The EU AI Act did not get postponed.
Some of its deadlines did. That distinction matters, because the rules most likely to affect an ordinary business using AI are already in force.
Since 2 August 2026, the transparency requirements in Article 50 apply across the EU. They cover situations such as customer-facing chatbots, certain AI-generated or manipulated content, emotion recognition and biometric categorisation.
The deadlines for many high-risk systems, including some used in recruitment, education and credit assessment, were pushed back to 2027 and 2028.
So if your business uses AI, the useful question is no longer simply whether the AI Act applies. It is which part applies to what you are doing, and when.
This guide covers the practical distinctions.
If you only read one section
For most businesses, these are the points worth checking first.
The rest of the article explains where those distinctions come from.
First, the dates
The AI Act is Regulation (EU) 2024/1689. It entered into force on 1 August 2024, but its requirements were never intended to apply all at once.
That phased timetable is one reason coverage of the Act can be confusing: an article can correctly say that one set of obligations has started while another has been delayed.
The regulation was also amended in July 2026 by Regulation (EU) 2026/1744, sometimes referred to as the Digital Omnibus. Among other changes, that amendment moved several deadlines for high-risk systems.
Here is the timetable that matters now.
1 Aug 2024
The AI Act entered into force
PastThis started the timetable for the various provisions that would become applicable over the following years.
2 Feb 2025
Prohibited AI practices and AI-literacy requirements became applicable
AppliesCertain uses of AI have been prohibited since this date, including social scoring, some forms of manipulative AI and particular biometric uses. Organisations also became responsible for taking appropriate measures to support AI literacy among the people who use AI systems on their behalf.
2 Aug 2025
Rules for general-purpose AI models and the penalty provisions became applicable
AppliesThese obligations are particularly relevant to the companies providing the large general-purpose models used by other AI products.
2 Aug 2026
The Article 50 transparency rules became applicable
Applies nowThis is the date that matters for many businesses using AI in ordinary commercial settings. Depending on the use, the rules can require people to be told that they are interacting with AI, require certain AI-generated content to carry technical markings, or require disclosure of particular types of generated or manipulated content.
2 Dec 2026
The transition period for machine-readable marking ends
ComingGenerative AI systems placed on the market before 2 August 2026 have until this date to implement the machine-readable marking requirement. This is a transition period for that particular technical obligation. It does not postpone the rest of Article 50. Two additional prohibited practices introduced by the July 2026 amendment also become applicable on this date: AI systems used to generate non-consensual intimate imagery and systems used to generate child sexual abuse material.
2 Feb 2027
Interoperability commitments under the Code of Practice reach their next milestone
ComingSignatories have committed to making content markings verifiable outside their own systems through mechanisms such as standardised APIs, embedded indicators or shared verification services.
2 Aug 2027
Older general-purpose AI models must comply
ComingThis deadline applies to models placed on the market before 2 August 2025. It concerns the providers of those models rather than businesses that simply use them.
2 Dec 2027
The postponed requirements for stand-alone high-risk systems become applicable
PostponedThis includes certain AI systems used in areas such as recruitment, student assessment, creditworthiness and access to essential services. The previous deadline was 2 August 2026.
2 Aug 2028
The postponed deadline for AI embedded in regulated products arrives
PostponedThis covers high-risk AI used as part of products already subject to EU product-safety legislation, including some medical devices, machinery, toys and vehicles.
What this means for common uses of AI
The easiest way to approach the regulation is to start with what the system actually does.
Pick your situation
Every answer is on the page. The buttons only take you straight to the one you need.
Visitors generally need to know that they are interacting with an AI system.
The disclosure must reach them no later than their first interaction. It does not need to look like a legal notice — a clear sentence is enough.
If the chatbot comes from a third-party provider, some responsibilities remain with that provider. That does not necessarily remove your own responsibilities as the organisation deploying the chatbot.
Who is responsible depends on the role each party actually performs and, for the disclosure requirement, on factors including who decided to deploy the system and who determines how it is used.
There is no general AI Act rule requiring every piece of AI-assisted writing to be labelled.
The disclosure requirement for text is narrower. It applies to AI-generated or AI-manipulated text published for the purpose of informing the public about matters of public interest.
