Single / Post
- Posted Date:
- Aug 23, 2026
- Category:
EU AI Act after 2 August 2026: what companies must do

For months, 2 August 2026 was presented as the date when the AI Act would reach most businesses. Then, five days before that deadline, the rules changed. Regulation (EU) 2026/1744 softened the AI literacy provision and postponed the core requirements for high risk systems. Any compliance guide written in June or early July may therefore describe a timetable that is no longer current. Regulation (EU) 2026/1744
The key question is not whether a company develops AI. It is what role the company plays in relation to each system and how that system is used. An organisation that only buys and uses external tools can still have obligations under the Act.
Three conclusions to keep in mind
- Article 50 transparency duties have applied since 2 August 2026.
- The AI Act does not require every AI generated image to carry a visible label.
- Core high risk duties for recruitment systems were postponed, but AI literacy and prohibited practices already apply.
The timetable after the July amendment
The AI Act is being phased in. The date on which the regulation entered into force is therefore not the same as the date on which a particular obligation became applicable.
- 1 August 2024: the AI Act entered into force.
- 2 February 2025: the definitions, Article 4 on AI literacy and Article 5 on prohibited practices began to apply.
- 2 August 2025: provisions on general purpose AI models, governance and most penalties began to apply.
- 27 July 2026: the amending regulation entered into force, changing Article 4 and the high risk deadlines.
- 2 August 2026: Article 50 transparency duties and Article 101 on penalties for providers of general purpose AI models began to apply.
- 11 August 2026: the Polish Act on Artificial Intelligence Systems entered into force in its main part.
What Article 50 means for an ordinary company
Article 50 is about transparency. The person on the other side should know when they are interacting with AI or encountering content that could be mistaken for authentic material. It is not one universal labelling rule. The provision assigns different duties to providers and deployers.
A provider of a system designed to interact directly with people must ensure that users are informed they are dealing with AI, unless this is obvious in the circumstances. A company deploying a chatbot should verify that the information appears at the start of the conversation rather than being buried in the terms.
A deployer publishing a deepfake must disclose that the material was artificially generated or manipulated. The notice must be understandable to a person at first contact with the content, not hidden only in file metadata.
Disclosure may also be required for AI generated or manipulated text published to inform the public about matters of public interest. The exception covers material that has undergone genuine human or editorial review and for which a person or organisation accepts editorial responsibility. The Commission stresses that correcting grammar or polishing the style is not enough. The human review must address the substance. European Commission guidance on Article 50
A deployer using emotion recognition or biometric categorisation must inform the people exposed to the system. In the workplace, however, emotion recognition is generally prohibited under Article 5, apart from narrow medical or safety exceptions.
No, every AI image does not need a visible label
This is the most common overinterpretation of Article 50. The technical marking of generated content is the provider's duty. A company using an external image generator does not automatically inherit that obligation simply because it publishes the output.
A provider of a system that generates text, images, audio or video must make the output machine readable and detectable as AI generated or manipulated. Systems placed on the market before 2 August 2026 have until 2 December 2026 to meet that requirement.
The deployer's visible disclosure duty concerns deepfakes: material that imitates an existing person, object, place, organisation or event and could falsely appear authentic. A fictional illustration that does not impersonate anything real is not automatically a deepfake. An image presented as a genuine photograph of a real person or event may be. EU icons for labelling AI generated content
The practical response is not to add the same caption to every visual. It is to establish a clear publication rule for content that could mislead an audience about authenticity.

