Skip to content
biwak

Guides

Law & privacy

What does the EU AI Act require of companies, and from when?

The EU AI Act after the Digital Omnibus: what has applied since 2 August 2026, which deadlines follow until 2028, what the labelling obligation requires and what SMEs should do now.

Responsible:

Published

Updated 13 min read

Which deadlines apply from when?

The Regulation applies in stages. The Digital Omnibus of 8 July 2026 postponed some dates and added two new ones. The table gives each date, the group it affects, and in the last column what it means for an office that only uses third-party AI tools, i.e. is a deployer and does not use a high-risk system.

Timeline of the EU AI Act after the Digital Omnibus
DateWhat appliesWho it affectsFor an office that only uses AI
1 August 2024The Regulation enters into force, still without obligations.—Nothing to do
2 February 2025Prohibited practices (Art. 5) and AI literacy (Art. 4).All providers and deployersYes: support employees in working with AI; avoid prohibited practices such as emotion recognition in the workplace
2 August 2025Obligations for general-purpose AI models, authority structure, rules on penalties.Providers of such models, Member StatesNo, this affects the model makers
27 July 2026Digital Omnibus in force; Art. 4 now only requires measures to promote AI literacy.All providers and deployersYes, the weakened obligation under Art. 4 continues to apply
29 July 2026German implementing act (KI-MIG) in force; the Federal Network Agency is the central market surveillance authority.Companies in GermanyOnly as a point of contact: the Federal Network Agency
2 August 2026General date of application, including the transparency obligations of Art. 50; authorities enforce the Regulation, and the Commission can fine providers of general-purpose models (Art. 101).Providers and deployersYes, if you publish deepfakes or AI texts on matters of public interest: label them
2 December 2026Machine-readable marking (Art. 50(2)) for generative systems that were on the market before 2 August 2026. Newly prohibited: systems that generate sexualised depictions of identifiable persons without their explicit consent, or depictions of child sexual abuse.Providers of generative systems; everyoneMarking is the vendor's job; the new prohibitions apply to everyone
2 August 2027End of the transitional period for general-purpose models that were on the market before 2 August 2025 (Art. 111(3)).Providers of such modelsNo
2 December 2027Obligations for high-risk systems under Annex III, for example in employment, education and creditworthiness assessment (Chapter III, Sections 1 to 3).Providers and deployers of such systemsOnly if AI has a say in applications, promotions or loans; a writing or spreadsheet assistant is not covered
2 August 2028Obligations for high-risk systems in products under Annex I, Section A, such as lifts or toys. The Omnibus moved machinery to Section B; its AI requirements are to come via the Machinery Regulation (EU) 2023/1230.Manufacturers and providersNo, unless you manufacture such products
2 August 2030High-risk systems intended to be used by public authorities must meet the requirements (Art. 111(2)).Public authorities and their providersNo

The basis is Art. 111 and 113 of Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744, published in the Official Journal on 24 July 2026; the amended dates are in Art. 1 points 39 and 40 of that Regulation. Checked on 23 September 2026, with the dates checked again on 24 September 2026, against the Official Journal text and the European Commission's timeline.

Are you a provider or a deployer?

The obligations depend on the role, not on the size of the business. A provider is anyone who develops an AI system or has one developed and places it on the market or puts it into service under its own name (Art. 3(3)). A deployer is anyone who uses an AI system under its own authority in a professional capacity (Art. 3(4)). If your office uses someone else's AI assistant, its maker is the provider and your company is the deployer.

According to the Commission's guidelines on Art. 50, employees working under the company's instructions are not deployers in their own right. On the other hand, anyone who builds a chatbot themselves and uses it under their own name also becomes a provider. And under Art. 25(1)(c), a deployer becomes the provider of a high-risk system if it changes the intended purpose in such a way that the system becomes high-risk — for example, if a writing assistant is to be used to assess employees' performance in future.

Art. 4: what does AI literacy mean since the Omnibus?

Since 27 July 2026, providers and deployers “take measures to support the development of AI literacy of their staff” and of other persons working on their behalf. Prior knowledge, experience, education, the context of use and the persons affected must be taken into account. Nobody owes a particular level of literacy for each individual person; this is now expressly stated in the law. Until 26 July 2026, Art. 4 required ensuring “to their best extent” that a “sufficient level of AI literacy” existed.

In practice, the building blocks stay the same: a short briefing per role, clear rules on which data may go into which tool, a named contact person and a note of who was trained when. Under Art. 4(2), the Commission publishes practical examples on its central information platform. Neither Art. 99(3) to (5) of the Regulation nor § 15 KI-MIG contains a specific offence carrying a fine for Art. 4; Art. 4 nevertheless remains an obligation. How to set up training and evidence is explained in the article on AI literacy training under Art. 4.

