
Your team uses AI to draft emails and your website has a chatbot. Does that mean you need a certificate, a legal audit and another folder full of policies? Start by identifying what the AI actually does. Your obligations and deadlines depend on its purpose and your role.
The EU AI Act applies in stages. Transparency rules have applied since August 2026, while the current timetable gives high-risk systems later deadlines. This guide is for businesses using AI at work. Classifying a particular system requires examining its purpose and operation.
When the AI Act rules apply
The Digital Omnibus amendment changed parts of the timetable. The delay for high-risk systems is no longer merely a proposal awaiting approval. The Commission gives 27 July 2026 as the amendment’s entry into force. European Commission overview.
- Entry into force
Individual obligations apply in stages.
- General rules and prohibitions
AI literacy provisions also start applying.
- General-purpose AI models
Obligations for their providers begin applying.
- Article 50 transparency
This deadline has passed.
- Additional prohibitions and transition
New prohibitions on non-consensual sexual deepfakes and child sexual abuse material. Also the marking deadline for certain previously marketed systems.
- Annex III high-risk systems
Including certain recruitment and education uses.
- High-risk AI in regulated products
Systems covered by Annex I.
Selected milestones from the official implementation timeline, checked 22 September 2026. Check system-specific transitional provisions too.
Identify your role first
A business using someone else’s AI professionally is generally a deployer. Developing a system, or commissioning its development and putting it into service under your brand, can make you a provider. Outsourcing development does not automatically leave every obligation with the agency. Commission definitions.
Use a table like this for an initial inventory. These are illustrative situations, not legal classifications of particular products.
| Situation | What to check |
|---|---|
| Drafting a product description | Factual accuracy, rights to source materials and company data rules. |
| Answering customers through a chatbot | Your role, AI disclosure and the process for unanswered questions. |
| Evaluating job applicants | Potential high-risk classification, human oversight and effects on applicants. |
| Inferring workers’ emotions from biometric data | The workplace prohibition, with exceptions for medical or safety reasons. |
Prohibited uses, high-risk systems, transparency requirements and other applications provide an initial map, rather than four entirely separate boxes. Lower-risk uses still need to respect other legislation, such as data protection rules. Risk overview and examples.
Providers and deployers have different work to do
Once the relevant obligations apply, taking transitional provisions into account, a high-risk system’s deployer must address use according to instructions, competent human oversight and monitoring. Article 26 requires automatically generated logs under the deployer’s control to be kept for an appropriate period of at least six months unless other applicable legislation provides otherwise. This does not mean every business must create the model’s technical documentation. Article 26 deployer obligations.
AI literacy: what your team needs to understand
The Commission’s current guidance calls for supporting AI literacy according to people’s knowledge and use of the systems. It does not prescribe one mandatory course or certificate. Internal records are possible; their absence alone does not establish a breach. Specific training and competence requirements remain for human oversight of high-risk systems. AI literacy FAQ.
We recommend working through your team’s actual tasks. Sales staff should be able to spot an invented product feature, an accountant needs to know whether an invoice may be uploaded, and the chatbot administrator needs a way to handle incorrect answers. After discussing these situations, record what you covered and where people can find help. A certificate in a drawer will not catch a wrong price in a quotation.
Disclosures for chatbots, images and text
Providers must ensure people know they are interacting with AI unless that is obvious. Deployers disclose deepfakes and certain AI text informing the public on matters of public interest, with an exception for text subject to human review or editorial control and publication responsibility. Machine-readable marking is a separate provider obligation. Article 50 details and exceptions.
A deepfake is AI-generated or manipulated image, audio or video content that resembles a real or plausibly existing subject and can falsely appear authentic. Realistic appearance alone is not enough to establish that classification.
For your website, we recommend opening the chat in a private browsing window and checking what a customer sees before sending a message. A clear “I’m an AI assistant” is easier to understand than a notice buried in the terms. For realistic advertising videos, record what AI changed and check whether the result constitutes a deepfake. An automated spelling check is not a substantive review by a person.
A practical checklist for your first inventory
This is our suggested starting point. Completing a spreadsheet does not certify legal compliance.
- List tools and their purposes. Include personal accounts used at work. Record who uses each tool and the specific task.
- Map the input data. Identify personal information, contracts and confidential materials. Check terms, settings and access permissions for each service; a paid account alone guarantees nothing.
- Separate drafting assistance from decisions about people. Put writing a job advertisement and automatically rejecting applicants on different rows.
- Ask suppliers for documentation. Request the intended purpose, risk classification, your role and operational obligations.
- Assign an owner and next action. For example, the website administrator checks the chatbot disclosure, while HR submits the recruitment system for legal assessment. Add a deadline.
- Agree how to handle errors and changes. Identify who receives reports and who can suspend the system. Revisit the inventory when a tool or its use changes.
Penalties and Czech supervision
The headline maximum for prohibited practices is €35 million or 7% of worldwide annual turnover. This is not a universal rate for every mistake involving AI. Penalties depend on the breach and its circumstances. Commission enforcement overview.
In its 31 August 2026 announcement, the Czech Telecommunication Office described a new AI unit starting on 1 September and preparations for future supervisory powers. That announcement links exercising those powers to approval of the relevant legislation and anticipates cooperation with other institutions. It does not establish that the office already supervises every AI use in Czechia. CTU announcement.
Frequently asked questions
Must every business purchase AI Act training?
The Commission does not prescribe one course or mandatory certificate. Adapt measures to people’s work and knowledge; specific requirements apply to high-risk human oversight.
Is correcting spelling enough for AI text?
For the public-interest text exception, the Commission does not treat a purely linguistic check as substantive human review or editorial control.
Does the delay mean businesses can ignore AI?
No. The delays concern particular high-risk rules. Transparency, prohibitions and AI literacy have their own deadlines.
Updated 22 September 2026 using the linked official sources. This text update was created with AI assistance. Examples and checklists are practical suggestions, not an assessment of a particular system.


