The AI Act Hasn’t Been Postponed. What Your Business Needs to Do Now
The AI Act hasn’t been postponed. Only part of the rules for high-risk systems has been pushed back. The rules for chatbots, deepfakes and AI-generated content have applied since 2 August 2026. Here’s what applies, what has moved and what your business needs to do right now.

Summer 2026 left a lot of businesses confused about EU AI regulation. In July, the Digital Omnibus on AI was published in the Official Journal of the EU, delaying the obligations for high-risk systems by more than a year. Many companies drew a simple conclusion: the AI Act has been put off, so we can forget about it for now.
But just nine days later, on 2 August 2026, the transparency rules under Article 50 kicked in. They affect almost every business that has a chatbot on its website, uses a voice assistant or publishes AI-generated images and videos. And the bans on certain practices and the duty to support AI literacy have been in force since February 2025.
This article is an overview, not legal advice. For your specific situation, talk to a lawyer.
01What already applies and what has moved
The Omnibus mainly moved the obligations for high-risk systems, which now start in December 2027 and August 2028. Everything else is on the original schedule. Older systems got four extra months for machine-readable labelling of AI content, and one new ban applies from December 2026.
The Omnibus went through the legislative process unusually fast. The European Parliament approved it on 16 June 2026, the Council on 29 June, and it was published in the Official Journal on 24 July 2026 as Regulation (EU) 2026/1744, just nine days before most of the AI Act was due to apply.
| From | What applies | Relevant to you if |
|---|---|---|
| 2 Feb 2025 | Ban on unacceptable practices (for example, manipulation, social scoring, emotion recognition of employees at work) | you use AI that assesses or influences people |
| 2 Feb 2025 | Duty to support employees’ AI literacy | your staff work with AI, including ChatGPT and similar tools |
| 2 Aug 2025 | Rules for providers of general-purpose AI models, plus the penalty framework | you develop your own large language model (most businesses don’t) |
| 2 Aug 2026 | Transparency under Article 50: chatbots, deepfakes, emotion recognition, labelling AI content | you have a chatbot or voice assistant, or publish AI content |
| 2 Dec 2026 | End of the grace period for machine-readable labelling of AI content for systems placed on the market before 2 Aug 2026; new ban on AI that creates intimate images of people without their consent | you run or sell a tool that generates images, video, audio or text |
| 2 Dec 2027 | Obligations for high-risk systems under Annex III (recruitment and employee assessment, credit, education, critical infrastructure) | AI helps you screen candidates, assess people or make credit decisions |
| 2 Aug 2028 | Obligations for AI as a safety component of regulated products (Annex I) | you make medical devices, toys, lifts or similar products with AI |

The delay for high-risk systems doesn’t mean you can relax until the end of 2027. If you use AI to screen job applicants, for example, you’ll need documentation, human oversight and risk management in place by then. For a larger company, that’s two budget cycles and one or two sizeable IT projects. Starting in autumn 2027 means starting too late.
02Article 50 in practice: four situations that affect ordinary businesses
Article 50 doesn’t mean you have to add “created with AI” to every email. It’s about not misleading people: they should know when they’re talking to a machine, and they shouldn’t mistake a fake video for a real one.

1. Chatbots and voice assistants
When a person interacts with your system, they need to know they’re dealing with AI, unless that’s obvious from the context. They have to be told clearly, at the latest during the first interaction.
In practice, this means:
- the chatbot on your website introduces itself as a virtual assistant in its opening message, not as “Sarah from customer support”,
- a voice bot on your hotline says so right at the start of the call,
- an AI assistant that holds its own conversations with customers by email or on social media has to say so too. According to the European Commission, simple automated replies with no real two-way conversation fall outside this obligation.
Technically, this is usually a simple change. What’s much harder is working out everywhere in the company that AI is already talking to customers. Individual teams often set up chatbots on their own, and nobody has a complete list.

2. AI-generated images, video, audio and text
This depends on your company’s role:
- If you develop or sell a content generation tool (say, a product photo generator built into your e-commerce platform), its output has to carry a machine-readable marker, such as a watermark or metadata. This applies to new systems from 2 August 2026 and to older ones from 2 December 2026.
