EU AI Act in 2026: What Your Company Must Comply With Now
· CompaniesAutomation
Transparency, AI literacy and GPAI rules already bite; high-risk moved to 2027. The verified August 2026 timeline and a 90-day compliance plan for an SME.
EU AI Act obligations for companies in 2026 are no longer a future problem. If your business uses AI in the EU, three blocks already apply: the banned practices and the AI literacy duty since 2 February 2025, the general-purpose AI (GPAI) model rules since 2 August 2025, and the Article 50 transparency duties since 2 August 2026. What was postponed by the AI Digital Omnibus, published in the Official Journal on 24 July 2026, is the high-risk regime — not the rest.
That confusion is now the biggest practical risk. Since July, the idea that "Europe has delayed the AI Act" has spread, and we have watched boards shelve the file because of it. We run our own businesses with AI agents in production and had to do this work for ourselves first. This is the map we use, with dates verified as of 11 August 2026 and anything unconfirmed flagged as such.
Which AI Act obligations already apply in August 2026?
The banned practices, the AI literacy duty, the GPAI model obligations and — since 2 August 2026 — the Article 50 transparency duties all apply today. What does not apply yet is the high-risk regime, pushed to December 2027 and August 2028 depending on the category. The timeline, after Regulation (EU) 2026/1744 (the AI Digital Omnibus), looks like this:
| Date | What applies | Who it hits |
|---|---|---|
| 2 Feb 2025 | Prohibited practices (Art. 5) and AI literacy (Art. 4) | Providers and deploying companies |
| 2 Aug 2025 | General-purpose AI model obligations and governance structure | Model providers |
| 2 Aug 2026 | Article 50 transparency; AI Office enforcement powers over GPAI | Deploying companies included |
| 2 Dec 2026 | End of the transition for marking synthetic content in systems already on the market | Generative AI providers |
| 2 Dec 2027 | Annex III high-risk: HR, education, credit, critical infrastructure (was 2 Aug 2026) | Providers and deployers |
| 2 Aug 2028 | High-risk embedded in regulated products (Annex I) | Product manufacturers |
If your company does not build models or sell AI systems, your focus is the 2 August 2026 row and the 2 February 2025 row. Those are the two that bind you as a deployer, and both are met with internal procedure rather than product lawyers.
What did the July 2026 Digital Omnibus actually change?
The AI Digital Omnibus postponed the high-risk system obligations and widened the AI Office's remit; it repealed nothing that was already enforceable. It was published in the Official Journal on 24 July 2026 and entered into force three days later, on 27 July 2026.
Three moves with real consequences:
- Stand-alone high-risk (Annex III) moves to 2 December 2027. This covers the uses that most affect an ordinary SME: CV screening and hiring decisions, credit scoring, student assessment. If you froze an AI recruiting project because of the 2 August 2026 deadline, you have 16 extra months to prepare it — not to ignore it.
- High-risk embedded in regulated products (Annex I) moves to 2 August 2028. This affects CE-marked manufacturers: machinery, medical devices, lifts, toys.
- Transparency untouched. Article 50 applies from 2 August 2026 on its original schedule. The only concession is a transition until 2 December 2026 for machine-readable marking of generated content, and only for systems already on the market before 2 August.
Bluntly: the high-risk delay changes nothing for the vast majority of European SMEs, because they do not operate high-risk systems. What does apply to them — transparency and literacy — is unchanged.
What is GPAI, and why does it matter if you only use ChatGPT or Claude?
GPAI means general-purpose AI models: the foundation models that serve many different tasks, such as those from OpenAI, Anthropic, Google, Meta or Mistral. Their obligations — technical documentation, copyright policy, a summary of training content and, for models with systemic risk, evaluation and incident reporting — sit with the model provider, not with you.
This produces two mirror-image mistakes. The first is assuming that using a GPAI model makes you a subject of that chapter: it does not, if you simply consume it through an API or a subscription. The second, more dangerous, is concluding that you therefore have no duties at all. You do — through Article 50, Article 4 and your contracts, because your provider's documentation is what underpins your own compliance file.
Since 2 August 2026 the AI Office can also fine GPAI providers directly up to 3% of worldwide annual turnover or €15 million, whichever is higher. That works in your favour: the documentation you need to request from your model vendor now has a real incentive to exist.
One boundary is worth being clear about: you shift from deployer to provider when you put your own brand on an AI system you distribute, when you substantially modify a high-risk system, or when you change its intended purpose. Running an internal assistant on someone else's model keeps you a deployer; packaging it and selling it under your name makes you the provider of that system. Our operating rule: if it leaves your organisation with your name on it, document it from day one.
What do the transparency rules require from 2 August 2026?
Article 50 exists so people know when they are dealing with AI or with AI-generated content. It splits duties between the system provider and the deployer — you, if you run it in your business — and these four are yours:
- AI interaction. If you run a chatbot, a voice agent or an assistant that talks to customers, the person must know they are not talking to a human, unless it is obvious. No legal notice required: identifying itself as an assistant at the start is enough.
- Deepfakes and manipulated content. If you publish AI-generated or manipulated image, audio or video that looks real, you must disclose it clearly and distinguishably. There is an exception for artistic, satirical or fictional work.
