- Since 2 August 2026 most of the regulation's obligations apply, including transparency for chatbots and generated content, and the high-risk regime.
- A company that uses an AI tool (the "deployer") has its own duties, distinct from the provider's.
- A partial postponement for some high-risk systems is being discussed in Brussels; do not build your plan on it.
- For an SME, compliance comes down to an inventory, a classification and three documents. No more.
Where the timetable stands
The regulation entered into force in August 2024 and applies in stages. Prohibitions (social scoring, manipulation, emotion recognition at work) have been effective since February 2025, together with the AI literacy obligation for staff. Rules for general-purpose AI models followed in August 2025. 2 August 2026 marks the major stage: transparency, high-risk systems listed in Annex III, fully applicable penalties.
A point of honesty: at the time of writing, discussions exist in Brussels to postpone the application of some obligations linked to high-risk systems, as part of a broader simplification of digital legislation. Nothing is final. Our advice is to treat the timetable as written: what you put in place will never be wasted.
What really concerns you
If you use a chatbot or generate content
People must know they are talking to a machine, unless it is obvious. Generated content that could pass for authentic (images, audio, video) must be labelled as such. For a website with an assistant, a clear notice and a sentence in the first message settle it. For generated marketing content, an internal labelling policy.
If you use AI to recruit, evaluate or grant credit
These uses appear in the list of high-risk systems. Even if you did not design the tool, as a deployer you must use it according to its instructions, ensure real human oversight, keep logs, inform the people concerned and, in some cases, carry out a fundamental rights impact assessment.
If you buy AI from a vendor
Require the technical documentation, the instructions for use, information on training data where due, and a contractual clause on compliance with the regulation. A vendor that cannot produce them is transferring its risk to you.
The ten-point checklist
| Item | What you need to have |
|---|---|
| 1. Inventory | The list of all AI tools in use, including those used by employees |
| 2. Classification | For each tool: prohibited, high risk, transparency, minimal risk |
| 3. Owner | A named person for the topic, even part-time |
| 4. AI literacy | A documented awareness session for the staff concerned |
| 5. Transparency | Notices on chatbots and labelling of generated content |
| 6. Human oversight | Who can stop or correct the system, and how |
| 7. Logs | Retention of usage records for high-risk systems |
| 8. Vendors | Documentation and compliance clauses in contracts |
| 9. Informing people | Employees and customers informed when a high-risk system concerns them |
| 10. Annual review | A set date to redo the inventory |
A register of AI systems (one page per tool), a signed usage policy, and for each high-risk system an oversight sheet: who monitors, which indicators, what stop procedure. With these three pieces you demonstrate a serious approach.
The mistakes we see most
The first mistake is believing the regulation only concerns those who develop AI. The second is forgetting tools quietly built into business software: automatic CV sorting in HR software, scoring in a CRM. The third is producing heavy documentation nobody will keep up to date, instead of a simple, living register.
"Compliance is not a binder. It is knowing, at any moment, which AI tools run in your company and who watches them."
Conclusion
The August 2026 stage makes the regulation concrete for almost every company, even those that never wrote a line of code. The good news is that for an SME the essentials take two weeks with an honest inventory and three short documents. The worst choice would be to wait for a postponement that is not secured.
FAQ
We only use ChatGPT and Copilot, are we concerned?
Yes, at least by the AI literacy obligation and by transparency if you publish generated content. These uses are minimal risk, the burden is light, but it exists.
What is a "deployer"?
Any company or organisation that uses an AI system under its own responsibility in the course of its activity. That is the case for almost every company today.
Do we need an AI officer like the DPO for GDPR?
The regulation does not require it, but naming an owner, even part-time, is the most effective way to move the topic forward. The DPO is often well placed.
What do we concretely risk in 2026?
National supervisory authorities are being set up and will start with information requests and formal notices. Financial penalties will first target serious breaches and prohibited practices.