EU AI Act 2026: New Obligations for Businesses

Andreas Straub • Jul 24, 2026

15 mins Read Time

Starting August 2, 2026, the EU AI Act will introduce new transparency requirements for chatbots, deepfakes, and AI-generated content. We explain all the deadlines, fines, and what companies need to do now.
Black robot hand assembling an EU flag puzzle on a wooden surface

Table of Contents

Key Takeaways

  • Transparency obligation from 2 August: AI-generated content must be labelled (EU Commission, 2026).
  • Penalties up to EUR 35 million: Three tiers from 1% to 7% of global annual turnover, exceeding the GDPR (Regulation EU 2024/1689, Art. 99).
  • High-risk AI postponed: Obligations for AI in areas such as human resources or credit scoring apply only from December 2027 (Gibson Dunn, 2026).
  • Active enforcement from August 2026: A network of authorities, including the Federal Network Agency, BaFin, and state authorities, monitors compliance and can impose substantial fines for violations (LTO.de, 2026).

The EU AI Act is the world's first comprehensive law regulating artificial intelligence. Since entering into force on 1 August 2024, two phases have already taken effect: the prohibition of particularly dangerous AI practices (February 2025) and the obligations for General Purpose AI (August 2025). On 2 August 2026, the third and most extensive phase follows, bringing transparency obligations, enforcement powers, new prohibitions, and a penalty framework.

In addition, there is the Digital Omnibus on AI, an amending regulation adopted in June 2026 that adjusts the AI Act, postpones deadlines, and introduces new prohibitions. This article explains everything that currently applies, what has been postponed, and what businesses must implement immediately.

On 2 August 2026, the following take effect simultaneously: transparency obligations for AI systems (Article 50), obligations to promote AI literacy (Article 4), deployer obligations including risk assessment and provider verification, enforcement powers for the EU AI Office, new prohibitions under the Digital Omnibus, and the full penalty framework.

What Is the EU AI Act

The AI Regulation (officially: Regulation EU 2024/1689) establishes a uniform legal framework for artificial intelligence across the entire EU. Like the GDPR, it applies directly in all 27 member states without national implementing legislation. The Regulation applies to anyone who provides, deploys, or professionally uses AI systems in the EU, regardless of whether the company is headquartered in the EU. It follows a risk-based approach: AI systems are classified into four categories — prohibited, high-risk, limited risk, and minimal.

  • Prohibited (e.g. social scoring, manipulative AI)
  • High-risk (e.g. recruitment, credit scoring)
  • Limited risk (e.g. chatbots, deepfake generators)
  • Minimal (e.g. spam filters, recommendation algorithms)
Woman presenting the EU AI Act in an office to a group seated at a conference table

What already applies

Since 2 February 2025, certain AI practices have been completely prohibited: social scoring, manipulative AI systems, real-time biometric identification in public spaces, emotion recognition in the workplace and in educational institutions, and untargeted scraping of facial images (TÜV Consulting, 2026). Furthermore, since 2 February 2025, companies in the EU must ensure that their employees have sufficient AI literacy. Every person who works professionally with AI systems should understand their basic functioning, risks, and limitations.

Since 2 August 2025, obligations apply to providers of General Purpose AI (general-purpose AI), including technical documentation, summaries of training data, and copyright policies (TÜV Consulting, 2026). Every deployed AI system must be identified and assigned to one of the four risk categories.

The AI Act distinguishes two central roles: providers develop AI systems and place them on the market, deployers use them under their own responsibility in a professional capacity. Both must promote the AI literacy of their staff, although the Digital Omnibus has lowered the required standard of this obligation (Gibson Dunn, 2026). Deployers must additionally verify whether third-party AI tools they use meet the requirements of the AI Act.

Relationship with the GDPR

The AI Act and the GDPR apply in parallel. The GDPR protects personal data, while the AI Act regulates the safety and transparency of the AI system itself. Anyone deploying an AI system that processes personal data must comply with both regulations. Article 10 of the AI Act explicitly references the GDPR with regard to training data. Companies that already conduct data protection impact assessments can leverage synergies. However, the AI Act obligations are additional and do not replace existing data protection duties. The same applies to the European Accessibility Act (EAA), which has required businesses to make their digital services accessible since 2025.

Transparency Obligations from 2 August 2026

Article 50 of the AI Regulation governs the transparency obligations that apply from 2 August 2026. They affect both providers and deployers of AI systems and represent the current state of regulation for most businesses. Violations are subject to penalties of up to EUR 15 million or 3% of global annual turnover (Regulation EU 2024/1689, Art. 99).

Laptop showing August 2026 calendar during a meeting on a wooden table

Chatbots and AI Assistants

Deployers of AI systems that interact directly with individuals must inform those individuals that they are communicating with an AI system. This applies to chatbots on websites, voicebots in call centres, AI-powered telephone assistants, and virtual assistants in apps. The information must be provided no later than the start of the interaction, i.e. before the user makes their first input or the conversation begins.

