JournalAugust 10, 202617 min readUpdated August 11, 2026

The EU AI Act in 2026: what businesses need to know now

The transparency rules are now in force. Some high-risk requirements have moved to 2027 and 2028. Here is what that means in practice.

The EU AI Act did not get postponed.

Some of its deadlines did. That distinction matters, because the rules most likely to affect an ordinary business using AI are already in force.

Since 2 August 2026, the transparency requirements in Article 50 apply across the EU. They cover situations such as customer-facing chatbots, certain AI-generated or manipulated content, emotion recognition and biometric categorisation.

The deadlines for many high-risk systems, including some used in recruitment, education and credit assessment, were pushed back to 2027 and 2028.

So if your business uses AI, the useful question is no longer simply whether the AI Act applies. It is which part applies to what you are doing, and when.

This guide covers the practical distinctions.

If you only read one section

For most businesses, these are the points worth checking first.

The rest of the article explains where those distinctions come from.

First, the dates

The AI Act is Regulation (EU) 2024/1689. It entered into force on 1 August 2024, but its requirements were never intended to apply all at once.

That phased timetable is one reason coverage of the Act can be confusing: an article can correctly say that one set of obligations has started while another has been delayed.

The regulation was also amended in July 2026 by Regulation (EU) 2026/1744, sometimes referred to as the Digital Omnibus. Among other changes, that amendment moved several deadlines for high-risk systems.

Here is the timetable that matters now.

  1. 1 Aug 2024

    The AI Act entered into force

    Past

    This started the timetable for the various provisions that would become applicable over the following years.

  2. 2 Feb 2025

    Prohibited AI practices and AI-literacy requirements became applicable

    Applies

    Certain uses of AI have been prohibited since this date, including social scoring, some forms of manipulative AI and particular biometric uses. Organisations also became responsible for taking appropriate measures to support AI literacy among the people who use AI systems on their behalf.

  3. 2 Aug 2025

    Rules for general-purpose AI models and the penalty provisions became applicable

    Applies

    These obligations are particularly relevant to the companies providing the large general-purpose models used by other AI products.

  4. 2 Aug 2026

    The Article 50 transparency rules became applicable

    Applies now

    This is the date that matters for many businesses using AI in ordinary commercial settings. Depending on the use, the rules can require people to be told that they are interacting with AI, require certain AI-generated content to carry technical markings, or require disclosure of particular types of generated or manipulated content.

  5. 2 Dec 2026

    The transition period for machine-readable marking ends

    Coming

    Generative AI systems placed on the market before 2 August 2026 have until this date to implement the machine-readable marking requirement. This is a transition period for that particular technical obligation. It does not postpone the rest of Article 50. Two additional prohibited practices introduced by the July 2026 amendment also become applicable on this date: AI systems used to generate non-consensual intimate imagery and systems used to generate child sexual abuse material.

  6. 2 Feb 2027

    Interoperability commitments under the Code of Practice reach their next milestone

    Coming

    Signatories have committed to making content markings verifiable outside their own systems through mechanisms such as standardised APIs, embedded indicators or shared verification services.

  7. 2 Aug 2027

    Older general-purpose AI models must comply

    Coming

    This deadline applies to models placed on the market before 2 August 2025. It concerns the providers of those models rather than businesses that simply use them.

  8. 2 Dec 2027

    The postponed requirements for stand-alone high-risk systems become applicable

    Postponed

    This includes certain AI systems used in areas such as recruitment, student assessment, creditworthiness and access to essential services. The previous deadline was 2 August 2026.

  9. 2 Aug 2028

    The postponed deadline for AI embedded in regulated products arrives

    Postponed

    This covers high-risk AI used as part of products already subject to EU product-safety legislation, including some medical devices, machinery, toys and vehicles.

What this means for common uses of AI

The easiest way to approach the regulation is to start with what the system actually does.

Pick your situation

Every answer is on the page. The buttons only take you straight to the one you need.

Visitors generally need to know that they are interacting with an AI system.

The disclosure must reach them no later than their first interaction. It does not need to look like a legal notice — a clear sentence is enough.

If the chatbot comes from a third-party provider, some responsibilities remain with that provider. That does not necessarily remove your own responsibilities as the organisation deploying the chatbot.

Who is responsible depends on the role each party actually performs and, for the disclosure requirement, on factors including who decided to deploy the system and who determines how it is used.

Some AI uses are already prohibited

The prohibited-practices provisions have applied since 2 February 2025.