Ordinary product descriptions, advertising and commercial campaign copy will not normally fall into that category simply because AI was involved in drafting them.
There is also an important exception where the text has gone through human review or editorial control and a person takes responsibility for its publication.
For businesses using AI as a writing tool rather than an autonomous publisher, that distinction matters considerably.
This needs a more careful assessment.
A routine edit to a photograph is not the same as generating an image from scratch or materially changing what the original photograph depicts.
Adjusting colour, brightness, contrast or crop will not normally be treated in the same way as adding people, removing objects or altering the substance of a scene.
Where AI-generated or manipulated visual content resembles real people, places, objects or events and could reasonably appear authentic, a disclosure requirement may apply. The wording should describe what actually happened — the exact labels are further down, in the Article 50 section.
Using AI does not automatically make an e-commerce business high risk.
Product recommendations and dynamic pricing are not, on their own, what turns a system into a high-risk system under the AI Act.
But an online shop may still use AI in ways that trigger other rules. Examples include a customer-support chatbot, AI-generated product imagery that appears photographic, or certain automated content.
Data-protection and consumer-protection law may also apply independently.
There is one important high-risk example: AI used to assess the creditworthiness of individuals. A credit decision associated with a buy-now-pay-later product, for example, may fall into the high-risk category. The postponed high-risk deadline for stand-alone systems is 2 December 2027.
Certain AI systems used in recruitment and worker management are classified as high risk.
The specific requirements associated with that classification have been postponed until 2 December 2027.
That does not mean AI used in recruitment is currently unregulated. The rules already in force still matter, including the prohibition on certain practices, AI-literacy requirements and any transparency obligations relevant to the system being used.
Once the high-risk provisions become applicable, additional requirements can include human oversight, record-keeping and information for affected people.
This is an area where several parts of the AI Act can overlap.
A system analysing callers' voices, cameras attempting to infer how customers feel, or biometric access-control technology may engage transparency rules, high-risk rules or outright prohibitions depending on what the system does and where it is used.
Emotion recognition in the workplace and in educational settings is already prohibited except in the limited circumstances allowed by the regulation. Some biometric categorisation is prohibited as well.
The important point is that disclosure does not make an otherwise prohibited use acceptable. If the use itself is banned, adding a notice does not fix it.
Here, your legal role becomes particularly important.
The AI Act distinguishes between providers, deployers, importers and distributors, and those roles carry different obligations.
The label used in a contract is not decisive. What matters is what each organisation actually does.
Who developed the system? Who places it on the market? Under whose name? Who decides how it will be used? Those facts determine the role.
Some AI uses are already prohibited
The prohibited-practices provisions have applied since 2 February 2025.
They include:
- certain AI systems using subliminal, manipulative or deceptive techniques where they materially distort behaviour and are likely to cause significant harm;
- exploiting vulnerabilities linked to age, disability or socio-economic circumstances;
- certain forms of social scoring;
- predicting whether someone will commit a criminal offence solely from profiling or personality traits;
- untargeted scraping of facial images from the internet or CCTV footage to build facial-recognition databases;
- emotion recognition in workplaces and educational institutions, except where permitted for medical or safety reasons;
- biometric categorisation used to infer characteristics such as race, political opinions, trade-union membership, religious beliefs or sexual orientation;
- real-time remote biometric identification in public spaces for law-enforcement purposes, except in the specific circumstances allowed by the regulation.
For an ordinary business, two areas deserve particular attention.
The first is software that claims to score an employee's mood, tone, engagement or attitude. Features like these can appear inside larger HR or call-centre platforms without being marketed primarily as AI systems.
The second is biometric technology used to categorise customers.
If a vendor offers functionality of this kind, find out what the system actually measures before enabling it.
From 2 December 2026, the list of prohibited practices also includes AI systems used to generate non-consensual intimate imagery and systems used to generate child sexual abuse material.
Article 50: the transparency rules businesses are most likely to encounter
Article 50 contains several different transparency requirements. Treating them as one general rule about "labelling AI" leads to confusion.
They address different situations and place obligations on different actors.
