The EU AI Act Explained: What Businesses Using AI Tools Must Do in 2026
A practical guide to the EU AI Act for companies that use AI assistants like ChatGPT: main deadlines, AI literacy, transparency duties, high-risk uses, fines and the 2026 Digital Omnibus delays.
9 min readThe EU AI Act is the world's first comprehensive AI law, and it also covers companies that only use AI. If your team uses ChatGPT, Copilot or any other AI assistant at work, part of it applies to you.
This guide is for the typical company that uses AI tools without developing them.
Provider or deployer?
The AI Act assigns obligations by role. Providers develop an AI system or model and place it on the market (OpenAI, Google, Mistral and so on). Deployers use an AI system under their own authority in a professional context.
If your employees use an AI chat assistant to draft emails, summarise documents or analyse data, your company is a deployer. Deployers have lighter obligations than providers, and those obligations grow quickly depending on what you use the AI for.
The deadlines
The AI Act entered into force on 1 August 2024 and applies in stages:
| Date | What applies |
|---|---|
| 2 February 2025 | Prohibited AI practices and the AI literacy obligation |
| 2 August 2025 | Rules for general-purpose AI models, governance and penalties |
| 2 August 2026 | Transparency obligations (Article 50) and most remaining provisions |
| 2 December 2027 | High-risk systems listed in Annex III (employment, credit, education…) |
| 2 August 2028 | High-risk AI embedded in regulated products (Annex I) |
The last two dates changed in 2026. The Digital Omnibus on AI, adopted in June 2026 and in force since July 2026, postponed the high-risk deadlines because harmonised standards and national authorities were not ready. The rules themselves still stand.
AI literacy (already in force)
Since February 2025, Article 4 requires providers and deployers to take measures to ensure a sufficient level of AI literacy among staff who use AI systems.
In practice, employees should know what the tool can't do (including that it can give wrong answers), which data they may put into it, and how to check outputs before relying on them.
No certification is required, but you should be able to show what you did: training sessions, an internal AI policy, guidelines for approved tools. Most companies are already behind on this one.
Prohibited uses
Some uses are banned outright, including social scoring, manipulative techniques that exploit vulnerabilities, untargeted scraping of facial images, and emotion recognition in the workplace (except for medical or safety reasons).
Normal office use of AI assistants is nowhere near these lines. If someone proposes analysing employees' video calls to "measure engagement", though, the answer is no.
Transparency (from August 2026)
Article 50 introduces transparency duties. For deployers, three matter most:
- If you publish deepfakes (AI-generated or manipulated images, audio or video of real people, places or events), you must disclose that they are artificial.
- If you publish AI-generated text to inform the public on matters of public interest, you must disclose it, unless the text has gone through human review and someone holds editorial responsibility.
- If you deploy a chatbot that interacts with customers, people must be told they are talking to an AI, unless it's obvious.
Using AI internally to draft documents that a person then reviews and signs is generally not affected.
High-risk use cases
A general-purpose chatbot is not high-risk by itself, but using it for a high-risk purpose can make you a deployer of a high-risk system. Many companies don't expect this. Annex III includes recruitment and HR (screening CVs, ranking candidates, evaluating performance, deciding on promotions or terminations), access to essential services (assessing creditworthiness, pricing life and health insurance) and education (evaluating students or deciding on admission).
If you do any of this, from December 2027 you will need human oversight, monitoring, log retention, information for affected workers and, in some cases, a fundamental rights impact assessment. Under the AI Act, asking an AI to "rank these 200 CVs" carries real obligations.
Fines
Penalties are a fixed amount or a percentage of global annual turnover, whichever is higher (for SMEs and start-ups, whichever is lower):
- up to €35 million or 7% for prohibited practices;
- up to €15 million or 3% for most other obligations;
- up to €7.5 million or 1% for supplying incorrect information to authorities.
The GDPR still applies
The AI Act sits on top of the GDPR. Every time an employee pastes personal data into an AI tool, the usual GDPR questions apply: legal basis, processor agreement, international transfers, retention.
The tool you choose affects how much of that risk you carry. With an assistant that encrypts prompts end to end and processes them in a hardware-secured enclave, with no retention and no training, most of the data protection risk is gone before you start your AI Act assessment. We cover this in Is ChatGPT GDPR compliant?.
A 5-step action plan
- List the AI tools used in the company, including the ones nobody approved.
- Sort the use cases into general productivity, customer-facing, and potentially high-risk (HR, credit, education).
- Write an AI policy covering approved tools, forbidden data, review of outputs and who to ask.
- Train your people. A short, practical AI literacy session is enough to start, and it's already mandatory.
- Choose tools that reduce risk: a DPA, EU processing, no training, and ideally confidential computing so the provider can't see your data.
FAQ
Does the EU AI Act apply to companies that only use ChatGPT?
Yes. Companies that use AI systems professionally are "deployers". At minimum they must ensure AI literacy among staff, avoid prohibited uses and respect transparency rules. Obligations increase if the AI is used for high-risk purposes like hiring.
Was the EU AI Act delayed?
Partly. The Digital Omnibus on AI, in force since July 2026, moved the deadlines for high-risk systems to December 2027 and August 2028. Prohibitions, AI literacy, general-purpose AI rules and most transparency obligations kept their original dates.
Is using AI to screen CVs high-risk?
Yes. AI systems used for recruitment or selection, including filtering applications and evaluating candidates, are listed as high-risk in Annex III of the AI Act.
Do I need to tell clients I used AI to write a document?
Generally not. The disclosure duty covers deepfakes, chatbots interacting with people, and AI-generated text published to inform the public on matters of public interest without human editorial review. Sector rules and contracts may require more.