They include:

  • certain AI systems using subliminal, manipulative or deceptive techniques where they materially distort behaviour and are likely to cause significant harm;
  • exploiting vulnerabilities linked to age, disability or socio-economic circumstances;
  • certain forms of social scoring;
  • predicting whether someone will commit a criminal offence solely from profiling or personality traits;
  • untargeted scraping of facial images from the internet or CCTV footage to build facial-recognition databases;
  • emotion recognition in workplaces and educational institutions, except where permitted for medical or safety reasons;
  • biometric categorisation used to infer characteristics such as race, political opinions, trade-union membership, religious beliefs or sexual orientation;
  • real-time remote biometric identification in public spaces for law-enforcement purposes, except in the specific circumstances allowed by the regulation.

For an ordinary business, two areas deserve particular attention.

The first is software that claims to score an employee's mood, tone, engagement or attitude. Features like these can appear inside larger HR or call-centre platforms without being marketed primarily as AI systems.

The second is biometric technology used to categorise customers.

If a vendor offers functionality of this kind, find out what the system actually measures before enabling it.

From 2 December 2026, the list of prohibited practices also includes AI systems used to generate non-consensual intimate imagery and systems used to generate child sexual abuse material.

Article 50: the transparency rules businesses are most likely to encounter

Article 50 contains several different transparency requirements. Treating them as one general rule about "labelling AI" leads to confusion.

They address different situations and place obligations on different actors.

AI systems that interact with people

People who interact directly with an AI system must generally be informed that they are dealing with AI, unless that fact would be obvious to a reasonably well-informed, observant and circumspect person in the circumstances.

The audience matters. What is obvious to a technical professional may not be obvious to a consumer encountering the same interface.

The rule is aimed at direct interaction. A system that operates entirely in the background and never interacts with the person concerned is a different case.

For customer-facing chatbots, the practical solution is usually simple: state clearly that the assistant is AI before or at the start of the conversation.

Suggested chatbot wording

You are chatting with an AI assistant, not a member of our team.

As a practical measure, keep the message visible without an extra click and, where useful, put a clear route to a person from the team next to it.

Machine-readable marking of generated content

Providers of generative AI systems must ensure that generated or manipulated audio, images, video and text can be identified as artificially generated or manipulated in a machine-readable format.

This is different from a visible disclosure aimed at a person.

The requirement can be implemented through mechanisms such as signed metadata or imperceptible watermarking.

For most businesses buying access to an existing generative AI product, this technical obligation belongs to the provider of the system.

The rules also contain exceptions, including for standard editing functions and outputs that do not substantially alter the input. The Commission's guidance identifies additional situations where the requirement does not apply in the same way, including machine-to-machine communications, certain intermediate industrial outputs, machine translation, source code and very short outputs.

Systems already on the market before 2 August 2026 have until 2 December 2026 to implement this requirement.

Emotion recognition and biometric categorisation

Where people are exposed to an emotion-recognition or biometric-categorisation system covered by Article 50, they must be informed.

This can matter in areas such as retail analytics, call centres and security.

It is important to check the prohibited-practices provisions first. Some uses — particularly certain forms of emotion recognition involving employees — are prohibited rather than merely subject to disclosure.

Deepfakes and other content that appears authentic

A business publishing AI-generated or AI-manipulated images, audio or video may have to disclose the use of AI where the content resembles real people, objects, places or events and could falsely appear authentic.

There does not need to be an intention to deceive.

The relevant question is how the content may reasonably be understood by the audience that sees it.

Artistic, satirical and fictional works receive more flexible treatment, allowing the disclosure to be made in a way that does not unnecessarily interfere with the work. That exception should not be assumed to cover ordinary commercial material simply because it has a creative treatment.

Image wording

For an image created entirely with AI

AI-generated image.

For a real photograph materially altered with AI

Image altered using AI.

The distinction is useful both legally and editorially. A generated image and a modified photograph are not interchangeable.

For text, the rule is narrower. It concerns AI-generated or AI-manipulated text published to inform the public about matters of public interest.

Where a person reviews the material, exercises editorial control and takes responsibility for publication, the regulation provides an exception.

That is why "all AI-written text must be labelled" is an inaccurate summary of Article 50.

What about content created before 2 August 2026?

For image, audio and video, the relevant date is when the content was generated or manipulated.

Content created before 2 August 2026 is not subject to the new disclosure requirement retroactively, although voluntary disclosure may still be appropriate.

