AI consulting
EU AI Act compliance
Transparency obligations have applied since 2 August 2026; high-risk systems follow a new timeline after the Digital Omnibus. