EU AI Act for business: what you must do if you use AI, when the rules apply after the July 2026 amendment, who enforces them and what fines can reach.

The EU AI Act, the European regulation on artificial intelligence, is, for most small companies, not a compliance project but four concrete tasks. You do not use prohibited practices. You take measures that support the skills of people working with AI (Art. 4). You tell people they are dealing with AI, and you label deepfakes and some published texts (Art. 50). And if AI evaluates job candidates, employees or customers' creditworthiness, you prepare for the duties for high-risk systems, which start to apply on 2.12.2027.
Which of these duties applies to your company is decided by its role: provider of an AI system or deployer. It does not matter whether you pay for the tool. Who inspects you and how penalties are set is decided by each member state; the Commission's AI Act Service Desk answers questions, including in your own language.
State of the law on 8.10.2026, after the amendment made by Regulation 2026/1744 of July 2026. This describes the rules and the official explanations of the European Commission, not legal advice: for any borderline case decide with a lawyer.
The AI Act is [Regulation (EU) 2024/1689](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:02024R1689-20260727), which applies directly in every member state of the Union without being transposed into national law. It entered into force on 1.08.2024, but at that point it did not yet require anything. Art. 113 spreads its application over stages from 2.02.2025 to 2.08.2028, and the general date of application is 2.08.2026. Texts that say "the AI Act has applied since 1.08.2024" confuse entry into force with application of the provisions.
On its page on the AI Act (updated 3 August 2026) the European Commission divides AI systems into four risk levels: unacceptable, high, transparency risk and minimal. The Commission puts "the vast majority of AI systems currently used in the EU" in the last group, for example AI-enabled video games and spam filters, and for them the AI Act introduces no rules. That is the Commission's assessment, not a measurement.
An AI system is, under Art. 3(1), a machine-based system that is designed to operate with varying levels of autonomy and that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations or decisions. In its non-binding guidelines on this definition (29.07.2025) the Commission notes that it is not possible to determine automatically which systems fall within it. Each tool is assessed separately.
The AI Act was amended in July 2026. Regulation (EU) 2026/1744 of 8.07.2026, named the "Digital Omnibus on AI" (the Commission calls it the AI Omnibus), was published on 24.07.2026 and entered into force on 27.07.2026. For a company that uses AI it changed five things:
Texts from before 27.07.2026 that write about high risk "from August 2026" are therefore out of date. We show all the dates from 2024 to 2028 on one timeline in the guide AI in business; here we arrange them by whom they concern.
Your duties depend on your role, and for a company that uses AI two matter: provider and deployer. Art. 3(3) defines a provider as a body that develops an AI system or "has an AI system developed" and places it on the market or puts it into service under its own name or trademark, "whether for payment or free of charge". A deployer is, under Art. 3(4), a body "using an AI system under its authority", except where the system is used in the course of a personal non-professional activity.
A company whose employees use ready-made tools, such as ChatGPT, Copilot, Gemini or a ready-made chat on a website, is therefore a deployer. That includes a sole trader: Art. 2(10) excludes only deployers who are natural persons using AI systems "in the course of a purely personal non-professional activity". How a business plan of such a tool differs from a private one is compared in the article ChatGPT Business, Copilot or Gemini for business.
Who is your company under the AI Act: provider or deployer
Regulation (EU) 2024/1689, Art. 2(1), 3(3)–(4) and 25(1); Commission guidelines on Article 50, C(2026) 5054, points (11)–(14); read 8 October 2026
Decision diagram without numbers. Question one: did you build the AI system yourself, or commission its building, and do you run it under your own name or trademark? Yes: you are a provider. Question two: do you use another company's ready-made tool without changes? Yes: you are a deployer, and the provider is the maker of the tool. Question three: did you modify an existing generative system, for example with new training data, and do you run it under your own name? Yes: you are the provider of the new system. A separate path for high-risk systems: putting your own name or trademark on such a system, making a substantial modification, or changing its intended purpose so that it becomes high-risk makes you a provider. Grey box: intermediate cases, for example a ready-made SaaS chat configured and running under your own brand, are not settled in the guidelines: a lawyer or the AI Act Service Desk.