For public-interest text, publication date matters. Text drafted before 2 August but published afterwards can fall within the rule unless the editorial-control exception applies.

Provider, deployer, importer or distributor?

A large part of AI Act compliance comes down to identifying the correct role.

RoleIn practical terms
ProviderDevelops an AI system, or has one developed, and places it on the market under its own name or trademark.
DeployerUses an AI system professionally under its own authority.
ImporterIs established in the EU and places an AI system from a non-EU provider on the EU market.
DistributorMakes an AI system available in the supply chain without being the provider or importer.

Most businesses that subscribe to an existing AI product and use it internally will be deployers.

A company can nevertheless have different roles for different systems. A business might be a deployer of one third-party AI product and a provider of another product it developed itself.

Rebranding a system does not always make you its provider

This point is often oversimplified.

Article 25 contains circumstances in which another actor can assume provider obligations for a high-risk system, including particular cases involving branding or substantial modification.

That should not be turned into a universal rule that adding your logo to any AI tool automatically makes you its provider.

Outside that high-risk context, the general provider definition still matters: developing a system, or having it developed, and placing it on the market under your own name or trademark.

There is also a separate route by which a party can assume provider responsibilities after changing the intended purpose of a system in a way that makes it high risk.

For a chatbot, transparency should be considered separately from that classification. A business may be responsible for ensuring that its visitors are properly informed even where it is not the provider of the underlying AI system.

Contracts are useful for allocating practical responsibilities between the parties. They do not override the roles created by the regulation.

What makes an AI system "high risk"?

The term is used frequently, but not every consequential use of AI is automatically high risk.

Broadly, systems enter the high-risk regime through two routes.

Uses listed in Annex III

These include certain AI systems used in:

  • biometrics;
  • critical infrastructure;
  • education and assessment;
  • recruitment and worker management;
  • access to essential public and private services;
  • creditworthiness assessment;
  • some insurance decisions;
  • law enforcement;
  • migration and asylum;
  • justice;
  • democratic processes.

There are qualifications and exceptions within these categories, so appearing somewhere in a listed sector does not by itself settle the classification.

Some systems performing narrow procedural, preparatory or supporting tasks may fall outside the high-risk classification where they do not materially influence the outcome of the decision.

That exception does not apply in the same way where the system profiles natural persons.

AI used as a safety component of regulated products

AI can also be high risk where it is a safety component of a product already covered by particular EU product legislation and subject to third-party conformity assessment.

Examples can include medical devices, machinery, vehicles, toys and other regulated products.

Why the distinction matters

The compliance burden for a high-risk system is very different from a simple transparency requirement.

Depending on the role involved, the high-risk regime can bring requirements covering risk management, data governance, technical documentation, record-keeping, human oversight, conformity assessment and registration.

A standard chatbot disclosure is not remotely the same compliance exercise.

Using an AI tool built outside the EU

Buying software from a US company does not take an EU business outside the AI Act.

A business established in the EU can still be a deployer when it uses an AI system supplied by a company elsewhere.

The regulation can also apply to certain providers and deployers established outside the EU where the output produced by the AI system is used within the Union.

The location of the vendor therefore does not answer the compliance question by itself.

What falls outside the AI Act?

The regulation contains exclusions for areas including national security, defence and military activities, as well as certain scientific-research activities.

Strictly personal, non-professional use is also treated differently.

Testing carried out before a system is placed on the market can fall outside the regulation in certain circumstances, although testing in real-world conditions has its own rules.

Free and open-source AI also benefits from some exemptions. Those exemptions are not universal and do not simply remove high-risk systems, prohibited practices or Article 50 transparency obligations from the regulation.

What about SMEs?

There is no blanket exemption for small businesses.

The AI Act contains measures intended to reduce the burden on SMEs and start-ups in some circumstances, including simplified documentation, regulatory-sandbox access and potentially lower conformity-assessment costs.

Many of those measures are most relevant to businesses providing high-risk systems.

For an ordinary small business using a chatbot, for example, being an SME does not remove the transparency requirement.

The size of the business becomes particularly important when calculating maximum penalties.

How the penalties work

The AI Act sets different maximum penalties for different categories of infringement.

Type of infringementMaximum penalty
Prohibited practices€35 million or 7% of worldwide annual turnover
Other obligations, including transparency requirements€15 million or 3%
Supplying incorrect, incomplete or misleading information to authorities€7.5 million or 1%

For undertakings covered by the standard regime, the percentage can produce a higher maximum than the fixed amount.

