In under a month — 2 August 2026 — the next wave of obligations under the European AI Act kicks in. And there's perfect confusion around the deadline: half the internet says the AI Act is being postponed, the other half warns of fines in the millions of euros. The truth is somewhere in between — and for most companies it's surprisingly good news.
In late June the EU definitively approved the package known as the Digital Omnibus (European Parliament on 16 June, Council of the EU on 29 June 2026). It postpones the strictest part of the rules — the obligations for so-called high-risk systems — to December 2027. But the transparency obligations stayed unchanged. And those apply to practically every company that has a chatbot on its website or publishes AI-generated content.
The AI Act in a nutshell
The AI Act is the world's first comprehensive regulation of artificial intelligence. It applies directly across the whole EU — no national law needs to "switch it on". It works on a simple principle: the greater the risk an AI system poses, the stricter the rules for it. Obligations phase in gradually:
February 2025 — bans and AI literacy. Manipulative practices and social scoring are banned. At the same time, there's an obligation to ensure that people working with AI in a company understand what they're using.
August 2025 — rules for large models. Obligations for providers of general-purpose AI models — OpenAI, Anthropic, Google. They don't concern ordinary companies.
August 2026 — transparency. Labelling of chatbots, AI content and deepfakes. This is the wave that hits ordinary companies — and it's what the rest of this article is about.
December 2027 — high-risk systems. Originally due from August 2026, the Digital Omnibus postponed them by 16 months.
What applies from 2 August 2026
1. A chatbot must disclose it's AI
If AI communicates with customers on your website, phone line or WhatsApp, the customer must know. They must not think they're writing to a human. In practice, a clear sentence in the chatbot's opening message or at the start of the call is enough — "I'm the AI assistant of XY".
There's an exception where it's "obvious from context" — but I don't recommend relying on it. Labelling costs nothing and, in my experience, doesn't reduce conversion. Customers don't care whether they're talking to AI — they care whether they get an answer immediately. All the AI agents I deploy have the disclosure built in, so there's nothing to sort out.
2. AI content that looks real must be labelled
Photos, videos and audio created or edited by AI that depict realistic-looking people, places or events — so-called deepfakes — must carry information that it's AI-generated. This also applies to marketing: an AI avatar in an ad is fine, but if it looks like a real person, it needs a label. For AI UGC ads I handle this as standard — a subtle disclosure that takes nothing away from the creative.
The second part of the obligation — machine-readable labelling of generated content (a watermark in the metadata) — got a transition period until 2 December 2026. This part is largely handled for you by the tools themselves; major providers already add watermarks to their outputs.
3. Emotion recognition and biometrics
If you use emotion-recognition or biometric-categorisation systems, you must inform the people affected. For the vast majority of small and medium businesses this is a fringe matter — I mention it for completeness.
What already applies — and many companies don't know it
The AI literacy obligation has been running since February 2025. It means a company that uses AI must ensure employees can handle it appropriately for their role. No certificate, no exam — internal training and clear rules are enough: what may be entered into AI tools (watch out for personal data and company know-how), how to verify outputs, who is responsible for them. A detailed guide to complying in a single afternoon is in this article.
If you don't have this covered, it's the ideal first step — and, by the way, it solves more than just compliance. Most AI problems in companies don't arise from regulation, but from everyone using it their own way.
What's postponed to December 2027
The postponement applies to high-risk systems — AI that decides about people: CV screening in recruitment, credit scoring, educational assessment, critical infrastructure. For standalone systems the new deadline is 2 December 2027; for AI built into regulated products, August 2028.
But note — a postponement isn't a cancellation. If you use AI to, say, pre-screen job applicants, use the extra time: prepare your documentation, set up human oversight and verify the system doesn't disadvantage any group. In December 2027 it won't be voluntary anymore.
The fines at stake
On paper, high: up to €35 million or 7% of global turnover for banned practices; up to €15 million or 3% of turnover for breaches of other obligations — including transparency. For small and medium businesses the lower of the two amounts always applies. In the Czech Republic, oversight is to be exercised by the Czech Telecommunication Office under the forthcoming AI act.
The reality? Nobody will start handing out ruinous fines to small e-shops in August. Supervisory authorities will first focus on big players and flagrant cases. But "I didn't know" won't fly — and when labelling a chatbot is a five-minute job, it makes no sense to risk either a fine or your reputation.
Checklist: 5 steps you can complete before August
1. Map where you use AI. Website chatbot, image and text generation, AI in e-mailing, recruitment, analytics. Without an overview, you don't know what concerns you.
2. Label your chatbot. One sentence in the opening message: "I'm an AI assistant." Five minutes of work, obligation met.
3. Set rules for AI content. Label realistic-looking AI photos and videos; for generated text it's not mandatory. One internal rule the whole team knows.
4. Train your team. AI literacy has applied since last year. A workshop is enough: what to enter into AI, how to verify outputs, who's responsible.
5. Do you use AI in recruitment or scoring? Start preparing for December 2027 now — documentation and human oversight can't be caught up over a weekend.
The honest conclusion
The AI Act is no reason to panic — and certainly no reason to stop using AI. For 90% of small businesses, meeting the August obligations is a matter of a few hours, not lawyers costing a fortune. Companies that sort it out now are at ease. Those that put it off will be firefighting in August.
And there's a positive angle: transparency paradoxically helps companies that play fair. The customer knows when they're talking to AI, gets a fast answer and fair dealing — and that counts for more today than a perfect illusion of a human on the other side.
Frequently asked questions about the AI Act
As part of an AI audit I map where you use AI, what of it falls under the AI Act, and what has the potential to save you time and money instead. Concrete steps, no legalese.
Free non-binding consultationI build AI solutions for businesses — from chatbots to knowledge systems. I write about what actually works, no buzzwords. More about me →