Provider or deployer? This determines the obligations
The company's role should be determined separately for each tool. The scope of its obligations follows from that classification.
A provider develops an AI system, or has it developed, and places it on the market or puts it into service under its own name or trade mark. A deployer uses an AI system under its authority in a professional context. A company whose staff use ChatGPT, Copilot or an external image generator will usually be a deployer.
That role can change. A company may be treated as the provider if it places somebody else's system on the market under its own name, makes a substantial modification, or changes the intended purpose in a way that brings the system into the high risk category. The right question is not simply whether the company wrote the model, but what it does with the system and under whose name.
AI literacy has applied since February 2025
Article 4 applies to providers and deployers, including businesses that only use external AI tools. The obligation has applied since 2 February 2025.
Since 27 July 2026, the provision has required organisations to take measures supporting the development of AI literacy among staff and others using AI on their behalf. The measures should reflect people's knowledge, experience, training and the context in which the system is used. A company does not have to guarantee a specified level for every person.
There is no mandatory EU course, fixed number of training hours or official certificate. Effective training should match real tasks and risks. HR needs to understand discrimination, prohibited practices and human oversight. Marketing needs to understand hallucinations, source verification, rights in content and publication rules. European Commission guidance on AI literacy
A short record of the date, scope, material and participants is a sensible way to document that the organisation acted.
It is also important to distinguish a disclosure duty from a prohibition. A system analysing a candidate's tone of voice, facial expression or mood may amount to emotion recognition. In the workplace, that use is generally prohibited rather than merely subject to notice.
Recruitment: the ban applies now, high risk duties later
High risk systems can include tools used to recruit or select candidates, screen applications, evaluate applicants, make decisions on promotion or termination, allocate tasks, or monitor workers.
The core duties for that group were due to apply from 2 August 2026, but the amendment moved the date to 2 December 2027. For AI that is a product, or a safety component of a product, covered by specified EU product legislation, the date moved from 2 August 2027 to 2 August 2028.
The reason was delay in preparing harmonised standards, common specifications, guidance and national authorities. The deadlines were changed by regulation rather than merely by a Commission announcement. Commission notice on the AI Omnibus
The postponement is not a reason to leave recruitment tools unchecked. Companies should already identify systems that influence decisions about people, document what they do and ask vendors how they will meet the 2027 requirements. Article 4 and the prohibited practices in Article 5 apply independently of the postponement.

Poland's law and the transitional enforcement period
Poland's Act on Artificial Intelligence Systems of 3 July 2026 was published as Journal of Laws 2026, item 1003, and entered into force in its main part on 11 August 2026. It does not replace the EU regulation. It creates the national supervisory framework around rules that apply directly. Journal of Laws 2026, item 1003
The market surveillance authority and single point of contact is to be the Commission for the Development and Security of Artificial Intelligence, KRiBSI. It is to supervise compliance with the AI Act and issue decisions on infringements.
The chapter on administrative fines and several other parts of the Polish act do not begin to apply until 28 October 2026. On 23 August, the national enforcement system is therefore still in a transitional phase. This does not suspend obligations arising directly under the AI Act.
The penalty ceilings
The highest ceiling, for prohibited practices under Article 5, is EUR 35 million or 7 percent of worldwide annual turnover. Breaches of specified operator obligations, including Article 50, can reach EUR 15 million or 3 percent. Incorrect, incomplete or misleading information supplied to an authority can attract up to EUR 7.5 million or 1 percent. Penalties against providers of general purpose AI models are imposed by the European Commission.
For SMEs, the lower of the fixed amount and the turnover percentage is the maximum. Employee numbers alone do not determine SME status, because the EU definition also considers financial thresholds and links with other enterprises.
A practical checklist for this week
- Create an inventory of every AI tool used by the company, including tools introduced informally by employees.
- Record the vendor, business purpose, users, data involved, outputs and whether the system affects decisions about people.
- For each tool, determine whether the company is a provider or a deployer.
- Check that chatbots clearly disclose the use of AI at the start of the interaction.
- Separate recruitment and workforce management systems for an early high risk review.
- Ask vendors in writing how they meet Article 50 and how they are preparing for the high risk requirements.
- Deliver role specific AI literacy training and keep a brief record.
- Adopt a publication procedure covering deepfakes, public interest text and meaningful human editorial review.
What remains uncertain
The AI Act does not expressly assign the EUR 15 million or 3 percent ceiling to a breach of Article 4 alone. A specific penalty for inadequate AI literacy should not be stated without a basis in national law.
I have not found official confirmation that the chair of KRiBSI had been formally appointed by 23 August 2026. The statutory appointment period had not yet expired.
The amendment expressly postpones sections 1 to 3 of Chapter III, but not section 5 in the same general terms. A product specific analysis may therefore be needed rather than assuming that every provision in Chapter III moved automatically.
The practical conclusion
The AI Act does not require every company to build a large compliance structure. It does require companies to know where AI is used, identify their legal role, train people for the risks they actually face and introduce controls that work in daily operations.
This article is not legal advice. Where classification, sanctions or a particular product are unclear, the right next step is a legal assessment. My work begins with the operational side: mapping real AI use, translating requirements into workable procedures, and preparing teams to use these tools with clear human responsibility.
Latest / Articles
[ ALL ARTICLES ]BROWSE CATEGORIES