In its guidelines on Article 50 of 20.07.2026 the Commission gives three examples that settle the most common questions about role. The guidelines are not binding — an authoritative interpretation can ultimately only be given by the Court of Justice of the European Union — but they show how the Commission reads the rules:
The guidelines also explain that a deployer's authority means taking responsibility for the decision to deploy the system and for the manner of its actual use, and does not necessarily require technical control. Employees acting under the company's instructions are not separate deployers. A company remains a deployer even if it involves third parties, such as contractors or freelancers, to operate the AI on its behalf. A company that merely commissions an advertising agency to produce an advertisement, without taking decisions about whether and how the agency uses AI, is not a deployer.
For high-risk systems the rule is written in the regulation itself. Art. 25(1) treats any distributor, importer, deployer or other third party as a provider if they put their name or trademark on a high-risk system, make a substantial modification to it, or modify its intended purpose so that the system becomes high-risk.
There is a case the guidelines do not settle: a ready-made SaaS chat that you configure yourself. Your own instructions, your own knowledge base from which the chat answers (that is how RAG works), a widget in your brand colours, but no training of the model. That is neither "use without modification" nor "modification with new training data". Settle such a case with a lawyer or ask the Commission's AI Act Service Desk (see the section on authorities below).
Some duties apply to every company from 2025, some only to providers, and the duties for high-risk systems start only in December 2027. The matrix below collects the dates from Art. 111 and 113 of the AI Act as amended by Regulation 2026/1744.
AI Act: which duty, who it applies to and from when
Regulation (EU) 2024/1689, Art. 70, 99, 111(4) and 113 as amended by Regulation (EU) 2026/1744; read 8 October 2026
Matrix: rows are duties, columns are who is affected and the date of application. Prohibited practices (Art. 5): everyone, from 2.02.2025; new prohibitions in Art. 5(1)(ba) and (bb) (intimate material without consent and material depicting child sexual abuse): from 2.12.2026. AI literacy (Art. 4): providers and deployers, from 2.02.2025. Telling people they are dealing with AI (Art. 50(1)): provider, from 2.08.2026. Marking of content in a machine-readable format (Art. 50(2)): provider, from 2.08.2026, and for systems placed on the market before 2.08.2026 from 2.12.2026. Disclosure of deepfakes and of texts on matters of public interest (Art. 50(4)): deployer, from 2.08.2026. High-risk systems in Annex III: provider and deployer, from 2.12.2027. High-risk systems in Annex I: from 2.08.2028. Strip for member states: the chapter on penalties applies from 2.08.2025 (Art. 113(b)); each member state designates its market surveillance authority and sets penalty rules (Art. 70 and 99(1)); details depend on the member state.
According to the Commission, from 2.08.2026 the AI Office and the authorities of the member states are responsible for implementing, supervising and enforcing the AI Act. The AI Office holds enforcement powers over general-purpose AI models; in the Commission's Q&A on Art. 50, compliance "will mainly be enforced by national competent market surveillance authorities". Who they are in your country is covered in the section on authorities below.
Art. 5 prohibits several uses of AI regardless of role and company size, and the ban has applied since 2.02.2025. In business terms:
For an employer the key one is letter (f). It prohibits "the placing on the market, the putting into service for this specific purpose, or the use of AI systems to infer emotions of a natural person in the areas of workplace and education institutions, except where the use of the AI system is intended to be put in place or into the market for medical or safety reasons".
From 2.12.2026 two new prohibitions are added: AI systems that generate or manipulate realistic images, video or audio of an identifiable person's intimate parts or sexually explicit activities without that person's "freely-given, specific, informed, unambiguous and explicit consent" (letter ba), and material depicting the sexual abuse of children (letter bb). On its page the Commission counts them together as the ninth prohibited practice; in the regulation they are two new letters of Art. 5.
Breaching Art. 5 attracts the highest tier of fines: up to EUR 35 million or up to 7% of worldwide annual turnover (Art. 99(3)). On 4.02.2025 the Commission published guidelines on prohibited practices with explanations and examples; they are non-binding.