- Public-interest text. AI-generated text published to inform the public on matters of general interest — health, politics, environment, consumer safety — must be labelled. Key exception: the duty falls away where there is human review with editorial control and someone takes responsibility for the content.
- Emotion recognition and biometric categorisation. You must inform the people exposed to these systems. And note: emotion recognition in the workplace and in education has been outright prohibited since February 2025.
Our recommendation goes beyond the letter: in the agents we build, the AI disclosure is always explicit, even where the law would accept that it is "obvious". Transparency does not hurt conversion — a useless assistant does — and it removes the regulatory argument entirely.
The duty almost nobody has met: AI literacy
Since 2 February 2025, Article 4 requires that staff using AI systems have a sufficient level of competence, taking into account their training, the context of use and the people affected. It is the obligation with the lowest compliance cost and the highest non-compliance rate across European business.
There is no direct fine attached to Article 4, which is why it gets ignored. That is a miscalculation: when an authority investigates any other breach, the absence of training weighs on the penalty, and it is the first evidence requested because it is the easiest to check. It is also the only part of this regulation that pays for itself, which we cover in our guide to AI training for employees and its ROI.
Meeting it in an SME is affordable: initial training by role (leadership, sales, operations, admin), a written usage policy, an attendance record and an annual review. Realistic budget for a 20-50 person company: €1,500-6,000 in year one, depending on whether the training is generic or tailored to your processes.
What does non-compliance cost?
The penalty regime has three tiers: up to €35 million or 7% of worldwide turnover for prohibited practices; up to €15 million or 3% for most other obligations, transparency included; and up to €7.5 million or 1.5% for supplying incorrect information to authorities. For SMEs and start-ups, the lower of the two figures applies, not the higher.
These are theoretical ceilings and should be read as such: no European SME is getting a €15 million fine for failing to disclose that its chatbot is a chatbot. The near-term risk is different — information requests that eat weeks, B2B contracts that now carry AI Act compliance clauses, and public tenders that require it. National supervisory authorities and their sanctioning procedures were still being finalised in several member states in August 2026, so treat national deadlines as provisional.
A 90-day plan for an SME
- Inventory the AI in use. Official subscriptions, assistants embedded in your CRM or ERP, and whatever the team uses on its own. There is no compliance without an inventory, and it almost always turns up more than expected.
- Classify each use. Does it touch customers? Does it generate published content? Does it feed decisions about people (hiring, credit, assessment)? That third category is what puts you on the December 2027 clock.
- Close the transparency gaps. Review chatbots, voice agents and published content, and add the Article 50 disclosures where they are missing. This is days of work, not months.
- Training and usage policy. A session per role, a one-page document on what is and is not allowed, and an attendance record.
- Traceability and permissions. Every automated action logged, every agent on least privilege — the approach we set out in our guide to AI agent governance and permissions.
- Check where your data lives. The AI Act does not replace the GDPR: if you process personal or confidential data, architecture still matters, as we explain comparing on-premise versus cloud AI.
What the AI Act does not require
It does not require you to certify your tools, appoint an AI-specific DPO, commission external audits if you do not operate high-risk systems, or stop using US models. Nor does it require labelling a draft an employee generates with AI and then reviews and signs.
We say this because the "AI Act compliance" market has filled up with proposals that sell far more than is needed. For an SME using AI in marketing, customer service and admin, compliance fits into an inventory, four transparency notices, one training round and a written policy. If someone quotes you €30,000 for that, ask them to point at the specific article that requires it. And if you would rather work it through with a team that builds and runs these systems every week, that is how we operate as an AI consulting partner.
Frequently asked questions
Did the Digital Omnibus delay the whole AI Act?
No. Regulation (EU) 2026/1744 postponed the high-risk system obligations — Annex III to 2 December 2027 and product-embedded systems to 2 August 2028 — and adjusted some governance points. The prohibitions, AI literacy, GPAI rules and Article 50 transparency all kept their original dates.
If I use ChatGPT or Claude at work, do GPAI obligations apply to me?
Not as a model provider: those sit with OpenAI, Anthropic and their peers. As a deploying company you are covered by Article 4 literacy, Article 50 transparency where the output reaches third parties, and the GDPR for the data you feed in. Keep the documentation your provider publishes — it is the backbone of your own file.
Do I have to disclose that an email or a blog post was written by AI?
In ordinary commercial communication, no. The Article 50 labelling duty covers text published to inform the public on matters of general interest, and it falls away where there is human review with editorial control and someone answering for the content.
Is using AI in recruitment high-risk?
Yes: CV screening and hiring decisions sit in Annex III. The difference is that the regime now starts on 2 December 2027 rather than 2 August 2026. You can keep using it, but document human oversight and bias controls now — arriving at that date without a historical audit trail means redoing the work.
Who enforces this?
National market surveillance authorities in each member state, alongside existing sectoral regulators for data protection and financial services, plus the Commission's AI Office for general-purpose models. Several national enforcement frameworks were still in progress in August 2026, so treat national procedures and amounts as not yet settled.