Illustration of AI transparency, business obligations and EU AI Act deadlines

KI-Buster Blog · Artificial Intelligence / Business / Regulation

EU AI Act Since August 2026: What Businesses Really Need to Do

Chatbots, AI-generated images and automated candidate screening: since August 2026, the EU AI Act's transparency duties actually apply—while the AI Omnibus simultaneously pushed back the high-risk deadlines.

Published and fact-checked against current EU primary sources on October 1, 2026

Note: This article provides general information and is not individual legal advice.

A customer chatbot answers questions. Marketing generates images with AI. HR has software suggesting which candidates to shortlist. Three everyday uses—with very different legal consequences.

Since August 2026, the EU AI Act has become much more concrete for businesses. At the same time, many older checklists are outdated: the AI Omnibus entered into force on July 27, 2026, and pushed back the high-risk deadlines, among other changes. A business still working from the original timeline alone may be prioritizing the wrong things.

Three questions matter now: which AI does your business actually use, what role does it play, and which duties already apply to that specific use?

This article shows you where to start—from the disclosure in a customer chat to preparing for sensitive AI applications.

What applies since August 2, 2026?

Since August 2, 2026, the transparency duties in Article 50 generally apply. These include certain disclosures for direct AI interactions and requirements for artificially generated or manipulated content. At the same time, enforcement of applicable rules by EU and national authorities has gained importance.

That does not mean every company now needs to buy an AI certificate, nor that every high-risk duty already applies.

The current timeline has several stages:

EU AI Act timeline after the AI Omnibus
DateScopeWhat it means for businesses
February 2, 2025Original prohibitions on certain AI practices and the start of AI literacy rulesAlready relevant for a while; Article 4 has since been amended.
August 2, 2025Rules for providers of general-purpose AI (GPAI) modelsModel providers face their own duties; ordinary use of an AI service does not automatically make a business a model provider.
August 2, 2026Notably the transparency duties under Article 50Review customer interactions and relevant AI content.
December 2, 2026Transitional period for certain systems already placed on the market before August 2, 2026, under Article 50(2)Concerns technical labelling by certain providers, not a general grace period for all transparency duties.
December 2, 2027High-risk rules for Annex III systemsFor example, certain uses in employment, education or creditworthiness assessment.
August 2, 2028High-risk rules for relevant systems embedded in regulated products under Annex IAlso requires checking product-law classification and special rules.

In practice: the delayed high-risk deadlines do not suspend transparency rules and prohibitions that already apply.

Does the AI Act apply to small businesses too?

Yes. What matters is primarily the system, its purpose and the business's role. Headcount alone does not determine applicability.

A trades business that uses an AI service professionally can be a deployer. A small agency that offers its own AI system under its own name can be a provider. The EU explicitly distinguishes these roles.

Typical roles under the EU AI Act
RoleTypical situationFirst question to ask
DeployerYour business uses someone else's AI system in-house.Which deployer duties apply to this specific use?
ProviderYour business develops a system, or has one developed, and places it on the market under its own name.Which provider duties follow from its function and risk classification?
Multiple rolesYou develop your own system and use it yourselves at the same time.Which duties apply from both roles combined?

It is worth checking carefully, especially for in-house AI assistants built on third-party models. The fact that the underlying language model comes from another company does not by itself answer the role question for the finished application.

Customer chatbots: the AI disclosure has to appear at the right moment

Under the conditions set out in Article 50, people interacting with AI should be able to recognize that. The design duty falls on the provider. An exception applies when the AI nature is obvious from the context.

For use on your own website, a simple acceptance test helps: open the chat as a new visitor. Is it clear, before or at the latest during the first interaction, that AI is responding?

One possible disclosure reads:

You're chatting with our AI assistant. Its answers can contain mistakes. For anything else, our support team is happy to help.

The opening words create transparency. The note about possible errors and the team contact is a recommended design choice, not a legally mandated wording.

Practical test: Check the disclosure on mobile, in freshly started sessions, and with the assistive technologies people actually use. A desktop screenshot alone does not show how the chat behaves in everyday use.

