Important: This is technical and operational guidance, not legal advice. The rules that apply depend on your role, system and use case.

Why the timeline causes confusion

The EU AI Act did not begin on one single date. Different parts became applicable at different times, and the 2026 AI Omnibus extended the main deadlines for high-risk systems. A checklist copied from early 2025 may therefore contain dates that are no longer current.

For most Irish SMEs, the immediate job is not to master every article. It is to know which AI tools are in use, how they are used and whether any use affects employees, customers or important decisions.

2 February 2025: the first duties began

The rules on prohibited AI practices began applying, alongside the original Article 4 expectation that providers and deployers take measures to support an appropriate level of AI literacy. The 2026 simplification changed how that literacy requirement operates, but staff still need enough knowledge to use AI safely in context.

In practice, a business should be able to show that people using tools such as ChatGPT, Copilot or an AI-enabled CRM understand basic limits: checking outputs, protecting personal information, recognising bias and escalating important decisions.

2 August 2025: general-purpose AI rules

Obligations for providers of general-purpose AI models began applying. Most SMEs using a commercial model are not the model provider, but the change matters because it should improve the information available from vendors about capabilities, limitations and training.

If your business builds a product on top of a general-purpose model, do not assume that the model supplier carries every responsibility. Your own product, instructions, integrations and intended use still need to be assessed.

2 August 2026: transparency and enforcement

Most of the Act became applicable and enforcement powers began. Article 50 transparency rules now matter for relevant systems. People must be told when they are interacting directly with AI where that would not already be obvious. Certain deepfakes and AI-generated public-interest content need appropriate labelling, while providers have machine-readable marking duties for relevant generated content.

For an SME, this may mean reviewing chatbot introductions, synthetic marketing content, automated communications and any tool that analyses emotion or uses biometric categorisation.

2 December 2027 and 2 August 2028: high-risk systems

Following the 2026 changes, rules for systems used in sensitive Annex III areas—including employment, education, credit and essential services—apply from 2 December 2027. High-risk AI embedded in certain regulated products follows on 2 August 2028.

Those dates are not a reason to wait. A recruitment system cannot be properly documented, tested and governed in the week before a deadline. Businesses using AI in sensitive decisions should identify it now and obtain specialist legal and technical advice.

Plain-English takeaway

Your first deadline is the one that already passed.

Every organisation using AI should know what it uses, who owns it and whether staff understand the risks. Later high-risk dates give time to prepare—not permission to ignore the system.

What to do this month

Official sources: EU AI Act ↗ · European Commission implementation timeline ↗ · AI Act enforcement timeline ↗