Up front — not legal advice: This article offers orientation; it does not replace legal counsel. For binding assessments of your specific case, bring in a specialist lawyer. The short answer for most companies: from August 2, 2026, the transparency obligations apply — label chatbots as AI, mark AI-generated content, disclose deepfakes. The heavy high-risk obligations were pushed to the end of 2027 and affect only a few in any case.
Hardly any framework has caused as much uncertainty in the AI world as the EU AI Act. Between headlines about million-euro fines and reports of watered-down deadlines, it is hard to tell what actually matters for an ordinary company. This piece separates the essential from the noise: What already applies, what arrives in August 2026, what was postponed — and what is still open?
What is the EU AI Act — in one paragraph
The EU AI Act is the world's first comprehensive AI law. Its basic principle is as simple as it is sound: It regulates not the technology itself, but the risk of the application. An AI spam filter is treated differently than an AI that decides on creditworthiness or job applications. The higher the risk to people and fundamental rights, the stricter the obligations. From this follow four risk classes — and for your company the decisive question is: which class does your AI use fall into?
The four risk classes — explained simply
| Risk class | Examples | What applies |
|---|---|---|
| Prohibited | Social scoring, untargeted scraping of facial images, manipulative systems | Completely banned (in force since Feb 2025) |
| High-risk | AI in candidate selection, lending, critical infrastructure, certain medical devices | Strict requirements — but postponed (Dec 2027 / Aug 2028) |
| Limited risk | Chatbots, AI-generated text/images/videos, deepfakes | Transparency: label & disclose (from Aug 2026) |
| Minimal risk | Spam filters, AI in games, product recommendations | No special obligations |
The vast majority of companies that use AI day to day — a chatbot on the website, generated text and images, automated support replies — land in the "limited risk" class. And that is exactly the one that now becomes relevant. (A special role is played by the rules for large AI foundation models, so-called GPAI — those have applied since August 2025, but mainly concern the model providers themselves, not the ordinary user.) Where AI is even worth deploying in operations, our AI use cases for companies show — this article clarifies the legal side of it.
What really counts from August 2026: the transparency obligations
August 2, 2026 is the date that matters for the broad mass of companies. From then on the transparency obligations of Article 50 take effect — and from then on, violations can be met with fines. The most important key dates at a glance:
| Date | What happens | Status |
|---|---|---|
| Feb 2, 2025 | Prohibited practices (Art. 5) banned | Already applies |
| Aug 2, 2025 | Rules for AI foundation models (GPAI) | Already applies |
| Aug 2, 2026 | Transparency obligations (Art. 50) + fine enforcement | New — not postponed |
| Dec 2, 2026 | Transition period for labeling existing systems expires | New |
| Dec 2, 2027 | High-risk obligations (Annex III) | Postponed |
| Aug 2, 2028 | High-risk in regulated products (Annex I) | Postponed |
As of July 2026. The postponed deadlines are based on the "Digital Omnibus" package, formally adopted in June 2026 (European Parliament on June 16, Council of the EU on June 29, 2026; see the section below). All figures per official EU sources and law-firm analyses (see sources).
1. Disclose chatbots & voice as AI
Users must recognize, at the latest on the first interaction, that they are talking to an AI — not a human. A website chatbot or a phone assistant therefore needs a clear notice ("You are chatting with an AI assistant"). Exception: when it is obvious anyway to an attentive person. This is the most common obligation in practice — and it can be implemented with a single sentence.
2. Label AI-generated content
Providers of generative AI must mark their outputs — text, image, audio, video — as artificially created in a machine-readable way, for example via a technical watermark or the C2PA provenance standard. For systems newly entering the market, this applies immediately from the key date; for systems already running, there is a grace period until December 2, 2026. This obligation primarily targets the providers of the AI tools — relevant to you if you offer a generative AI product yourself.
3. Disclose deepfakes & public content
Anyone publishing AI-generated or AI-manipulated images, audio, or videos (deepfakes) must disclose the artificial origin. Something similar applies to AI text on matters of public interest — here with an exception if the text underwent editorial review. For marketing and social media teams, this is the point most likely to be overlooked by accident.
4. AI competence of employees ("AI literacy")
Weiterlesen — kostenlos
Den vollständigen Inhalt freischalten
Trag deine E-Mail-Adresse ein und bestätige sie: Du abonnierst den Signal-Forge-Newsletter von FORGE und erhältst sofort Zugang zu diesem und allen weiteren registrierungspflichtigen Inhalten. Die Abmeldung ist jederzeit möglich.
Schon registriert? Der Link aus deiner Bestätigungs-Mail schaltet dieses Gerät wieder frei.
