The classic trap
Recital 179 sets out a staggered application calendar that many organisations misread: they remember the 2 August 2026 date and forget that the Article 5 prohibitions have been applicable since 2 February 2025, that obligations on general-purpose AI models and the penalty regime activate on 2 August 2025, and that codes of practice had to be ready by 2 May 2025. In practice, a company deploying today a social scoring system, untargeted facial scraping, or workplace emotion recognition is already in breach, regardless of whether the EU AI Office governance is fully in place. The Luxembourg CNPD can already rely on these prohibitions through their articulation with the GDPR, and civil courts can give them immediate effect.
The calendar milestones to embed in your AI compliance roadmap
- 2 February 2025: Article 5 prohibitions (unacceptable practices) and general provisions (Title I) applicable. Any system in production must be inventoried and screened against this list.
- 2 May 2025: publication of codes of practice for general-purpose AI (GPAI) model providers.
- 2 August 2025: GPAI provider obligations, governance structure (notified bodies, national authorities), and the penalty regime. Member States must have notified their penalty rules to the Commission.
- 2 August 2026: general application of the Regulation, including obligations on Annex III high-risk systems.
- 2 August 2027: application to high-risk systems embedded in regulated products (Annex I).
The legal trap in the recital: anticipated civil effect
Recital 179 expressly states that anticipating the prohibitions is also intended to have an effect on other procedures, notably in civil law. This means a contract concerning a prohibited AI system can already be challenged for nullity, a victim can already invoke these prohibitions before a Luxembourg court, and your supplier warranty clauses must integrate these pivot dates. Failing to audit your AI estate before 2 August 2025 is now a documentable management failure.
How Luxgap automates this risk
Our Luxgap AI Act Countdown Sentinel turns the Regulation's staggered application calendar into an operational dashboard that continuously scans your AI estate and triggers the right actions on the right date, without relying on declarative input from an AI committee. The tool connects to your Microsoft 365 (Copilot, Power Platform), Google Workspace, AWS Bedrock, Azure OpenAI, Salesforce Einstein, Odoo, your HRIS (Workday, Sopra HR), and your network gateways to automatically discover each AI use case, classify it against Article 5, Annex III, and the GPAI regime, and match it against the applicable pivot date.
- Automatically detects each AI model or system active in your IS through API logs, SaaS subscriptions, and outbound DNS, without business questionnaires.
- Classifies each use as prohibited practice (Article 5), high-risk (Annex III), limited risk, or GPAI according to the Regulation criteria and EU AI Office guidance.
- Computes for each system its personal pivot date (2 February 2025, 2 August 2025, 2 August 2026, 2 August 2027) and triggers the matching obligations: immediate withdrawal, FRIA, declaration, CE marking, EU database registration.
- Alerts in real time on Teams or Slack as soon as a new AI use appears, with automatic risk-level qualification and deadline.
- Produces a time-stamped PDF report, opposable in audits or civil litigation, demonstrating deployment diligence and compliance with application dates.
- Embeds automated monitoring of the GPAI codes of practice published by the EU AI Office and proposes the corresponding compliance adjustments.
Available as part of a Luxgap DPO or CISO mandate or as a dedicated SaaS module depending on your scope. Request a tailored quote and our teams will prepare a demonstration on your real AI estate, with a free 48-hour white audit to map your systems and their pivot dates before any commitment.