EU AI Act Timeline: When Each Rule Starts to Bite
The EU AI Act applies in stages, not all at once, and the high-risk dates have just moved, so here's what each date means for a small UK business.
The short version
- It's phased, not a big bang: the Act entered into force on 1 August 2024, but its rules switch on over several years rather than all at once.
- Already live: bans on a short list of unacceptable AI uses, plus a duty to build basic AI literacy, have applied since 2 February 2025.
- The big date has moved: the EU agreed in May 2026 to push most high-risk obligations back to 2 December 2027 (with product-embedded AI to 2 August 2028), but that change isn't legally final until it's published.
- Most small firms sit low: if you use everyday AI tools, you're likely in the minimal- or limited-risk tiers, where the duties are light.
If you run a small business and someone’s told you the EU AI Act is coming for you, take a breath. The law doesn’t land all at once, and most of it was never written for a firm that uses a chatbot to draft emails or an AI feature inside software it already pays for.
The Act switches on in layers, each with its own date. Some of those dates have recently moved, which is worth knowing before you panic about a deadline that may no longer apply. Here’s the timeline in plain English, including the bit that changed in 2026.
What is the EU AI Act timeline, in one view?
The EU AI Act phases its rules in over several years: entry into force in August 2024, bans and AI literacy in February 2025, general-purpose AI rules in August 2025, and the bulk of high-risk obligations originally in August 2026, though that high-risk date has now been pushed back to December 2027.
Think of it as a staircase rather than a cliff. Each step targets a different kind of AI, and the riskier the use, the later and heavier the obligations. For the majority of small businesses, the early steps are the only ones that touch you at all, and even then lightly.
The dates that matter:
- 1 August 2024 — the Act enters into force. Nothing is required of anyone yet; the clock simply starts.
- 2 February 2025 — bans on a small set of prohibited AI uses apply, and the duty to support basic AI literacy among staff begins.
- 2 August 2025 — obligations for providers of general-purpose AI models (the large foundation models behind many tools) start to apply, along with the Act’s governance rules.
- 2 December 2027 — most obligations for high-risk AI systems now apply. This was originally 2 August 2026, but the EU agreed in May 2026 to defer it.
- 2 August 2028 — the date for high-risk AI built into products that are already regulated under other EU safety laws. This was originally 2 August 2027.
If you want the bigger picture of where your business fits before reading on, our small business guide to the EU AI Act walks through it from the start.
What’s already in force (and what to check)?
Since 2 February 2025, two things have applied: the EU AI Act’s outright bans on certain uses, and a duty to support basic AI understanding among staff who work with AI.
The bans cover a short list of uses the EU decided are simply unacceptable, such as AI that manipulates people in harmful ways, social scoring of individuals, and certain kinds of biometric surveillance. For an ordinary small business these are easy to avoid, because you’d almost never go near them in normal work. It’s still worth a quick sanity-check that nothing you’ve bought or built strays into that territory.
The AI literacy duty is the one that quietly applies to far more firms. If your people use AI tools as part of their job, you’re expected to take reasonable measures so they understand what the tool does, where it can go wrong, and how to use it sensibly. This isn’t a formal exam or a certificate. It’s closer to good induction: a short briefing, some written guidance, a sensible policy.
A quick, proportionate way to meet the literacy duty
Write down which AI tools your team uses, what they're allowed to use them for, and the obvious don'ts (no confidential client data into a public chatbot, always check AI output before it goes out the door). A simple acceptable-use policy does most of the work. We've sketched out what that looks like in our AI acceptable use policy template for SMEs.
What landed in August 2025?
From 2 August 2025, the rules for general-purpose AI models began to apply, mostly placing duties on the companies that build those large models rather than on the businesses that use them.
General-purpose AI means the big underlying models that lots of tools are built on top of. The obligations here, around transparency, documentation, and copyright, fall chiefly on the model providers. If you’re a small firm using a product that happens to run on one of those models, the heavy lifting sits with the provider, not you.
Why it still matters to you: these rules push the tools you rely on towards being better documented and clearer about their limits. That’s useful background when you’re choosing what to adopt, but it isn’t a compliance task landing on your desk.
What changed in 2026, and what’s coming next?
In May 2026 the EU agreed a simplification package, often called the Digital Omnibus, that pushes the main high-risk deadlines back by more than a year and adds a new prohibition, though the new dates only become binding once the package is formally published.
Here’s what the agreement does. The bulk of high-risk obligations, originally due on 2 August 2026, move to 2 December 2027. High-risk AI embedded in already-regulated products moves from 2 August 2027 to 2 August 2028. There’s also a new ban, taking effect on 2 December 2026, on AI used to generate non-consensual intimate imagery and child sexual abuse material.
One important caveat. As of mid-2026 this was a political agreement, expected to be formally adopted over the summer and published in the EU’s Official Journal shortly after. The new dates aren’t legally binding until that publication happens. Until then, the original dates technically still stand, so if you genuinely operate high-risk AI, plan against the official position rather than a headline.
The headline date everyone repeated was August 2026, but for the typical small firm the date that already matters is February 2025: the literacy duty and the bans. Get those right and you’ve covered the part most likely to apply to you.
“High-risk” is a defined category, not a vibe. It covers AI used in specific sensitive contexts, for example screening job applicants, scoring people for credit, or systems used in essential services and safety-critical products. If you operate AI in one of those areas, the 2027 and 2028 dates bring real obligations: risk management, data quality, human oversight, record-keeping, and the rest.
Here’s the reassuring part for most readers. Using an off-the-shelf AI tool to write copy, summarise notes, or answer customer questions is not high-risk. Most small businesses won’t touch the high-risk tier at all. If you want to be sure which bucket you’re in, our piece on the EU AI Act risk tiers explains how the four levels work and what lands you in each.
What should a small business actually do at each stage?
For most small firms the to-do list is short: avoid the banned uses, build basic AI literacy now, and only worry about the high-risk dates if you genuinely operate high-risk AI.
A sensible, calm sequence:
- Now: list the AI tools your team uses and write a short acceptable-use policy. This covers the literacy duty and gives you a clean record of how AI is used in the business.
- Now: confirm none of your AI use falls into the prohibited list. For an ordinary business this is a five-minute check.
- Before adopting anything new: ask whether a tool would put you in the high-risk tier (recruitment, credit, biometrics, safety-critical use). If yes, that’s when the high-risk obligations come into play and you’d plan against the official dates.
- Ongoing: keep a light eye on whether the high-risk dates settle, given the 2026 changes, but don’t redesign your business around dates that may not apply to you.
Where SecurSentry fits
We're building a compliance platform to help UK small businesses get the practical groundwork in place: writing the policies, keeping the records, and understanding which obligations actually apply to you across frameworks like this one. It's not live yet, but if working through the EU AI Act on your own feels like a lot, that's exactly the kind of thing we want to make simpler.
The honest summary: the EU AI Act timeline looks intimidating as a wall of dates, but for most small businesses it comes down to a couple of light, sensible habits you can sort now, plus an awareness of the high-risk dates in case your work ever takes you there. Those high-risk dates have just been pushed back, which buys most firms more breathing room. Knowing where you sit is most of the battle, and you’re probably sitting lower than you feared.