The labelling can be provided in written, visual, or audible form, depending on the communication channel. For a website chatbot, a visible notice such as "You are communicating with an AI assistant" is sufficient. For telephone bots, the notice must be provided audibly at the start of the conversation. An exception exists only where it is obvious to a reasonably well-informed, attentive, and circumspect person that they are interacting with an AI system. The labelling must be "clear and distinguishable" (artificialintelligenceact.eu, 2026).

For businesses, a clear principle applies from August 2026: whoever deploys AI must be transparent about it. Users and viewers must be able to recognise when they are interacting with an AI or viewing AI-generated content. The labelling does not need to be complicated — a visible notice on the website or in the respective medium is sufficient in most cases. What matters is that the information is visible before or at the point of use and is not buried in the legal notice. The only exception applies to content that a company creates with AI assistance but subsequently reviews itself and publishes under its own editorial responsibility.

Deepfakes and Manipulated Content

The AI Act defines deepfakes as AI-generated or manipulated image, audio, or video content that resembles real persons, objects, places, or events and could falsely appear authentic. Deployers who publish such content must disclose the AI origin no later than at the time of first publication (EU Commission FAQ, 2026). This applies not only to obvious forgeries but also to subtle manipulations, for example when a person in a video speaks different words than those actually said.

For businesses, this is particularly relevant in marketing and advertising. AI-generated product images, virtual testimonials, or synthetic speakers in promotional videos must be labelled as AI-generated if they create the impression of showing real people or scenes. Purely decorative or abstract AI images — such as generated background patterns or stylised graphics — do not fall under the deepfake regulation, as they do not imitate real persons or events.

For artistic, satirical, fictional, or similar creative works, a discreet label that does not impair the user experience is sufficient. A brief note in the credits of a video or a footnote is adequate here. For all other deepfakes, the labelling must be clearly visible and provided no later than at first publication. The technical implementation falls to providers: they must design their AI systems so that the generated content is recognisable as AI-generated in machine-readable form.

AI-Generated Text

Texts generated by AI systems and published on matters of public interest must be labelled as AI-generated. The EU Commission FAQ defines the concept of "public interest" deliberately broadly: it encompasses politics, health, the environment, the economy, consumer protection, science, education, and other socially relevant topics. In practice, this means that virtually every published AI text falls under this regulation — whether blog post, newsletter, press release, or social media post.

An important exception: where the text has undergone genuine human editorial review, the labelling obligation does not apply. This means that a person with subject-matter expertise has reviewed the AI-generated text, verified the facts, and adjusted the content where necessary. Mere spell-checking or superficial proofreading is not sufficient. The EU Commission FAQ makes clear: anyone who merely copies an AI text and publishes it without substantive review cannot rely on the exception. However, anyone who uses an AI draft as a starting point, reviews the content with professional expertise, and releases it under their own responsibility does not need to label it.

Regardless of text labelling, a separate technical obligation applies to providers of AI systems: every AI system that generates synthetic content — whether images, videos, audio, or text — must mark that content as AI-generated in machine-readable form. This is achieved through watermarks, metadata, cryptographic signatures, or comparable methods. A transitional period applies specifically for this watermarking obligation: AI systems that were already on the market before 2 August 2026 must implement the machine-readable marking only from 2 December 2026 (Gibson Dunn, 2026). Content created before 2 August 2026 does not need to be retroactively labelled. The corresponding technical standards are being developed by CEN-CENELEC but have not yet been finalised.

Measure / Practical Example / Obligation

Measure
Chatbot labelling
Practical Example
Customer service bot, AI appointment booking, automated consultations
Obligation
Inform users before interaction that they are communicating with AI
Measure
Deepfake disclosure
Practical Example
AI-generated team photos, product videos with AI voice
Obligation
Visibly label content as AI-generated or AI-manipulated
Measure
AI text labelling
Practical Example
Blog articles via ChatGPT, AI press releases
Obligation
Label texts on matters of public interest as AI-generated (exception: editorial review)
Measure
Machine-readable marking
Practical Example
AI image generators, text-to-speech, video AI
Obligation
Embed watermarks or metadata in all synthetic outputs. Legacy systems: by 2 Dec. 2026

Penalty Framework: Three Tiers up to EUR 35 Million

The EU AI Act provides for a three-tiered penalty system that significantly exceeds the GDPR (maximum EUR 20 million or 4% of turnover) in its upper limits (Regulation EU 2024/1689, Art. 99).

Violations of the prohibited AI practices under Article 5 are subject to penalties of up to EUR 35 million or 7% of global annual turnover. This covers social scoring, manipulative AI, unlawful biometric identification, and the new Omnibus prohibitions.

Violations of the transparency obligations (Article 50) and obligations for providers and deployers of high-risk AI carry penalties of up to EUR 15 million or 3% of global annual turnover.

Providing false, incomplete, or misleading information to supervisory authorities incurs penalties of up to EUR 7.5 million or 1% of global annual turnover. For SMEs and start-ups, the lower amount (fixed amount or turnover share) applies at each tier, not the higher.

Active enforcement begins on 2 August 2026. The supervisory authorities can penalise violations of the prohibitions in effect since February 2025 and the new transparency obligations with these fines. The EU AI Office oversees the GPAI obligations at the European level. In Germany, the Federal Network Agency takes on market supervision, supported by the KI-MIG passed by the Bundestag on 11 June (LTO.de, 2026).