Art. 4 requires a company that uses AI to take measures supporting people's skills, not to guarantee a specific level. After the July 2026 amendment the provision reads: providers and deployers of AI systems "shall take measures to support the development of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf", taking into account their technical knowledge, experience, education and training and the context the systems are used in. It continues: "This obligation does not require providers or deployers to guarantee any specific level of AI literacy of any individual." The duty has applied since 2.02.2025.
In its questions and answers on AI literacy (updated 27.07.2026) the Commission answers the questions every small company asks:
The Commission also describes the minimum: ensure a general understanding of AI in the organisation, consider your role (provider or deployer), consider the risk of the systems you use, and base concrete actions on that analysis. It warns that in many cases simply relying on the systems' instructions for use or asking staff to read them might be ineffective. Supervision of Art. 4 belongs to national market surveillance authorities, not the AI Office. For SMEs the Commission points to the European Digital Innovation Hubs (EDIHs, "more than 200 one-stop shops") and to the AI Skills Academy, which has operated since 1.05.2026.
An internal AI use policy is our recommendation, not a statutory requirement. One page that records which tools the company uses, for what, what data must not be pasted into them and who answers questions can also serve as an internal record of the measures taken.
A separate and future duty concerns high-risk systems: from 2.12.2027 oversight of them must be assigned to people who have "the necessary competence, training and authority, as well as the necessary support" (Art. 26(2)).
Art. 50 splits the duties: the provider is responsible for telling people they are dealing with AI and for technical marking of content, and the company that uses AI for disclosing deepfakes and certain texts. The duties apply from 2.08.2026.
Art. 50(1) obliges the provider to design the system so that the persons concerned are informed that they are interacting with an AI system, "unless this is obvious from the point of view of a natural person who is reasonably well-informed, observant and circumspect". Para. 5 adds that the information must be given "in a clear and distinguishable manner at the latest at the time of the first interaction or exposure" and must conform to the applicable accessibility requirements; who is bound by digital accessibility, and how, we cover in the article on WCAG.
According to the Commission's guidelines it is enough for a chat to start the conversation by mentioning that it is based on AI technology, or for an email generated by an AI agent to carry an AI label at the top. It is not enough to disclose it only in terms and conditions, URLs or documentation, to use unclear signals such as a generic reference to "assistant", a general statement like "Services on this website use AI", or a statement solely referring to the underlying technology such as "this system uses LLMs". The "obvious" exception should be interpreted restrictively, according to the Commission.
Three cases from the guidelines matter for customer service:
On agents the guidelines are explicit: AI agents are covered by Art. 50(1) if they are capable of interacting with the persons instructing them or with other natural persons in the execution of their tasks, such as making bookings, managing correspondence, negotiating or concluding contracts or executing purchases. They must disclose both their artificial nature and the person on whose behalf they are acting. More about agents is in the article AI agent in business, and about a chat in an online shop and who is responsible for this duty with a ready-made bot, in the text on ecommerce customer service.
Art. 50(2) requires providers of generative systems to ensure that outputs "are marked in a machine-readable format and detectable as artificially generated or manipulated". That is the work of the generator's maker, not of the company that uses it. The exception covers systems that perform an assistive function for standard editing.
The rules contain no duty to label every piece of content created with the help of AI. Art. 50(4) concerns the deployer, that is you, and covers two things. If you publish images, audio or video that are a deepfake, you disclose that they have been artificially generated or manipulated. A deepfake is, under Art. 3(60), content that resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful.
That is why the guidelines give an example from selling. An AI-generated image of a product in an advertisement or on packaging that can affect the audience's perception and mislead as to the actual product appearance, characteristics or use, for example by making it appear more appealing or of better quality than in real life, is a deepfake. A real product, such as a car, shown against an AI-generated background is not, as long as the advertisement is not likely to mislead about the product itself. Colour correction, background extension or re-scaling of product images is likely to have only a minor impact, according to the Commission. Where to legally get photographs for a website is covered in the text on images for a company website.
You disclose a text only if you publish it to inform the public on matters of public interest. The Commission excludes advertising and product descriptions, unless they contain claims about, for example, health, consumer safety or sustainability, and also private correspondence and internal texts. As an example of a text in scope it gives a corporate report published on a listed company's website containing investor information.