AI systems that interact with people
People who interact directly with an AI system must generally be informed that they are dealing with AI, unless that fact would be obvious to a reasonably well-informed, observant and circumspect person in the circumstances.
The audience matters. What is obvious to a technical professional may not be obvious to a consumer encountering the same interface.
The rule is aimed at direct interaction. A system that operates entirely in the background and never interacts with the person concerned is a different case.
For customer-facing chatbots, the practical solution is usually simple: state clearly that the assistant is AI before or at the start of the conversation.
Suggested chatbot wording
You are chatting with an AI assistant, not a member of our team.
As a practical measure, keep the message visible without an extra click and, where useful, put a clear route to a person from the team next to it.
Machine-readable marking of generated content
Providers of generative AI systems must ensure that generated or manipulated audio, images, video and text can be identified as artificially generated or manipulated in a machine-readable format.
This is different from a visible disclosure aimed at a person.
The requirement can be implemented through mechanisms such as signed metadata or imperceptible watermarking.
For most businesses buying access to an existing generative AI product, this technical obligation belongs to the provider of the system.
The rules also contain exceptions, including for standard editing functions and outputs that do not substantially alter the input. The Commission's guidance identifies additional situations where the requirement does not apply in the same way, including machine-to-machine communications, certain intermediate industrial outputs, machine translation, source code and very short outputs.
Systems already on the market before 2 August 2026 have until 2 December 2026 to implement this requirement.
Emotion recognition and biometric categorisation
Where people are exposed to an emotion-recognition or biometric-categorisation system covered by Article 50, they must be informed.
This can matter in areas such as retail analytics, call centres and security.
It is important to check the prohibited-practices provisions first. Some uses — particularly certain forms of emotion recognition involving employees — are prohibited rather than merely subject to disclosure.
Deepfakes and other content that appears authentic
A business publishing AI-generated or AI-manipulated images, audio or video may have to disclose the use of AI where the content resembles real people, objects, places or events and could falsely appear authentic.
There does not need to be an intention to deceive.
The relevant question is how the content may reasonably be understood by the audience that sees it.
Artistic, satirical and fictional works receive more flexible treatment, allowing the disclosure to be made in a way that does not unnecessarily interfere with the work. That exception should not be assumed to cover ordinary commercial material simply because it has a creative treatment.
Image wording
For an image created entirely with AI
AI-generated image.
For a real photograph materially altered with AI
Image altered using AI.
The distinction is useful both legally and editorially. A generated image and a modified photograph are not interchangeable.
For text, the rule is narrower. It concerns AI-generated or AI-manipulated text published to inform the public about matters of public interest.
Where a person reviews the material, exercises editorial control and takes responsibility for publication, the regulation provides an exception.
That is why "all AI-written text must be labelled" is an inaccurate summary of Article 50.
What about content created before 2 August 2026?
For image, audio and video, the relevant date is when the content was generated or manipulated.
Content created before 2 August 2026 is not subject to the new disclosure requirement retroactively, although voluntary disclosure may still be appropriate.
For public-interest text, publication date matters. Text drafted before 2 August but published afterwards can fall within the rule unless the editorial-control exception applies.
Provider, deployer, importer or distributor?
A large part of AI Act compliance comes down to identifying the correct role.
| Role | In practical terms |
|---|---|
| Provider | Develops an AI system, or has one developed, and places it on the market under its own name or trademark. |
| Deployer | Uses an AI system professionally under its own authority. |
| Importer | Is established in the EU and places an AI system from a non-EU provider on the EU market. |
| Distributor | Makes an AI system available in the supply chain without being the provider or importer. |
Most businesses that subscribe to an existing AI product and use it internally will be deployers.
A company can nevertheless have different roles for different systems. A business might be a deployer of one third-party AI product and a provider of another product it developed itself.
Rebranding a system does not always make you its provider
This point is often oversimplified.
Article 25 contains circumstances in which another actor can assume provider obligations for a high-risk system, including particular cases involving branding or substantial modification.
That should not be turned into a universal rule that adding your logo to any AI tool automatically makes you its provider.
Outside that high-risk context, the general provider definition still matters: developing a system, or having it developed, and placing it on the market under your own name or trademark.
There is also a separate route by which a party can assume provider responsibilities after changing the intended purpose of a system in a way that makes it high risk.
