The EU AI Act doesn't switch on all at once. It arrives in waves — and in 2026 the EU moved some of the dates. If you run a small organisation, the honest question isn't "are we compliant?" It's "what has actually started, what starts next, and which parts don't touch us for years?" This is the plain-English answer.
This is a map, not a legal opinion. It's written for people who run charities and small nonprofits, not for lawyers — so you can see the shape of the timeline, work out which parts realistically apply to you, and stop worrying about the parts that don't.
This article is general information, not legal advice. It does not constitute legal advice, Vedomia does not certify compliance, and nothing here guarantees legal conformity. Dates and details of the AI Act are still settling and can change; for your specific situation, speak to a qualified solicitor.
Why the timeline changed in 2026
When the AI Act was first published, its obligations were spread across dates from February 2025 to August 2027. But in November 2025 the European Commission published a simplification package known informally as the "Digital Omnibus," and in June 2026 the European Parliament and the Council gave it their final approval. Among other things, it pushed the biggest and most demanding obligations — the ones for "high-risk" AI — further into the future.
The practical effect for a small charity is reassuring: the parts most likely to be heavy lifting were delayed, while the parts most likely to touch your everyday work — transparency when people interact with AI — stayed on their original date. Let's walk through it in order.
Already in force: 2 February 2025
Two obligations have applied since early 2025. They are live now.
- Prohibited practices (Article 5). A short list of AI uses that are simply banned in the EU — for example social scoring, and certain manipulative or exploitative systems. Most charities never go near these, but it's worth knowing the banned list exists. (The 2026 update also added a ban on AI used to create non-consensual intimate imagery, with a transition period running to December 2026.)
- AI literacy (Article 4). The duty to make sure the people using AI on your behalf understand it well enough for the tools and risks involved. The 2026 update softened the wording — the emphasis is now on supporting your people's understanding rather than guaranteeing a fixed level — but the practical expectation is unchanged: don't let staff and volunteers use AI blind, and keep a simple record that you took it seriously. We cover this in detail in our guide to Article 4.
The two obligations already in force are the two most within reach for a small organisation: know what's banned, and make sure your people understand the AI they use.
Already in force: 2 August 2025
From August 2025, two more pieces clicked into place — though neither is a day-to-day task for most charities:
- Rules for general-purpose AI models (Articles 51–56). These land on the makers of large models — the companies behind the big chatbots and AI engines — not on the organisations that simply use them. As a charity, you are a user of these tools, so this obligation sits with your suppliers, not with you.
- The governance and enforcement machinery. Each member state designated its national authorities, and the EU's AI Office moved into its supervisory role. This is the plumbing that will oversee everything else.
The one to plan for: 2 August 2026
This is the date most likely to matter to an ordinary charity, because it's about transparency when people meet AI — and it stayed put when the harder obligations moved.
From 2 August 2026, the transparency obligations in Article 50 apply. In plain terms, they mean:
- If people interact with an AI system — such as a chatbot — they must be told they're dealing with AI, unless it's obvious, at the point of first interaction.
- If you publish AI-generated or AI-manipulated content that could mislead — including "deepfake" images, audio or video — you must disclose that it's artificial.
- Providers of tools that generate synthetic content must mark that content so it's detectable as AI-generated (a machine-readable "watermark"). This sits mostly with the tool makers, and content already on the market has a short grace period into December 2026.
For a charity, the honest self-check is simple: do we run a chatbot or AI assistant that talks to the public? Do we ever post AI-generated images or video that a reasonable person might take as real? If yes, August 2026 is your cue to add a clear line of disclosure. If no, this obligation may not touch you at all — but knowing that for certain is itself worth the ten minutes.
Pushed back: high-risk systems (2027 and 2028)
The heaviest obligations in the AI Act apply to "high-risk" systems — AI used in sensitive areas such as employment decisions, access to essential services, education, or the handling of vulnerable people. These carry the demanding requirements: risk management, data governance, logging, documentation, and formal human oversight.