For chatbots you buy in, clarify with the vendor who implements the disclosure and whether it survives future updates.

Labelling AI content: not every use triggers the same duty

In marketing, two different levels are often mixed up.

Technical labelling: providers of certain generative AI systems must mark outputs in a machine-readable format and make them detectable as artificially generated or manipulated. Article 50 provides exceptions, including for certain assistive standard editing.

Disclosure to people: deployers face rules in particular for deepfakes and certain published AI text. An invisible technical marker does not replace a perceivable disclosure where one is required.

Deepfakes: a realistic result needs extra attention

An artificially generated video in which a real CEO appears to make a statement can be a deepfake. What matters are the legal criteria and the impression of authenticity. Not every abstract AI illustration automatically falls into the same category.

For your marketing, add an extra review question: could the audience understand this as a genuine recording of a real person, place or event? Where that applies, the artificial generation or manipulation must be disclosed.

AI-generated text: editorial responsibility matters

Article 50 covers AI-generated or manipulated text published to inform the public on matters of public interest. An exception applies where human review or editorial control exists, with a natural or legal person holding editorial responsibility.

The Commission is clear: a purely superficial check or spell-check is not enough. What's meant is substantive review involving professional judgment.

Recommendation for company blogs: record who checked claims and sources and approved publication. An automatically inserted author name does not, by itself, document actual review.

The question is not only "Was AI involved?" but also "What are we publishing, for whom, and with what editorial review?"

AI literacy: still required, but no blanket mandatory certificate

The 2026 amendments simplified Article 4. Under the Commission's updated guidance, providers and deployers must still take measures to support the AI literacy of people acting on their behalf.

Measures should account for knowledge, experience, training and context of use. A specific individual competence level is not guaranteed. This does not create a general mandatory certificate or a particular governance structure either.

A sensible starting point for a small business could look like this:

Practical AI literacy exercises
AudienceRecommended exercise
Office and customer serviceSpot and correct a confidently worded but wrong AI answer.
MarketingCheck an AI image for deceptive potential and verify a text against its sources.
IT and developmentReview an AI-generated change plan for permissions, side effects and rollback.
LeadershipDecide which new AI uses require review before rollout.

Record the date, audience, content and open questions. That is a practical record of your measures; this recommendation does not prescribe a specific form.

Read more in AI Literacy 2026: EU AI Act Training and Certificates (Read article).

Prohibited uses remain an immediate issue

The original prohibitions have applied since February 2025. Under their respective legal conditions, they cover, for example, certain manipulative practices, social scoring and emotion recognition in the workplace.

With HR software in particular, do not rely on the product description alone. Terms like "engagement," "team sentiment," or "smart HR analytics" do not by themselves explain which function is actually being used.

Recommended procurement question: which data does the feature process, which traits does it infer from that data, and which decisions or assessments does it influence?

A feature that raises concerns should not be approved until its classification is reliably resolved. A transparency notice alone does not make a prohibited use lawful.

High-risk AI: later deadlines still need preparation today

For relevant high-risk systems under Annex III, December 2, 2027 now applies. That extra time can be used to select and vet suitable systems.

Annex III lists, among others, AI for candidate sourcing and application assessment, certain employment decisions, and the evaluation of a natural person's creditworthiness. Not every AI feature in HR is therefore automatically classified the same way.

The difference shows in two example prompts:

"Make our job ad easier to read."

"Score all applications and rank candidates for interview invitations."

The second task has AI directly influencing the selection of people. Here, review needs to go much deeper. A later human click does not automatically remove a possible high-risk classification.

Recommendation for upcoming purchases: ask vendors about intended use, the reasoning behind their classification, their planned approach to upcoming requirements, and the oversight options provided. Don't accept a blanket claim like "our software is AI Act compliant" as a substitute for specifics.

For existing systems, also document the rollout date and later changes so the relevant transitional rules can be assessed.

Privacy remains a separate assessment

Processing personal data still requires its own lawful basis under data protection law. Germany's federal data protection authority, the BfDI, describes this as a core principle of data protection law.

An AI disclosure in a customer chat does not by itself answer which customer data you may process there. Likewise, running a local server alone does not make processing privacy-compliant.