Different pace across member states

The deadline for designating national AI supervisory authorities expired on 2 August 2025. The level of implementation varies considerably. Finland, Belgium, and Poland have already established operational structures. France has designated the CNIL as the responsible authority but, as of April 2026, still lacks complete supervisory structures. For companies operating across borders, this means a fragmented supervisory landscape with varying interpretations (TÜV Consulting, 2026).

What Businesses Need to Do Now

The postponement of the high-risk obligations is no reason for inaction. The transparency obligations apply from 2 August 2026, and the supervisory authorities are beginning active inspections. Especially those planning a new website should factor in the AI Act requirements from the outset in their web design.

AI Inventory and Risk Assessment

Every business should record which AI systems it uses or provides. Whether a chatbot on the website, an AI-powered recruiting tool, automated text generation, or AI-based image editing — every system must be identified and assigned to a risk category, because the classification determines which obligations apply, what documentation is required, and what penalties apply for violations (prohibited, high-risk, limited risk, minimal). At the same time, the business must clarify its own role.

Prohibited AI systems include social scoring, manipulative AI, and real-time biometric surveillance in public spaces. High-risk AI encompasses systems in sensitive areas: recruitment and hiring, credit scoring, automated grading in education, law enforcement, and critical infrastructure. These are subject to the strictest requirements including conformity assessment and CE marking (obligations postponed to December 2027).

Limited risk applies to chatbots, deepfake generators, and AI text generators. They are subject to the transparency obligations under Article 50, i.e. labelling and disclosure (TÜV Consulting, 2026). Minimal risk applies to spam filters, AI-powered inventory optimisation, or recommendation algorithms, for example. These AI systems are not subject to any specific requirements under the AI Act.

Group of five colleagues in a meeting in an office with laptops and notes

Implementing Transparency Obligations

For businesses, a clear principle applies from August 2026: whoever deploys AI must be transparent about it. Users and viewers must be able to recognise when they are interacting with an AI or viewing AI-generated content. The labelling does not need to be complicated — a visible notice on the website or in the respective medium is sufficient in most cases. What matters is that the information is visible before or at the point of use and is not buried in the legal notice. The only exception applies to content that a company creates with AI assistance but subsequently reviews itself and publishes under its own editorial responsibility. As with accessible website design, AI transparency is also about making information accessible and understandable for all users.

Training and Governance

The Digital Omnibus has significantly lowered the requirements for the AI literacy obligation. However, this does not mean that businesses can ignore the topic. A lack of training can be considered an aggravating factor in the event of violations, while documented training programmes can serve as a mitigating factor. The EU recommends a four-step approach: building general AI understanding, clarifying one's own role in AI deployment, assessing the risk levels of the systems in use, and developing targeted measures for each employee group.

In practice, the training must be relevant to the respective work context. Those who create AI texts in online marketing must be familiar with the labelling obligations. Those who manage a chatbot in customer service need knowledge of the disclosure obligation. And those who procure or evaluate AI tools should be able to classify the risk categories of the AI Act.

Larger companies should additionally establish an AI governance structure. This does not require a dedicated "AI Officer", but it does require clear responsibilities for compliance with the EU AI Act. This includes an up-to-date AI inventory, regular risk assessments, and a process for reporting serious incidents. Particularly important is the vetting of third-party providers. Especially with SaaS tools such as ChatGPT, Midjourney, or Copilot, the transparency obligation lies with the deployer — i.e. the company itself, not the software provider.

Relief Measures for SMEs and Mid-Sized Companies

The original AI Act already provided relief measures for SMEs, such as reduced penalties and preferential access to regulatory sandboxes. The Digital Omnibus on AI has significantly expanded this differentiation: the strict AI literacy obligation has been softened to a recommendation, the high-risk deadlines have been postponed by 16 months, and a new category of Small Mid-Caps has been created that covers the typical mid-sized business segment (Deloitte, 2026).

Man in checked shirt using a laptop in a café, next to a plant

In addition to the standard SME definition (fewer than 250 employees, less than EUR 50 million turnover), there is now a new category: Small Mid-Caps. This covers companies with fewer than 750 employees and annual turnover of no more than EUR 150 million (Orrick, 2026). Simplified documentation obligations apply to these companies.

SMEs and start-ups pay the lower amount at each penalty tier (fixed amount or turnover share), receive preferential access to regulatory sandboxes, and can use simplified forms for technical documentation. Those commissioning a custom web application can factor in these relief measures from the planning stage.

What Is Still to Come

On 2 December 2027, the high-risk obligations for standalone AI systems (Annex III) will become applicable, followed on 2 August 2028 by the obligations for AI in regulated products (Annex I). Public bodies have until August 2030 to adapt (Gibson Dunn, 2026).

Frequently Asked Questions

Yes. There is no general exemption based on company size. Anyone who deploys or provides AI systems commercially falls under the AI Regulation. However, SMEs receive reduced fines, simplified documentation, and preferential sandbox access (artificialintelligenceact.eu, 2024).

Related Articles

Sources