For a chatbot, transparency should be considered separately from that classification. A business may be responsible for ensuring that its visitors are properly informed even where it is not the provider of the underlying AI system.
Contracts are useful for allocating practical responsibilities between the parties. They do not override the roles created by the regulation.
What makes an AI system "high risk"?
The term is used frequently, but not every consequential use of AI is automatically high risk.
Broadly, systems enter the high-risk regime through two routes.
Uses listed in Annex III
These include certain AI systems used in:
- biometrics;
- critical infrastructure;
- education and assessment;
- recruitment and worker management;
- access to essential public and private services;
- creditworthiness assessment;
- some insurance decisions;
- law enforcement;
- migration and asylum;
- justice;
- democratic processes.
There are qualifications and exceptions within these categories, so appearing somewhere in a listed sector does not by itself settle the classification.
Some systems performing narrow procedural, preparatory or supporting tasks may fall outside the high-risk classification where they do not materially influence the outcome of the decision.
That exception does not apply in the same way where the system profiles natural persons.
AI used as a safety component of regulated products
AI can also be high risk where it is a safety component of a product already covered by particular EU product legislation and subject to third-party conformity assessment.
Examples can include medical devices, machinery, vehicles, toys and other regulated products.
Why the distinction matters
The compliance burden for a high-risk system is very different from a simple transparency requirement.
Depending on the role involved, the high-risk regime can bring requirements covering risk management, data governance, technical documentation, record-keeping, human oversight, conformity assessment and registration.
A standard chatbot disclosure is not remotely the same compliance exercise.
Using an AI tool built outside the EU
Buying software from a US company does not take an EU business outside the AI Act.
A business established in the EU can still be a deployer when it uses an AI system supplied by a company elsewhere.
The regulation can also apply to certain providers and deployers established outside the EU where the output produced by the AI system is used within the Union.
The location of the vendor therefore does not answer the compliance question by itself.
What falls outside the AI Act?
The regulation contains exclusions for areas including national security, defence and military activities, as well as certain scientific-research activities.
Strictly personal, non-professional use is also treated differently.
Testing carried out before a system is placed on the market can fall outside the regulation in certain circumstances, although testing in real-world conditions has its own rules.
Free and open-source AI also benefits from some exemptions. Those exemptions are not universal and do not simply remove high-risk systems, prohibited practices or Article 50 transparency obligations from the regulation.
What about SMEs?
There is no blanket exemption for small businesses.
The AI Act contains measures intended to reduce the burden on SMEs and start-ups in some circumstances, including simplified documentation, regulatory-sandbox access and potentially lower conformity-assessment costs.
Many of those measures are most relevant to businesses providing high-risk systems.
For an ordinary small business using a chatbot, for example, being an SME does not remove the transparency requirement.
The size of the business becomes particularly important when calculating maximum penalties.
How the penalties work
The AI Act sets different maximum penalties for different categories of infringement.
| Type of infringement | Maximum penalty |
|---|---|
| Prohibited practices | €35 million or 7% of worldwide annual turnover |
| Other obligations, including transparency requirements | €15 million or 3% |
| Supplying incorrect, incomplete or misleading information to authorities | €7.5 million or 1% |
For undertakings covered by the standard regime, the percentage can produce a higher maximum than the fixed amount.
For SMEs, the calculation is more favourable: the lower of the relevant fixed amount and percentage is used as the maximum.
That distinction matters.
For a business with €1 million in annual turnover, 3% is €30,000. The maximum is therefore not automatically €15 million simply because that figure appears in the regulation.
The July 2026 amendment extended similar treatment to qualifying small mid-cap companies: businesses with fewer than 750 employees and either annual turnover not exceeding €150 million or an annual balance-sheet total not exceeding €129 million.
The maximum is not the same as the fine that would actually be imposed. Authorities must consider factors including the seriousness and duration of the infringement, the number of people affected, previous infringements, the size of the organisation, financial benefit and cooperation with the authorities.
There is a separate enforcement regime for providers of general-purpose AI models, where the European Commission and the AI Office have direct powers.
Where Romania stands
Romania has not yet completed the national framework required for domestic enforcement of the AI Act.