For internal sign-off, a joint review by the business unit, IT and privacy is advisable: what information goes in? Who can access the results? What data gets stored? Which functions are actually necessary?

A clear internal policy helps put this into practice: AI Policy for Companies: What Employees Can and Cannot Do (Read article).

What fines are possible?

The AI Act distinguishes between types of infringement. Article 99 sets out, in particular, these upper limits:

Fine framework under Article 99
InfringementStatutory maximum
Prohibited AI practices€35 million or 7% of worldwide annual turnover
Certain other duty breaches, including Article 50€15 million or 3%
Certain false, incomplete or misleading information to authorities€7.5 million or 1%

For businesses, the higher figure generally applies; for SMEs, including start-ups, Article 99 contains a special rule applying the lower of the two limits. The actual sanction depends on severity, duration, consequences and other circumstances. These figures are not automatic penalties for every mistake.

Above all, the headline number should not be used as a blanket threat for a missing training record.

A practical 30-day action plan

The following plan is an organizational recommendation, not a new statutory deadline. Any existing violations must be addressed according to their urgency.

Week 1: Map actual AI use

Ask departments directly about the tools they use. Include AI features inside existing software and self-built automations too.

A simple table is enough to start: system, purpose, owner, vendor, data types, affected people, external communication, and current approval status.

Capture the actual function. "We use an office suite" is too vague when one team drafts text with it and another runs personal-data analysis.

Week 2: Close visible gaps

Review customer chats, voice assistants, videos and automatically published text. Fix missing disclosures and unclear approvals first. For potentially prohibited uses, trigger an immediate expert review.

Briefly document the decision: what was reviewed, who decided, and what changed.

Week 3: Brief staff hands-on

Use examples from your own business. Have support review a flawed AI answer and have IT assess a proposed system change. Explain which tools and data are approved for which tasks.

Name a point of contact. Staff should be able to flag uncertainty before it turns into a publication or an automated decision.

Week 4: Govern procurement and changes

Define a short review process for new tools and new uses. Revisit an existing approval whenever an assistant gets more data, acts more autonomously, or starts assessing people.

Set out a dedicated preparation plan for possible high-risk systems. Track open questions, vendor information needed, and who owns each item.

For technical ways to control unapproved tools, see Preventing Shadow AI: Technical and Organizational Measures for Companies (Read article).

FAQ: EU AI Act since August 2026

Is every AI use now subject to approval since August 2026?

No. The AI Act sets different requirements depending on the system, role and use. Ordinary professional use does not create a blanket approval requirement for every AI tool.

Must every employee complete the same AI training?

No. AI literacy measures should match actual use and prior knowledge. The Commission does not require a specific standard certificate.

Must every business email written with AI help be labelled?

No. Article 50 does not create a blanket visible labelling duty for every AI-assisted email. The cases it actually covers, and other relevant requirements, must be assessed separately.

Can businesses wait until 2027 because of the delayed deadlines?

No. The later high-risk deadlines do not affect duties that already apply. Customer chat disclosures, literacy measures and potential prohibited uses belong on the checklist now.

Where should a small business start?

With a manageable inventory and a named owner for each use. From there you can define concrete tasks: add disclosures, brief staff, request vendor information and assess sensitive uses more closely.

Conclusion: act now, don't panic

Today, list three AI tools your business actually uses and answer, for each: what do we use it for, who owns it, and who sees or is affected by the results? That's the best starting point, regardless of which deadline comes next.

For a complete overview of roles, duties and a full checklist, see EU AI Act for Small Businesses: What SMEs Need to Know (Read article).

Sources and further information

Editorial status: October 1, 2026. Primary sources: Regulation (EU) 2024/1689, European Commission: AI Omnibus enters into force, AI Act Service Desk: AI Act timeline, European Commission: Article 50 guidelines, European Commission: AI Literacy FAQ, AI Act Explorer: Article 50, AI Act Explorer: Annex III, AI Act Explorer: Article 99, and BfDI: fundamentals of data protection law (German). Businesses should monitor further guidance, especially for high-risk use cases.