The EU AI Act’s transparency rules have applied since 2 August 2026. Start with what your AI actually does: does it draft text, talk directly to customers or assess people? List the systems and their purposes, assign responsibility and check which disclosures are required. A writing assistant raises different obligations from a tool that shortlists job applicants.
A list of tools, purposes, data and responsible people gives you a useful starting point. It separates everyday office assistance from applications that need closer legal assessment. Data protection and other sector rules continue to apply alongside the AI Act.
The timeline, and what changed in 2026
The AI Act has been in force since August 1, 2024, but takes effect in stages. Since February 2, 2025, the prohibitions on certain practices have applied, such as social scoring or manipulative systems. Since August 2, 2025, the rules for providers of general-purpose AI models, meaning the large foundation models, have been in effect. Since August 2, 2026, the transparency obligations of Article 50 have applied, and the national supervisory authorities have their full enforcement and sanctioning powers.
The European Commission’s current timeline reflects the AI Omnibus, which entered into force on 27 July 2026. High-risk rules for the areas covered by Annex III apply from 2 December 2027; those for high-risk AI in regulated products apply from 2 August 2028. This postponement does not suspend the transparency duties already in effect.
The logic behind it: risk-based, not blanket regulation
The AI Act does not regulate "AI" as a technology, but concrete use cases, tiered by risk. At the top are prohibited practices. Below them are high-risk applications, subject to strict requirements for data quality, documentation, human oversight, and risk management. Below those are systems with limited risk, for which essentially transparency obligations apply. And at the bottom, the large remainder, for which the AI Act imposes hardly any specific requirements.
A company that uses an AI assistant to draft emails, summarize meeting minutes, or sketch out proposal texts is not operating a high-risk system. It sits in the lowest or second-lowest tier, and there the obligations are manageable.
What concretely applies to most businesses
For businesses using ordinary AI tools, two topics deserve practical attention: a capable team and the required transparency.
First, the team needs an adequate understanding of its tools. Employees should know what AI can do, where it tends to fail and which data they may use. The AI Omnibus amended Article 4 on AI literacy; the Commission explicitly flags its displayed article text as not yet updated. That older wording should therefore not be treated as proof of an unchanged general training duty. High-risk applications need a separate check of their applicable requirements.
Second, Article 50 transparency duties have applied since 2 August 2026. Providers must make direct AI interactions, such as chatbots, apparent unless they are already obvious. Businesses should check the notice when embedding third-party systems too. Publishing deepfakes or certain AI texts on matters of public interest requires a disclosure assessment; substantively reviewed text with editorial responsibility has an exception. The transition until 2 December 2026 only covers technical marking by providers of systems already marketed before the August deadline. Our guide to AI labelling covers the practical examples.
Start with the use: a draft checked and sent by an employee differs from a chatbot answering customers directly. Applicant assessment raises another question: which high-risk duties fall on the provider and the business using the system?
When you do slip into high-risk territory
The high-risk category is not a question of company size, but of use case. The most relevant scenario for SMEs is human resources: AI systems that filter applications, evaluate candidates, or prepare decisions about promotion and dismissal are explicitly classified as high-risk in Annex III of the law. The same applies, for instance, to creditworthiness assessments or systems in critical infrastructure. A twenty-person business that lets an AI tool pre-sort applicants is operating in a regulated area; a corporation that only uses AI for text drafts is not.
Anyone using or planning such applications doesn't need to abandon them immediately. But they should take the timeline until December 2027 seriously and clarify early on which requirements are coming their way, above all human oversight, documentation, and the question of whether the tool's provider is doing its homework.
Provider or deployer: the role question decides everything
The AI Act distributes obligations by role. The provider, meaning whoever develops an AI system and puts it on the market under their own name, carries the main burden for high-risk systems: conformity assessment procedures, technical documentation, quality management. The deployer, meaning whoever uses a system professionally under their own responsibility, has considerably leaner obligations: use the system as intended, ensure the prescribed oversight, and exercise additional care with high-risk systems.
Most SMEs are deployers. But the line can shift: anyone who substantially modifies a purchased system, offers it under their own brand, or repurposes it for a high-risk use can end up in the provider role themselves, with all the consequences. Anyone developing their own AI products and selling them to customers is a provider in any case. This role clarification is not a formality; it is the point that determines which catalog of obligations applies at all.
A pragmatic approach
Record four things for each system: purpose and data, provider or deployer role, possible risk category and the person responsible. Include tools introduced independently by individual teams. Then check for gaps in training, approvals and disclosures. For employment decisions or other sensitive uses, get the legal classification assessed before introducing the system.
If you are missing information for this overview, bring your tools and one or two typical workflows to an initial conversation with AI Værk. We can discuss the technical use, data flows and responsibilities, and identify questions to resolve before implementation. Where a binding legal assessment is needed, involve a suitably qualified adviser.