For SMEs, the calculation is more favourable: the lower of the relevant fixed amount and percentage is used as the maximum.

That distinction matters.

For a business with €1 million in annual turnover, 3% is €30,000. The maximum is therefore not automatically €15 million simply because that figure appears in the regulation.

The July 2026 amendment extended similar treatment to qualifying small mid-cap companies: businesses with fewer than 750 employees and either annual turnover not exceeding €150 million or an annual balance-sheet total not exceeding €129 million.

The maximum is not the same as the fine that would actually be imposed. Authorities must consider factors including the seriousness and duration of the infringement, the number of people affected, previous infringements, the size of the organisation, financial benefit and cooperation with the authorities.

There is a separate enforcement regime for providers of general-purpose AI models, where the European Commission and the AI Office have direct powers.

Where Romania stands

Romania has not yet completed the national framework required for domestic enforcement of the AI Act.

This point needs to be stated carefully.

The absence of that national framework does not mean that Romanian businesses can ignore the regulation.

EU regulations apply directly. The AI Act obligations that have reached their application date exist independently of whether Romania has finished organising its authorities.

What remains incomplete is the domestic enforcement mechanism.

A Romanian government memorandum dated 12 March 2026 proposed how responsibilities could be divided between authorities including ANCOM, ADR, ASF, the National Bank of Romania, the national data-protection authority, the Labour Inspectorate and several sector-specific bodies.

A memorandum does not, by itself, provide all of the legal powers required for inspection and sanctions.

On 24 July 2026, ANCOM said that the national framework was still being prepared and that Romanian authorities would be able to carry out checks and impose AI Act sanctions once the necessary national legislation entered into force.

The practical position is therefore unusual but not especially complicated.

When Romania completes that framework, the underlying obligations will not begin from that date. They already apply according to the EU timetable.

Other legal regimes can also operate in parallel. Where an AI system processes personal data, for example, the Romanian data-protection authority can act under the GDPR independently of the AI Act enforcement timetable.

AI Act and GDPR: two different questions

The AI Act and GDPR are often discussed together because the same system can be subject to both.

They are not interchangeable.

GDPR asks questions about personal data: what data you collect, why you process it, your legal basis, retention periods, security and people's rights.

The AI Act asks questions about the AI system itself and the way it is developed or used: its purpose, risk classification, the role of each organisation involved and any transparency or other regulatory requirements.

An AI chatbot can comply with GDPR and still fail an AI Act transparency requirement.

A system can also fall under parts of the AI Act without processing personal data at all.

In a real project, both frameworks may need to be considered separately.

A few common misunderstandings

The AI Act was postponed.
Not as a whole. Several high-risk deadlines were postponed to December 2027 and August 2028. Article 50 became applicable on 2 August 2026, and prohibited practices have applied since February 2025.
The postponement is still only a proposal.
No. The amending regulation was published on 24 July 2026 and entered into force on 27 July 2026.
The AI Act does not apply in Romania without a Romanian implementing law.
It does apply. The AI Act is an EU regulation and applies directly. Romania's outstanding national legislation concerns the domestic supervisory and enforcement framework.
Every AI-written article needs an AI label.
No. Article 50's text-disclosure rule concerns AI-generated or manipulated text published to inform the public on matters of public interest. There is also an exception where human review or editorial control takes place and a person takes responsibility for publication.
Adding your brand to an AI product automatically makes you the provider.
Not in every case. The answer depends on the role defined by the regulation and, for high-risk systems, the additional rules in Article 25. Rebranding should not be treated as a universal shortcut for determining provider status.
We only use tools such as ChatGPT, so the AI Act is not our concern.
Potentially it is. Using an AI system professionally can make an organisation a deployer. The obligations that matter then depend on what the system is used for. AI-literacy measures can also apply independently of whether the organisation develops AI itself.
Open-source AI is exempt.
Not across the board. Some exemptions exist, but they do not remove all obligations relating to high-risk systems, prohibited practices or transparency.
Small businesses get an exemption.
No general one. There are accommodations for smaller businesses, including more favourable maximum-penalty calculations, but the underlying requirements can still apply.

What we would check in a business today

You do not need to start with a hundred-page compliance programme. Start by finding out what AI is actually being used.

  1. List the AI systems in use

    Include tools that are obviously AI-driven and AI functionality hidden inside larger products: website chatbots, text and image generation, CV screening, recommendation systems, credit assessment, call analysis, video analytics and biometric access systems. This is not bureaucracy for its own sake. Without knowing where AI is being used, it is difficult to determine which rules are relevant.