- If you only use AI-generated content, the machine-readable marking is your tool provider’s job. Your obligations start with deepfakes and texts for the public, covered below.
3. Deepfakes and texts for the public
If you publish a realistic image, video or audio clip of a real person, place or event that was created or altered by AI, you have to disclose that it’s artificial. This covers, for example, an ad featuring an AI avatar that looks like a real person, or a video using a synthetic version of your CEO’s voice. For clearly artistic, satirical or fictional works, a disclosure that doesn’t spoil the work is enough. The Czech Telecommunication Office suggests labels such as “AI generated” for fully generated content and “AI modified” for content edited with AI.
Texts published to inform the public on matters of public interest must be labelled too. That doesn’t apply if the text has gone through human review or editorial control and someone takes editorial responsibility for publishing it. Both conditions have to be met. According to the European Commission, a spelling or grammar check alone isn’t enough; a person has to genuinely review the content. So a company blog post written with AI help and properly checked and approved before publication doesn’t need a label.
4. Emotion recognition and biometric categorisation
If you use a system that infers emotions from someone’s voice or face, or sorts people based on biometric data, you have to inform the people affected. One important caveat: using emotion recognition on employees at work has been banned outright since February 2025, except for medical or safety reasons. Analysing the “mood” of call centre agents could already be a problem today.
03AI literacy: the obligation everyone forgets
Every business whose staff work with AI has to support their AI literacy. This has applied since February 2025, and it covers everyday use of ChatGPT in the office too.
The Omnibus softened this obligation. Originally, companies had to “ensure a sufficient level” of AI literacy; now they have to “take measures to support” it. So you don’t have to prove that every employee has reached a certain level of knowledge. But you do need to be able to show that you’ve done something about it.
A sensible minimum is enough:
- a short training session on how AI works, where it gets things wrong and what data shouldn’t go into it,
- internal rules for using AI tools,
- a record of who completed the training and when.
You can sort out the training and the record in one go: our AI training for businesses covers the rules for using AI safely, and every participant gets a certificate of completion.
04Who enforces the rules and what the fines are
The AI Act applies directly across the EU, even in countries that haven’t yet passed their own implementing laws. Breaching the transparency rules can cost up to €15 million or 3% of worldwide annual turnover.
Each member state has to designate its own supervisory authorities, and many are running late. In the Czech Republic, the Ministry of Industry and Trade drafted the implementing act in September 2025; under the draft, the Czech Telecommunication Office (ČTÚ) will be the main market surveillance authority and single point of contact. In Slovakia, the government approved its bill on 26 August 2026, with the Ministry of Investments, Regional Development and Informatisation (MIRRI) as the main supervisor and a planned start date of 1 January 2027. None of this delays the obligations themselves: the rules apply regardless.
On 31 July 2026, ČTÚ published guidance for businesses. Its first recommendation is to work out your role. A provider, who places an AI system on the market under its own name, has different obligations from a deployer, who simply uses it in its business. If you run your own AI system, you’re both.
The AI Act sets three tiers of fines:
- Prohibited practices (Article 5), or 7% of turnover35.0
- Other obligations, including Article 50, or 3% of turnover15.0
- False or incomplete info to authorities, or 1% of turnover7.5
Percentages are of total worldwide annual turnover for the preceding year. Source: AI Act, Article 99.
Larger companies pay whichever amount is higher, while SMEs pay whichever is lower. The Omnibus also extended some relief to small mid-cap companies. For a typical business, the maximum fines are largely theoretical. A request to put things right is far more likely. The bigger risk is losing trust when a customer finds out they’ve been chatting to a bot that was pretending to be a person.
05Checklist: review your business in one afternoon
The first step isn’t a big legal project. It’s a simple list. Until you know where you’re using AI, you can’t tell which obligations apply to you.
Step 1: take stock of your AI
- List every AI tool the company uses, including ones teams have signed up for on their own (ChatGPT, Copilot, image generators, call transcription).
