AI Act 2026: What Your Company Must Do, What Fines It Faces, and How to Prepare

AI Act 2026: What Your Company Must Do, What Fines It Faces, and How to Prepare

The Artificial Intelligence Act (AI Act) is the world’s first comprehensive regulation of AI—and its most important requirements will affect companies as early as August 2, 2026. EU Regulation 2024/1689 does not apply only to tech giants. If your company uses a chatbot, an AI tool for recruiting employees, generates AI-generated content, or deploys machine learning in its products, the AI Act applies to you as well. In this article, you’ll find the current timeline (including changes from the so-called Digital Omnibus of May 2026), an overview of obligations by risk category, the amounts of fines, and a practical checklist on how to prepare.

What Is the AI Act and Why Was It Created

The AI Act (Regulation (EU) 2024/1689) is a harmonized legal framework for the development, placing on the market, and use of artificial intelligence systems in the European Union. It entered into force on August 1, 2024, and its provisions are being phased in.

The goal is not to ban AI, but to ensure that systems used in the EU are safe, transparent, and respectful of fundamental rights. The regulation operates on a risk-based principle: the higher the risk an AI system poses to people, the stricter the rulesapply.

Important: The AI Act has extraterritorial reach. It also applies to companies outside the EU if the outputs of their AI systems are used within the Union. So it doesn’t matter where your servers are located—what matters is who your AI affects.

Who Is Affected by the AI Act

The regulation distinguishes between several roles, each with different obligations:

  • Providers – companies that develop or market AI systems under their own brand. They bear the greatest share of the obligations.
  • Deployers – companies that use AI as part of their business operations. Yes, even an ordinary Slovak company using an AI tool to sort resumes is a “deployer” with specific obligations.
  • Importers and distributors – entities that make AI systems from third countries available on the EU market.

The scope covers virtually every organization that develops, sells, integrates, or actively uses AI—from startups and e-commerce sites to banks and hospitals.

Four Risk Categories: Where Does Your AI Fall?

1. Unacceptable risk—prohibited practices (effective February 2025)

Systems such as social scoring of citizens, manipulative techniques that exploit people’s vulnerabilities, emotion recognition in the workplace and in schools, and the untargeted collection of facial photographs are completely prohibited. News from the Digital Omnibus: as of December 2, 2026, there will be a ban on AI systems that generate intimate images without consent (so-called “nudifiers”) and material depicting child abuse.

2. High-Risk AI Systems (New Deadlines: December 2027 / August 2028)

This includes AI systems in the areas of recruitment, credit scoring, education, critical infrastructure, biometrics, medical devices, and law enforcement. Obligations include a risk management system, data management, technical documentation, human oversight, conformity assessment, and registration in the EU database.

Key change as of May 2026: The political agreement on the so-called Digital Omnibus has pushed back the deadlines for high-risk systems—standalone systems under Annex III (recruitment, scoring, education, etc.) must be compliant only as of December 2, 2027, AI embedded in regulated products (medical devices, elevators, machinery) as of August 2, 2028.

3. Limited Risk – Transparency Requirements (effective August 2, 2026)

This is the nearest deadline and the most relevant one for most companies. Article 50 of the AI Act requires the following as of August 2, 2026:

  • Chatbots and AI assistants: the user must be informed that they are communicating with an AI, not a human.
  • AI-generated content (text, images, audio, video): must be machine-readably labeled as artificially created. For systems placed on the market before August 2, 8, 2026, a grace period for labeling (watermarking) applies until December 2, 2026—for new systems, the requirement applies immediately.
  • Deepfakes: mandatory clear labeling indicating that the content was artificially created or manipulated.
  • Emotion recognition and biometric categorization: obligation to inform data subjects.

4. Minimal Risk

Most AI applications in use today (spam filters, AI in video games, recommendation systems) are not subject to specific obligations. However, voluntary compliance with codes of conduct is recommended.

Current AI Act Timeline (as of July 2026)

DateWhat Applies
February 2, 2025Prohibitions on Unacceptable Practices + Requirement for Employee AI Literacy
August 2, 2025Rules for general-purpose models (GPAI—e.g., large language models), governance structures
August 2, 2026Transparency obligations (Art. 50), full applicability of most of the regulation, powers of supervisory authorities
December 2, 2026Watermarking for older generative systems + new prohibitions (intimate content without consent, CSAM)
December 2, 2027High-risk systems according to Annex III (recruitment, scoring, education…)
August 2, 2028High-risk AI in regulated products (Annex I)

Note: The postponement of deadlines for high-risk systems results from the political agreement on the Digital Omnibus of May 7, 2026; formal adoption is expected before August 2026. The August 2, 2026 for transparency remains in effect.

