Zum Inhalt springen
Leitfäden

The AI Act for organisations that use AI

Which obligations reach you as a user of AI tools and models, from which date, and a 90-day plan to meet them. Updated for the July 2026 amendments.

Zuletzt geprüft
23 September 2026
Lesezeit
8 Min.

A Sluis guide for privacy, security and platform teams. Last checked 23 September 2026 against the AI Act as amended by Regulation (EU) 2026/1744.

Most organisations will never train a model. They buy AI tools, call model APIs and build assistants on top of them. This guide sets out which AI Act obligations reach an organisation in that position, from which date, and what to do about each.

In short

  • The AI Act has applied in general since 2 August 2026. The rules for high-risk AI systems do not apply yet: from 2 December 2027 for the uses listed in Annex III, such as recruitment and credit scoring, and from 2 August 2028 for AI built into regulated products.
  • Three sets of rules already reach ordinary business use of AI: the prohibited practices, the duty to support AI literacy, and the transparency rules for chatbots and published AI-generated content.
  • The AI literacy duty was softened in July 2026. You must take measures to support your staff's AI literacy. You no longer have to ensure that they reach a particular level.
  • The prohibition that most often catches ordinary businesses is emotion recognition in the workplace. Sentiment scoring of employees' voices on support calls is the usual example.
  • The AI Act does not require an EU provider or EU hosting. Where those requirements exist, they come from the GDPR, sector rules or procurement conditions.

Are you a provider or a deployer?

The Act distinguishes the provider, who develops an AI system and places it on the market or puts it into service under its own name, from the deployer, who uses an AI system under its own authority. "Putting into service" includes supplying a system for your own use, so an organisation can be both.

SituationYour roleWhat follows
Staff use Copilot, ChatGPT Enterprise, Le Chat or a similar toolDeployerProhibitions, AI literacy, and transparency where you publish AI-generated content
You build an internal assistant on a model API for your own staffProvider of that assistant, and its deployerFor a system that is not high-risk, mainly the Article 50 transparency duties
You add an AI feature to a product your customers useProvider of that featureArticle 50 duties towards the people who use it. The model's own obligations stay with the model's provider
You fine-tune a general-purpose model and make it availablePossibly a provider of a general-purpose modelThe Commission's July 2025 guidelines treat a modifier as a provider when the modification uses more than a third of the compute used to train the original model
You use AI to screen CVs, score credit or set insurance pricesDeployer of a high-risk system from 2 December 2027Article 26 duties, and for credit and insurance a fundamental rights impact assessment

You can also become the provider of a high-risk system by putting your name or trademark on it, by modifying it substantially, or by using a general-purpose system for a high-risk purpose (Article 25). That matters most to organisations that white-label AI tools for their own customers.

What applies now

Prohibited practices, since 2 February 2025

Article 5 bans a short list of uses outright. The ones that reach ordinary businesses:

  • Emotion recognition in the workplace or in education, unless for medical or safety reasons. This covers inferring emotions from voice, face or other biometric data. Call-centre analytics that score agents' stress or sentiment from their voices is the common case. Scoring the customer's sentiment from the words of a chat is a different question; scoring the employee from biometric signals is squarely in scope.
  • Manipulative or deceptive techniques that materially distort behaviour and cause significant harm, and exploiting vulnerabilities such as age or financial situation.
  • Social scoring that leads to unjustified or disproportionate treatment.
  • Biometric categorisation to infer sensitive traits such as ethnicity, political opinion or sexual orientation.
  • Untargeted scraping of facial images to build recognition databases.

From 2 December 2026 a further prohibition applies to AI systems that generate or manipulate non-consensual intimate material or child sexual abuse material. For deployers it bites only when a system is used for that purpose.

Fines for prohibited practices go up to EUR 35 million or 7% of worldwide annual turnover, whichever is higher.

What to do: search your AI inventory for voice analytics, webcam proctoring, "engagement" scoring and any feature that infers mood or attention from people's faces or voices. Switch off what falls within the ban. Keep a note of what you checked and when.

AI literacy, Article 4 as amended

Since 27 July 2026 the duty reads: providers and deployers "shall take measures to support the development of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf", taking into account their knowledge, experience and the context of use. The text adds that this "does not require providers or deployers to guarantee any specific level" of AI literacy.

