SecurSentry
← All notes
EU AI Act

EU AI Act Timeline: When Each Rule Starts to Bite

The EU AI Act applies in stages, not all at once, and the high-risk dates have just moved, so here's what each date means for a small UK business.

The short version

If you run a small business and someone’s told you the EU AI Act is coming for you, take a breath. The law doesn’t land all at once, and most of it was never written for a firm that uses a chatbot to draft emails or an AI feature inside software it already pays for.

The Act switches on in layers, each with its own date. Some of those dates have recently moved, which is worth knowing before you panic about a deadline that may no longer apply. Here’s the timeline in plain English, including the bit that changed in 2026.

What is the EU AI Act timeline, in one view?

The EU AI Act phases its rules in over several years: entry into force in August 2024, bans and AI literacy in February 2025, general-purpose AI rules in August 2025, and the bulk of high-risk obligations originally in August 2026, though that high-risk date has now been pushed back to December 2027.

Think of it as a staircase rather than a cliff. Each step targets a different kind of AI, and the riskier the use, the later and heavier the obligations. For the majority of small businesses, the early steps are the only ones that touch you at all, and even then lightly.

The dates that matter:

If you want the bigger picture of where your business fits before reading on, our small business guide to the EU AI Act walks through it from the start.

What’s already in force (and what to check)?

Since 2 February 2025, two things have applied: the EU AI Act’s outright bans on certain uses, and a duty to support basic AI understanding among staff who work with AI.

The bans cover a short list of uses the EU decided are simply unacceptable, such as AI that manipulates people in harmful ways, social scoring of individuals, and certain kinds of biometric surveillance. For an ordinary small business these are easy to avoid, because you’d almost never go near them in normal work. It’s still worth a quick sanity-check that nothing you’ve bought or built strays into that territory.

The AI literacy duty is the one that quietly applies to far more firms. If your people use AI tools as part of their job, you’re expected to take reasonable measures so they understand what the tool does, where it can go wrong, and how to use it sensibly. This isn’t a formal exam or a certificate. It’s closer to good induction: a short briefing, some written guidance, a sensible policy.

A quick, proportionate way to meet the literacy duty

Write down which AI tools your team uses, what they're allowed to use them for, and the obvious don'ts (no confidential client data into a public chatbot, always check AI output before it goes out the door). A simple acceptable-use policy does most of the work. We've sketched out what that looks like in our AI acceptable use policy template for SMEs.

What landed in August 2025?

From 2 August 2025, the rules for general-purpose AI models began to apply, mostly placing duties on the companies that build those large models rather than on the businesses that use them.

General-purpose AI means the big underlying models that lots of tools are built on top of. The obligations here, around transparency, documentation, and copyright, fall chiefly on the model providers. If you’re a small firm using a product that happens to run on one of those models, the heavy lifting sits with the provider, not you.

Why it still matters to you: these rules push the tools you rely on towards being better documented and clearer about their limits. That’s useful background when you’re choosing what to adopt, but it isn’t a compliance task landing on your desk.

What changed in 2026, and what’s coming next?

In May 2026 the EU agreed a simplification package, often called the Digital Omnibus, that pushes the main high-risk deadlines back by more than a year and adds a new prohibition, though the new dates only become binding once the package is formally published.

Here’s what the agreement does. The bulk of high-risk obligations, originally due on 2 August 2026, move to 2 December 2027. High-risk AI embedded in already-regulated products moves from 2 August 2027 to 2 August 2028. There’s also a new ban, taking effect on 2 December 2026, on AI used to generate non-consensual intimate imagery and child sexual abuse material.

One important caveat. As of mid-2026 this was a political agreement, expected to be formally adopted over the summer and published in the EU’s Official Journal shortly after. The new dates aren’t legally binding until that publication happens. Until then, the original dates technically still stand, so if you genuinely operate high-risk AI, plan against the official position rather than a headline.