This point needs to be stated carefully.
The absence of that national framework does not mean that Romanian businesses can ignore the regulation.
EU regulations apply directly. The AI Act obligations that have reached their application date exist independently of whether Romania has finished organising its authorities.
What remains incomplete is the domestic enforcement mechanism.
A Romanian government memorandum dated 12 March 2026 proposed how responsibilities could be divided between authorities including ANCOM, ADR, ASF, the National Bank of Romania, the national data-protection authority, the Labour Inspectorate and several sector-specific bodies.
A memorandum does not, by itself, provide all of the legal powers required for inspection and sanctions.
On 24 July 2026, ANCOM said that the national framework was still being prepared and that Romanian authorities would be able to carry out checks and impose AI Act sanctions once the necessary national legislation entered into force.
The practical position is therefore unusual but not especially complicated.
When Romania completes that framework, the underlying obligations will not begin from that date. They already apply according to the EU timetable.
Other legal regimes can also operate in parallel. Where an AI system processes personal data, for example, the Romanian data-protection authority can act under the GDPR independently of the AI Act enforcement timetable.
AI Act and GDPR: two different questions
The AI Act and GDPR are often discussed together because the same system can be subject to both.
They are not interchangeable.
GDPR asks questions about personal data: what data you collect, why you process it, your legal basis, retention periods, security and people's rights.
The AI Act asks questions about the AI system itself and the way it is developed or used: its purpose, risk classification, the role of each organisation involved and any transparency or other regulatory requirements.
An AI chatbot can comply with GDPR and still fail an AI Act transparency requirement.
A system can also fall under parts of the AI Act without processing personal data at all.
In a real project, both frameworks may need to be considered separately.
A few common misunderstandings
What is often said
What the regulation says
The AI Act was postponed.
- Not as a whole. Several high-risk deadlines were postponed to December 2027 and August 2028. Article 50 became applicable on 2 August 2026, and prohibited practices have applied since February 2025.
The postponement is still only a proposal.
- No. The amending regulation was published on 24 July 2026 and entered into force on 27 July 2026.
The AI Act does not apply in Romania without a Romanian implementing law.
- It does apply. The AI Act is an EU regulation and applies directly. Romania's outstanding national legislation concerns the domestic supervisory and enforcement framework.
Every AI-written article needs an AI label.
- No. Article 50's text-disclosure rule concerns AI-generated or manipulated text published to inform the public on matters of public interest. There is also an exception where human review or editorial control takes place and a person takes responsibility for publication.
Adding your brand to an AI product automatically makes you the provider.
- Not in every case. The answer depends on the role defined by the regulation and, for high-risk systems, the additional rules in Article 25. Rebranding should not be treated as a universal shortcut for determining provider status.
We only use tools such as ChatGPT, so the AI Act is not our concern.
- Potentially it is. Using an AI system professionally can make an organisation a deployer. The obligations that matter then depend on what the system is used for. AI-literacy measures can also apply independently of whether the organisation develops AI itself.
Open-source AI is exempt.
- Not across the board. Some exemptions exist, but they do not remove all obligations relating to high-risk systems, prohibited practices or transparency.
Small businesses get an exemption.
- No general one. There are accommodations for smaller businesses, including more favourable maximum-penalty calculations, but the underlying requirements can still apply.
What we would check in a business today
You do not need to start with a hundred-page compliance programme. Start by finding out what AI is actually being used.
List the AI systems in use
Include tools that are obviously AI-driven and AI functionality hidden inside larger products: website chatbots, text and image generation, CV screening, recommendation systems, credit assessment, call analysis, video analytics and biometric access systems. This is not bureaucracy for its own sake. Without knowing where AI is being used, it is difficult to determine which rules are relevant.
Check prohibited uses first
This should come before labels and disclosure notices. Pay particular attention to tools that attempt to infer employees' emotions, attitudes or behavioural states, and to biometric systems that classify people. If a use is prohibited, transparency is not a solution.
Work out your role
For each system, establish whether the business is acting as a provider, deployer, importer or distributor. A company can hold different roles for different products. Do not rely solely on the terminology in a supplier agreement — compare the contract with what the parties actually do.
