regulacyjna · 10 min czytania ·

AI Act — Implementation Timeline 2025-2027 and What Applies to Polish SMEs When

Regulation 2024/1689 (AI Act) comes into force in phases 2025-2027. A deadline map per article — prohibited practices, GPAI, high-risk systems, fines up to EUR 35 million. What applies when and how it affects SMEs.

A Regulation That Came Into Force in Phases — Not on a Single Day

Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 — the AI Act — was published in the Official Journal of the EU on 12 July 2024 and entered into force on 1 August 2024. That is twenty days after publication, in accordance with Article 113 of the Regulation.

Entry into force, however, does not mean all provisions apply immediately. The AI Act has one of the most elaborate phased implementation maps in the history of EU law — different groups of obligations start at four separate dates between February 2025 and August 2027. For a Polish SME that wants to know exactly when it needs to be compliant, this map is the starting point for any compliance plan.

In this article we break down the calendar into four phases, link each phase to specific articles of the Regulation, and explain what each deadline means in operational practice.

Phase 1 — 2 February 2025: Prohibited Practices

The first group of obligations came into force on 2 February 2025 — six months after the Regulation entered into force, pursuant to Article 113(a). It concerns Article 5 — the catalogue of AI practices prohibited across the EU.

The list of prohibited practices under Article 5 includes:

  • subliminal or manipulative techniques that influence a person’s behaviour in a way that causes harm (point a);
  • exploitation of vulnerabilities arising from age, disability or socio-economic situation (point b);
  • social scoring by public or private entities leading to unjustified unfavourable treatment (point c);
  • assessment of the risk of a person committing a crime based solely on profiling (point d);
  • mass scraping of facial images from the internet or CCTV to build facial recognition databases (point e);
  • emotion recognition in the workplace and in educational institutions — with narrow medical and safety exceptions (point f);
  • biometric categorisation of individuals to infer race, political opinions, religious beliefs or sexual orientation (point g);
  • real-time remote biometric identification in publicly accessible spaces for law enforcement purposes — with very narrow exceptions (point h).

For SMEs, points (f) and (g) are most relevant — because they cover solutions increasingly appearing in SaaS products for HR, marketing and call centres. If you use a tool that “detects customer mood” or “classifies an employee by voice characteristics” — this area requires immediate verification.

Financial penalties for breaching Article 5 are the highest in the entire Regulation — see the section on Article 99 below.

Phase 2 — 2 August 2025: GPAI and Governance

The second wave of obligations came into force on 2 August 2025 — twelve months after the Regulation entered into force. It covers three areas:

  • Chapter V — obligations for providers of general-purpose AI models (GPAI, Arts. 51–55);
  • Chapter VII — governance at EU and Member State level (AI Office, national supervisory authorities);
  • Chapter XII — penalties (Arts. 99–101) — in the scope relating to prohibited practices and GPAI.

GPAI refers to foundation models — in practice this concerns providers such as OpenAI, Anthropic, Google, Mistral, Meta. Polish SMEs are rarely GPAI providers — they are most commonly their customers through an API or embedded product. But Article 53 imposes obligations on GPAI providers regarding:

  • technical documentation of the model, including training and evaluation processes (Art. 53(1)(a));
  • information for downstream providers — i.e. your company, if you build on their model (point b);
  • compliance with copyright law (point c);
  • publication of a sufficiently detailed summary of training data (point d).

From an SME deployer perspective this means one practical thing — from August 2025 GPAI providers must make documentation available that they did not previously share. This opens a genuine possibility of auditing third-party AI in the stack.

The national supervisory authority in Poland — pursuant to Article 70 — must be designated by the Member State. At the time this article was published, the implementing legislation was progressing through the Sejm.

Phase 3 — 2 August 2026: High-Risk and the Bulk of the Regulation

This is the most important deadline on the entire map. On 2 August 2026 — twenty-four months after the Regulation entered into force — the bulk of the Regulation begins to apply, including the most substantial Chapter III on high-risk AI systems.

High-risk systems are listed in Article 6 and in Annex III, which enumerates eight areas:

  • biometrics (categorisation, emotion recognition outside prohibited areas);
  • critical infrastructure (traffic management, energy, water);
  • education and vocational training (admission, scoring, exam monitoring);
  • employment and HR (recruitment, performance assessment, task allocation);
  • access to essential public and private services (credit scoring, insurance, social benefits, emergency call classification);
  • law enforcement;
  • migration, asylum and border control;
  • justice and democratic processes.