A text on matters of public interest does not need labelling if two conditions are met at once. First, a person with relevant knowledge has reviewed its substance; fact-checking is the minimum according to the Commission, and spell-checking or grammar correction is not enough. Substantial changes made by AI after sign-off void that review. Second, a person, a company or a function (for example the editor-in-chief) bears editorial responsibility, and their identity and contact details are publicly available in an easily findable place.
Content generated before 2.08.2026 does not have to be labelled retroactively, unless you publish it on or after that date. The Commission and the AI Board have confirmed the code of practice on transparency of AI-generated content as an adequate voluntary tool to demonstrate compliance; according to the Commission's press release of 31.07.2026 more than 180 organisations signed it. To label content you may voluntarily use the icons created by the EU. Copyright in AI-generated content is a separate topic, outside the AI Act; we touch on it in the article on logo design.
A system becomes high-risk through its use, and for a typical small company the first such use is recruitment. High risk is associated with face recognition, but in a small company it is usually the HR function that meets it. Annex III point 4(a) covers "AI systems intended to be used for the recruitment or selection of natural persons, in particular to place targeted job advertisements, to analyse and filter job applications, and to evaluate candidates". On its page on the AI Act the Commission gives CV-sorting software for recruitment as an example: a tool that screens applications itself and ranks candidates.
Letter (b) of the same point covers systems for decisions on terms of employment, promotion and termination, for allocating tasks based on behaviour or personal traits, and for monitoring and evaluating the performance of workers. The other areas of Annex III that can concern SMEs are:
The exception in Art. 6(3): an Annex III system is not high-risk if it does not materially influence the outcome of decision-making, because it performs a narrow procedural task, improves the result of a previously completed human activity, detects patterns without replacing human assessment, or performs a preparatory task. The exception does not work when the system profiles people: such a system "shall always be considered to be high-risk". Check a tool that evaluates candidates on their characteristics from exactly that angle. We know the Commission's guidelines on classification only from the draft consulted until 23.07.2026.
From 2.12.2027 a company that uses a high-risk system from Annex III must, under Art. 26:
There is an exception for systems placed on the market or put into service before that date: the regulation applies to them only if they are subject to significant changes in their designs later (Art. 111(2); systems intended for public authorities have a separate deadline, 2.08.2030). Whether an update of a tool you buy by subscription is such a change, settle with a lawyer.
A fundamental rights impact assessment (Art. 27) does not concern a typical SME: it covers public bodies, private entities providing public services, and private companies that use systems for credit scoring or for life and health insurance. The duties of providers of high-risk systems, that is conformity assessment, documentation and registration, are a separate and heavier package, which the July 2026 amendment partly simplified for SMEs and small mid-cap companies.
A chat on a website and an AI agent are not high-risk systems by their nature: as with recruitment, the task you use them for decides.
The AI Act has three tiers of fines, and for SMEs the lower of the two amounts counts: the amount in euros or the percentage of turnover. Art. 99 provides for:
For large companies the higher amount applies. For SMEs, including start-ups, each fine "shall be up to the percentages or amount referred to in paragraphs 3, 4 and 5, whichever thereof is lower" (para. 6). After the July 2026 amendment the same rule applies to small mid-cap companies, but only for the thresholds in paragraphs 4 and 5 (para. 6a).
Upper limits of AI Act fines: general caps and an SME example (assumed turnover EUR 5 million)
Regulation (EU) 2024/1689, Art. 99(3)–(6); our calculation, assumed turnover EUR 5 million; read 8 October 2026
Horizontal bars in three pairs, our calculation. Prohibited practices, Art. 99(3): EUR 35 million, or 7% of worldwide annual turnover; for a company with an assumed turnover of EUR 5 million, 7% is EUR 350,000. Breach of, among others, Art. 26 and Art. 50, Art. 99(4): EUR 15 million, or 3%; for the same company, EUR 150,000. Incorrect or misleading information to authorities, Art. 99(5): EUR 7.5 million, or 1%; for the same company, EUR 50,000. Note: for SMEs the lower of the two amounts applies; these are upper limits in an example with an assumed turnover, not expected fines.
