On 2 August 2026, a new stage of the AI Act came into application. Since the Digital Omnibus package was adopted in late July, a comfortable idea has been circulating among business owners: everything has been postponed to 2027, so there is nothing to do. That is only half true. Part of the calendar was indeed deferred, but another part took effect on that date, and it concerns far more SMEs than the deferred part. This article separates the two, and sets out what a company should actually do.
Quick refresher: the AI Act in four risk levels
The regulation classifies AI uses by the risk they create, not by the technology behind them. Four levels, from strictest to lightest.
- Unacceptable risk: practices banned since February 2025, such as social scoring, behavioural manipulation and certain biometric surveillance
- High risk: eight domains listed in Annex III (recruitment, credit, education, justice, biometrics, critical infrastructure, essential services) with heavy duties on documentation, human oversight and traceability
- Limited risk: transparency duties, essentially telling people when they are dealing with AI
- Minimal risk: the vast majority of everyday uses, with no specific constraint
One clarification that matters, because it is often stated the wrong way round: the transparency duties are not reserved for systems classified as limited risk. They apply to any AI system used in one of the four situations described by Article 50, whatever its risk category.
What applies since 2 August 2026
This is the heart of the matter. Article 50 imposes transparency duties, and they are the ones that touch the everyday reality of an SME.
- Chatbots and conversational agents: anyone interacting with an AI must be told, unless it is already obvious
- Content generated or heavily edited by AI: images, video, audio and certain texts must be identifiable as such, in the cases set out by the regulation
- Deep fakes: labelling is mandatory, outside artistic exceptions
- Emotion recognition and biometric categorisation: people exposed to these systems must be informed
Two practical points deserve emphasis, because they are where most companies get it wrong. First, Article 50 sets no size threshold: a freelance operating a support chatbot is covered just as a large group is. Second, the European Commission has explicitly ruled out a mention buried in your terms and conditions, an imperceptible watermark, or a vague reference to an "assistant". The information must be clear, visible, and given at the latest on first interaction for a chatbot, or directly attached to the content for a visual.
On the text side, the duty is narrower than the rumour suggests. It targets texts published to inform the public on matters of public interest, and it falls away when the content has been through human review or editorial control, with a person or organisation taking editorial responsibility for the publication. In other words, no, you do not have to label every sentence an AI helped you write.
Also in force since that date: the Commission’s extended supervisory and enforcement powers over providers of general purpose AI models.
What was deferred, and until when
The Digital Omnibus on AI (Regulation (EU) 2026/1744), published in the Official Journal on 24 July 2026 and in force three days later, pushed back the heaviest part of the regime.
- Standalone high-risk systems under Annex III (recruitment, credit, education, biometrics): 2 December 2027
- High-risk systems embedded in already regulated products under Annex I (medical devices, connected toys): 2 August 2028
This is the source of the misunderstanding. Yes, the high-risk regime moved. No, that does not mean nothing applies. If your company uses AI for recruitment or credit scoring, you have until late 2027. If it runs a chatbot or publishes AI-generated visuals, the clock already ran out.
The full timeline
- 1 August 2024: the regulation enters into force
- 2 February 2025: banned practices, plus the AI literacy duty for staff (Article 4)
- 2 August 2025: regime for general purpose AI models and the general penalties framework
- 2 August 2026: transparency obligations (chatbots, deep fakes, AI content) and extended supervisory powers
- 2 December 2026: new prohibitions and the end of the transition period for marking existing AI content
- 2 December 2027: obligations for standalone high-risk systems under Annex III
- 2 August 2028: obligations for high-risk systems embedded in regulated products under Annex I
The penalties
The ceilings are high, and they are calculated on worldwide turnover. Up to 35 million euros or 7 percent for the gravest infringements, meaning the banned practices. Up to 15 million euros or 3 percent for failures to meet obligations, which includes the transparency duties discussed here. As with GDPR, these are ceilings rather than automatic fines, and enforcement is proportionate.
One point that catches many companies off guard: like GDPR, the AI Act reaches beyond the EU. A provider or deployer established outside Europe is covered as soon as its system is used within the Union.
Practical checklist: where an SME should start
None of this requires a compliance department. It requires a clear inventory and a few concrete adjustments.
- Inventory every AI use in the company, including AI features baked into the SaaS tools you already pay for: CRM, HR, marketing, support
- Qualify each use against the four risk levels, and check whether it falls into one of the four Article 50 situations
- For anything customer-facing, add the missing transparency notices: chatbot disclosure, labelling of generated content
- Check the staff AI literacy duty under Article 4, in force since February 2025 and widely overlooked
- Work out whether you are a provider or a deployer: if you use a third-party AI through a SaaS, the bulk of compliance sits with the provider, but you still carry deployer duties such as using the system per its instructions and maintaining oversight
- Document the exercise: a mapping done once serves every upcoming deadline
- For complex or grey-area uses, get support rather than guess
The high-risk regime moved. The transparency duties did not. Confusing the two is the most expensive mistake available right now.
The GDPR parallel
The pattern is the same as 2018. Companies that mapped their processing early handled each deadline calmly. Those that waited for the last moment discovered the subject under pressure, badly, and at greater cost. The AI Act is shaping up the same way.
For an SME today, the real risk is rarely an immediate fine. It is discovering the subject the day a client, a partner or a competitor raises it. A clear inventory of your AI uses costs little now and settles the question for several years of deadlines.
Want to know where your company actually stands? Book a 20-minute call. We map your AI and data uses with you and tell you honestly which ones need attention, and which ones do not.
Sources and disclaimer
Sources: Regulation (EU) 2024/1689 (AI Act) and Regulation (EU) 2026/1744 (Digital Omnibus on AI); European Commission guidelines on Article 50 and the code of practice on transparency of AI-generated content; the European Commission AI Act portal.
This article is informational and does not constitute legal advice. Deadlines and interpretations of this regulation continue to evolve. For your specific situation, consult your legal counsel.