Companies that use AI must ensure a minimum level of AI competence among their workforce. This obligation (Art. 4) has formally applied since February 2025; the regulatory supervision of it starts in August 2026. In practice, a basic internal training session is enough to get started: what may go in, what may not, where the limits are. Note: the simplification package adopted in June 2026 (see below) eases individual requirements; for the exact wording of Art. 4, the consolidated legal text governs.
What was postponed — and why it relieves most companies
Originally, the heavy high-risk obligations were also meant to take effect in August 2026. A simplification package, the so-called "Digital Omnibus," pushed them back: Annex III systems to December 2, 2027, AI embedded in products (Annex I) to August 2, 2028. The trigger was pressure from industry and the concern that Europe was slowing down its own AI economy.
Important context: high-risk affects only certain, clearly defined uses — personnel selection, creditworthiness, critical infrastructure, certain medical devices. An ordinary website chatbot or AI-assisted text creation does not fall under it. For most small and mid-sized companies that means: relief on the demanding requirements — but the lean transparency rules remain.
Freshly adopted: The Omnibus package was formally decided in June 2026 — the European Parliament agreed on June 16, the Council of the EU gave its final green light on June 29, 2026. The postponement of the high-risk deadlines is thereby settled; publication in the EU Official Journal and entry into force follow shortly after. Conversely, do not rely on anything changing about the transparency obligations — the Omnibus expressly left them untouched, and they remain a hard deadline of August 2, 2026.
Fines — the framework
The AI Act works with tiered fines (Art. 99). In each case the higher of the two values applies:
- Prohibited practices (Art. 5): up to 35 million euros or 7 % of global annual turnover.
- Other violations, including against the transparency obligations (Art. 50): up to 15 million euros or 3 %.
- False or misleading information to authorities: up to 7.5 million euros or 1 %.
For small and mid-sized companies and start-ups there is relief: here the lower of the two values applies — not the higher. Enforcement, that is the power to impose such fines, takes effect from August 2, 2026.
No reason to panic. The maximum amounts are ceilings for serious, deliberate violations by large providers — not the standard case for a missing chatbot notice. Anyone who takes the transparency obligations seriously, implements them cleanly, and documents this is on the safe side.
Your checklist — what you should do now
1. Take inventory. List everywhere AI is in use — and assign each case to a risk class. That is the basis for everything else. 2. Check chatbot/voice. Does the user immediately recognize they are talking to AI? If not → add a notice. 3. Label AI content. Do you publish generated images, videos, or audio? → mark them as AI-generated. 4. Disclose deepfakes. Always mark realistic AI composites as such. 5. Train the team. A short internal AI basics session covers the entry into the AI-literacy obligation. 6. Only for high-risk: Do you use AI in personnel, credit, or medicine? Then get legal advice — but you have time until the end of 2027.
Conclusion: tidy up instead of getting worked up
The EU AI Act is no reason to panic, but a good occasion to tidy up: to know everywhere AI works in the house, and to implement the few transparency rules cleanly. The effort involved is manageable for most companies — the effect on the trust of customers and partners is not. At FORGE, honest labeling is standard anyway: we disclose AI chatbots, mark AI-generated content, and build AI systems that are GDPR- and EU-compliant.
If you want to introduce AI agents cleanly and in a compliant way, our hands-on playbook on AI agents shows the concrete steps. And which AI model suits which task is clarified by our model comparison 2026. Rules change — a cleanly set up, transparent AI system outlasts them.
Sources
- Primary EU AI Act — Article 50 (transparency obligations: chatbot disclosure, labeling, deepfakes): artificialintelligenceact.eu/article/50
- Primary EU AI Act — Article 99 (fines: 35 M/7 %, 15 M/3 %, 7.5 M/1 %, SME cap): artificialintelligenceact.eu/article/99
- Official European Commission — Code of Practice on labeling AI-generated content: digital-strategy.ec.europa.eu
- Official Council of the EU — final approval of the Digital Omnibus on June 29, 2026 (Parliament on June 16): consilium.europa.eu
- Gibson Dunn — Digital Omnibus agreement: high-risk deadlines postponed (Annex III → Dec 2027, Annex I → Aug 2028): gibsondunn.com
- Latham & Watkins — AI Act Update: rule changes and extended deadlines: lw.com
- Travers Smith — postponement of deadlines & status of the AI-literacy obligation (Art. 4): traverssmith.com
- ComplianceHub — what falls due on August 2, 2026 (Art. 50 in detail, labeling transition period until Dec 2026): compliancehub.wiki