- For each tool, note who’s responsible for it and what data goes into it.
- Mark which tools interact directly with customers or employees.
- Mark where AI is used to create content you publish.
- Distinguish between your own solutions and third-party services.
Step 2: chatbots and voice assistants
- Your chatbot introduces itself as an AI assistant in its very first message.
- Your chatbot doesn’t have a human name and photo that could mislead people, or it’s clearly labelled as a virtual assistant.
- Your hotline voice bot says so at the start of the call.
- Customers can switch to a human. The AI Act doesn’t require this, but it does a lot for trust.
Step 3: AI-generated content
- You label realistic AI photos, videos and voices of real people or events in ads and on social media.
- AI-generated texts for the public are properly reviewed by a person before publication.
- If you run a tool that generates content yourself, check that its output carries a machine-readable marker by 2 December 2026 at the latest.
Step 4: AI that assesses people
- You don’t use emotion recognition on employees (such as analysing call centre agents’ mood). If you do, talk to a lawyer right away.
- Check whether AI helps you screen candidates, assess employees or evaluate credit. If it does, start preparing for the high-risk obligations that apply from December 2027.
Step 5: people and policies
- You have internal rules for using AI.
- Staff who work with AI have been trained, and you keep a record of it.
- Someone in the company is responsible for AI.
06Frequently asked questions
Has the AI Act been postponed?
No. The Digital Omnibus mainly delayed the obligations for high-risk systems, to 2 December 2027 and 2 August 2028. The bans on unacceptable practices and the AI literacy obligation have applied since February 2025, and the transparency rules for chatbots and AI content since 2 August 2026.
Do I have to label every text I write with AI help?
No. The obligation mainly covers deepfakes and texts on matters of public interest that nobody has reviewed. If a text is properly reviewed by a person before publication and someone takes responsibility for it, you don’t need to label it. For everyday emails, quotes or your company blog, usually nothing changes.
Does the chatbot on my website have to say it’s AI?
Yes, unless it’s obvious from the context. The easiest way is to put it in the first message, for example: “Hi, I’m an AI-powered virtual assistant. How can I help?”
Does the AI Act apply to small businesses?
Yes. The obligations depend on how you use AI, not on the size of your company. SMEs only benefit from a lower cap on fines and some relief when developing high-risk systems.
Who enforces the AI Act?
National market surveillance authorities in each member state, alongside the EU AI Office for general-purpose AI models. Some countries, including the Czech Republic and Slovakia, are still passing the laws that designate these authorities. The rules themselves already apply, because the regulation is directly applicable.
What if my chatbot comes from a third-party provider?
To your customers, the chatbot speaks for your company. Whoever built it, make sure it introduces itself correctly, and have your contract with the provider set out clearly who is responsible for what.
07Conclusion: keep using AI, just keep it under control
The AI Act isn’t a reason to stop using AI. It’s a reason to know where you use it, who’s responsible for it and what it does when it deals with customers. A business that has this written down has nothing to fear from the regulation.
Most of the changes Article 50 requires are technically simple: an opening message for your chatbot, a sentence at the start of a call, a label on an ad video. The inventory takes the most work, but you only need to do it once and then keep it up to date.
We design and roll out chatbots, AI assistants and internal AI systems that meet the transparency rules from day one. If you’d like, we can go through the AI you use today and tell you what needs to change.
AI for business: see what we can do
Would you rather talk it through? Call us on +420 771 166 199 and in 15 minutes you’ll know where you stand. Or send us a message through our contact form.
This article is an overview based on the situation as of 27 September 2026 and does not constitute legal advice.
08Sources
- EUR-Lex: Regulation (EU) 2026/1744
- Council of the EU: Artificial intelligence timeline
- European Commission: Transparency obligations under Article 50 (FAQ)
- AI Act Service Desk: Article 99, penalties
- ČTÚ: 2 August 2026 as a key date for the transparency rules (in Czech)
- Czech Ministry of Industry and Trade: draft AI act (in Czech)
- TASR: Slovak government approves AI supervision bill (in Slovak)