Updated October 7, 2026. This article provides general information, not legal advice. Requirements depend on the system, its intended use and the organisation's role.
A company can have an AI Act obligation without doing anything particularly exotic. A customer-service chatbot, an AI-generated video or employees using a writing assistant may be enough to bring parts of the law into the picture. 1 2 13
That is worth remembering after a summer dominated by changes to the timetable. The Digital Omnibus on AI entered into force on July 27, 2026. It moved the main high-risk requirements to December 2, 2027 for specified uses such as recruitment and credit assessment (Annex III), and to August 2, 2028 for the relevant product-related systems (Annex I). Article 50's transparency rules still began applying on August 2, 2026, subject to a limited transition for certain existing systems. The AI literacy obligation also remains in place, with revised wording. 1 3 4
For October, I would start with the AI people already encounter in your business. Check the customer-facing interfaces, look at what your publishing tools produce, and ask employees where the guidance is unclear. There is also a December deadline that some product teams should have in their release plans.
The dates that matter this autumn
| Date | What it means for businesses |
|---|---|
| February 2, 2025 | The original prohibited-practice rules and AI literacy obligation began to apply. |
| August 2, 2025 | Governance provisions and general-purpose AI model obligations began to apply, with a transition for older models. |
| August 2, 2026 | Article 50 transparency obligations began to apply. The general enforcement framework, including the Commission's powers to fine general-purpose AI model providers, became applicable. |
| December 2, 2026 | Providers of qualifying content-generating systems placed on the market before August 2, 2026 must meet Article 50(2)'s marking requirement. New prohibitions concerning non-consensual intimate content and child sexual abuse material also begin to apply. |
| August 2, 2027 | The deadline for providers of general-purpose AI models placed on the market before August 2, 2025 to meet the model obligations. |
| December 2, 2027 | The main high-risk requirements begin to apply to systems classified under Article 6(2) and Annex III. |
| August 2, 2028 | The main high-risk requirements begin to apply to systems classified under Article 6(1) and Annex I, subject to the relevant product-law arrangements. |
These are the main business-facing milestones, drawn from the amended application provisions and the Commission's guidance. Older systems and particular sectors have additional transitional arrangements, so the table should not replace a use-case assessment. 3 5 6 19
Work out what your company is responsible for
The distinction between a provider and a deployer can sound like legal housekeeping. It determines who has to do the work.
A company using a third-party AI assistant under its authority will usually be a deployer. A company that develops an AI system, or commissions one, and puts it on the market or into service under its own name is a provider. Both roles can exist in the same business. 7
Consider a company building a branded customer-service assistant around someone else's model API. It may be the provider of the finished system even though it never trained the underlying model. Commissioning a system for internal use can also create provider responsibilities. Buying access to a model does not, by itself, make the customer the provider of that model. 6 7
For your inventory, record the business purpose and owner alongside the vendor. Include who interacts with the system, who may be affected by its outputs, what data it handles and whether the company develops or modifies it. Revisit the assessment when a tool moves into a new use, particularly work involving decisions about people.
Location and licensing need a little care, too. The Act can apply to providers outside the EU that supply its market, and to providers or deployers outside the EU whose system outputs are used in the Union. Free and open-source systems are not universally exempt: the exclusion does not cover systems caught by the high-risk, prohibited-practice or Article 50 rules. 8
Check the chatbot as a customer would
When people interact directly with an AI system, Article 50 generally requires the provider to make that clear. There is an exception where the AI nature of the interaction is obvious to a reasonably well-informed, observant and circumspect person in the circumstances. The required information must be clear, accessible and supplied no later than the first interaction or exposure. 9
For an ordinary support chatbot, a short opening message such as "You're speaking with an AI assistant" is a sensible starting point. Test it on a phone. Try the embedded widget, the messaging integration and any voice channel. Check whether a customer can reach the conversation without ever seeing or hearing the notice.
The direct-interaction condition is important. An employee using AI to help draft a reply is a different situation from an AI agent communicating with the customer itself. The Commission's guidance distinguishes direct AI interaction from communication through a human intermediary. Other transparency rules may still be relevant to the content. 10
December 2 is the next marking deadline
Article 50 distinguishes between telling a person that content is artificial and making that content detectable by machines. A visible label and a technical provenance marker do different jobs. 9 11
Providers of systems generating synthetic text, images, audio or video must meet the applicable machine-readable marking and detectability requirements. The marking solution must be effective and interoperable, with robustness and reliability to the extent technically feasible. The law also accounts for implementation costs, the type of content and the state of the art. It also provides exceptions, including assistance with standard editing or changes that do not substantially alter the input or its meaning. 9
The immediate deadline depends on when the system entered the market. For qualifying systems placed on the market before August 2, 2026, the Omnibus gives providers until December 2, 2026 to comply with Article 50(2). Systems first placed on the market from August 2 do not receive that four-month transition. This extension does not postpone chatbot notices or the deployer's deepfake and public-interest-text disclosures. 3 5
A useful October review would follow a sample output through the whole product. What happens when someone downloads it, edits it or publishes it through the company's content-management system? Ask the vendor what marking it supplies, which transformations it supports and where its limitations are. Record what you actually tested.