For a Polish SME this means obligations under Arts. 8–22 — including a risk management system (Art. 9), data governance (Art. 10), technical documentation (Art. 11), logging (Art. 12), transparency towards the deployer (Art. 13), human oversight (Art. 14), accuracy and robustness (Art. 15), and conformity assessment (Art. 43).

A detailed breakdown of the high-risk categories is available in the dedicated article AI Act — When Does a Polish SME Become a High-Risk AI System Provider.

Phase 4 — 2 August 2027: Remaining Systems

The final deadline — 2 August 2027 — concerns high-risk systems that are safety components of products already covered by existing EU harmonisation legislation (e.g. the Machinery Directive, medical devices, aviation). The list of these acts is in Annex I of the AI Act.

For this group of providers, the Regulation allows an additional year to adapt — because their products already undergo certification procedures (CE marking) and these must be integrated with the new AI Act requirements. Most Polish SMEs do not fall into this category — unless they manufacture medical, mechanical or electronic hardware with an AI component.

Penalties — Article 99

Financial sanctions for AI Act violations are tiered. Article 99(3)–(5) defines three levels:

InfringementMaximum penalty
Prohibited practices (Art. 5)EUR 35 million or 7% of total worldwide annual turnover — whichever is higher
Breach of obligations relating to high-risk systems and GPAIEUR 15 million or 3% of turnover
Supply of incorrect, incomplete or misleading information to supervisory authoritiesEUR 7.5 million or 1% of turnover

For SMEs, Article 99(6) additionally introduces a proportionality principle — a penalty for an SME or startup is the lower of the two values (percentage of turnover or fixed amount), not the higher. This is a meaningful distinction, but not an exemption from liability.

Three Things for an SME to Do in 2026

From the perspective of the CTO and Board of a Polish SME — regardless of industry — the 2025–2027 calendar boils down to three operational actions in the current year:

First — check whether you are using any prohibited practices. Phase 1 is already in force. If your HR tool has an “emotion detection during recruitment interview” function, or if your CRM classifies customers by biometric characteristics — this is a potential Article 5 risk right now. An AI stack inventory is the first step.

Second — classify AI systems per Annex III. August 2026 is closer than it appears. Every AI system in the organisation should be assigned to one of three categories — prohibited, high-risk, or limited/minimal risk. Classification determines the scope of obligations per system.

Third — start with mapping, not with tools. Most SMEs do not need a six-figure GRC platform. They need an AI systems register, a risk register, and a procedure for classifying new systems at the point of purchase. These three artefacts can be maintained in a spreadsheet and Confluence for the first twelve months — with migration to a dedicated tool only when the scale requires it.

QA10 — Where We Check This

Within the AiP Audit we map the client’s AI stack against the 2025–2027 calendar and identify which systems require action before August 2026. This is not a legal report — it is an operational task list for the CTO and Compliance.

NEWSLETTER // MONTHLY AI DIGEST FOR BUSINESS

What next // you read the article · time to talk?

Do these topics apply to your company?

30 minutes with the CEO. No sales rep. We will check together whether what you read applies to you.

Book a call with the CEO Check ROI calculator
Paleta poleceń
  • Strona główna/
  • Kontakt/kontakt/
  • Kalkulator ROI/kalkulator/
  • Audyt AiP/audyt-aip/
  • QDeployment/qdeployment/
  • QCare/qcare/
  • Pełen proces/proces/
  • MenToR — AI dla uczelni/mentor/
  • Engineering Lab/engineering-lab/
  • Venture Projects/projekty/
  • O nas/o-nas/
  • Case Studies/case-studies/
  • Baza wiedzy/baza-wiedzy/
  • Umów diagnostykę 30 min/kontakt/#booking
  • Oblicz ROI/kalkulator/
  • Kalkulator Dig.IT/kalkulator/
  • dlaNGO MVP demo/projekty/#dlango-mvp
  • LSO:ATOM/o-nas/#lso-atom
  • FAQ /projekty//projekty/#faq
CtrlK|Esc|Enter19