AI Tools

EU AI Act 2026: What SMEs Actually Have to Do Now

Übergabe von Unterlagen im Büro als Sinnbild für die Dokumentationspflichten des EU AI Act

Images: created using AI

Short answer: The EU AI Act still applies, but the Digital Omnibus pushed the high-risk obligations back to December 2027 and August 2028. For most small and mid-sized companies, what actually matters from 2 August 2026 are the transparency duties in Article 50 and staff AI literacy.

What changed in July 2026

Six days before the original deadline, the EU pulled the emergency brake. On 27 July 2026, Regulation (EU) 2026/1744 entered into force, published in the Official Journal on 24 July 2026 and generally known as the Digital Omnibus on AI. It amends the AI Act in several places, above all by moving the date on which the heavy obligations for high-risk systems become enforceable.

For many owner-managed companies this is both a relief and a trap. A relief, because the time pressure is gone. A trap, because it is easy to conclude that the AI Act has been shelved. It has not. Part of it has applied unchanged since 2 August 2026.

The revised deadlines at a glance

Obligation Applies from Typically affects
Prohibited AI practices (Art. 5), including the newly added bans already in force every company
AI literacy of staff (Art. 4, softened wording) already in force every company using AI
Transparency and labelling duties (Art. 50) 2 August 2026 chatbots, voice bots, AI-generated content
Watermarking for systems placed on the market before 2 Aug 2026 2 December 2026 providers of generative AI systems
High-risk duties, stand-alone Annex III systems 2 December 2027 e.g. AI in recruiting or credit scoring
High-risk duties, AI as a safety component under Annex I 2 August 2028 machinery, medical devices, aviation
Stand: August 2026. Sources: Regulation (EU) 2026/1744 and the White & Case analysis of 4 August 2026.

What has actually applied since 2 August 2026

Transparency under Article 50

The postponement covers Chapter III only, meaning the high-risk block. The transparency requirements in Article 50 are untouched and have applied since 2 August 2026. In practice: if you run a chatbot or a phone assistant, people must be able to tell that they are dealing with a machine. For most SMEs this is the only part of the AI Act that becomes immediately visible.

The effort involved is modest. One line in the chat window, one sentence before the call connects, one note under automatically generated text. What matters is consistency across every touchpoint, not just the ones somebody happened to remember.

Labelling generated content

Systems that produce synthetic audio, image, video or text content carry a labelling duty. Systems already on the market before 2 August 2026 get a grace period until 2 December 2026. Anything placed on the market after that date has to comply straight away. That distinction matters more in daily life than it sounds, because it decides whether a tool you bought in gives you breathing room or not.

AI literacy under Article 4

The Omnibus softened the AI literacy duty. Providers and deployers now have to take measures to support an adequate level of AI literacy rather than ensure it. The expectation of a trained workforce remains, the liability exposure drops. The Commission and member states are to help with practical compliance examples. If you already have an internal AI policy and a short training session, you are in good shape. We described what that rollout looks like step by step in how to roll out ChatGPT in your company.

Are you a provider or a deployer?

The AI Act works with roles, and the role decides the duties. Most SMEs are deployers: they buy an AI tool and use it in their own operations. Deployers have their own obligations, but far lighter ones than providers. A company can still slide into the provider role, for instance by offering an AI system under its own name, substantially modifying it, or giving a third-party system a new intended purpose. This happens more often than people expect, typically when a purchased language model is marketed as the core of an in-house product.

One clarification from the Omnibus helps here: AI systems that merely assist users or optimise performance are not automatically treated as safety components as long as their failure creates no health or safety risk. That takes a lot of ordinary productivity tooling out of the high-risk category.

A worked example: what preparation really costs

A service company with 40 employees uses AI in several places. The groundwork is easy to estimate:

  • Build an AI inventory: 14 tools in use, 20 minutes each for capture and role assessment, roughly 4.7 hours.
  • Implement transparency notices: 3 customer touchpoints (website chat, phone assistant, automated email replies), one hour each, 3 hours.
  • Write and agree an internal AI policy: 6 hours.
  • Short training for everyone: 40 people at 45 minutes each, 30 hours of staff time.