What Penalties Are Imposed for Violating the AI Act

The penalties exceed even the dreaded fines under the GDPR:

  • Prohibited practices: up to €35 million or 7% of global annual turnover (whichever is higher)
  • Breaches of obligations regarding high-risk systems and transparency: up to €15 million or 3% of turnover
  • Providing false information to authorities: up to €7.5 million or 1% of turnover

By comparison: the maximum fine under the GDPR is 4% of turnover. The EU is thus sending a clear signal that it takes AI compliance seriously. Furthermore, data protection authorities are already actively enforcing the GDPR in the context of AI—so the risks are mounting.

How to Prepare: A 6-Step Checklist

According to recent surveys, up to 78% of organizations have not yet taken significant steps toward compliance, and more than half do not even have a basic inventory of their AI systems. Here is the process we recommend to our clients:

  1. Inventory of AI systems. Map every AI tool you use, develop, or procure—including third-party SaaS tools.
  2. Risk classification. Determine which category each system falls into. Many companies discover that they are using a high-risk system without even realizing it (typically AI in recruitment).
  3. Transparency audit under Article 50. Identify chatbots, generative content, and deepfake-capable systems—the deadline is August 2, 2026.
  4. AI governance and documentation. Establish internal policies, responsibilities, human oversight, and record-keeping. Companies that are GDPR-compliant have a head start, but the AI Act goes beyond data protection.
  5. AI literacy among employees. The requirement to train staff working with AI takes effect in February 2025.
  6. Ongoing monitoring. The Commission’s harmonized standards and guidelines are constantly being updated—stay informed or secure a partner to do it for you.

The AI Act isn’t just an obligation—it’s a competitive advantage

Demonstrable readiness for the AI Act is increasingly seen as a sign of credibility in the European market. Companies that have their AI governance in order win tenders, build customer trust, and avoid costly retrofits. Creating technical documentation “from scratch” takes 3–6 months—it’s not worth waiting.

Need help with AI Act compliance?

At DataSwans, we help companies map their AI systems, classify risks, and establish governance so you can meet deadlines without unnecessary red tape. Schedule a no-obligation consultation →

Frequently Asked Questions (FAQ)

When will the AI Act take effect?

The AI Act takes effect on August 1, 2024, and will be implemented gradually. Prohibitions take effect in February 2025, the rules for GPAI models from August 2025, transparency obligations from August 2, 2026, and high-risk systems from December 2027 and August 2028, respectively.

Does the AI Act also apply to small businesses in Slovakia?

Yes. If you use an AI system (e.g., a chatbot on your website, AI for recruitment, or AI-generated content), you have the obligations of a deploying entity. While smaller penalties apply to small and medium-sized enterprises, the obligations remain.

Do I have to label content created by artificial intelligence?

Yes. Starting August 2, 2026, AI-generated content must be machine-readably labeled, and deepfakes must be clearly labeled. For systems placed on the market before this date, a transition period applies until December 2, 2026.

What is the maximum fine for violating the AI Act?

Up to €35 million or 7% of global annual turnover for prohibited practices—more than under the GDPR.

What is the Digital Omnibus, and what did it change?

It is a package of amendments to the AI Act that EU institutions politically agreed upon on May 7, 2026. It pushed back the deadlines for high-risk systems (to December 2027 and August 2028), introduced new prohibitions, and simplified certain obligations. The deadline for transparency (August 2026) remains unchanged.

Sources

  1. European Commission – AI Act (official framework): https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai
  2. AI Act Service Desk – Official Timeline: https://ai-act-service-desk.ec.europa.eu/en/ai-act/timeline/timeline-implementation-eu-ai-act
  3. Regulation (EU) 2024/1689 (full text, EUR-Lex): https://eur-lex.europa.eu/eli/reg/2024/1689/oj
  4. Covington – EU AI Act Update (May 2026): https://www.insideglobaltech.com/2026/05/28/eu-ai-act-update-timeline-relief-targeted-simplification-and-new-prohibitions/
  5. Latham & Watkins – AI Act Update (May 2026): https://www.lw.com/en/insights/ai-act-update-eu-resolves-to-change-rules-and-extend-deadlines
  6. Sidley – EU AI Act Transparency Obligations (June 2026): https://datamatters.sidley.com/2026/06/24/eu-ai-act-transparency-obligations-preparing-for-compliance-by-august-2-2026/
  7. Gibson Dunn – EU AI Act Omnibus Agreement (May 2026): https://www.gibsondunn.com/eu-ai-act-omnibus-agreement-postponed-high-risk-deadlines-and-other-key-changes/

This article is for informational purposes only and does not constitute legal advice.