The headline date everyone repeated was August 2026, but for the typical small firm the date that already matters is February 2025: the literacy duty and the bans. Get those right and you’ve covered the part most likely to apply to you.

“High-risk” is a defined category, not a vibe. It covers AI used in specific sensitive contexts, for example screening job applicants, scoring people for credit, or systems used in essential services and safety-critical products. If you operate AI in one of those areas, the 2027 and 2028 dates bring real obligations: risk management, data quality, human oversight, record-keeping, and the rest.

Here’s the reassuring part for most readers. Using an off-the-shelf AI tool to write copy, summarise notes, or answer customer questions is not high-risk. Most small businesses won’t touch the high-risk tier at all. If you want to be sure which bucket you’re in, our piece on the EU AI Act risk tiers explains how the four levels work and what lands you in each.

What should a small business actually do at each stage?

For most small firms the to-do list is short: avoid the banned uses, build basic AI literacy now, and only worry about the high-risk dates if you genuinely operate high-risk AI.

A sensible, calm sequence:

Where SecurSentry fits

We're building a compliance platform to help UK small businesses get the practical groundwork in place: writing the policies, keeping the records, and understanding which obligations actually apply to you across frameworks like this one. It's not live yet, but if working through the EU AI Act on your own feels like a lot, that's exactly the kind of thing we want to make simpler.

The honest summary: the EU AI Act timeline looks intimidating as a wall of dates, but for most small businesses it comes down to a couple of light, sensible habits you can sort now, plus an awareness of the high-risk dates in case your work ever takes you there. Those high-risk dates have just been pushed back, which buys most firms more breathing room. Knowing where you sit is most of the battle, and you’re probably sitting lower than you feared.

Frequently asked questions

When does the EU AI Act actually apply?

It applies in stages. The law entered into force on 1 August 2024, the bans on prohibited uses and the AI literacy duty applied from 2 February 2025, and the rules for general-purpose AI models from 2 August 2025. Most high-risk obligations were originally due on 2 August 2026, but in May 2026 the EU agreed to defer them to 2 December 2027 (and product-embedded high-risk AI to 2 August 2028). So there is no single switch-on date, and the high-risk dates are mid-change.

Does the EU AI Act apply to UK businesses after Brexit?

It can. The Act has extraterritorial reach: it applies to organisations outside the EU if they place an AI system on the EU market, or if the system's output is used in the EU. A UK firm selling into the EU, or whose AI affects people in the EU, may fall in scope. If you only serve UK customers and use ordinary off-the-shelf tools, the direct obligations on you are usually limited.

What is the most important EU AI Act deadline for a small business?

For most small firms, the date already past matters most: since 2 February 2025 you should make sure staff who use AI have a basic understanding of it, and that you're not using any banned applications. The high-risk dates mainly affect firms that build or deploy AI in sensitive areas like recruitment scoring or credit decisions, which most small businesses do not, and those dates have now been pushed back to late 2027 and 2028.

Could the EU AI Act dates change again?

They already have. In May 2026 the Council and Parliament agreed a simplification package, often called the Digital Omnibus, that postpones the main high-risk deadlines. That agreement was expected to be formally adopted in summer 2026, and the new dates only become legally binding once it's published in the EU's Official Journal. Until then the original dates technically still stand, so if a high-risk date affects you, check the official position rather than relying on a headline.

Written by The SecurSentry Team

We write plain-English notes on security and compliance for small businesses — the things we wish someone had explained to us. Read more notes →

More from the blog

UK GDPR

What a Record of Processing Activities (ROPA) Is, and How to Build One

19 Jul 2026 · 7 min
UK GDPR

Personal Data Breach: What a Small Business Must Do

16 Jul 2026 · 6 min
Security questionnaires

Security Questionnaire Examples, Explained Simply

10 Jul 2026 · 7 min

Be first to know when we launch.

Leave your email and we'll let you know the moment SecurSentry is ready. One email — no newsletters, no spam.

Just one email, at launch. We never share your data. Privacy policy.

You're on the list — we'll be in touch at launch.