Security

AI Act: what companies must do from 2 August 2026

7 min read
AI Act: what companies must do from 2 August 2026

The AI Act is the EU regulation on artificial intelligence (Regulation 2024/1689). From 2 August 2026 it is operational on transparency, oversight and fines. For an SME using ChatGPT, Copilot or a third-party chatbot the role is almost always deployer (user), not provider: no CE marking or conformity assessment as if you were an “AI product”. What you need is an inventory, recognisable interaction with people, staff literacy (already since 2025) and data rules.

Annex III high-risk duties were moved to 2 December 2027 (standalone systems) and 2 August 2028 (systems in harmonised products), according to the simplification package described by the Commission. August 2026 is not “everything at once”; it is when you can be checked on what is already in force.

This is general information, not legal advice. Dates and duties should be checked on your concrete case with a qualified professional.

What the AI Act is, in one useful sentence

The AI Act is Regulation (EU) 2024/1689: harmonised rules on artificial intelligence in the European Union. It classifies uses by risk level and ties obligations to that risk.

The European Commission summarises it as a risk-based approach, with bans on unacceptable practices, stricter duties for high-risk systems, transparency duties for certain uses (e.g. chatbots and synthetic content), and few extra rules for minimal risk. The official overview is on the Regulatory framework for AI page.

Which deadlines matter now (August 2026)

Not all deadlines are the same. According to the Commission:

  • from 2 February 2025, bans on prohibited practices and AI literacy obligations apply (Art. 4);
  • from 2 August 2025, governance rules and obligations for GPAI (general-purpose AI) models apply;
  • from 2 August 2026, enforcement and transparency obligations relevant to chatbots and AI-generated or altered content start (Commission press release, 31 July 2026);
  • obligations for high-risk systems in Annex III were moved to 2 December 2027, and those for systems embedded in regulated products (Annex I) to 2 August 2028, following the simplification package (“AI Omnibus”) described by the Commission.
DateWhat is in force
2 February 2025Prohibited practices and AI literacy (Art. 4)
2 August 2025Governance and GPAI model duties (model providers)
2 August 2026Art. 50 (transparency), market surveillance, fine regime
2 December 2027Annex III high-risk systems (after Omnibus)
2 August 2028High-risk systems in harmonised products (Annex I)

What to do in practice (working order)

A work list, not a certification. Legal detail: Article 50 and deployer vs provider checklist.

  1. AI inventory (1–2 days). Sheet with: system, vendor, who uses it, for what, data touched, your role, rough risk. Include AI hidden in ERP, CRM and marketing tools.
  2. Site chatbot → visible disclosure. Whoever provides a system that talks to people must make that recognisable, unless it is already obvious. Design duty sits with the provider; if you branded or substantially customised it, the line moves. Still put a line at chat open: “You are speaking with a virtual assistant based on artificial intelligence.”
  3. ChatGPT / Copilot for internal email → usually no AI Act label. Assistive uses that do not materially alter published content stay out. Generated images, video, cloned voice or public-interest texts: disclosure applies. The sharper risk on a consumer account is often GDPR (customer data without a DPA): move to a business plan with a processing contract.
  4. Training (Art. 4), already due. A paper trail: short sessions on real use, attendance, kept materials. See mandatory AI Act training.
  5. Short internal policy. What not to upload (personal data, CAD, price lists, tenders), human review, who authorises new tools.
  6. Inform workers if AI is used in people management. Law 132/2025 reinforces this. CV screening, evaluation or productivity monitoring can approach Annex III (2027 horizon): do not ignore it because it feels far away.

Fines for transparency breaches: up to 3% of turnover (or €15 million), with proportionality for SMEs. In Italy: ACN (market surveillance) and AgID (notification / promotion), plus sector supervisors.

Free orientation: the Commission AI Act Service Desk and Chamber of Commerce PID / EDIH desks. Have a professional validate supplier-contract wording.

Who the AI Act deployer is (and what they must do)

In the AI Act, a provider develops and places a system on the market (or puts it into service under its own name). A deployer uses an AI system under its authority in a professional context (Art. 3, points 3 and 4).

If your SME uses ChatGPT, Copilot, an internal document assistant, or a ticket agent, in most cases you are a deployer. You are not “outside the rules”: you are inside, with proportionate obligations.

Practical steps we recommend operationally (not as an exhaustive legal list):

  1. Inventory: which AI tools you use, for which processes, with which data.
  2. Rough risk classification: generic support use vs decisions about people (HR, credit, access to services).
  3. Transparency: if a chatbot talks to customers or users, it must be clear they are interacting with an AI system, not a person (Art. 50 / August 2026 enforcement).
  4. Literacy: train people who use AI at work (already applicable since February 2025).
  5. Ownership: who is accountable for output quality and escalation.
  6. Data: GDPR alignment on what can be uploaded and where.

Zendata works on the operational piece: usable, traceable, governed systems—not as a substitute for legal advice.

High-risk systems: when to worry in earnest

High risk is not “any AI in the company.” The Commission lists sensitive use cases, including (examples): safety components in critical infrastructure, education and exam scoring, recruitment and worker management, credit scoring and access to essential services, biometrics in certain contexts, justice and migration. Details and updated list: official AI Act page.

If you use AI only for email drafts, internal search, or document summarisation with human oversight, you are in a different scenario from automated candidate ranking. The distinction matters: it avoids useless panic and delays where preparation is actually needed.

FAQ

What is the AI Act?
Regulation (EU) 2024/1689: EU rules on artificial intelligence, by risk level. An SME using ChatGPT or Copilot is usually a deployer, not a provider. From 2 August 2026: transparency, oversight, fines. Annex III high-risk: 2027–2028.

Does the AI Act ban ChatGPT at work?
No. It does not introduce a general ban. It introduces differentiated obligations and, for certain uses, transparency and responsibility.

Are SMEs exempt?
Not automatically. The regulation includes support measures and simplifications for SMEs/start-ups, but professional use is in scope. Assess the concrete case.

What changed on 2 August 2026?
According to the Commission, enforcement and transparency obligations on AI interaction and certain generated/altered content start. Annex III high-risk obligations remain on a later horizon (December 2027, subject to further updates).

What must companies do from 2 August 2026?
Inventory, role, chatbot disclosure, literacy, data rules and policy. Not high-risk provider documentation.

Must we label emails written with ChatGPT?
Usually no, if they stay internal or commercially reviewed by a person. Yes for deepfakes or public-interest texts without substantial editorial control.

Do we need a lawyer, or is an AI vendor enough?
You need operational clarity and, on relevant legal points, professional advice. A technical vendor does not replace a legal assessment.

Sources

Dig deeper in the series

We do not replace a lawyer. If you tell us which tools you use (ChatGPT, Copilot, a site chatbot) and on which data, in one call we can say what is inventory / literacy / disclosure — and what is a process to put into production with evidence. Write to info@zendata.it.

Pietro Ciattaglia, CEO of Zendata AI, Rome