There are further scope distinctions in the Commission's guidance, including exclusions for source code and certain exclusively machine-to-machine outputs. A product team relying on an exception should check its conditions rather than assume that everything labelled "internal" or "business-to-business" falls outside the rules. 10
The voluntary Code of Practice on Transparency of AI-generated Content provides a practical framework for marking and labelling. The Commission and AI Board have assessed it as adequate. Companies can demonstrate compliance through other appropriate means, but signing the code is not a substitute for implementing the relevant measures. 11
Publishing teams need a different set of checks
Deployers must disclose AI-generated or manipulated images, audio or video that constitute deepfakes. The term covers content that falsely appears authentic while resembling existing people, objects, places, entities or events. Evidently creative, fictional, satirical and similar works have a more flexible disclosure rule, allowing notice that does not interfere with enjoyment of the work. They are not automatically exempt. 7 9
For text, the duty concerns material published to inform the public on matters of public interest. There is an exception when the content has undergone human review or editorial control and a natural or legal person holds editorial responsibility for publication. 9
That gives an editor a real job. The Commission distinguishes substantive review from superficial checks such as spelling or grammar correction. The review should examine the content, with the knowledge and judgement needed to assess it; editorial control includes the authority to approve, change or reject the substance. 10
For a company publishing an AI-assisted article about public health or regulation, I would keep a simple approval record: who reviewed it, which sources they checked and which version was approved. Those are practical recordkeeping suggestions, not a prescribed Article 50 form. They also help when somebody later asks where a claim came from.
The exception concerns the deployer's disclosure duty for public-interest text. It does not remove a provider's separate marking obligation where that obligation applies. 9
Some uses need more than a notice
Deployers of emotion-recognition or biometric-categorisation systems have transparency duties under Article 50, alongside applicable data-protection requirements. Before designing a notice, however, check whether the intended use is permitted at all. 2 9
The Act already prohibits AI used to infer emotions in workplaces and educational institutions, apart from medical or safety exceptions. Adding a consent box or an AI disclosure does not override that prohibition. 12
The new December prohibitions concerning non-consensual intimate content and child sexual abuse material also deserve attention from generative-media providers. Their scope includes specific conditions concerning intended purpose, foreseeable misuse and safeguards. Providers should review those conditions against their product rather than treat this as another labelling requirement. 5 12
Give staff guidance they can use at work
Article 4 requires providers and deployers to take measures supporting AI literacy among staff and others operating or using AI on their behalf. Those measures should reflect existing knowledge and training, the context of use and the people affected. The revised text expressly says organisations do not have to guarantee a particular literacy level for every individual. 4
The Commission also confirms that Article 4 does not require a particular certificate, an AI officer or a prescribed governance structure. Internal records of training and other guidance initiatives can be used. 13
That leaves room for something more useful than the same presentation for everyone. A recruiter may need practice spotting unsupported inferences about candidates and knowing when to seek advice. A developer integrating an AI service needs guidance on the system's limitations and the company's data-handling rules. Choose examples from the work people actually do.
I would also check whether employees can answer ordinary questions without guessing. Which tools are approved for this task? What information can go into them? What needs checking before an output is used? Who can help when the policy does not cover the situation?
Keep the training materials and a proportionate record of what was delivered. Follow up on recurring questions, and revise guidance when the tools or their uses change. A survey can help identify where support is needed, but a self-reported confidence score cannot establish that someone is competent or that the company has complied with the Act.
Model providers have their own obligations
General-purpose AI model obligations began applying on August 2, 2025. Models placed on the market before that date have until August 2, 2027. The Commission's enforcement powers, including fines, became applicable on August 2, 2026. 6
The model-level duties include technical documentation, information for downstream system providers, a copyright-compliance policy and a public summary of training content. Qualifying open-source models have exemptions from some documentation duties, not from the whole framework. Models with systemic risk face additional requirements for evaluation, risk mitigation, serious-incident reporting and cybersecurity. 14 15
For a business buying a model API, this is mainly a procurement and integration question. Ask for the information needed to understand the model's capabilities and limitations. Establish how the supplier communicates changes and incidents. Keep model-level obligations separate from the responsibilities your company has for the product it builds or the way it uses it.