Labelling obligation: what has Art. 50 required since 2 August 2026?

Art. 50 has applied since 2 August 2026 and divides labelling between two roles. Providers build the notice and the machine-readable marking into their systems. Deployers, that is, the companies that use AI, disclose when they publish deepfakes or certain AI texts. If you use AI for letters, quotes and internal analyses, you therefore generally do not have to label these texts; it is different for realistic AI images, videos and audio recordings and for texts on matters of public interest. Examples for chatbots, deepfakes and publications are in the article on the AI labelling obligation under Art. 50.

The transparency obligations of Art. 50
ObligationWhoWhat exactlyFrom when
Para. 1: notice in direct interactionProviderPeople learn that they are talking or writing to an AI system, unless this is obvious.2 August 2026, without a transitional period
Para. 2: machine-readable markingProviders of generative systemsGenerated audio, image, video and text content is marked in a machine-readable way as artificially generated. Mere assistance with standard editing is exempt.2 August 2026; for systems that were on the market before, 2 December 2026
Para. 3: emotion recognition, biometric categorisationDeployersThe persons concerned are informed about the use.2 August 2026
Para. 4, first subparagraph: deepfakesDeployersDisclose that image, audio or video content has been artificially generated or manipulated. For evidently artistic or satirical works, an unobtrusive notice is sufficient.2 August 2026
Para. 4, second subparagraph: AI texts on matters of public interestDeployersDisclose when published texts are intended to inform the public. The obligation does not apply if a person has reviewed the content and someone holds editorial responsibility.2 August 2026

What this means in everyday office work is explained in the Commission's guidelines of 20 July 2026. Business correspondence with individual recipients and internal texts do not count as “published”. Advertising copy and product descriptions do not fall under the text obligation as long as they contain no statements on, for example, health, consumer safety or sustainability. The human review must cover the content; a spell check is not enough, and if you make substantive changes with AI after approval, you lose the exemption. Content generated before 2 August 2026 does not have to be labelled retrospectively; an older AI text that is only published afterwards, however, does.

For a chatbot on a website, the guidelines consider the notice necessary because customers may take the answers for human ones. An internal assistant for trained employees, by contrast, they regard as obvious. The obligation under para. 1 falls on the provider; if you build a chatbot yourself and use it under your own name, that is you. Every notice must be clearly recognisable at the latest at the first contact (Art. 50(5)).

For implementation, there has been a Code of Practice on Transparency of AI-generated Content since 10 June 2026, with EU icons for labelling. It is voluntary; the Commission and the AI Board have confirmed that it is suitable for demonstrating compliance with the obligations. Breaches of Art. 50 can be fined up to €15 million or 3% of worldwide annual turnover, with the lower of the two amounts for small and medium-sized enterprises.

When is an AI system high-risk?

High-risk systems are mainly those in the areas of use listed in Annex III. For employers, point 4 matters, employment and workers management: systems for recruitment and selection, for decisions on working conditions, promotion and termination, for allocating tasks based on individual behaviour or personal traits, and for monitoring and evaluating performance and behaviour. A tool that drafts texts, summarises or analyses tables is not covered merely because employees use it.

Art. 6(3) exempts a system listed in Annex III if it does not pose a significant risk, for example because it only performs a narrow procedural task, improves the result of a previously completed human activity, detects decision-making patterns without replacing the human assessment, or only performs a preparatory task for an assessment. The provider must document this assessment before placing the system on the market, and must register the system (Art. 6(4), Art. 49(2)); the Omnibus only simplified the registration. Systems that perform profiling of natural persons always remain high-risk.

From 2 December 2027, deployers of such systems have their own obligations (Art. 26): use in accordance with the instructions for use, human oversight by trained persons, keeping the automatically generated logs for at least six months to the extent they are under your control, and informing workers' representatives and the affected employees before use in the workplace.

Status of interpretive guidance: the Commission's guidelines on high-risk classification have been available as a draft since 19 May 2026; the consultation ran until 23 July 2026. A final version had not been published on the Commission's website as of 23 September 2026. If you document a classification today, you should check it again against the final version and record the date of the check.

Which AI practices are prohibited?

Since 2 February 2025, Art. 5 has prohibited, among other things, manipulative techniques, exploiting vulnerabilities, social scoring, and inferring emotions in the workplace and in educational institutions, except for medical or safety reasons (Art. 5(1)(f)). Under Art. 3(39), emotion recognition requires biometric data, such as voice or face. Sentiment analysis of plain text may therefore not fall under this prohibition; it nevertheless remains an issue for data protection and the works council. From 2 December 2026, the two prohibitions from the Omnibus listed in the timeline are added.

Who supervises in Germany, and how high are the fines?

