August 2, 2026 has passed. For a company using a chatbot, publishing synthetic content or adding AI to a recruitment process, the question is no longer how to prepare for one deadline. The task is to separate rules that already apply from requirements whose dates have moved.
Regulation (EU) 2026/1744 postponed part of the high-risk AI timeline. It did not remove the Article 50 transparency duties that have applied since August 2, 2026, or the AI literacy duty already in force. This article provides a practical way to sort typical company use cases. It is not a substitute for legal advice where AI affects recruitment, credit, biometrics, health or another consequential decision.
What applies since August 2, 2026
The AI Act does not have a single application date. These are the main milestones as of August 2026:
| Date | Rules concerned |
|---|---|
| February 2, 2025 | AI literacy for providers and deployers, plus an initial set of prohibited practices |
| August 2, 2025 | Duties for general-purpose AI models placed on the market from that date |
| August 2, 2026 | General application date and Article 50 transparency duties |
| December 2, 2026 | End of the transition granted to providers of certain synthetic-content systems placed on the market before August 2, 2026 |
| December 2, 2027 | Chapter III, Sections 1 to 3 requirements for high-risk systems under Article 6(2) and Annex III |
| August 2, 2028 | The same sections for high-risk systems under Article 6(1) and Annex I |
The 2027 and 2028 dates come from Regulation (EU) 2026/1744. The delay covers the Chapter III requirements identified in that regulation. It does not create a regulatory gap for every high-risk use. Other EU rules, the GDPR, employment law and contractual commitments may still apply.
Start by identifying your role
A business may be a customer of an AI tool, a "deployer" under the regulation, or a provider if it develops a system or places it on the market under its own name. Those roles do not carry the same duties.
Record at least the following for every use case:
- the tool and its provider;
- the intended purpose;
- the people affected;
- the data sent to the system;
- the decision or content it produces;
- the human owner who checks the result;
- the information given to affected people.
This inventory exposes sensitive uses and supports the separate privacy analysis required when personal data is involved.
AI literacy must fit the actual use
Article 4 of Regulation (EU) 2024/1689 requires providers and deployers to take measures, to their best extent, to ensure a sufficient level of AI literacy among people operating AI systems on their behalf.
The regulation does not prescribe one training course for every company. Measures should reflect the team's knowledge, the context and the people on whom the system is used. A company can start with:
- a list of permitted and prohibited tools;
- rules for confidential and personal data;
- training based on the real use cases;
- a method for checking outputs;
- dated records of training and subsequent updates.
A team using a writing assistant does not need the same preparation as an HR team relying on candidate scores. Training should follow the risk, not a generic compliance package.
Transparency: three common situations
Article 50 contains distinct duties. Saying that every piece of AI-assisted content must carry a label is too broad.
A person interacts with an AI system
When a chatbot or agent interacts directly with a person, the person must generally be informed that they are interacting with AI unless this is obvious from the circumstances. The information should be provided no later than the first interaction and remain accessible.
For a website assistant, an explicit "AI assistant" label and one short sentence in the conversation window are more useful than a clause buried in the terms of service.
A system generates synthetic content
Providers of systems that generate or manipulate audio, image, video or text must make outputs detectable and marked in a machine-readable format. Regulation 2026/1744 gives providers whose systems were already on the market before August 2, 2026 until December 2, 2026 to meet this specific duty.
That transition concerns the relevant providers. It does not delay every transparency duty for every user.
A company publishes a deepfake or certain public-interest text
Deployers must disclose deepfakes. A disclosure duty also covers certain AI-generated or manipulated text published to inform the public on matters of public interest. An exception applies where the content has undergone human review or editorial control and a person holds editorial responsibility.
The Commission's Article 50 transparency guidelines and questions and answers explain these distinctions.
High-risk systems: the timeline has changed
Recruitment, worker evaluation, certain credit, education and essential-service use cases may fall within Annex III. Classification depends on the exact function of the system, not the presence of an "AI" feature in a software product.
Regulation 2026/1744 now makes Chapter III, Sections 1 to 3 applicable:
- on December 2, 2027 for systems classified as high-risk under Article 6(2) and Annex III;
- on August 2, 2028 for systems under Article 6(1) and Annex I, including certain safety components of regulated products.
A company using a potentially high-risk tool should not wait until those dates. Ask the vendor how it classifies the system, what documentation and logs are available, how human oversight works and what will change before the relevant deadline.
A checklist that does not promise automatic compliance
A useful compliance file can be small, but its contents depend on the use cases. Start with these steps:
- inventory AI systems, including tools adopted directly by staff;
- identify the provider, deployer and affected people for each system;
- check the transparency duties that already apply;
- isolate uses involving recruitment, credit, education, health, biometrics or essential services;
- document human review and the response to an error;
- train users according to their role;
- review the register when the model, data or purpose changes.
A sensitive process should not become fully autonomous because a model returns a score. The guide to human approval in production AI agents explains how to place practical control points.
Fines and enforcement: avoid shortcuts
The regulation sets several maximum levels, including EUR 35 million or 7% of worldwide annual turnover for certain prohibited practices, and EUR 15 million or 3% for other infringements. The applicable calculation depends on the breach. Where the regulation provides for it, an SME is subject to the lower maximum. Gravity, proportionality and other circumstances still matter.
It is also inaccurate to name one data protection authority as the sole enforcer for every part of the AI Act. National market-surveillance authorities carry most enforcement responsibilities, while the AI Office has a specific role for certain systems and models. The competent authority must be checked for the country, sector and use concerned.
Official sources
- Regulation (EU) 2024/1689, the Artificial Intelligence Act
- Regulation (EU) 2026/1744 amending parts of the high-risk timeline
- European Commission guidelines on Article 50 transparency duties
- European Commission questions and answers on Article 50
The next decision
Do not start by buying a generic compliance package. Take one live use case, identify the company's role, the people affected and the rule that applies on the review date. Repeat the exercise for the remaining tools.
For ordinary uses, this will usually produce an inventory, clear information and appropriate training. If a system contributes to a consequential decision, have its classification and timeline reviewed before increasing automation. Kirako can help audit AI uses and processes, while legal validation remains a separate profession.
Also available: Read in French