The original version required organisations to ensure a sufficient level of literacy. The amended version is an obligation to make an effort, scaled to the people and the use. The Commission is required to publish practical examples of compliance.

What to do: a proportionate programme is enough, and a paper trail makes it demonstrable.

  • An AI use policy that says which tools are approved, for what, and with which data.
  • Short role-based briefings: what the tools are good and bad at, what must never go into a prompt, how to check an output before relying on it.
  • A record of what was provided, to whom and when. Industry reporting of the Commission's Q&A says no certificate is required.

Transparency, since 2 August 2026

Article 50 sets out who must tell whom about AI. The Commission published guidelines on these duties on 20 July 2026, alongside a code of practice on marking and labelling AI-generated content.

WhoDutyTypical case
Provider of a system that interacts with peopleTell people they are dealing with an AI system, unless that is obviousThe support chatbot on your website, if you built it
Provider of a system that generates contentMark outputs as AI-generated in a machine-readable wayA text or image generator offered to customers. Systems already on the market before 2 August 2026 have until 2 December 2026
Deployer of emotion recognition or biometric categorisationInform the people exposed to itWhere such use is lawful at all
Deployer of a deepfakeDisclose that the content was generated or manipulatedSynthetic video or audio of a real person
Deployer publishing AI-generated text on matters of public interestDisclose it, unless a person reviewed it and an organisation takes editorial responsibilityArticles and reports published to inform the public

For a chatbot, a line at the start of the conversation does the job: "You are chatting with an AI assistant." If a person can take over, say how.

What applies from 2 December 2027

The high-risk rules cover AI used in the areas listed in Annex III. The Commission's summary lists biometrics, critical infrastructure, education, employment and worker management, access to essential private and public services including credit scoring, law enforcement, migration and border control, and the administration of justice and democratic processes.

A deployer of a high-risk system must, under Article 26:

  • use it according to the provider's instructions for use;
  • assign human oversight to people with the competence, training and authority to exercise it;
  • make sure input data under its control is relevant and representative for the purpose;
  • monitor the system and report serious incidents to the provider and the authorities;
  • keep the logs the system generates, for at least six months;
  • inform workers' representatives and the affected workers before using a high-risk system at the workplace;
  • inform people when a high-risk system is used to make or support decisions about them.

Public bodies, private entities providing public services, and deployers of credit scoring or life and health insurance pricing must also carry out a fundamental rights impact assessment before first use (Article 27).

High-risk systems already on the market or in service before the applicable date fall under these rules only if their design changes significantly after that date. Systems intended for use by public authorities must comply by 2 August 2030 regardless (Article 111(2)).

What to do now: if a use in your inventory falls in an Annex III area, ask the supplier how it will support your Article 26 duties: instructions for use, logging, and the information you need for a DPIA. Put the question in the next contract renewal rather than waiting for 2027.

A 90-day plan

  1. Inventory. List every AI system in use, including AI features inside SaaS tools. Record the system, supplier, purpose, users, data involved and whether people outside the organisation interact with it.
  2. Classify. For each: could it be a prohibited practice? Is it in an Annex III area? Does it talk to the public? Does it produce content you publish?
  3. Stop prohibited uses. Switch them off and record the decision.
  4. Add transparency notices to chatbots and to published AI-generated content.
  5. Set up AI literacy measures: the use policy, role briefings and a training record.
  6. Update contracts. Ask suppliers how they meet Article 50 and, for Annex III uses, how they will support your Article 26 duties.
  7. Diary the dates. 2 December 2026 for the new prohibition and the marking deadline for existing systems. 2 December 2027 for Annex III. 2 August 2028 for Annex I.

Checklist

  • AI inventory complete, including AI features inside existing software
  • Each system classified: prohibited, high-risk (Annex III), transparency-relevant, or none
  • No emotion recognition applied to employees or students
  • AI use policy published to staff
  • Role-based AI briefings delivered and recorded
  • Chatbots tell users they are talking to an AI system
  • Published AI-generated content labelled where Article 50 requires it
  • Supplier contracts address Article 50, and Article 26 for Annex III uses
  • Owner and review date assigned for each high-risk use before 2 December 2027

Sources

Alle Leitfäden
Nächster LeitfadenKeeping personal data out of AI prompts