€35 million · 7%
prohibited practices (Art. 99(3))
€15 million · 3%
including deployer obligations under Art. 26 and transparency under Art. 50 (Art. 99(4))
€7.5 million · 1%
incorrect or incomplete information supplied to authorities (Art. 99(5))

The percentages refer to worldwide annual turnover in the previous year; the higher of the two values applies. For small and medium-sized enterprises, the lower one applies (Art. 99(6)), and since the Omnibus also for small mid-cap enterprises, but for them only for fines under paras. 4 and 5 (Art. 99(6a)). In Germany, the Federal Network Agency has been the competent market surveillance authority since 29 July 2026, unless another authority has been designated; for supervised financial companies, it is BaFin (§ 2 KI-MIG). The Commission's AI Office is responsible for the obligations of providers of general-purpose models.

What SMEs should do now

In this order
  • Take stock: which AI systems does the company use, for what, and in which role — as a deployer or, for its own developments, as a provider?
  • AI literacy under Art. 4: define a briefing per role, write down rules for data and tools, and record attendance with the date.
  • Labelling under Art. 50: label deepfakes, review the content of published AI texts on matters of public interest or label them, and check the notice on your website chatbot.
  • Rule out prohibited practices: no emotion recognition in the workplace, no tools for manipulative purposes.
  • Check for personnel decisions: if AI helps with selection, assessment or task allocation, document the high-risk classification with the date and plan for the obligations from 2 December 2027.
  • Fix the purpose: record in the contract and in an internal rule that an office assistant will not be repurposed for performance assessment.
  • Also check GDPR and works council: the EU AI Act replaces neither a data protection impact assessment nor co-determination.
  • Put the dates in your calendar: 2 December 2026, 2 December 2027 and 2 August 2028, plus the Commission's final high-risk guidelines.

What the data protection threshold assessment looks like is explained in the guide on data protection impact assessments for AI; when the works council has a say is covered in the article Works councils and AI.

Frequently asked questions

Does the EU AI Act also apply to small businesses?

Yes. The Regulation is based on role and risk, not on the size of the business. Small and medium-sized enterprises receive concessions, such as lower maximum fines and simplified documentation for high-risk systems, but no exemption. For an office that only uses AI, Art. 4 and Art. 50 are what matter most.

Do we have to label AI-generated texts?

Only in certain cases. Art. 50(4) requires disclosure for texts published to inform the public on matters of public interest, and even then not if a person has reviewed the content and someone holds editorial responsibility. According to the Commission's guidelines of 20 July 2026, emails, quotes, internal reports and ordinary advertising copy are not covered. Realistic AI images, videos or audio recordings that could appear genuine, on the other hand, must be recognisable as artificial.

Is an AI assistant for office work a high-risk system?

Generally not. Drafting, summarising, explaining and analysing are not personnel decisions. It becomes high-risk if the results are used for selection, assessment, task allocation, promotion or termination, or if the system is intended for this. The line runs along the intended purpose, and you help define it with your rules and key figures.

What did the Digital Omnibus change?

Regulation (EU) 2026/1744 has been in force since 27 July 2026. It switched Art. 4 to measures that promote AI literacy, postponed the high-risk obligations to 2 December 2027 (Annex III) and 2 August 2028 (Annex I), introduced a transitional period until 2 December 2026 for the machine-readable marking of older generative systems, and added two new prohibitions from the same day.

Who supervises compliance in Germany?

Since 29 July 2026, under the KI-MIG, the Federal Network Agency has been the central market surveillance authority, unless another authority has been designated; for supervised financial companies, BaFin. The obligations of providers of general-purpose models are supervised by the European Commission's AI Office. The data protection supervisory authorities remain responsible for data protection.

Does the EU AI Act change anything about our GDPR obligations?

No, it applies alongside them. Legal basis, impact assessment, processing on behalf and third-country assessment are still required unchanged. In practice, the same function often triggers both assessments; that is why it pays to keep them in one document.

Sources

  1. Regulation (EU) 2024/1689 (AI Act), Official Journal of the EU
  2. Regulation (EU) 2026/1744 (Digital Omnibus on AI), Official Journal of 24 July 2026
  3. German AI Market Surveillance and Innovation Promotion Act (KI-MIG), in force since 29 July 2026
  4. European Commission: Regulatory framework on AI (timeline)
  5. European Commission: guidelines on the transparency obligations under Art. 50, 20 July 2026
  6. European Commission: Code of Practice on Transparency of AI-generated Content, 10 June 2026
  7. European Commission: draft guidelines on high-risk classification, 19 May 2026

This text is not legal advice. It is the groundwork we had to do for ourselves, with the legal references, so that your lawyer does not have to start from scratch. Where a question depends on your circumstances, the text says so.

Further reading

All articles