Single / Post
- Posted Date:
- Aug 23, 2026
- Category:
EU AI Act after 2 August 2026: what companies must do

For months, 2 August 2026 was presented as the date when the AI Act would reach most businesses. Then, five days before that deadline, the rules changed. Regulation (EU) 2026/1744 softened the AI literacy provision and postponed the core requirements for high risk systems. Any compliance guide written in June or early July may therefore describe a timetable that is no longer current. Regulation (EU) 2026/1744
The key question is not whether a company develops AI. It is what role the company plays in relation to each system and how that system is used. An organisation that only buys and uses external tools can still have obligations under the Act.
Three conclusions to keep in mind
- Article 50 transparency duties have applied since 2 August 2026.
- The AI Act does not require every AI generated image to carry a visible label.
- Core high risk duties for recruitment systems were postponed, but AI literacy and prohibited practices already apply.
The timetable after the July amendment
The AI Act is being phased in. The date on which the regulation entered into force is therefore not the same as the date on which a particular obligation became applicable.
- 1 August 2024: the AI Act entered into force.
- 2 February 2025: the definitions, Article 4 on AI literacy and Article 5 on prohibited practices began to apply.
- 2 August 2025: provisions on general purpose AI models, governance and most penalties began to apply.
- 27 July 2026: the amending regulation entered into force, changing Article 4 and the high risk deadlines.
- 2 August 2026: Article 50 transparency duties and Article 101 on penalties for providers of general purpose AI models began to apply.
- 11 August 2026: the Polish Act on Artificial Intelligence Systems entered into force in its main part.
What Article 50 means in four common situations
Article 50 does not create one labelling rule for every kind of AI content. It covers several situations, and the responsible party is not always the same.
- Website chatbot. The provider must ensure that people are told they are dealing with AI, unless this is already obvious. A company using the chatbot should make sure the notice appears at the start of the conversation, not only in the terms.
- Deepfake. A company publishing AI generated or manipulated material that convincingly imitates a real person, object, place, organisation or event must disclose that the material is not authentic. Hiding the information in file metadata is not enough.
- Public interest text. Disclosure may be required when AI generated or manipulated text is published to inform the public about a matter of public interest. Genuine human editorial review can bring the material within an exception, but correcting grammar or improving the style is not enough. The substance must also be checked, and someone must accept editorial responsibility.
- Emotion recognition or biometric categorisation. People exposed to such a system must be informed. In the workplace, however, emotion recognition is generally prohibited, apart from narrow medical or safety exceptions.
The Commission's guidance explains these four categories and the exceptions that may apply to them. European Commission guidance on Article 50
No, every AI image does not need a visible label
This is the most common overinterpretation of Article 50. The technical marking of generated content is the provider's duty. A company using an external image generator does not automatically inherit that obligation simply because it publishes the output.
A provider of a system that generates text, images, audio or video must make the output machine readable and detectable as AI generated or manipulated. Systems placed on the market before 2 August 2026 have until 2 December 2026 to meet that requirement.
The deployer's visible disclosure duty concerns deepfakes: material that imitates an existing person, object, place, organisation or event and could falsely appear authentic. A fictional illustration that does not impersonate anything real is not automatically a deepfake. An image presented as a genuine photograph of a real person or event may be. EU icons for labelling AI generated content
The practical response is not to add the same caption to every visual. It is to establish a clear publication rule for content that could mislead an audience about authenticity.