Use the high-risk extension to settle the difficult cases
Annex III covers specified uses, including recruitment and worker-management decisions, educational assessment, individual creditworthiness, and risk assessment and pricing for life and health insurance. It also covers certain biometric, essential-service and critical-infrastructure uses, among other areas. The details of the use case matter. 16
A writing assistant helping HR tidy a staff newsletter should not be treated as equivalent to a system ranking job applicants. Article 6 contains conditions under which some Annex III systems may fall outside the high-risk classification. That exception is limited; Annex III systems that profile natural persons are always treated as high-risk under that provision. Product-related cases also require a check of the safety-component and conformity-assessment conditions. 17
For a potentially high-risk system, use the extra time to establish how it will be assessed and operated. Providers and deployers have different responsibilities. Relevant preparations can include risk management, technical documentation, testing and arrangements for human oversight. Ask the supplier for its intended-purpose documentation before you build a process around a feature it was never meant to support. 1 7
Older systems have separate transitional rules, including provisions tied to significant design changes. A business relying on those rules should retain evidence of the system's introduction and subsequent changes. 3
The AI Act timetable does not suspend other applicable law. Data protection, consumer protection and product-safety requirements continue to matter, as do applicable worker protections. A later high-risk deadline should never be treated as permission to ignore them. 8
Enforcement: know which obligation you are discussing
The AI Office supervises general-purpose AI models and specified AI systems, including systems developed by the underlying model provider or another provider in the same business group. Its remit also includes AI systems integrated into designated very large online platforms and search engines. National authorities handle other AI systems, while the European Data Protection Supervisor covers EU institutions. 19
Under Article 99, prohibited-practice infringements can attract fines of up to €35 million or 7% of worldwide annual turnover for the preceding financial year, whichever is higher. Article 50 infringements can reach €15 million or 3% on the same basis. SMEs benefit from the lower of the relevant fixed amount or percentage. The Omnibus extends that lower-cap treatment to small mid-cap companies for specified infringements, including Article 50, but not for prohibited practices. 18
These are maximum penalties for particular infringements. The facts of the case matter, including its severity, the company's size, cooperation and mitigation. It would be misleading to attach one headline fine to every weakness in an AI training programme. 18
What I would finish before the end of autumn
For a manageable review, I would give each of these jobs an owner:
- Test the disclosures in live customer-facing AI interfaces and resolve any missing entry points.
- Check which systems qualify for the December 2 marking transition, then verify the implementation plan with the people building or supplying them.
- Agree a publishing workflow for deepfakes and public-interest text, including substantive editorial review where that exception is used.
- Review staff guidance against actual tasks, and refer uncertain or potentially high-risk uses for specialist assessment.
Keep the resulting decisions, vendor responses and test records together. Someone taking over the work should be able to understand what was checked and what still needs attention without reconstructing it from meeting invitations.
Behaviture AI Adoption Pulse helps teams examine the workforce side of this work: reported AI use, approved-tool fit, policy clarity and training needs. Employees receive private guidance, while leaders see privacy-qualified aggregate findings. The optional EU AI Literacy Evidence Pack supports literacy planning, documentation and governance review. It does not provide legal advice, certify compliance or replace a conformity assessment. 20
Explore Behaviture's free AI Adoption Snapshot to start identifying where employees need clearer guidance or better support.
References
Legal text takes precedence over explanatory guidance. References were checked on October 7, 2026.
- European Commission. AI Act: regulatory framework and application timeline.
- European Commission. Guidelines on transparency obligations for providers and deployers of certain AI systems.
- European Union. Regulation (EU) 2026/1744, Digital Omnibus on AI. See particularly Article 1(39) and (40), amending Articles 111 and 113 of the AI Act.
- European Commission, AI Act Service Desk. Article 4: AI literacy, as amended.
- European Commission, AI Act Service Desk. Article 113: entry into force and application, as amended.
- European Commission. Guidelines for providers of general-purpose AI models.
- European Commission, AI Act Service Desk. Article 3: definitions.
- European Commission, AI Act Service Desk. Article 2: scope, as amended.
- European Commission, AI Act Service Desk. Article 50: transparency obligations.
- European Commission. Transparency obligations under Article 50: questions and answers.
- European Commission. Code of Practice on Transparency of AI-generated Content.
- European Commission, AI Act Service Desk. Article 5: prohibited AI practices, as amended.
- European Commission. AI literacy: questions and answers.
- European Commission, AI Act Service Desk. Article 53: obligations for providers of general-purpose AI models.
- European Commission, AI Act Service Desk. Article 55: obligations for general-purpose AI models with systemic risk.
- European Commission, AI Act Service Desk. Annex III: specified high-risk uses.
- European Commission, AI Act Service Desk. Article 6: high-risk classification rules, as amended.
- European Commission, AI Act Service Desk. Article 99: penalties, as amended.
- European Commission. The enforcement framework of the AI Act.
- Behaviture. AI Adoption Pulse and EU AI Literacy Evidence Pack.