TL;DR: The EU AI Act is the EU regulation on artificial intelligence. For most companies the key part is the Article 50 transparency obligations taking effect on 2 August 2026: disclosing chatbots, labelling AI content and deepfakes. High-risk systems are a separate, narrower category with later deadlines. Below: the timeline and a concrete to-do list. {.lead}
The EU AI Act sounds intimidating, but for an ordinary company it boils down to a few common-sense rules. The most important thing is to separate what applies to everyone (transparency) from what applies to the few (high risk).
Who does the EU AI Act apply to?
The most common misconception is “this is only for tech companies”. Not true. The AI Act places obligations on providers (those who build or place AI systems on the market) and on deployers (companies that use AI). So an ordinary company using a chatbot, a content generator or AI in recruitment also has obligations — most often those under Article 50.
EU AI Act timeline
| Date | What takes effect |
|---|---|
| 2 February 2025 | Ban on prohibited practices (e.g. social scoring) |
| 2 August 2025 | Rules for general-purpose AI models (GPAI) |
| 2 August 2026 | Transparency obligations (Art. 50) — apply to most companies |
| 2 December 2027* | High-risk systems under Annex III (*after the proposed Digital Omnibus) |
| 2 August 2028* | High-risk systems embedded in products (Annex I) |
The asterisks mark deadlines that the proposed Digital Omnibus may change — as of publication it is a draft.
Article 50 transparency — this is what applies to you
This is the heart of it for most companies. From 2 August 2026:
- Chatbots — tell users they are talking to AI before the conversation starts.
- AI-generated content — label text, graphics, audio and video created with significant AI involvement.
- Deepfakes — disclose synthetic material (e.g. synthetic voice or face).
These are simple to meet — they need awareness and a few rules, not costly projects. Check them with the free AI Act checklist.
What does the EU AI Act ban outright?
The top risk tier is prohibited practices (in force since February 2025). They rarely affect an ordinary company, but it’s worth knowing them so you don’t adopt one by accident — for example social scoring of citizens, manipulative techniques exploiting vulnerabilities, or unjustified emotion recognition in the workplace. If you’re considering a tool that “scores” staff or customers in an unusual way, check whether it falls here or into high-risk systems.
What about ChatGPT and other general-purpose models?
Providers of general-purpose AI (GPAI) models — such as large language models — have their own obligations (mainly documentation) that took effect in August 2025. For your company as a user of such a tool, this mainly means you rely on a provider that is itself regulated — and your obligations concern how you use it (transparency, data, an internal AI policy).
A 2026 action plan — 5 steps
- Inventory the AI tools used in the company.
- Detect Shadow AI and give your team safe rules.
- Write an AI policy — one page of rules.
- Implement transparency — content labelling and chatbot disclosure.
- Check for high risk — whether any system falls into that category.
The fastest way through this is an AI readiness audit, which turns these steps into a concrete plan for your company. Book an audit or start with the checklist.
Informational material; not legal advice.
This material is informational and does not constitute legal advice. The law may change — for doubts about a specific situation, consult a lawyer.