Essential Takeaways
The EU AI Act is law as of May 2024, and the Digital Omnibus on AI (in force July 2026) has since revised parts of the compliance timeline.
The first major deadline is end-of-2024/early-2025, when the ban on 'unacceptable risk' AI systems came into force.
Article 50 transparency and Article 4 AI literacy duties are unaffected by the Omnibus and remain due from 2 August 2026.
High-risk system obligations were postponed: stand-alone Annex III systems now have until 2 December 2027, and AI embedded in regulated products (Annex I) until 2 August 2028.
Even UK-based SMEs must comply if their AI systems or their outputs are used in the EU.
Immediate actions include creating an AI inventory, classifying systems by risk level, and reviewing vendor contracts.
The EU AI Act is no longer a future concern; it is a present reality for businesses in and trading with the European Union. In May 2024, the Act was formally adopted, triggering a series of compliance deadlines that every organisation using artificial intelligence must understand.
As an AI governance advisor with over 20 years of experience in regulated industries, I've seen the conversation with SME boards shift dramatically. The question is no longer 'what if?' but 'what now?'. The official timeline for the EU AI Act is set, and for small and medium-sized enterprises, proactive preparation is the key to managing risk and seizing competitive advantage.
This article provides the latest official timeline, explains what each deadline means for you, and offers a practical, step-by-step plan to get your organisation ready.
What is the Current Status of the EU AI Act?
On 21 May 2024, the Council of the European Union gave its final approval to the AI Act. This was the last legislative step. The Act was then published in the EU's Official Journal, which means it is now officially law and the compliance clocks have started ticking.
This landmark regulation takes a risk-based approach. The obligations for an AI system depend on the level of risk it poses to health, safety, or fundamental rights. For SMEs, this means you must first understand what kind of AI you are using or building before you can determine your compliance burden.
Note: The EU AI Act has 'extraterritorial' scope. This means even if your SME is based in the UK, US, or elsewhere, the law applies to you if you place AI systems on the EU market, or if the output of your AI system is used within the EU. We explain this further in our guide, The EU AI Act: What UK SMEs Need to Know.
The Official EU AI Act Timeline: Key Deadlines You Must Know
The regulation will be implemented in stages. In our work advising leadership teams, we stress the importance of mapping your AI systems against this timeline. Some rules apply much sooner than others.
Here is a breakdown of the key dates and what they mean for your business.
Deadline | Date | What It Means For You |
|---|---|---|
Entry into Force | June/July 2024 | The compliance countdown begins. The law is officially on the books. |
Prohibited AI Ban | Dec 2024 / Jan 2025 | Ban on Prohibited AI practices takes effect. You must cease using any AI systems that fall into the 'unacceptable risk' category. |
GPAI Rules | March/April 2025 | Rules for General-Purpose AI (GPAI) models apply. If you use or provide foundational models (like GPT-4), new transparency and documentation rules kick in. |
Transparency & AI Literacy | 2 August 2026 | Article 50 transparency obligations and the Article 4 AI literacy duty apply. These are unaffected by the EU AI Act Omnibus delay and remain on the original schedule. This is the deadline most SMEs still face in 2026. |
Legacy System Transparency | 2 December 2026 | Article 50(2) transparency requirements extend to legacy systems already on the market, and new prohibited practices (AI-generated non-consensual intimate imagery and CSAM) take effect. |
High-Risk (Stand-Alone) | 2 December 2027 | High-risk obligations apply to stand-alone Annex III AI systems (recruitment, credit scoring, education, law enforcement, and similar). Originally due August 2026, this was postponed under the EU AI Act Omnibus, which entered into force in July 2026. |
High-Risk (Embedded) | 2 August 2028 | High-risk obligations apply to AI embedded in regulated products under Annex I (e.g., medical devices, machinery, vehicles). |
Which Parts of the EU AI Act Apply First?
The most immediate deadline concerns prohibited AI. By the end of 2024, you must ensure you are not using any AI systems that the Act deems an 'unacceptable risk'.
These include systems that:
Use manipulative or deceptive techniques to distort behaviour.
Exploit vulnerabilities of a specific group of persons.
Facilitate social scoring by public authorities.
Perform real-time remote biometric identification in public spaces for law enforcement (with narrow exceptions).
Warning: The ban on prohibited AI is the first major compliance test. In our reviews of SME AI programmes, we often find unsanctioned 'Shadow AI' tools in use for marketing or HR that could fall into a grey area. An immediate audit of your AI inventory is essential.
What Should SMEs Be Doing Right Now to Prepare?
Waiting until 2026 is not a viable strategy. The work required to classify systems, review contracts, and implement controls takes time. As an IAPP-certified Artificial Intelligence Governance Professional (AIGP), I recommend a structured, phased approach.
Here are five steps you can take today.
1. Conduct an AI Inventory
You cannot govern what you don't know you have. Start by creating a register of all AI systems used across your business, from marketing automation and HR software to customer service chatbots and developer tools. Note who owns it, what it's used for, and what data it processes.
2. Classify Your AI Systems
Using your inventory, classify each system according to the EU AI Act's risk pyramid:
Unacceptable Risk: Banned systems. Identify and decommission these immediately.
