EU AI Act: The Final Timeline and Your Compliance Plan
The EU AI Act's final timeline is here. Understand the key dates from 2024 to 2026 and learn the practical steps your SME must take now to ensure compliance and build trust.
By Harmeen Birk, AI Governance Advisor · · 6 min read
The EU AI Act is no longer a future concern; it is a present reality for businesses in and trading with the European Union. In May 2024, the Act was formally adopted, triggering a series of compliance deadlines that every organisation using artificial intelligence must understand.
As an AI governance advisor with over 20 years of experience in regulated industries, I've seen the conversation with SME boards shift dramatically. The question is no longer 'what if?' but 'what now?'. The official timeline for the EU AI Act is set, and for small and medium-sized enterprises, proactive preparation is the key to managing risk and seizing competitive advantage.
This article provides the latest official timeline, explains what each deadline means for you, and offers a practical, step-by-step plan to get your organisation ready.
What is the Current Status of the EU AI Act?
On 21 May 2024, the Council of the European Union gave its final approval to the AI Act. This was the last legislative step. The Act was then published in the EU's Official Journal, which means it is now officially law and the compliance clocks have started ticking.
This landmark regulation takes a risk-based approach. The obligations for an AI system depend on the level of risk it poses to health, safety, or fundamental rights. For SMEs, this means you must first understand what kind of AI you are using or building before you can determine your compliance burden.
[!note] The EU AI Act has 'extraterritorial' scope. This means even if your SME is based in the UK, US, or elsewhere, the law applies to you if you place AI systems on the EU market, or if the output of your AI system is used within the EU. We explain this further in our guide, The EU AI Act: What UK SMEs Need to Know.
The Official EU AI Act Timeline: Key Deadlines You Must Know
The regulation will be implemented in stages. In our work advising leadership teams, we stress the importance of mapping your AI systems against this timeline. Some rules apply much sooner than others.
Here is a breakdown of the key dates and what they mean for your business.
| Deadline | Date (Approx.) | What It Means For You |
|---|---|---|
| Entry into Force | June/July 2024 | The 24-month countdown to full compliance begins. The law is officially on the books. |
| 6 Months | Dec 2024 / Jan 2025 | Ban on Prohibited AI practices takes effect. You must cease using any AI systems that fall into the 'unacceptable risk' category. |
| 9 Months | March/April 2025 | Rules for General-Purpose AI (GPAI) models apply. If you use or provide foundational models (like GPT-4), new transparency and documentation rules kick in. |
| 12 Months | June/July 2025 | Most obligations for providers of High-Risk AI systems apply. If you are building and selling high-risk AI, this is a critical deadline for conformity assessments and documentation. |
| 24 Months | June/July 2026 | Full application of the Act. Most obligations, including those for users of high-risk AI systems, come into full force. This is the main deadline for many SMEs. |
| 36 Months | June/July 2027 | Rules apply to high-risk systems already governed by other EU laws (e.g., medical devices, machinery). |
Which Parts of the EU AI Act Apply First?
The most immediate deadline concerns prohibited AI. By the end of 2024, you must ensure you are not using any AI systems that the Act deems an 'unacceptable risk'.
These include systems that:
- Use manipulative or deceptive techniques to distort behaviour.
- Exploit vulnerabilities of a specific group of persons.
- Facilitate social scoring by public authorities.
- Perform real-time remote biometric identification in public spaces for law enforcement (with narrow exceptions).
[!warning] The ban on prohibited AI is the first major compliance test. In our reviews of SME AI programmes, we often find unsanctioned 'Shadow AI' tools in use for marketing or HR that could fall into a grey area. An immediate audit of your AI inventory is essential.
What Should SMEs Be Doing Right Now to Prepare?
Waiting until 2026 is not a viable strategy. The work required to classify systems, review contracts, and implement controls takes time. As an IAPP-certified Artificial Intelligence Governance Professional (AIGP), I recommend a structured, phased approach.
Here are five steps you can take today.
1. Conduct an AI Inventory
You cannot govern what you don't know you have. Start by creating a register of all AI systems used across your business, from marketing automation and HR software to customer service chatbots and developer tools. Note who owns it, what it's used for, and what data it processes.
2. Classify Your AI Systems
Using your inventory, classify each system according to the EU AI Act's risk pyramid:
- Unacceptable Risk: Banned systems. Identify and decommission these immediately.
- High-Risk: Systems used in critical areas like recruitment, credit scoring, or medical diagnostics. These face the most stringent requirements.
- Limited Risk: Systems with transparency obligations, like chatbots or deepfakes. You must inform users they are interacting with an AI.
- Minimal Risk: The vast majority of AI systems (e.g., spam filters, video games). The Act encourages voluntary codes of conduct but imposes no new legal obligations.
3. Prioritise Your High-Risk Obligations
If you identify any high-risk systems, this is your priority. Under the Act, these systems require robust risk management, high-quality data governance, detailed technical documentation, human oversight, and high levels of accuracy and cybersecurity. Frameworks like the NIST AI Risk Management Framework provide an excellent foundation for these controls.
4. Review Vendor and Supplier Contracts
Many SMEs are users of AI, not developers. You are still responsible for ensuring the high-risk systems you deploy are compliant. Scrutinise your contracts with AI vendors. Do they accept their obligations as a 'provider' under the Act? Do they provide the necessary technical documentation and transparency to allow you to meet your obligations as a 'deployer'?
[!tip] Start building your governance foundation now. A simple, effective framework can be implemented quickly. Our 30-Day AI Governance Plan shows how you can establish core controls and demonstrate responsible AI practices to customers and regulators.
5. Adopt a Governance Framework
Compliance should not be an ad-hoc scramble. Adopting a formal AI management system, such as ISO/IEC 42001, provides a structured and repeatable process for managing AI risk and demonstrating compliance. In our experience, organisations with a recognised framework find it significantly easier to map their activities to the EU AI Act's requirements and prepare for conformity assessments.
How the EU AI Act Affects UK-Based SMEs
While the UK government is pursuing its own 'pro-innovation' approach to AI regulation, as detailed in its February 2024 response to the AI white paper, this does not give UK firms a free pass.
Due to its extraterritorial reach, the EU AI Act sets a de facto global standard. If your product is available to customers in the EU, you must comply. We see boards struggle most with underestimating this reach. For most UK SMEs with international ambitions, aligning with the EU AI Act is the most commercially pragmatic path forward.
Building your governance to meet the EU's requirements will likely satisfy the principles-based approach of the UK and other jurisdictions, providing a robust foundation for global operations. An assurance scheme like AI Assured helps you build one framework that maps to multiple regulations, saving significant time and effort.
Ultimately, the EU AI Act's timeline is a call to action. It's an opportunity to move beyond reactive compliance and build a proactive AI governance strategy that fosters innovation, manages risk, and earns trust. The companies that act now will be the ones that lead tomorrow.