of Rome overturned the €15 million fine that Italy's Garante had imposed on OpenAI in November 2024 over ChatGPT's handling of personal data, including failures in legal basis, transparency, and age verification. This reversal — the only final GDPR enforcement action concerning generative AI to date — signals that some courts are urging caution before applying existing data protection rules to novel AI architectures. It does not, however, signal that GDPR enforcement is retreating.
Clearview AI has now accumulated over €100 million in fines across Europe since 2020, with the Dutch Data Protection Authority adding €30.5 million in September 2024 for unlawful data collection. The Irish Data Protection Commission took direct enforcement action against X in August 2024, compelling it to stop using EU users' public posts to train its Grok chatbot. The direction of travel is clear: regulators are actively scrutinising AI training practices against data protection law, and professional services firms using third-party AI tools should be asking their vendors hard questions about how training data was sourced.
Copyright and Liability: The Litigation Picture
Two European court cases are reshaping how intellectual property intersects with AI.
In November 2025, the Regional Court of Munich ruled in GEMA v OpenAI that training generative AI on copyrighted song lyrics without a licence violates German copyright law. The court held that memorisation within the model constitutes reproduction, and that generating those lyrics as output constitutes public communication. OpenAI was found directly liable. For any professional services firm producing AI-generated content — whether legal documents, marketing copy, financial reports, or HR materials — this decision raises direct questions about the IP provenance of AI outputs.
The Court of Justice of the European Union is now set to hear Like Company v Google, a case brought by a Hungarian publisher challenging Google's Gemini chatbot for reproducing editorial content. The CJEU's ruling will set binding precedent across all EU Member States on AI and copyright. Firms should monitor this case closely; its outcome will directly inform what lawful AI content generation looks like in practice.
What Firms Should Be Doing Now
The staggered timeline creates a false sense of distance from compliance. In reality, the groundwork — risk classification, vendor due diligence, staff training, documentation — takes time, and regulators expect to see it done properly.
Specifically, professional services businesses should:
- Audit their AI tools against the Act's risk classifications, including GPAI systems already in use
- Review vendor contracts for GDPR compliance representations, particularly around training data and data processing agreements
- Implement AI literacy programmes that meet the Act's February 2025 requirement — this is already overdue for many firms
- Assess copyright exposure from AI-generated outputs in light of the Munich ruling
- Monitor the CJEU's Like Company v Google decision and update content policies accordingly
Get Ahead of the Curve with Ops Intel
The complexity of EU AI compliance is not going to reduce. Deadlines are shifting, courts are setting precedents, and enforcement is becoming more targeted. Professional services firms that treat AI compliance as a one-time exercise will find themselves repeatedly behind.
Ops Intel works with professional services businesses globally to build AI compliance programmes that are practical, proportionate, and built to last. From risk classification and staff training to vendor assessments and regulatory monitoring, we provide the expertise your business needs to operate confidently in an increasingly regulated environment.
Contact Ops Intel today to discuss your EU AI Act compliance position and find out where your firm stands before the next deadline arrives.
Work with Ops Intel
Need help navigating AI compliance?
We build AI compliance frameworks and automation systems for professional services firms worldwide. Book a free 30-minute call or email us directly.