The AI Act application dates: what applies from when
The regulation does not have one start date but several. The ban on nine AI practices and the AI literacy rule have applied since 2 February 2025. Since 2 August 2026 the regulation applies as a whole, including the transparency obligation: your customer must know at the latest at the first interaction that they are talking to AI. The rules for high-risk systems follow on 2 December 2027, and for AI in physical products on 2 August 2028.
Published on
One regulation, several start dates
The AI Act is a single law, but it did not take effect on a single day. Article 113 says so itself: the regulation enters into force on the twentieth day following its publication in the Official Journal of the European Union, and applies from 2 August 2026. That is the headline date. Around it sit earlier and later dates for separate parts of the same law.
That makes the question "does the AI Act already apply to me?" unanswerable in that form. The useful question is: which obligation, and from when. For an SME using AI for email, WhatsApp or the phone, three things matter: the ban on certain practices, the duty around AI literacy, and the transparency obligation. Those three did not start on the same day, and the last one is the only one that visibly changes your day-to-day customer communication.
The phased rollout is a deliberate choice by the legislator. What can harm people directly — the prohibited practices — had to go quickly. What requires an entire conformity system, such as the rules for high-risk systems with technical documentation, standards and supervisory bodies, was given extra years. In between sits the transparency obligation: no conformity system is needed for it, but companies did need time to adjust systems and scripts.
Something else explains the order: the regulation is risk-based. The higher the risk to people or to society, the stricter the rules. Systems with unacceptable risk are prohibited, high-risk systems must meet heavy requirements, systems with transparency risk must identify themselves, and the rest falls outside the regulation. That order of severity is roughly the order in which the rules took effect: first the ban, then transparency, and the high-risk regime last.
What came first: the prohibited practices
The first obligations took effect on 2 February 2025. Those were the prohibitions and the rule on AI literacy. So this part already applied a year and a half before the regulation as a whole became applicable.
The European Commission lists nine prohibited practices. Among them: harmful AI-based manipulation and deception, harmful AI-based exploitation of vulnerabilities, social scoring, and risk assessment or prediction of individual criminal behaviour. For an employer, one stands out: measuring the emotions of employees in the workplace. That ban has one exception, written into the prohibition itself: Article 5(1)(f) allows use intended for medical or safety reasons.
A prohibition works differently from the rules you are used to in privacy law. Under the GDPR you pick a lawful basis and may then process. With a prohibition there is no basis. Consent from your staff does not help, a data processing agreement does not help, and a careful balancing exercise does not help either. What does count is whether you fall under the exception written into the prohibition itself; outside it, it is simply not allowed.
That is more relevant than it sounds, because products sold as "sentiment analysis on your team", "mood measurement in the call centre" or "engagement monitoring" operate in exactly that territory. If a vendor offers you something like that on top of an AI customer assistant, it is not an extra module but a separate legal decision — and usually one you are not allowed to take.
AI literacy has applied since the same day
On that same 2 February 2025, Article 4 took effect: AI literacy. The current text says that providers and deployers of AI systems take measures to support the development of AI literacy of their staff and other persons operating and using AI systems on their behalf, taking into account their knowledge and experience.
Note the word "support". The original 2024 text asked you to ensure a sufficient level of AI literacy. That wording was softened by the Digital Omnibus — Regulation (EU) 2026/1744, in force on 27 July 2026. Anyone reading an explainer today that quotes the 2024 text is reading outdated law. In practice the difference matters: you must get your people up to speed, but you do not have to run an exam or guarantee a fixed level of knowledge.
What you do instead need not be big. For a company with a handful of people on customer service, a short internal instruction covering four things is enough: which AI system is running, what it may and may not handle on its own, where a colleague takes over the conversation, and how to spot an answer that looks confident but is wrong. Put it on paper and date it. Not because the law prescribes a document, but because otherwise you cannot show two years from now that you did anything.
What changed on 2 August 2026
On 2 August 2026 the regulation became applicable as a whole. For an ordinary SME that is above all the day the transparency obligation started to apply. The Dutch data protection authority summarised it for the public like this: more and more organisations use AI for their customer service, and from 2 August it must be clear when someone is communicating with an AI assistant rather than a human. The regulator itself gives calling a GP practice and chatting with a webshop as examples. So this is not a theoretical provision for tech companies; it is about precisely the channels an SME uses AI in.
Article 50 also determines when that notice must appear. The information is provided to the natural persons concerned in a clear and distinguishable manner at the latest at the time of the first interaction or exposure. Two words carry the weight there: "latest" and "first". A line in your privacy statement is too late. An answer to the question "are you a robot?" is too late. The notice belongs there before or while the customer reads or hears the system's first reply.
Per channel that means something different:
- Chat on your site: the first line the visitor sees, not a tooltip behind an information icon.
- Email: recognisable in the message itself, not only in the signature at the bottom of a long thread.
- WhatsApp: in the first message of the conversation, and again when a new conversation starts after a longer gap.
- Phone: in the opening line, before the caller states their question. In a sales call a separate statutory opening line is added on top, because there you must also say straight away who you are, on whose behalf you are calling and that the purpose is to sell something.