The 2026 Digital Omnibus moved these dates:
- 2 December 2027 — for stand-alone high-risk systems (the "Annex III" category). Previously this was 2 August 2026.
- 2 August 2028 — for AI built into already-regulated products such as medical devices or machinery (the "Annex I" category).
Does this apply to you? Most small charities do not build high-risk AI. But you might use one — for example, if you adopt an AI tool that scores or ranks people for a service, a job, or support. If any AI you use helps make a significant decision about a person, that's the corner of the Act to watch, and the extra time to 2027 is genuinely useful breathing room. It is not, however, a reason to look away — the systems you'd need to document take longer to build than the deadline suggests.
The timeline at a glance
EU AI Act — key dates for charities
| Date | What applies | Likely relevance to a small charity |
|---|---|---|
| 2 Feb 2025 in force |
Prohibited practices (Art. 5); AI literacy (Art. 4) | High — know the banned list; make sure your people understand the AI they use, and record it |
| 2 Aug 2025 in force |
General-purpose AI model rules; national authorities & governance | Low — sits with the tool makers, not with you as a user |
| 2 Aug 2026 | Transparency obligations (Art. 50) — AI disclosure, labelling AI-generated content | High if you run a public chatbot or post AI-generated media; check now |
| 2 Dec 2027 | High-risk stand-alone systems (Annex III) | Medium — matters if you use AI to make significant decisions about people |
| 2 Aug 2028 | High-risk AI inside regulated products (Annex I) | Low for most charities |
Simplified overview based on the AI Act as amended in 2026. Not legal advice; confirm specifics for your situation.
The one-line takeaway: the parts already in force (literacy, prohibited uses) are the ones a small charity can act on today; the part to prepare for is August 2026 transparency; and the heavy high-risk rules were pushed to 2027–2028. Sort your response in that order.
What a charity can actually do this quarter
You don't need a compliance department. You need one honest inventory and a few short decisions.
1. Write down where AI already lives in your organisation
One row per use: the tool, who uses it, and what for — including AI features hidden inside your CRM, email or design software. Almost every obligation above starts from this single list, and it's the one thing only you can produce.
2. Flag anything public-facing
Mark which of those uses talk to the public or produce content people see — a chatbot, an AI email responder, AI-generated images. Those are your August 2026 transparency candidates.
3. Flag anything that decides about a person
Mark any AI that scores, ranks, filters or prioritises people. Those are your high-risk candidates to watch toward 2027 — and, separately, they may already engage data-protection duties today.
4. Keep the list — and a date
Store the inventory where your governance records live, with the date you last reviewed it. When someone asks what you've done about the AI Act, this list is your answer.
How Vedomia can help
Vedomia is an Irish company focused on one thing: helping organisations make their processes and their use of AI visible, explainable and auditable. We work mainly with charities, nonprofits and publicly funded organisations.
Every date on this timeline starts from the same foundation — knowing exactly where AI lives in your organisation, and being able to show it. That's where we start.
- Transparency Self-Audit (free). Around 20 questions across four pillars — Visibility, Sequence, Justification, Auditability. It helps you surface where AI is used, where people meet it, and where your evidence is thin.
- Mapped with you (€1,450, one-off). A single 90-minute session: you describe how one key process really runs, Sandra maps it live, and you leave with a finished, official document — the process end to end, where AI enters it, the evidence to keep and a prioritised 30–90 day plan. No homework, and it begins with a free Clarity Call.
To be clear about what we do and don't do: Vedomia supports readiness, helps you document your AI use, and identifies transparency gaps. We do not certify compliance, and nothing we provide guarantees legal conformity. This is not legal advice.
The AI Act is easier to face as a timeline than as a wall. Most of it either doesn't touch a small charity or hasn't started yet — and the parts that have are the ones you can handle in an afternoon.
This article is general information about the EU AI Act and does not constitute legal advice.
Prepared with the help of an AI assistant, reviewed by Sandra Fedakova.
Want to see where AI is used across your organisation — and where the gaps are?
Take the Free Transparency Self-Audit