EU AI Act: Three obligations already apply — the fourth hits you on 2 August

Last updated: 26 May 2026 · 5 min read · Topic: Allgemein

"The AI law only affects the big tech companies." That assumption is widespread — and a costly mistake. The EU AI Act phases in its obligations over three years. Three already apply to you; the fourth and most visible becomes binding on 2 August 2026. As I write this — late May 2026 — that is roughly ten weeks away.

Maximilian Meisner
Maximilian Meisner
About the author →

What becomes binding on 2 August 2026

The EU AI Act has been in force since 1 August 2024. That does not mean all obligations apply immediately: they phase in over several years. The bulk of them become binding on 2 August 2026.

The part that affects you most directly as a website operator is Article 50: the transparency obligations. At its core, this means one simple, hard rule: when a person interacts with your AI, they must know it.

Every chatbot that interacts with users from 2 August 2026 must disclose that it is an AI — regardless of how long it has been running. There is no grandfather clause.

This applies not only to chatbots. It also covers AI-generated text, images, audio, and video. Anyone who produces content with generative AI must label it in machine-readable form; anyone who publishes deepfakes must make the artificial origin visible to people. Four paragraphs, four distinct obligations — and all four take effect on the same day.

In parallel, obligations for high-risk AI under Annex III take effect on 2 August 2026. Annex III lists eight areas in which AI is classified as high-risk — including staff recruitment, creditworthiness assessment, and access to education. If you use AI to pre-screen applicants or assess credit ratings, you are directly affected: you must ensure human oversight and retain automated logs for at least six months. A Fundamental Rights Impact Assessment (FRIA) is required on top of that — but only for certain deployers: public bodies, providers of public services, and operators using AI for creditworthiness and insurance risk assessments.

Three obligations already in force

This is where it gets uncomfortable, because most people overlook this part. Whilst everyone focuses on August, three tiers of the AI Act already apply:

Prohibition of certain AI practices (Art. 5)
since 2 February 2025. Manipulative behaviour, exploiting the vulnerabilities of protected groups, and indiscriminate scraping of facial images from the internet are simply prohibited.
AI literacy (Art. 4)
also since 2 February 2025.
Obligations for general-purpose AI models (GPAI)
since 2 August 2025, primarily relevant to providers of large language models. As a deployer, it is still worth reviewing their compliance documentation — it makes your own evidential obligations easier later.

For you as an SME, the second is the most uncomfortable, because it truly affects everyone. Art. 4 — AI literacy — applies not from August but since 2 February 2025.

Every business that uses AI systems must ensure that the staff who operate them or use their outputs have sufficient AI literacy — regardless of the risk category.

This is the lowest-threshold breach in the entire law, and precisely for that reason the most dangerous: it affects anyone who uses Copilot, ChatGPT, or any AI tool in their business. No high-risk system required, no exemption for small teams.

The good news is also your most effective lever: any business that has trained its staff with a documented record is in a far stronger position with any regulator. And "documented" means nothing bureaucratic — a simple log with the date, attendees, and topics covered is usually sufficient. The training not only fulfils the obligation; it also protects you if things go wrong.

Are you a provider or a deployer? That makes all the difference

At this point many people make an error that causes unnecessary worry. They read "AI providers must do X" and assume all the obligations fall on them.

The strictest obligations do apply to providers — those who develop and place an AI system on the market. But the vast majority of SMEs are not providers; they are deployers: they buy a ready-made tool and use it. And deployer obligations are considerably lighter.

In practice, this means: you do not need to certify the algorithm. You need to know what you are deploying, train your staff, label transparently, and — for high-risk applications — ensure oversight and logging. That is achievable — provided you do not wait until 1 August to start.

What a breach will cost you

Let us look at the numbers — they explain why this is not a minor issue. The AI Act scales its fines:

Prohibited AI practices
up to €35 million or 7% of global annual turnover.
Other breaches — including Art. 50
up to €15 million or 3% of annual turnover.
A missing AI disclosure on a chatbot is not a trivial offence. It falls in the same fine bracket as a serious DSGVO breach — up to €15 million.

There is some relief for SMEs and start-ups: Article 99 explicitly gives the supervisory authority discretion to set lower rates, and whichever of the two values is lower applies. But do not assume that "lower" means "harmless". The DSGVO showed us how seriously that discretion is exercised.

An honest note to close this section: the EU is currently negotiating a so-called "Digital Omnibus" intended to extend certain high-risk obligations — there is talk, for example, of pushing back the deadline for employment-related systems. Nothing has been decided. Until the Omnibus is formally adopted before 2 August 2026, the current timetable stands — word for word. Planning around a postponement that has not yet been agreed is not a plan. It is a bet.

What you can usefully tackle now

Three things I strongly recommend to every business using AI:

Carry out an honest inventory
Which AI tools are running in your business — on the website, in support, in recruitment, in the office suite? You can only protect yourself against what you know about.
Get the training done
Art. 4 has applied since February 2025. A documented basic AI training session for the staff who work with the tools closes the most obvious gap.
Label your chatbot
A visible notice "You are speaking with an AI" is quick to implement — and that is exactly what Article 50 requires from August.

All three steps have one thing in common: they are not specialist tasks but a matter of documentation, labelling, and training. Anyone who works through them calmly and in order will be ready for the deadline — without panic and without external consultants.

Sources

1. EU Artificial Intelligence Act — Article 50 (transparency obligations)

2. EU Artificial Intelligence Act — Implementation Timeline

3. European Commission — Regulatory framework on AI

4. TÜV Rheinland Consulting — Transparency obligations in the EU AI Act (Art. 50)

5. DLA Piper — Digital AI Omnibus: deferral of high-risk AI obligations

Häufige Fragen

Does the EU AI Act apply to my small business?

Yes. The AI literacy obligation (Art. 4) and the transparency obligations (Art. 50) apply regardless of business size. There is no de minimis threshold for small businesses — only when calculating fines does the authority take size into account.

Direktlink zu dieser Frage →
I only use ChatGPT or Copilot — does that make me a provider?

No. Anyone who uses a ready-made AI tool is a deployer, not a provider. The lighter deployer obligations apply: AI literacy, transparency, and — for high-risk use — oversight and logging.

Direktlink zu dieser Frage →
Do I really need to label my chatbot, even if it is obviously a bot?

Yes. Article 50 expressly requires disclosure even where it would be obvious to an attentive user. The notice must be clear and timely — not buried in the small print.

Direktlink zu dieser Frage →
What is a Fundamental Rights Impact Assessment (FRIA)?

A documented assessment of the impact a high-risk AI system has on the fundamental rights of the people it affects — for example, non-discrimination or the protection of personal data. It is mandatory from 2 August 2026 only for certain deployers — principally public bodies, providers of public services, and operators in the credit and insurance sectors.

Direktlink zu dieser Frage →
What happens if the "Digital Omnibus" delays the deadlines?

In that case, certain high-risk obligations may be pushed back. Until that is formally agreed, 2 August 2026 stands. The transparency and AI literacy obligations are unaffected in any event.

Direktlink zu dieser Frage →

Related articles