Why does this matter?
Many half-truths about the AI Act are doing the rounds. Some businesses no longer dare to use AI, others receive a quote for a "legally required" programme. In reality the law is easy to follow, as long as you know which category your use falls into. For most businesses that is the lightest one.
Four risk levels
| Level | Examples | What applies | Since |
|---|---|---|---|
| Prohibited | Social scoring, manipulating people, inferring emotions at work or at school | Not allowed | 2 February 2025 |
| High risk | Selecting job applicants, evaluating employees, assessing creditworthiness | Risk management, documentation, human oversight, registration | 2 December 2027 (AI in regulated products: 2 August 2028) |
| Transparency | Chatbots, phone assistants, imitated images and voices | People must know that it is AI | 2 August 2026 |
| Minimal | Preparing emails and reports, searching your own documents, translating | No specific obligations |
The dates for high risk were postponed in 2026. Originally those rules were due to take effect on 2 August 2026.
Provider or deployer?
The law distinguishes between whoever makes an AI system and places it on the market (the provider) and whoever uses it in their business (called the "deployer" in the Act). The heaviest obligations lie with the provider. Most businesses are deployers. Makers of large language models have had their own obligations since 2 August 2025, and those do not affect you directly as a deployer.
AI literacy: what does the text really say?
Article 4 has applied since 2 February 2025 to every organisation that uses AI, large or small. The text was weakened in 2026. Since 27 July 2026 (Regulation 2026/1744, the Digital Omnibus on AI) the obligation reads that you "take measures to support the development of AI literacy" among your employees and among those who work with AI on your behalf. The law explicitly adds that you do not have to guarantee a particular level.
What that involves depends on what your people do. Someone who uses AI to prepare texts must know what they may and may not put into it, and that the result can be wrong. Someone who manages an AI system that prepares decisions must know more.
Do you have to disclose that something was made by AI?
It does not depend on the channel, nor on how much AI is involved. It depends on whether a human really reviews the message and sends it personally, or whether the AI system itself communicates with someone. The rules come from Article 50 and apply to email, WhatsApp, chat and phone in the same way. The European Commission clarified them in guidelines on 20 July 2026, and the examples below follow that clarification.
| Situation | Disclose? | Why |
|---|---|---|
| An email, message, quote or report that AI drafts and that you review and send yourself | No | The recipient is communicating with you, not with the AI system. The condition is that you really review it: the fact that review is possible is not enough |
| A customer service employee who uses an AI tool to reply | No | Same reason: a human is conducting the conversation |
| A chatbot or AI assistant that talks to customers itself via chat, email or WhatsApp | Yes | Anyone communicating with an AI system must know it. Also when the system starts the conversation itself |
| An AI agent that writes and sends emails, books appointments or negotiates on your behalf | Yes | The agent makes clear that it is AI, and also on whose behalf it acts. For example with a notice at the top of the email |
| An AI voice that answers the phone or makes calls itself | Yes, spoken at the start of the call | Same rule. A sound signal alone is not enough |
| A voice, image or video that imitates an existing person or a real event | Yes, always | Separate rule for imitated images and voices |
| An automatic message from a classic system without AI, such as a fixed template or an out-of-office reply | No | That is not an AI system |
| An internal assistant for employees who are trained and know that they are working with AI | No | Then it is obvious. That exception is interpreted narrowly, though: there must be almost no doubt |
| A text on your website or social media that informs the public about a matter of public interest, such as health, safety or policy | Yes, unless a human reviews its content and someone bears responsibility for it | A spelling check alone does not count as review. Advertising and product descriptions in principle do not fall under this |
- How do you disclose it? Clearly, and at the latest at the first contact. A chatbot says it in its first message, a phone assistant in its first sentence.
- What is not enough? A notice that appears only in the general terms and conditions, a vague name such as "assistant", or a general sentence such as "this website uses AI".
- Who has to provide it? The provider of the system builds in the disclosure. If you use an existing product, it is normally included. If you build an assistant yourself, or have one built that you deploy under your own name, then you are the provider in the eyes of the law and you have to provide it.
- You do not have to mention "with the help of AI". The law makes no distinction between a little AI and entirely AI.
- Technical marking. Providers of AI systems must ensure that what their system generates is technically recognisable as generated. For systems that were already on the market before 2 August 2026, this applies from 2 December 2026.
The guidelines are a clarification by the Commission, not law. Supervisory authorities do use them as guidance. Apart from the AI Act, you remain liable for what goes out in your name. And towards consumers, consumer law continues to apply: the fact that a service runs on AI can be a characteristic you must communicate in advance, even when it seems obvious.
What is not mandatory?
For a business that does not use high-risk AI, the AI Act does not impose the following:
- an AI inventory or register
- a formal AI policy in a prescribed form
- a certificate, exam or accredited training course
- an audit, or supporting documents for one
- an external guidance programme
The AI Act also attaches no fine amount of its own to Article 4. That does not mean you can ignore it: anyone who does nothing and causes harm is in a weaker position.
So what do you do?
- Give a short, practical training on the tools you actually use, and keep track of who has followed it.
- Make simple agreements: which tools are allowed, which data must not go into them, and that a human reviews the result.
- Say so when someone is talking to AI. A chatbot or phone assistant makes clear from the start that it is not a human.
- Stay away from emotion recognition. Tools that infer employees' mood from their voice or face are prohibited at work.
- Keep a list of your AI tools. Not mandatory, but useful: without an overview you cannot shield anything.
- Apply the GDPR. As soon as personal data goes into an AI tool, those rules simply apply, and they already existed.
Fines
For prohibited practices the fine runs up to 35 million euros or 7% of worldwide annual turnover. For most other infringements, including the transparency rules, it is up to 15 million euros or 3%. For SMEs the lower of the two amounts applies in each case.
When do you need to go deeper?
- You use AI in recruitment, evaluation or dismissal. That is high risk. Prepare for the 2027 rules.
- You build an AI application yourself and sell it. Then you are a provider and more obligations apply.
- You let AI make decisions about people on its own. Then the GDPR also comes into play, which restricts automated decisions.
For most businesses, the AI Act asks two things: teach your people to work with AI, and be honest about it.
Related terms
- Data Act: a different law, about data from devices and about the cloud.
- Recording conversations: where the AI Act and the GDPR meet.
- AI hallucination: why a human must review the result.
- CLOUD Act: what it means that your AI provider is American.
Sources: AI Act (Regulation 2024/1689) · Digital Omnibus on AI (Regulation 2026/1744) · European Commission guidelines on Article 50 · GDPR (Regulation 2016/679)
This article is not legal advice. The rules were checked on 6 October 2026. For a specific situation, it is best to consult a lawyer.