The EU AI Act entered into force on August 1, 2024 and applies in stages. Prohibited-practice and AI-literacy rules started in 2025. Many provisions, including Article 50 transparency obligations, apply from August 2, 2026, while certain high-risk-system requirements follow later dates.
Saying “the AI Act starts in 2026” is therefore an oversimplification. A small website may have straightforward disclosure and staff-training tasks, while recruitment, credit, biometric, or safety uses can require a much deeper assessment.
Policy snapshot: July 26, 2026. This article provides general technical and compliance information and is not legal advice. The law, guidance, national enforcement arrangements, and your obligations may change or depend on specific facts.
What is the EU AI Act?
The Act is a risk-based legal framework. It prohibits certain uses, imposes obligations for high-risk systems and general-purpose AI models, requires AI literacy, and creates transparency rules for some interactive and synthetic-content systems. Many limited- or minimal-risk uses receive no special high-risk regime.
- Prohibited practices: uses the law does not permit.
- AI literacy: measures to ensure staff and operators understand appropriate use and risk.
- Transparency: disclosures for specified interactive systems and generated or manipulated content.
- High-risk systems: regulated uses affecting areas such as employment, education, essential services, biometrics, or product safety.
- GPAI obligations: duties primarily directed at providers of general-purpose AI models.
Current application timeline

- August 1, 2024: the Act entered into force.
- February 2, 2025: prohibited practices, definitions, and AI-literacy provisions began applying.
- August 2, 2025: governance and general-purpose AI obligations began applying.
- August 2, 2026: broad application and Article 50 transparency rules.
- December 2, 2027: current Commission information identifies this as the latest date for certain Annex III high-risk areas.
- August 2, 2028: current information identifies this date for high-risk systems embedded in regulated products.
The final AI Omnibus changes entered into force in July 2026. Confirm the consolidated legal text before relying on a high-risk deadline.
Does the Act apply to a small website?
It depends on what the organization does and its legal role. A provider develops or places a system on the market under its name. A deployer uses an AI system under its authority. Importers, distributors, and product manufacturers have other roles. Simply using a general-purpose service does not automatically make a blogger the provider of the underlying model.
Small organizations are not universally exempt. Proportionality and some simplified measures exist, but role, risk, affected people, and intended purpose remain important.
Chatbots and disclosure
Article 50 generally requires people to be informed when they are interacting directly with an AI system unless this is obvious to a reasonably informed, observant person, with additional legal details and exceptions. Place disclosure before or at the start of the interaction, make human assistance easy to find, and avoid presenting the bot as a human employee.
Example for discussion: “This chat is handled by an AI system. Responses may be incorrect. Contact our staff for human assistance.”
This example is not guaranteed legal wording. Adapt it to the service, language, audience, and professional advice.
AI-generated and manipulated content
Article 50 separates duties. Providers of systems that generate synthetic audio, image, video, or text may need machine-readable marking. Deployers may need to disclose deepfakes and certain AI-generated or manipulated text published to inform the public on matters of public interest. Exceptions and treatment differ where content receives human review or editorial control and a person holds editorial responsibility.
Do not reduce this to “label everything made with AI.” Spelling correction, brainstorming, a human-written article based on an outline, mostly generated public-interest text, and a realistic synthetic video present different facts. Document the human review, editorial responsibility, and reason for the chosen disclosure.
AI literacy for employees
Providers and deployers must take measures to ensure a sufficient level of AI literacy among staff and others operating systems on their behalf, considering knowledge, experience, context, and affected people. The law does not prescribe one universal certificate or course length.
- Define approved tools and prohibited data.
- Teach verification of factual outputs and escalation of consequential decisions.
- Cover hallucinations, bias, privacy, security, and prompt injection.
- Record basic training, audience, date, and material.
Common uses and risk signals
- Customer-service chatbot: assess Article 50 disclosure, privacy, accuracy, and human handoff.
- Marketing text and product images: assess misleading claims, consumer law, copyright, and synthetic-content rules.
- Office productivity: set data and verification rules; usually not high-risk merely because AI is used.
- CV ranking, employee monitoring, credit, insurance, and biometrics: obtain specialist review because these may fall into sensitive or high-risk categories.
Ten practical actions
- Inventory every AI tool and embedded feature.
- Identify your provider, deployer, or other role.
- Remove prohibited uses.
- Train staff and record the training.
- Document data sources, recipients, decisions, and affected people.
- Add appropriate chatbot disclosures and human handoff.
- Review synthetic-media and public-interest labeling.
- Maintain meaningful human review.
- Review vendor contracts, instructions, logs, and documentation.
- Obtain legal advice for high-risk or ambiguous uses.
Frequently asked questions
Does the AI Act apply outside the EU?
It can have extraterritorial reach, including where a system is placed in the EU market or its output is used in the EU. Get advice for cross-border cases.
Must every AI-written blog post be labeled?
No blanket rule says every AI-assisted sentence must be labeled. Article 50’s public-interest text rule, human review, editorial responsibility, deepfake provisions, and other laws must be assessed.
Does GDPR still apply?
Yes. The AI Act does not replace GDPR, consumer-protection, employment, intellectual-property, or sector-specific rules.
What are the fines?
Maximums depend on the violation. Article 50 enforcement information cites up to €15 million or 3% of preceding worldwide annual turnover, with proportionality for smaller organizations. Do not treat a maximum as the likely outcome in every case.
Verify your role and current consolidated law through EUR-Lex, the European Commission’s AI Act pages, and the AI Act Service Desk. Seek qualified legal advice for sensitive or high-risk uses.

Comments