First decide whether you are the provider or the deployer
A company can play a different role in relation to each tool. That role determines which duties apply.
- Provider. The business develops an AI system, or has one developed, and offers it or puts it into service under its own name or trade mark.
- Deployer. The business uses an AI system in its professional work. A company whose staff use ChatGPT, Copilot or an external image generator will usually fall into this category.
That role can change. A company may be treated as the provider if it places somebody else's system on the market under its own name, makes a substantial modification, or changes the intended purpose in a way that brings the system into the high risk category. The right question is not simply whether the company wrote the model, but what it does with the system and under whose name.
AI literacy has applied since February 2025
Article 4 applies to providers and deployers, including businesses that only use external AI tools. The obligation has applied since 2 February 2025.
Since 27 July 2026, the provision has required organisations to take measures supporting the development of AI literacy among staff and others using AI on their behalf. The measures should reflect people's knowledge, experience, training and the context in which the system is used. A company does not have to guarantee a specified level for every person.
There is no mandatory EU course, fixed number of training hours or official certificate. Effective training should match real tasks and risks. HR needs to understand discrimination, prohibited practices and human oversight. Marketing needs to understand hallucinations, source verification, rights in content and publication rules. European Commission guidance on AI literacy
A short record of the date, scope, material and participants is a sensible way to document that the organisation acted.
It is also important to distinguish a disclosure duty from a prohibition. A system analysing a candidate's tone of voice, facial expression or mood may amount to emotion recognition. In the workplace, that use is generally prohibited rather than merely subject to notice.
Recruitment: some rules apply now, others from 2027
AI tools used to screen applications, rank candidates or influence hiring decisions can be classed as high risk. The same applies to certain systems used for promotion, dismissal, task allocation or employee monitoring.
The main duties for these high risk systems were due to apply from 2 August 2026. The amendment moved that date to 2 December 2027.
A separate deadline applies to AI built into products covered by specified EU product safety legislation. For that group, the date moved from 2 August 2027 to 2 August 2028. This distinction is most relevant to manufacturers and businesses placing such products on the market.
The reason was delay in preparing harmonised standards, common specifications, guidance and national authorities. The deadlines were changed by regulation rather than merely by a Commission announcement. Commission notice on the AI Omnibus
The postponement is not a reason to leave recruitment tools unchecked. Companies should already identify systems that influence decisions about people, document what they do and ask vendors how they will meet the 2027 requirements. Article 4 and the prohibited practices in Article 5 apply independently of the postponement.

Poland's law and the transitional enforcement period
Poland's Act on Artificial Intelligence Systems of 3 July 2026 was published as Journal of Laws 2026, item 1003, and entered into force in its main part on 11 August 2026. It does not replace the EU regulation. It creates the national supervisory framework around rules that apply directly. Journal of Laws 2026, item 1003
The market surveillance authority and single point of contact is to be the Commission for the Development and Security of Artificial Intelligence, KRiBSI. It is to supervise compliance with the AI Act and issue decisions on infringements.
The chapter on administrative fines and several other parts of the Polish act do not begin to apply until 28 October 2026. On 23 August, the national enforcement system is therefore still in a transitional phase. This does not suspend obligations arising directly under the AI Act.
The penalty ceilings
These are statutory maximums, not automatic fines for every infringement. The authority must still consider the circumstances of the case.
- Prohibited practices under Article 5: up to EUR 35 million or 7 percent of worldwide annual turnover.
- Specified operator duties, including Article 50: up to EUR 15 million or 3 percent of turnover.
- Incorrect, incomplete or misleading information supplied to an authority: up to EUR 7.5 million or 1 percent of turnover.
Penalties against providers of general purpose AI models are imposed by the European Commission.
For SMEs, the lower of the fixed amount and the turnover percentage is the maximum. Employee numbers alone do not determine SME status, because the EU definition also considers financial thresholds and links with other enterprises.
A practical checklist for this week
- Create an inventory of every AI tool used by the company, including tools introduced informally by employees.
- Record the vendor, business purpose, users, data involved, outputs and whether the system affects decisions about people.
- For each tool, determine whether the company is a provider or a deployer.
- Check that chatbots clearly disclose the use of AI at the start of the interaction.
- Separate recruitment and workforce management systems for an early high risk assessment.
- Ask vendors in writing how they meet Article 50 and how they are preparing for the high risk requirements.
- Deliver role specific AI literacy training and keep a brief record.
- Adopt a publication procedure covering deepfakes, public interest text and meaningful human editorial review.
What remains uncertain
The AI Act does not expressly assign the EUR 15 million or 3 percent ceiling to a breach of Article 4 alone. A specific penalty for inadequate AI literacy should not be stated without a basis in national law.
I have not found official confirmation that the chair of KRiBSI had been formally appointed by 23 August 2026. The statutory appointment period had not yet expired.
The amendment postpones sections 1 to 3 of Chapter III. It does not use the same general wording for section 5. Manufacturers should therefore check the rules for their specific product instead of assuming that every provision in the chapter moved automatically.
The practical conclusion
The AI Act does not require every company to build a large compliance structure. It does require companies to know where AI is used, identify their legal role, train people for the risks they actually face and introduce controls that work in daily operations.
This article is not legal advice. Where classification, sanctions or a particular product are unclear, the right next step is a legal assessment. My work begins with the operational side: mapping real AI use, translating requirements into workable procedures, and preparing teams to use these tools with clear human responsibility.
Latest / Articles
[ ALL ARTICLES ]BROWSE CATEGORIES





