Why does this matter?

Many half-truths about the AI Act are doing the rounds. Some businesses no longer dare to use AI, others receive a quote for a "legally required" programme. In reality the law is easy to follow, as long as you know which category your use falls into. For most businesses that is the lightest one.

Four risk levels

LevelExamplesWhat appliesSince
ProhibitedSocial scoring, manipulating people, inferring emotions at work or at schoolNot allowed2 February 2025
High riskSelecting job applicants, evaluating employees, assessing creditworthinessRisk management, documentation, human oversight, registration2 December 2027 (AI in regulated products: 2 August 2028)
TransparencyChatbots, phone assistants, imitated images and voicesPeople must know that it is AI2 August 2026
MinimalPreparing emails and reports, searching your own documents, translatingNo specific obligations

The dates for high risk were postponed in 2026. Originally those rules were due to take effect on 2 August 2026.

Provider or deployer?

The law distinguishes between whoever makes an AI system and places it on the market (the provider) and whoever uses it in their business (called the "deployer" in the Act). The heaviest obligations lie with the provider. Most businesses are deployers. Makers of large language models have had their own obligations since 2 August 2025, and those do not affect you directly as a deployer.

AI literacy: what does the text really say?

Article 4 has applied since 2 February 2025 to every organisation that uses AI, large or small. The text was weakened in 2026. Since 27 July 2026 (Regulation 2026/1744, the Digital Omnibus on AI) the obligation reads that you "take measures to support the development of AI literacy" among your employees and among those who work with AI on your behalf. The law explicitly adds that you do not have to guarantee a particular level.

What that involves depends on what your people do. Someone who uses AI to prepare texts must know what they may and may not put into it, and that the result can be wrong. Someone who manages an AI system that prepares decisions must know more.

Do you have to disclose that something was made by AI?

It does not depend on the channel, nor on how much AI is involved. It depends on whether a human really reviews the message and sends it personally, or whether the AI system itself communicates with someone. The rules come from Article 50 and apply to email, WhatsApp, chat and phone in the same way. The European Commission clarified them in guidelines on 20 July 2026, and the examples below follow that clarification.

SituationDisclose?Why
An email, message, quote or report that AI drafts and that you review and send yourselfNoThe recipient is communicating with you, not with the AI system. The condition is that you really review it: the fact that review is possible is not enough
A customer service employee who uses an AI tool to replyNoSame reason: a human is conducting the conversation
A chatbot or AI assistant that talks to customers itself via chat, email or WhatsAppYesAnyone communicating with an AI system must know it. Also when the system starts the conversation itself
An AI agent that writes and sends emails, books appointments or negotiates on your behalfYesThe agent makes clear that it is AI, and also on whose behalf it acts. For example with a notice at the top of the email
An AI voice that answers the phone or makes calls itselfYes, spoken at the start of the callSame rule. A sound signal alone is not enough
A voice, image or video that imitates an existing person or a real eventYes, alwaysSeparate rule for imitated images and voices
An automatic message from a classic system without AI, such as a fixed template or an out-of-office replyNoThat is not an AI system
An internal assistant for employees who are trained and know that they are working with AINoThen it is obvious. That exception is interpreted narrowly, though: there must be almost no doubt
A text on your website or social media that informs the public about a matter of public interest, such as health, safety or policyYes, unless a human reviews its content and someone bears responsibility for itA spelling check alone does not count as review. Advertising and product descriptions in principle do not fall under this

The guidelines are a clarification by the Commission, not law. Supervisory authorities do use them as guidance. Apart from the AI Act, you remain liable for what goes out in your name. And towards consumers, consumer law continues to apply: the fact that a service runs on AI can be a characteristic you must communicate in advance, even when it seems obvious.

What is not mandatory?

For a business that does not use high-risk AI, the AI Act does not impose the following:

The AI Act also attaches no fine amount of its own to Article 4. That does not mean you can ignore it: anyone who does nothing and causes harm is in a weaker position.

So what do you do?

Fines

For prohibited practices the fine runs up to 35 million euros or 7% of worldwide annual turnover. For most other infringements, including the transparency rules, it is up to 15 million euros or 3%. For SMEs the lower of the two amounts applies in each case.

When do you need to go deeper?

For most businesses, the AI Act asks two things: teach your people to work with AI, and be honest about it.

How Sevendays handles this: every AI application we set up comes with a short training for the team and clear agreements about what may go into it. Assistants that talk to customers say that they are AI. You can read what such a training looks like in getting your team to work with AI, and what we build is under AI and examples.

Related terms

Sources: AI Act (Regulation 2024/1689) · Digital Omnibus on AI (Regulation 2026/1744) · European Commission guidelines on Article 50 · GDPR (Regulation 2016/679)

This article is not legal advice. The rules were checked on 6 October 2026. For a specific situation, it is best to consult a lawyer.