Review customer-facing AI
If a chatbot or another AI system communicates directly with people, check what users see when the interaction begins. If it is not obvious that they are dealing with AI, add a clear disclosure. This is often one of the simplest AI Act issues to fix.
Review how AI-generated visual content is published
For content created from 2 August 2026 onwards, distinguish between ordinary editing and material AI generation or manipulation. Where content could be taken for an authentic photograph, recording or video, check whether disclosure is required.
Decide who has editorial responsibility for AI-assisted text
If AI is used during drafting, make sure a person actually reviews the final text where editorial control is being relied upon. This does not require an elaborate approval workflow. It does require genuine human review rather than an assumption that somebody probably looked at the text.
Clarify responsibilities with suppliers and clients
Contracts should state how the parties understand their respective roles and who is responsible for practical compliance work. That can include notices, documentation, technical changes and associated costs. The contract does not determine how a regulator will classify the parties, but it can prevent unnecessary disputes between them.
Give staff enough AI training for the work they actually do
The AI-literacy requirement has applied since February 2025. There is no universal training certificate or fixed number of hours that every organisation must complete. Training should instead reflect the tools being used, the people using them and the risks involved. For many organisations, a reasonable starting point is documented internal guidance covering which AI tools are approved, what their limitations are, what data must not be entered into external services, where human review is required, and who to ask when a new or uncertain use appears.
If you use AI to make consequential decisions about people, plan for 2027 now
Businesses using AI in recruitment, credit, education or other areas likely to fall within the high-risk regime have more time before the relevant obligations become applicable. That time is useful. Systems that will need human oversight, logging, documentation, information for affected people or conformity work are easier to address before the deadline than immediately before it. The relevant deadline for stand-alone high-risk systems is 2 December 2027.
What happens next
The regulatory framework is still being completed.
At the time of this update, harmonised standards for the Article 50 transparency obligations have not yet been cited in the Official Journal.
In the meantime, the Code of Practice on transparency provides a practical reference. It was published on 10 June 2026 and found adequate by the European Commission and the European AI Board in July.
The Code discusses technical approaches including cryptographically signed provenance metadata, timestamps, imperceptible watermarking and optional content fingerprinting.
C2PA, commonly associated with Content Credentials, is one of the standards already used for digital provenance information.
For businesses in Romania, there is another development to watch: the national legislation needed to give the relevant Romanian authorities their full inspection and sanctioning powers under the AI Act.
About this guide
The AI Act will continue to develop through technical standards, Commission guidance, national legislation and enforcement practice.
We update this article when those changes materially affect the guidance above rather than rewriting it for every minor development.
Change log
- 11 August 2026, revision 3 — The English edition was rewritten in full for clarity and natural English while retaining the underlying legal information, dates and conclusions.
- 10 August 2026, revision 2 — Updated following an external editorial review. The article now distinguishes more clearly between entry into force and application dates, narrows the statement about enforcement in Romania, separates generated from altered content, and clarifies the position on AI literacy and small mid-cap companies.
- 10 August 2026 — First publication.
If you find something that appears to be outdated or incorrect, let us know. We will review it and record any substantive correction here.
Sources
This guide is based primarily on:
- Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744;
- the European Commission's AI Act implementation timeline;
- the Commission's guidelines on Article 50 transparency obligations;
- the Code of Practice on transparency;
- the European Commission AI Act Service Desk;
- the Commission's material on AI literacy;
- ANCOM's statement of 24 July 2026 on the status of the Romanian enforcement framework.
This article is intended as general information, not legal advice. For decisions involving a specific organisation, system or use case, check the regulation and seek legal advice where appropriate.
Why we wrote this
We build digital products, use AI in our own work and operate products that include AI in production.
When the Article 50 requirements became applicable, we wanted a practical answer to a fairly simple question: what has actually changed for a business using AI today?
Most of what we found fell into one of two categories. The legal material was accurate but difficult to navigate without already knowing the regulation, while much of the general coverage reduced a complicated timetable to the claim that "the AI Act was postponed".
Neither was particularly useful if you needed to decide what to change in a real product.
This guide is our attempt to make that distinction clear, while keeping the primary sources close enough that the details can be checked.


