GUIDE 03
The EU AI Act
Short answer
The EU AI Act obligation most businesses have was not delayed. Article 50 transparency has applied since 2 August 2026: a chatbot must tell people it is a chatbot, AI-generated images and video must be labelled, and national authorities can enforce both now. What moved to December 2027 was the high-risk regime, which covers recruitment screening, credit scoring and biometrics.
The workbook sets out what is enforceable today, what the Digital Omnibus actually moved, and the five steps that take a normal company from exposed to documented.
What is inside
- Chapter 01 — What applies to you today: prohibitions, AI literacy, transparency
- Chapter 02 — The chatbot rule, and why a vendor’s product is still your obligation
- Chapter 03 — What the Digital Omnibus actually delayed, and what it did not
- Chapter 04 — Every deadline in one table
- Chapter 05 — Five steps: inventory, roles, disclosures, literacy, Annex III
- Chapter 06 — Penalties, enforcement, and why non-EU businesses are in scope
Download the workbook
PDF, 14 pages. A business email address is required.
Thank you. Your download starts in 3 seconds.
Which rules apply to your business today?
Three sets of obligations are already enforceable, and the Digital Omnibus touched none of them.
Prohibited practices and AI literacy have applied since 2 February 2025. The prohibitions cover manipulative techniques, exploitation of vulnerabilities and social scoring, and carry the highest penalties in the Act. The literacy obligation is quieter and more widely missed: if your staff operate AI systems, you must take measures to ensure they understand them, and you should be able to show what those measures were.
General-purpose AI model obligations have applied since 2 August 2025, and fall on the companies building the models rather than on the businesses using them.
Article 50 transparency has applied since 2 August 2026. This is the one that reaches ordinary businesses, and it applies whether or not your system is high-risk.
Does your chatbot have to say it is a chatbot?
Yes, unless that is already obvious to a reasonably well-informed person. Article 50(1) requires an interactive AI system to be designed so people are told they are dealing with a machine, and the disclosure must be clear, distinguishable and delivered no later than the first interaction. A line in a privacy policy does not meet it.
The obligation reaches you even when the software belongs to someone else. The Act splits duties between the provider, which develops the system, and the deployer, which puts it in front of people. Marking synthetic output is the provider’s job. Disclosing a deepfake, and disclosing AI-generated text published on matters of public interest, falls on the deployer. If your site shows a third-party assistant to EU customers, you are the deployer, and a custom front end that suppresses the provider’s marking is your exposure rather than theirs.
Penalties for Article 50 reach €15 million or 3% of worldwide annual turnover, whichever is higher.
What did the Digital Omnibus actually delay?
Two dates, and nothing else. The Council gave final approval on 29 June 2026, and the stated reason was that the harmonised technical standards needed for compliance were not finished.
| Obligation | Was | Now |
|---|---|---|
| Annex III high-risk — recruitment, credit scoring, education, essential services, biometrics | 2 August 2026 | 2 December 2027 |
| Annex I high-risk — AI inside regulated products such as medical devices and machinery | 2 August 2027 | 2 August 2028 |
| Article 50 transparency | 2 August 2026 | Unchanged |
| Prohibited practices and AI literacy | 2 February 2025 | Unchanged |
| General-purpose AI model obligations | 2 August 2025 | Unchanged |
Is anything you run high-risk?
For most businesses, no. Annex III covers AI used in recruitment and employment decisions, credit scoring, access to essential services, education, law enforcement, migration and certain biometric applications.
Recruitment is the one that catches ordinary companies. If a system screens applications, ranks candidates or materially assists a hiring decision, it is an Annex III high-risk system and you are its deployer. Your deadline is 2 December 2027, and the obligations were deferred rather than reduced: a risk management system, data governance documentation, technical files, human oversight procedures and a fundamental rights impact assessment where required.
What happens next, and when?
Two dates sit between now and the high-risk deadline. On 2 December 2026 the transition period ends for the Article 50(2) marking obligation on systems already on the market before August, and two new prohibitions phase in covering AI-generated child sexual abuse material and non-consensual intimate imagery. On 2 December 2027 the Annex III high-risk regime applies.
The Act reaches providers and deployers wherever they are established, where the output is used in the Union. A business outside the EU serving EU customers is in scope.
Questions we are asked
Was the EU AI Act delayed?
Partly. The Digital Omnibus, approved by the Council on 29 June 2026, moved the high-risk compliance deadline from 2 August 2026 to 2 December 2027 for Annex III systems, and to 2 August 2028 for AI embedded in regulated products. Article 50 transparency obligations were not deferred and have applied since 2 August 2026.
Does my chatbot need to disclose that it is AI?
Yes, under Article 50(1), unless the artificial nature of the interaction is already obvious. The disclosure must be clear, distinguishable and given no later than the first interaction. It applies whether the chatbot is your own build or a third-party product on your site.
The chatbot is our vendor’s software. Are we still responsible?
Yes, for the deployer obligations. The provider marks synthetic output; the deployer makes sure the disclosure reaches the user. You are the deployer of any system you put in front of your customers, and you must not remove or suppress the marking the provider embedded.
Do we have to label AI-generated images and text?
Deepfake image, audio and video content must be disclosed by the deployer. AI-generated text must be disclosed where it is published to inform the public on matters of public interest, unless it went through genuine human editorial review with a person or organisation holding editorial responsibility. The Commission’s May 2026 guidelines state that a human simply checking the output is not enough.
What are the penalties?
Up to €35 million or 7% of worldwide annual turnover for prohibited practices, up to €15 million or 3% for most other obligations including Article 50 transparency, and up to €7.5 million or 1% for supplying incorrect information to authorities. The higher of the two figures applies, and turnover means group worldwide turnover.
Does the Act apply to a company outside the EU?
It applies to providers and deployers wherever they are established, where the output of the system is used in the Union. A business serving EU customers is in scope regardless of where it is registered.
Contact us
Send us the brief or book a short call. You get concrete next steps in reply.