Total: about 43.7 hours. At an internal rate of 65 euros per hour that is roughly 2,840 euros as a one-off. Add around 8 hours a year for maintaining the inventory and refreshing the training, roughly 520 euros annually. That is a fraction of what most companies already spend on licences for the same tools, and it is the part you can actually show to somebody.

Relief measures aimed at smaller companies

The Omnibus extends existing relief for SMEs and small mid-cap companies: simplified technical documentation, proportionate quality management obligations, mitigated penalties, and continued priority access to regulatory sandboxes. The substantive requirements do not disappear, but the route to demonstrating compliance becomes more proportionate. For a twelve-person business that is the difference between feasible and not.

Two new prohibitions were added as well: generating or manipulating child sexual abuse material, and so-called nudifier applications that produce non-consensual intimate depictions of identifiable people. Anyone providing or deploying generative AI should review their technical safeguards and terms of use accordingly.

Four steps for the coming weeks

  1. Build the inventory. Which AI tools are running, who introduced them, what data flows into them? Without that list every further assessment is guesswork. Our AI check gives you a structured starting point.
  2. Clarify your role. Are you a deployer for every tool, or do you slip into the provider role somewhere?
  3. Catch up on transparency. Every customer touchpoint involving AI gets a clear notice. It is the one duty that is immediately visible.
  4. Build competence. One hour of basic training, a written policy, a named contact person. Document what you did.

If you are reworking your tool selection anyway, choosing the right AI stack sets out the method. And because the AI Act and data protection law apply side by side, it is worth reading up on GDPR-compliant AI tools at the same time.

Frequently asked questions

Has the Digital Omnibus abolished the EU AI Act?

No. The AI Act applies in full. Only the point at which the Chapter III high-risk obligations become enforceable has moved. Prohibitions, AI literacy and transparency duties are unaffected.

We only use ChatGPT and an invoicing tool. Are we in scope?

As a deployer, almost certainly yes; as a provider, almost certainly not. What matters for you is staff AI literacy and, if customers interact directly with an AI system, the transparency duty. High-risk requirements normally do not apply to that kind of use.

When does AI in recruiting become a high-risk system?

Employment is one of the areas listed in Annex III. A system that automatically filters or rejects applications typically falls under it. Under the new timeline, the associated duties apply from 2 December 2027.

Do we have to label AI-generated text on our website?

The labelling duty is aimed primarily at the providers of the generating systems and at cases where content could be mistaken for authentic material. A blanket notice under every blog post is not required. For synthetic images, voices and video the position is stricter.

What happens if we do nothing?

AI Act penalties are tiered and mitigated for SMEs. The bigger day-to-day risk is a different one: without an inventory and a policy you lose track of which company data ends up in which tool. That usually catches up with you before a regulator does.

Conclusion

The Digital Omnibus buys mid-sized companies time, but it does not take work off their plate. What makes sense now is exactly what underpins any AI rollout: know what is running, clarify roles, train people, be transparent. If you would like a second opinion, get in touch or take a look at our AI tools services.

Legal note: this article reflects the position as of August 2026 and is not legal advice. A detailed legal analysis of the amendments is available in the White & Case alert of 4 August 2026.

Related: the practical way to evidence Article 4 is a short written rule, described in AI policy for employees.

Share
Newsletter

One real-world process, once a month

We only write when we have something substantial: a process we built ourselves, what it cost, what it saves — and where it got stuck. If nothing usable comes together in a given month, you get no email that month. You can unsubscribe from any email with one click.

  • Around once a month
  • Unsubscribe with one click
  • No sharing with third parties

Back to top

Get started

Ready to really put AI to work?

Tell us about your project in a few minutes — you’ll get an honest initial assessment, with no sales pressure.

  • Free & no obligation
  • Reply usually within 1 business day
  • GDPR-compliant