AI Act: What's Really Changing and the Key Dates

Edited by Solucom · June 1, 2026

Every two weeks, there’s an alarming headline about the AI Act: fines in the millions, deadlines, red tape. If you own a small or medium-sized business, there’s really only one question: What changes for me, and when? The answer, in most cases, is much less scary than it seems — but there are two or three dates you’ll want to be clear on. Let's go over them together, without panic and without unnecessary jargon. (A necessary clarification: this information is for general guidance, not legal advice for your specific situation.)

What Is AI Act, in a Nutshell

The AI Act is the first European regulation governing artificial intelligence. The rationale behind it is simple: The riskier the use of AI is for people, the more rules it must comply with.. It came into effect on August 1, 2024, but it doesn't all apply at once: the obligations come into effect in stages, on different dates. And it is precisely here that confusion arises, because many online articles cite now-past deadlines.

The dates that really matter

  • February 2, 2025 — already in effect. Are they active Prohibitions on practices considered unacceptable (e.g., social scoring or certain forms of manipulation). An obligation has also been triggered to AI literacyThose who use or provide AI systems must ensure that the personnel involved have adequate basic training.
  • August 2, 2025—effective immediately. obligations for the General AI models (i «LLMs», like the large models behind ChatGPT and similar). They are mainly for those who produce those models, not who uses them: it's useful for you to know, but it usually doesn't affect you directly.
  • August 2, 2026 — coming soon. The obligations are triggered transparencyAI-generated or manipulated content (text, images, audio, video, deepfakes) must be flagged as such in cases where it is required. This is the date that most easily affects even an SME that uses AI for content.
  • December 2, 2027, and August 2, 2028 — high-risk systems. The heaviest obligations, those for uses high risk, have been postponed: December 2, 2027, for uses listed in Annex III (e.g., AI used for personnel selection or credit scoring) and August 2, 2028, for AI integrated into existing regulated products (medical devices, elevators, radio equipment).

A note of honesty, important: this postponement comes from the so-called «Digital Omnibus», on which European institutions have reached a Interim agreement May 7, 2026. Formal adoption and publication are expected in the following months. The dates above are the agreed-upon ones; barring any surprises, they will become definitive, but it's worth double-checking them before making binding decisions.

«High risk» does not mean «any use of AI».»

This is the point that alleviates half the anxiety. The AI Act categorizes uses into four risk levels, and The vast majority of SMEs are in the lower brackets (minimal or limited risk). Using AI to draft content, summarize documents, generate social media images, or respond to customers doesn't, in itself, make you a «high-risk» company. If you want to understand where you fall, I've explained the tiers with examples in four risk levels of AI Act.

A practical example

Imagine two different companies.

Case A — a marketing agency. Use AI to write draft texts and generate images for clients. This is not a high-risk use. What concerns you concretely? Two things: ensuring the team has a minimum training on AI (even today) and, from August 2026, report AI-generated content where applicable. Nothing else dramatic.

Case B – A company that filters resumes with AI. Use an automated system to screen candidates during the hiring process. This is a practice high risk (Annex III): entails serious obligations — documentation, human supervision, data management. The good news is the timing (obligations kick in at the end of 2027); the bad news is that you can't improvise, and it's advisable to prepare in advance.

When AI Act Affects You Personally

  • Use AI to decide on peopleAssumptions, credit, access to services. This is where it's easy to fall into high risk.
  • Publish generated content From AI to the public: transparency counts from August 2026.
  • Hi staff using AI In daily work: the obligation for basic training is already active.

When, on the other hand, you can rest easy

If you use AI for low-impact internal tasks—drafting, summarizing, research, organization—and do not make automatic decisions about people, you will almost always fall into the lower tiers. Common sense and a minimum of transparency are needed, not a dedicated legal department.

Common errors

  • «It doesn't concern me, I don't develop AI.». False: The AI Act also applies to those who USA AI, not just those who build it.
  • Trusting old dates. Many sources still cite August 2, 2026, for the high risk: this deadline has now been postponed. Always check the source and the date.
  • Ignore the training. AI literacy is the easiest obligation to meet and the most neglected.
  • Confusing information and advice. For delicate uses, consult a professional: an article provides guidance, not legal advice.

The first, concrete step

Take twenty minutes and do a little Inventory of AI uses in business: where you use it, for what purpose, with what data, and if at any point it makes decisions about people. Three columns on a sheet are enough. From that list, you immediately understand two things: what risk category you fall into and if there's even one «sensitive» use to keep an eye on. It's the quickest way to turn anxiety from a newspaper headline into concrete action.

What can you do today, without stress?

A months-long project isn't necessary. Four steps, achievable for any company, are enough:

  • Assemble the team, even for just an hour. An internal session on «what we can and cannot do with AI» already covers the obligation of literacy and reduces real errors (for example, pasting confidential data into public tools).
  • Decide on a data rule. Blacklisting what never ends up in an external AI: sensitive personal data, customer information, company secrets. Writing it down in black and white is worth more than ten generic policies.
  • Prepare the transparency. If you publish AI-generated content, get used to flagging it where appropriate: it will be mandatory from August 2026, but it's also a matter of trust with your readers.
  • Name a reference person. Someone who keeps an eye on the topic and knows who to ask. Not a full-time legal expert: someone who doesn't let the issue go without an owner.

Four simple things that, together, keep you on track with existing obligations and prepare you for upcoming ones.

The few things to remember

For most SMEs, AI Act isn’t the monster portrayed in the headlines: it’s a set of risk-proportionate rules, with few truly significant deadlines. The prohibitions and training requirements are already in place; transparency requirements take effect in August 2026; and the most onerous obligations for high-risk firms have been postponed to 2027–2028. Knowing where you stand is more valuable than memorizing any specific deadline.

Frequently Asked Questions

Does AI Act apply to AI users as well, not just AI developers?

Yes. The regulation also applies to professional users of AI systems, not just to those who produce them. For example, the obligation for staff literacy and transparency regarding generated content also concerns companies that simply use AI tools.

Is my small or medium-sized business considered high-risk?

Almost always no. High-risk uses are specific cases listed by the regulation, such as AI for personnel selection, credit scoring, or product safety. Using AI for drafts, content, or internal support normally falls into low-risk categories.

Is it true that some of the AI Act deadlines have been postponed?

Yes. With the provisional agreement on the Digital Omnibus of May 7, 2026, the obligations for high-risk systems have been postponed: to December 2, 2027, for uses in Annex III, and to August 2, 2028, for AI integrated into regulated products. Formal adoption is expected in the following months, so it is advisable to check the dates before making any binding decisions.

Are you unsure where your company falls? We can do a simple mapping of your AI usage together and tell you, without alarmism, what really concerns you and what doesn't. See how we handle AI Act compliance o write to us for an initial meeting.