The calculation (our arithmetic): for an SME with an assumed annual turnover of EUR 5 million the percentages give EUR 350,000 (7%), EUR 150,000 (3%) and EUR 50,000 (1%). Each is lower than EUR 35 million, 15 million and 7.5 million, so the percentages are the upper limits under Art. 99(6). These are upper limits in an example with an assumed turnover, not expected fines. How a member state that does not use the euro converts the amounts is set by national rules, which we have not reviewed.
The actual size of a fine is set by the authority. Art. 99(7) lists the circumstances it takes into account, including the size, annual turnover and market share of the company and its degree of cooperation, and para. 1 requires member states to take into account the interests and economic viability of SMEs. Who inspects, the procedure, the appeal routes and any reductions are set by each member state; the AI Act fixes the ceilings and the factors. Depending on the legal system, fines may be imposed by national courts or other bodies, with effective judicial remedies and due process (Art. 99(9) and (10)).
Art. 4 is not on the list of breaches in Art. 99(4).
The AI Act is enforced mainly by national market surveillance authorities, so who inspects you, and how, depends on the member state. Under Art. 70(1) each member state establishes or designates as national competent authorities at least one notifying authority and at least one market surveillance authority; where there are several, one is designated as the single point of contact, and the Commission makes the list of those points publicly available (Art. 70(2)). The Commission's page on market surveillance authorities under the AI Act (last updated 7 September 2026) says that the list is updated continuously and that, for the contact points marked with an asterisk, the national designation decision is still pending final adoption. As of that list several member states had not yet finally designated their contact point; if a member state fails to designate an authority, the Commission may launch a formal infringement procedure.
National authorities "may provide guidance and advice on the implementation of this Regulation, in particular to SMEs, including start-ups" (Art. 70(8)). The word is "may": there is no EU-wide right to a binding opinion, and any binding-ruling procedure is national. The Commission's AI Act Service Desk offers a compliance checker, a tool that assists in evaluating whether AI systems and general-purpose AI models meet the requirements, and a team of experts to whom you can submit questions, "including in your own language". We found no statement on whether its answers are binding, so we do not call them binding.
The AI Act does not replace the GDPR: if an AI tool processes personal data, both apply at once. Art. 2(7) of the regulation provides that it does not affect Regulation (EU) 2016/679, and the duty in Art. 26(9) to use the provider's information for the data protection impact assessment under Art. 35 GDPR links the two.
Before a tool is used on customer or employee data, you need (our reading of what the GDPR requires) a contract with the provider (Art. 28 GDPR for most cloud AI services), a legal basis for processing, information for the people whose data goes into the tool, and knowledge of where the data is stored and whether it leaves the European Economic Area. If a tool is meant to take decisions about people on its own, without an employee, change the way you use it or give it up. Several national data-protection authorities publish their own AI guidance for SMEs; check yours.
The European Data Protection Board says in its Opinion 28/2024 (17.12.2024) that supervisory authorities should take into account whether the controller deploying a model conducted an appropriate assessment, as part of its accountability obligations, to ascertain that the model was not developed by unlawfully processing personal data. What must go into the privacy notice on a website we describe in the text on GDPR on a website, and how to find out where company data lives in the piece on company data security.
Ten points organise what we described above; it is our list, not an official one, and it does not replace a legal assessment.
Yes. A company whose employees use ChatGPT at work is a deployer under the AI Act. Art. 4 has applied to it since 2 February 2025: it has to take measures supporting its staff's AI literacy, for example knowledge of hallucinations, as the European Commission answers in its questions and answers on AI literacy. Under Art. 50(4) it must disclose generated deepfakes and texts published to inform the public on matters of public interest, if it publishes any. Only purely personal non-professional use is excluded (Art. 2(10)), so the AI Act also covers a sole trader.
Not all of them. According to the European Commission's guidelines of 20 July 2026, advertisements and product descriptions generated by AI are not subject to the text-labelling duty unless they contain claims about, for example, health, consumer safety or sustainability. You label a deepfake, and a generated product photo that shows the product better than it is can be one. Texts on matters of public interest are labelled unless a person has reviewed them substantively and editorial responsibility is public. The guidelines are not binding.