High-Risk: Systems used in critical areas like recruitment, credit scoring, or medical diagnostics. These face the most stringent requirements.
Limited Risk: Systems with transparency obligations, like chatbots or deepfakes. You must inform users they are interacting with an AI.
Minimal Risk: The vast majority of AI systems (e.g., spam filters, video games). The Act encourages voluntary codes of conduct but imposes no new legal obligations.
3. Prioritise Your High-Risk Obligations
If you identify any high-risk systems, this is your priority. Under the Act, these systems require robust risk management, high-quality data governance, detailed technical documentation, human oversight, and high levels of accuracy and cybersecurity. Frameworks like the NIST AI Risk Management Framework provide an excellent foundation for these controls.
4. Review Vendor and Supplier Contracts
Many SMEs are users of AI, not developers. You are still responsible for ensuring the high-risk systems you deploy are compliant. Scrutinise your contracts with AI vendors. Do they accept their obligations as a 'provider' under the Act? Do they provide the necessary technical documentation and transparency to allow you to meet your obligations as a 'deployer'?
Tip: Start building your governance foundation now. A simple, effective framework can be implemented quickly. Our 30-Day AI Governance Plan shows how you can establish core controls and demonstrate responsible AI practices to customers and regulators.
5. Adopt a Governance Framework
Compliance should not be an ad-hoc scramble. Adopting a formal AI management system, such as ISO/IEC 42001, provides a structured and repeatable process for managing AI risk and demonstrating compliance. In our experience, organisations with a recognised framework find it significantly easier to map their activities to the EU AI Act's requirements and prepare for conformity assessments.
How the EU AI Act Affects UK-Based SMEs
While the UK government is pursuing its own 'pro-innovation' approach to AI regulation, as detailed in its February 2024 response to the AI white paper, this does not give UK firms a free pass.
Due to its extraterritorial reach, the EU AI Act sets a de facto global standard. If your product is available to customers in the EU, you must comply. We see boards struggle most with underestimating this reach. For most UK SMEs with international ambitions, aligning with the EU AI Act is the most commercially pragmatic path forward.
Building your governance to meet the EU's requirements will likely satisfy the principles-based approach of the UK and other jurisdictions, providing a robust foundation for global operations. An assurance scheme like AI Assured helps you build one framework that maps to multiple regulations, saving significant time and effort.
Ultimately, the EU AI Act's timeline is a call to action. It's an opportunity to move beyond reactive compliance and build a proactive AI governance strategy that fosters innovation, manages risk, and earns trust. The companies that act now will be the ones that lead tomorrow.
Scope
AI Assured is a governance programme, not an accredited certification body. It does not issue ISO/IEC 42001 certificates or statutory sign-off for the EU AI Act, FCA, FDA, NYC LL144 or other regulatory regimes. Articles are general information, not legal or regulatory advice.
Frequently asked questions
What is the final deadline for the EU AI Act?
The timeline was revised by the EU AI Act Omnibus, in force since July 2026. High-risk obligations for stand-alone AI systems (Annex III, e.g. recruitment, credit scoring) now apply from 2 December 2027, and for AI embedded in regulated products (Annex I) from 2 August 2028. Rules banning prohibited AI already applied from the end of 2024, and Article 50 transparency plus Article 4 AI literacy duties remain due from 2 August 2026, unaffected by the delay.
Does the EU AI Act apply to my small business?
Yes, if your business operates in the EU or your AI's output is used there. The compliance obligations depend on the risk level of your AI system, not the size of your company. Many SMEs will only have minimal or limited-risk systems with few obligations.
What is considered a 'high-risk' AI system?
High-risk AI systems are those used in critical sectors listed in the Act's annexes. This includes AI for recruitment, employee management, credit scoring, critical infrastructure, education, law enforcement, and medical devices. These systems face the strictest rules.
What are the penalties for non-compliance with the EU AI Act?
The penalties are severe and can be up to €35 million or 7% of global annual turnover, whichever is higher, for violations like using prohibited AI. Other infringements carry fines of up to €15 million or 3% of turnover.
How is the EU AI Act different from GDPR?
GDPR protects personal data, focusing on how it is collected, processed, and stored. The EU AI Act regulates the AI systems themselves, focusing on the risks they pose to health, safety, and fundamental rights, regardless of whether they process personal data.
What is a General-Purpose AI (GPAI) model?
A General-Purpose AI (GPAI) model, or foundation model, is a large AI model like OpenAI's GPT-4 that can be adapted for a wide range of tasks. Under the AI Act, these models have specific transparency requirements, such as providing technical documentation to downstream users.
Sources
Harmeen Birk, AI Governance Advisor
Harmeen Birk is an ex-Citi senior AI strategist and executive advisor with over 20 years of experience leading large-scale data and AI programs within global financial institutions. As an IAPP-trained Artificial Intelligence Governance Professional (AIGP) she specialises in bridging the gap between rigorous compliance and practical innovation. Her expertise focuses on establishing robust AI governance frameworks and responsible AI practices for mid-market companies, boards, and emerging tech vendors.
Credentials: AI Governance Advisors, Institutions & Financial Services | Ex-Citi | HBS | AIGP | CGI


