AI consulting

EU AI Act compliance

Transparency obligations have applied since 2 August 2026; high-risk systems follow a new timeline after the Digital Omnibus. Find out which obligations apply to you.

What is the EU AI Act?

The EU AI Act (Regulation (EU) 2024/1689) is the EU's first general regulation of artificial intelligence. It entered into force on 1 August 2024 and its obligations apply in stages. Regulation (EU) 2026/1744 (the “Digital Omnibus on AI”, effective from 27 July 2026) postponed the deadlines for high-risk systems; since 2 August 2026 the transparency obligations and the remaining parts of the Act outside the high-risk area have applied.

Together with the law firm of Mgr. Barbora Surmanová we offer a complete solution: technical and process compliance plus the legal documentation.

Blog article: the AI Act and what businesses need to know

AI Act timeline

  1. 2 Feb 2025
    in force

    Ban on unacceptable practices (Art. 5: social scoring, manipulative techniques) and the duty of AI literacy for staff (Art. 4).

  2. 2 Aug 2025
    in force

    Obligations for providers of general-purpose AI models (GPAI), national supervisory authorities, governance.

  3. 2 Aug 2026
    new

    Transparency under Art. 50: informing people that they are interacting with AI, labelling deepfakes, machine-readable marking of AI-generated content; application of the rest of the Act except high-risk systems.

  4. 2 Dec 2026
    next

    New prohibitions (so-called nudifier apps, child sexual abuse material) and the end of the transition period for content marking by generative systems placed on the market before 2 August 2026.

  5. 2 Dec 2027
    next

    High-risk systems under Annex III (HR, education, credit, critical infrastructure).

  6. 2 Aug 2028
    next

    High-risk systems under Annex I (AI embedded in regulated products).

Where we are today: August 2026. Timeline under Regulation (EU) 2026/1744 (Digital Omnibus on AI).

Penalties: Up to €35 million or 7 % of worldwide turnover for prohibited practices, €15 million or 3 % for breaches of other obligations, and €7.5 million or 1 % for supplying incorrect information to the authorities.

Risk categories of AI systems

The AI Act classifies AI systems into four risk categories

Unacceptable risk

Biometric surveillance, social scoring

Prohibited since February 2025

High risk

HR systems, education, critical infrastructure

Strict requirements from 2 Dec 2027 (Annex III) and 2 Aug 2028 (Annex I)

Limited risk

Chatbots, deepfake generators

Transparency towards users since August 2026

Minimal risk

Recommender systems, spam filters

Voluntary codes of conduct

Does the AI Act apply to you?

  • Do your staff use ChatGPT, Copilot or other AI tools at work? Then the AI literacy obligation applies (Art. 4).
  • Do you use AI in recruitment, staff appraisals or credit scoring? That is probably a high-risk system.
  • Does a chatbot talk to your customers, or do you generate AI content? Transparency obligations apply (Art. 50).
  • Do you develop or sell AI solutions? You are a provider with your own set of obligations.
  • Do you know which AI tools are actually used in your company and who approved them? Without an inventory, the obligations cannot be met.

How we can help

Risk assessment

Classification of your AI systems by AI Act risk category: prohibited, high, limited and minimal risk.

Compliance plan

An action plan for meeting the requirements: documentation, transparency, human oversight, data governance.

Documentation

Technical documentation, declarations of conformity and system records as required by the AI Act.

AI literacy training

AI literacy training for staff, mandatory for every business using AI since 2 February 2025.

AI Act assessment

Find out which AI systems you use, which risk category they fall into and what you need to do. Initial consultation free of charge.