AI Act Timeline: What Businesses Using Chatbots Should Do First
The AI Act entered into force on 1 August 2024. Its duties, though, will apply in stages, and if you run a website chatbot the date to circle is 2 August 2026. That’s the AI Act timeline in a nutshell, based on the Commission’s announcement of the entry into force. Where should a small business begin? Three things: list where AI is used, brief staff, and plan how the bot will disclose that it is automated. What follows is a practical overview, not legal advice.
What does the AI Act entry into force change in August 2024?
Entry into force starts the clock. It does not switch on every obligation at once. The regulation was proposed in April 2021 and agreed by the European Parliament and the Council in December 2023, and it creates one uniform framework across all EU countries, as the Commission’s summary of the new law explains. People mix up two terms here all the time. “In force” means the text is now binding law with fixed deadlines. “Applicable” means a specific duty can actually be demanded from you, and that moment arrives later, rule by rule.
So a small company gets real time to prepare. Using it well is a different matter. An inventory of tools, a staff briefing and a change to the chat widget are easy tasks when spread over months, and stressful ones when squeezed into the final weeks. And suppliers will be busier closer to each deadline (they always are), so questions sent early get better answers.
The AI Act timeline: which dates matter for a chatbot owner
Three upcoming dates structure the rollout. Only one of them targets chatbots directly. They are set out on the Commission’s page on the AI regulatory framework:
- 2 February 2025 - the ban on prohibited practices and the AI literacy duty will apply. This concerns every company that uses AI, whatever its size.
- 2 August 2025 - rules for general-purpose AI models will apply. These address the providers of such models, not the firms that simply use products built on them.
- 2 August 2026 - most remaining rules will apply, including the transparency duty for chatbots. This one concerns any business running a bot that talks to people.
For a customer-service bot, the last entry is the main deadline: it is the chatbot transparency obligation date. But don’t skip the first one. It comes soonest and it covers staff rather than software. The middle date? Mostly something to follow through your vendor.
How the risk-based approach works in plain words
The more harm an AI use can cause, the stricter the rules. Most everyday tools sit at the lighter end. At the top are practices that will be banned outright. Below them come high-risk uses, which carry heavy requirements before a system can be offered or deployed. Then there is specific transparency risk, where the main duty is to tell people what they are dealing with. And at the bottom, minimal risk, where the regulation adds no new obligations.
What decides the tier is the use, not the tech under the hood. The same language model can power a harmless FAQ assistant or a tool that makes decisions about people, and those two land in different places. Your job is simply to locate your own chatbot on this scale.
What the AI Act means for chatbots on a company website
A typical customer-service chatbot falls under transparency obligations: users must know they are talking to a machine. The Commission names chatbots as its example of specific transparency risk, so there is not much room to argue about where an ordinary support assistant belongs. A bot that answers visitors’ questions from the company’s own documents? Textbook case. No tool settles the matter for you, though - the duty rests on how the business presents and runs it.
In practice it all comes down to the notice itself: where it appears, how it is phrased, and whether a visitor sees it before typing. The wording for telling customers about the bot is a topic of its own and is not covered here. For now, knowing that a notice will be required and reserving time for it is enough.
Disclosure has limits, too. Informing someone that an answer came from software does not decide who pays for wrong answers. That remains a separate question for your terms, your content and your review process.
First steps for small businesses: what to do now
Inventory first. Then staff awareness, then a disclosure plan. The sequence looks like this:
- List every place AI is used: the website chatbot, content tools, and features built into software you already pay for.
- Note for each tool what it does and who talks to it - customers, employees or both.
- Pick one person responsible for keeping that record current.
- Draft where and how the chatbot will say it is automated.
- Ask suppliers how they are preparing for the regulation.
The AI Act for small businesses does not have to mean a compliance project. Keep the record simple. A one-page list is enough to begin with, and it can grow as tools are added. Planning to extend automation beyond text chat? Write the planned channels down as well, and weigh the considerations before integrating voicebots early, since a spoken assistant raises the same disclosure question in a different form.
The AI literacy obligation: what staff need to understand
From 2 February 2025, companies will need to make sure people working with AI understand it well enough for their role. Sounds grand. In a small team it is modest and concrete: employees should know what the chatbot can and cannot answer, where its replies come from, when to check them, and how to react when a customer complains about something it said.
A short internal note or a team briefing is a sensible format, in my view. Date it, store it next to the inventory, and update it whenever a tool is added or changed. Someone who joins later should be able to read it in a few minutes and know the rules of the house.
The AI Act timeline in one sentence, then: the law is in force now, literacy and the bans will apply from February 2025, model rules from August 2025, and chatbot transparency from August 2026. First steps are an inventory of AI use, a staff briefing and a plan for the disclosure notice. None of this is legal advice, so take doubtful cases to a lawyer.
FAQ
Does the AI Act already apply to my website chatbot?
Yes and no. The regulation has been in force since 1 August 2024, but the transparency duty for chatbots will apply from 2 August 2026. Until then the notice is not yet required under this law. Preparation can start now, and the inventory is the easiest place to begin.
Is a customer-service chatbot a high-risk AI system?
Typically not. A typical support bot falls under transparency obligations rather than the high-risk tier. But classification depends on what the system is used for, so an assistant doing more than answering questions may be assessed differently. In doubtful cases, check with a lawyer.
What should a small business do first under the AI Act?
Make a list of every place AI is used in the company. Next, brief staff ahead of February 2025 so they understand the tools they work with. Then plan how the chatbot will tell users they are talking to a machine.
Related posts
Feeding a Chatbot With PDFs and FAQs: How to Prepare Sources That Actually Answer
Why Your Chatbot Sounds Confident but Gets Things Wrong Most bot deployments that flop don’t flop at the model layer. They flop…
Multilingual Chatbots: What Changes When You Add a Second Language
Adding a second language to a chatbot looks like a config change. Flip a setting, wire in a translation layer, done. Then…
Chatbot Liability: Who Pays When Your Bot Gives a Wrong Answer
Short answer: in most cases, chatbot liability lands on the business running the bot on its website. And that makes sense. Customers…