Why the date matters: from the moment a provision applies, a supervisor can hold you to it. Before 2 August 2026, an AI customer assistant that did not identify itself was undesirable, but not in breach of this article. After that date it was. That is the difference between a recommendation and an obligation, and that difference sits precisely in a date. For the prohibitions that moment came a year and a half earlier.
There is a second side to Article 50 that is often skipped: AI-generated content must be recognisable as such. That affects you as soon as you have AI produce text or images you publish, not only when you have AI answer questions.
When do the rules for high-risk systems start?
The heaviest requirements in the regulation apply to high-risk systems. They come last, and the dates have recently moved. The European Commission now writes that the rules for high-risk AI systems will apply starting 2 December 2027, and that the rules on AI embedded in physical products — medical devices, toys, lifts — will apply starting 2 August 2028.
That is new. A lot of Dutch-language guidance still names 2 August 2027 as the high-risk date. Since the Digital Omnibus that is no longer correct. If you hear an adviser or a vendor talk about August 2027, you know immediately that their information predates 27 July 2026 — and then the question is which other parts of their story also come from the old text.
The reason for the postponement is not hard to guess: high-risk rules require technical standards, assessments and bodies able to carry them out. That system has to exist before you can hold companies to it. A transparency obligation does not have that problem — one sentence at the start of a conversation needs no assessment body.
Important to know: postponing the high-risk rules is not postponing the rest. The prohibitions, AI literacy and the transparency obligation simply continue to apply. They did not move along to 2027.
For the average SME the customer assistant itself is rarely high risk. The category is a list, not a feeling: Annex III to the regulation names the areas. The most likely path by which an ordinary company still ends up there is not customer contact but personnel — AI that filters job applications or scores candidates falls under that list. Anyone with plans in that direction still has room to set it up properly now, and will not have that room a year from now.
The timeline in one view
| Date | What applies from then | Who notices it |
|---|---|---|
| 2 February 2025 | Ban on nine AI practices and the obligation around AI literacy | Anyone providing or professionally using AI, even without customer contact |
| 27 July 2026 | The Digital Omnibus amends the regulation: Article 4 is softened and the high-risk dates move | Anyone relying on older guidance; the 2024 text is outdated in places |
| 2 August 2026 | The regulation becomes applicable, including the transparency obligation of Article 50 | Anyone letting customers chat, email or call with AI, and anyone publishing AI content |
| 2 December 2027 | The rules for high-risk AI systems start to apply | Anyone using AI in an Annex III area, such as recruitment and selection |
| 2 August 2028 | The rules for AI embedded in physical products start to apply | Manufacturers and anyone putting such products on the market under their own brand |
What you must have in place per phase
The first two phases are no longer a future concern. If you use AI for customer contact today, the following should already exist.
From the phase that started on 2 February 2025
- A list of the AI applications running in your business. Not only the chatbot: also the tool that summarises conversations, the assistant in your mailbox and the system that sorts incoming messages.
- A check of that list against the prohibitions. At a normal SME it comes down in practice to one question: am I measuring the emotions or mood of employees anywhere, outside medical or safety reasons?
- A short, dated instruction for the people who work with the system. That is how you fill in AI literacy.
From the phase that started on 2 August 2026
- A notice at the first interaction, in every channel where AI speaks on your behalf. Test it yourself: send a message as a customer and see whether it is there.
- Certainty that the notice cannot be switched off by accident. If it is a setting rather than a built-in property, it will get flipped at some point.
- Labelling of AI-generated content that you publish.
- Clarity about your own role. If you buy a system and use it under your own responsibility, you are a deployer and the heaviest part sits with the builder. If you put your own brand name on a high-risk system or modify it substantially, you shift into the provider role, with the obligations that come with it.
Preparation for December 2027
- Only relevant if you want to use AI in an Annex III area. For most companies that means recruitment and selection.
- Decide now who the provider is in that scenario, what gets recorded, and which human assesses the outcome. Retrofitting is far more expensive than agreeing it up front.
Three misunderstandings about the dates
"The AI Act only starts in 2027." No. That applies only to the high-risk rules. The ban on certain practices has applied since February 2025 and the transparency obligation since August 2026. Anyone waiting for 2027 is waiting for the part that probably does not affect them at all.
"The high-risk date is 2 August 2027." It was. Since the Digital Omnibus it is 2 December 2027 for Annex III systems and 2 August 2028 for AI in physical products.
"My vendor handles compliance." Partly. The heavy product obligations sit with the builder, but the duty to inform your customer at the first interaction sits with whoever deploys the system. That is you. A vendor can supply the switch; whether it is on in your channel is your responsibility.
How to check this in half an hour
You do not need a lawyer to get started. Walk through these five steps and note what you find at each one:
- Write down which AI runs in your business and in which channel customers encounter it.
- Send yourself a message as a customer in each channel. Is the notice there, and is it there immediately?
- Look in your contract to see whether the vendor calls itself a provider, and whether you are designated anywhere as a deployer.
- Check whether you measure staff emotions or mood anywhere. If so: switch it off, unless that use is intended for medical or safety reasons — that is the only exception the prohibition allows.
- Write one page of instructions for your team and put today's date on it.
That is the state of play per phase, with the dates as the legislator and the supervisors publish them. This article is not legal advice. The regulation has already been amended since it came in and that can happen again; before any concrete decision, check the current text of the articles named above.