EU AI Act: what a company must do by 2 December 2026
Which EU AI Act obligations already apply, what changes on 2 December 2026, what moved to 2027 and 2028, and a six-step checklist for companies using AI.
Status as of 26 September 2026. This is not legal advice but an overview to help you find your way. Talk to a lawyer about your own case.
The AI Act (Regulation (EU) 2024/1689) does not apply all at once. Some obligations have applied for more than a year, some since August, and on 2 December 2026 another transition period ends.
If your company uses ChatGPT, Copilot, translation tools, image generators or has a chatbot on its website, now is a good time to put things in order. Most of it is less work than it sounds.
First: are you a provider or a deployer?
The Act assigns duties by role, so this is the first question.
- A provider develops an AI system, or has one developed, and places it on the market or puts it into service under its own name.
- A deployer uses an AI system in its work.
Most companies are deployers: they use other people's tools. But if you put a chatbot on your website under your own name, or commission a custom model and offer it to customers as your product, you can also be the provider of that system. Decide the role tool by tool.
What already applies
Since 2 February 2025: AI literacy (Article 4)
A company that uses AI has to make sure the people working with it understand what the tool can do, where it goes wrong and how to handle data.
The Digital Omnibus (Regulation (EU) 2026/1744) softened this: it is now about measures that support AI literacy, not a guaranteed level of knowledge. The law asks for no certificates or exams. In practice a short written AI-use policy and a record of who has read it are enough.
The prohibited practices of Article 5 also apply since that date, for example manipulative techniques and social scoring. They are irrelevant for most companies, but worth checking once.
Since 2 August 2026: transparency (Article 50)
- People must know they are talking to AI. This covers chatbots and voice agents. The duty sits with the provider of the system; you check that the chatbot you use with customers says so clearly.
- Generated content must be machine-readably marked. Providers of generative systems must mark images, audio, video and text in a machine-readable way.
- Deployers label deepfakes, and AI-generated text published to inform the public on matters of public interest. The exception is text reviewed before publication by a person who holds editorial responsibility for it.
In July 2026 the Commission published guidelines on Article 50 with the details.
What happens on 2 December 2026
Generative systems already on the market before 2 August 2026 got a transition period for machine-readable marking of their outputs. It ends on 2 December 2026.
That concerns providers of such systems. If you use third-party tools, marking is your vendor's job. If you built a generator yourself and run it under your name, for catalogue images or speech synthesis in a call centre, it applies to you too.
Under the Omnibus, a new prohibition also starts that day: systems that generate non-consensual intimate imagery and child sexual abuse material.
What was postponed
The high-risk obligations were originally due in August 2026. The Digital Omnibus moved them:
| What | New date |
|---|---|
| Stand-alone high-risk systems in Annex III: recruitment and candidate screening, creditworthiness, access to public services, assessment in education | 2 Dec 2027 |
| AI in regulated products under Annex I, such as medical devices | 2 Aug 2028 |
If you use AI for any of these, you have about a year. Preparation means documentation, human oversight, logging and, for some deployers, a fundamental rights impact assessment. That takes time, so don't leave it to the last month.
Penalties
Up to EUR 15 million or 3 % of annual turnover for breaching most obligations, including Article 50. Up to EUR 35 million or 7 % for prohibited practices. For SMEs the lower of the two amounts applies.
A six-step checklist
- List the AI tools in the company: who uses them, for what and with which data.
- Record the role and risk class for each tool. Deployer or provider? Is the use case in Annex III? If so, start preparing for December 2027.
- Write a short AI-use policy and keep a record of who has read it (Article 4).
- Check disclosure: chatbots and voice agents you use with customers must say they are AI.
- Agree on labelling: deepfakes and AI text for the public get a label, or you introduce human editorial review.
- Check your vendor contracts: who is the provider, what documentation you receive, and where data is processed (a GDPR data-processing agreement).
Sources
- AI Act, Regulation (EU) 2024/1689 (EUR-Lex)
- Digital Omnibus on AI, Regulation (EU) 2026/1744 (EUR-Lex)
- Commission guidelines on the Article 50 transparency obligations
We take the Digital Omnibus dates from its publication in the Official Journal and from expert summaries. Once EUR-Lex publishes the consolidated text of the Act, check them there. This note is general information and does not replace legal advice.