  2. Check prohibited uses first

    This should come before labels and disclosure notices. Pay particular attention to tools that attempt to infer employees' emotions, attitudes or behavioural states, and to biometric systems that classify people. If a use is prohibited, transparency is not a solution.

  3. Work out your role

    For each system, establish whether the business is acting as a provider, deployer, importer or distributor. A company can hold different roles for different products. Do not rely solely on the terminology in a supplier agreement — compare the contract with what the parties actually do.

  4. Review customer-facing AI

    If a chatbot or another AI system communicates directly with people, check what users see when the interaction begins. If it is not obvious that they are dealing with AI, add a clear disclosure. This is often one of the simplest AI Act issues to fix.

  5. Review how AI-generated visual content is published

    For content created from 2 August 2026 onwards, distinguish between ordinary editing and material AI generation or manipulation. Where content could be taken for an authentic photograph, recording or video, check whether disclosure is required.

  6. Decide who has editorial responsibility for AI-assisted text

    If AI is used during drafting, make sure a person actually reviews the final text where editorial control is being relied upon. This does not require an elaborate approval workflow. It does require genuine human review rather than an assumption that somebody probably looked at the text.

  7. Clarify responsibilities with suppliers and clients

    Contracts should state how the parties understand their respective roles and who is responsible for practical compliance work. That can include notices, documentation, technical changes and associated costs. The contract does not determine how a regulator will classify the parties, but it can prevent unnecessary disputes between them.

  8. Give staff enough AI training for the work they actually do

    The AI-literacy requirement has applied since February 2025. There is no universal training certificate or fixed number of hours that every organisation must complete. Training should instead reflect the tools being used, the people using them and the risks involved. For many organisations, a reasonable starting point is documented internal guidance covering which AI tools are approved, what their limitations are, what data must not be entered into external services, where human review is required, and who to ask when a new or uncertain use appears.

  9. If you use AI to make consequential decisions about people, plan for 2027 now

    Businesses using AI in recruitment, credit, education or other areas likely to fall within the high-risk regime have more time before the relevant obligations become applicable. That time is useful. Systems that will need human oversight, logging, documentation, information for affected people or conformity work are easier to address before the deadline than immediately before it. The relevant deadline for stand-alone high-risk systems is 2 December 2027.

What happens next

The regulatory framework is still being completed.

At the time of this update, harmonised standards for the Article 50 transparency obligations have not yet been cited in the Official Journal.

In the meantime, the Code of Practice on transparency provides a practical reference. It was published on 10 June 2026 and found adequate by the European Commission and the European AI Board in July.

The Code discusses technical approaches including cryptographically signed provenance metadata, timestamps, imperceptible watermarking and optional content fingerprinting.

C2PA, commonly associated with Content Credentials, is one of the standards already used for digital provenance information.

For businesses in Romania, there is another development to watch: the national legislation needed to give the relevant Romanian authorities their full inspection and sanctioning powers under the AI Act.

About this guide

The AI Act will continue to develop through technical standards, Commission guidance, national legislation and enforcement practice.

We update this article when those changes materially affect the guidance above rather than rewriting it for every minor development.

Change log

  • 11 August 2026, revision 3 — The English edition was rewritten in full for clarity and natural English while retaining the underlying legal information, dates and conclusions.
  • 10 August 2026, revision 2 — Updated following an external editorial review. The article now distinguishes more clearly between entry into force and application dates, narrows the statement about enforcement in Romania, separates generated from altered content, and clarifies the position on AI literacy and small mid-cap companies.
  • 10 August 2026 — First publication.

If you find something that appears to be outdated or incorrect, let us know. We will review it and record any substantive correction here.

Sources

This guide is based primarily on:

This article is intended as general information, not legal advice. For decisions involving a specific organisation, system or use case, check the regulation and seek legal advice where appropriate.

Why we wrote this

We build digital products, use AI in our own work and operate products that include AI in production.

When the Article 50 requirements became applicable, we wanted a practical answer to a fairly simple question: what has actually changed for a business using AI today?

Most of what we found fell into one of two categories. The legal material was accurate but difficult to navigate without already knowing the regulation, while much of the general coverage reduced a complicated timetable to the claim that "the AI Act was postponed".

Neither was particularly useful if you needed to decide what to change in a real product.

This guide is our attempt to make that distinction clear, while keeping the primary sources close enough that the details can be checked.

Related work