No. The European Commission says in its questions and answers on AI literacy that no certificate is needed and that an internal record of trainings or other initiatives is enough. Art. 4 in its July 2026 wording does not require a specific level of skills, does not require measuring employees' knowledge and does not require appointing a person responsible for AI.
The chapter on penalties applies from 2 August 2025 and the general date of application is 2 August 2026. From that date the AI Office and the authorities of the member states are responsible for implementing, supervising and enforcing the rules; the AI Office has enforcement powers mainly over general-purpose AI models, and the Commission says the transparency duties of Art. 50 are enforced mainly by national market surveillance authorities. Each member state designates its authorities and sets its penalty rules (Art. 70 and 99(1)), and the Commission publishes a list of national contact points, last updated on 7 September 2026.
Art. 99 provides for up to EUR 35 million or 7% of worldwide annual turnover for prohibited practices, up to EUR 15 million or 3% for breaches of, among others, Art. 26 and Art. 50, and up to EUR 7.5 million or 1% for incorrect or misleading information to authorities. For SMEs the lower of the two amounts counts. In our example of a company with a turnover of EUR 5 million the upper limits are EUR 350,000, EUR 150,000 and EUR 50,000; that is a maximum, not an expected fine.
You can use the Commission's AI Act Service Desk, which offers a compliance checker and, according to the Commission, contact also in your own language; we found no statement that its answers are binding. National authorities "may provide guidance and advice", in particular to SMEs (Art. 70(8)), but there is no EU-wide right to a binding opinion; any such procedure is national. A lawyer decides borderline cases.
We leave the legal qualification to a lawyer — we build the system so that the Art. 50 duties can be met.
AI in business without the hype: how many EU firms use it, when an assistant is enough and when you need an agent, what it costs and what the AI Act requires.
ChatGPT Business, Copilot or Gemini: what a business plan changes, price per user in EUR, the data processing agreement and what your suite already has.
An AI agent is a system where a language model chooses its own steps and tools. When an agent makes sense in a business, what it costs and what the AI Act says.
Your Partner in Business, Digital Vantage Team
Digital Vantage team is a group of experienced professionals combining expertise in web development, software engineering, DevOps, UX/UI design and digital marketing. Together we carry out projects from concept to implementation - websites, e-commerce stores, dedicated applications and digital strategies. Our team combines years of experience from technology corporations with the flexibility and immediacy of working in a smaller, close-knit structure. We work in agile methodologies, focus on transparent communication and treat each project as if it were our own business. The strength of the team is the diversity of perspectives - from systems architecture and infrastructure, frontend and design, to SEO and content marketing strategy. As a result, the client receives a cohesive solution where technology, aesthetics and business goals go hand in hand.
Rate this article
Back to the guide: AI in business — where to start, what it costs and what the law says

ChatGPT Business, Copilot or Gemini: what a business plan changes, price per user in EUR, the data processing agreement and what your suite already has.

An AI agent is a system where a language model chooses its own steps and tools. When an agent makes sense in a business, what it costs and what the AI Act says.

AI in business without the hype: how many EU firms use it, when an assistant is enough and when you need an agent, what it costs and what the AI Act requires.

Four pricing mechanisms hidden in builder plans, what the second year actually costs, and what you can export when you outgrow the tool.

No sixty-character title limit, no keyword density, no writing for position zero: four rules Google contradicts, quoted, and what AI does to clicks.

Google shows just 14% of our articles. What Google says about content made for search, what scaled content abuse means, and where to start instead.

A free image is still under copyright; only the licence is free. What Unsplash and Pexels forbid, when stock is fine, when it is not, and what WebP saves.

Ecommerce customer service: WISMO tickets, the EU AI Act chatbot-disclosure duty from 2 August 2026, and the two support metrics that actually matter.

Product description SEO: what Google expects, Merchant Center title/description limits, the 500×500 px image rule, GTIN and the duplicate content myth.