EU AI Act: what applies today to an ordinary company
Since 2 August 2026 you have to make clear when a customer is talking to AI or looking at AI-generated imagery. The heavy duties for high-risk systems have been deferred to December 2027. Here is what that means for a company that uses AI but does not build it.
What already applies today
The regulation arrived in pieces, which is exactly why there is so much confusion about it. Here is what is genuinely on the table for an ordinary company.
- Prohibited practices, since 2 February 2025.Social scoring, and inferring emotions of workers in the workplace or pupils in the classroom. The Digital Omnibus added new prohibitions on top, with a transition period until 2 December 2026.
- AI literacy, since 2 February 2025.Anyone deploying AI has to make sure the people working with it understand well enough what they are doing. The law prescribes no particular course and no certificate, but you do have to show you did something about it.
- Transparency, since 2 August 2026.This is the part that reaches an ordinary company fastest, and it is set out separately below.
- General-purpose AI models, since 2 August 2025.Those duties sit with whoever builds the model. If you use Claude, ChatGPT or Gemini, the maker carries that part, not you.
What was deferred, and what that does not mean
Regulation (EU) 2026/1744, the Digital Omnibus on AI, appeared in the Official Journal on 24 July 2026 and entered into force three days later. It pushes back the heaviest duties.
- High-risk systems under Annex IIImove from 2 August 2026 to 2 December 2027. That is the category covering AI for recruitment, credit scoring or access to services.
- High-risk AI inside regulated products, Annex I,moves from 2 August 2027 to 2 August 2028.
Deferred is not cancelled. Anyone buying or commissioning such a system today is buying something that has to meet those requirements in eighteen months, which is usually exactly how long a project like that runs. And note: the transparency rules did not move.
The four situations where Article 50 reaches you
Article 50 bans nothing. It asks that people know a machine is involved. These are the four cases a smaller company actually runs into.
- A chatbot or AI voice talking to your customers.It has to make clear there is no human on the other side, unless that is obvious to everyone. Check that your supplier provides that notice and that it did not disappear when the bot was restyled in your brand.
- AI images, AI audio and AI video.These need machine-readable marking. That duty sits with whoever makes the tool, but you have to check that your tool does it and that the marking survives export or compression.
- Material that imitates real people, places or events.If you publish it, you have to state yourself that it was generated. That duty is entirely yours as the publisher, not your tool’s.
- Text about matters of public interest.What you publish to inform the public has to be recognisable as AI-written, unless a human reviewed it editorially and takes responsibility for it. For most marketing teams that comes down to writing that process down once.
Article 50 also covers systems that recognise emotions or categorise people biometrically. If you use those, you have to inform the person concerned.
What you can settle this month
None of these five needs a lawyer or a project. Together they cover most of what a company that uses AI has to be able to show today.
- List where AI is already being used.Including the free things people installed themselves. You cannot govern what you do not know is running.
- Put one rule in writing for customer contact.What you say when AI writes or speaks, and who decides that.
- Mark AI imagery and AI video in your communication.One fixed wording is enough, as long as it is always there.
- Ask your software supplier what sits under the bonnet.Which model, which role they take on under the regulation, and what they mark.
- Make sure whoever works with AI knows what the model can and cannot do.That is Article 4, and it is also the difference between saved time and an expensive mistake.
What doing nothing costs
Breaches of Article 50 sit in the middle tier: up to 15 million euro or 3 per cent of worldwide annual turnover, whichever is higher. The 35 million or 7 per cent figure everyone quotes is reserved for the prohibited practices in Article 5. For small and medium-sized companies the lower of the two amounts applies, not the higher one.
That is the argument we find least interesting, by the way. The first time this really hurts is usually a customer noticing they were talking to a machine without being told.
The timeline at a glance
| Date | What applies from then |
|---|---|
| 2 February 2025 | The prohibited practices in Article 5 and the AI literacy duty in Article 4. |
| 2 August 2025 | The rules for general-purpose AI models and the enforcement structure. |
| 2 August 2026 | The transparency duty in Article 50. Not deferred. |
| 2 December 2026 | End of the transition period for the prohibitions added by the Digital Omnibus. |
| 2 December 2027 | High-risk systems under Annex III, moved from 2 August 2026. |
| 2 August 2028 | High-risk AI in regulated products, Annex I, moved from 2 August 2027. |
This is not legal advice
We are not a law firm. This page sums up what the regulation says and when it starts to apply, so you know which questions to put to your lawyer. For an actual case, go to someone who is insured for that.
Frequently asked questions
Yes. The duties follow what you do with AI, not how many people you employ. Documentation requirements are lighter for small companies, and the lower cap applies to fines.
No, not if you only use AI. Registration in the EU database is for whoever places a high-risk system on the market themselves.
Yes, since 2 February 2025, through Article 4. The law prescribes no particular training or certificate. You have to be able to show that the people working with AI know what they are doing.
They carry the provider duties, you carry the deployer duties. In practice: use it as intended, have people who understand it, and be transparent towards your customers.
No. Only the high-risk duties. The prohibitions, AI literacy, the rules for general-purpose models and the Article 50 transparency all stay in place.
The transparency duty is about people confronted with the output. If everything stays in house there is nobody to inform, but the prohibitions and AI literacy apply in full. Inferring emotions from your own staff is exactly what is prohibited.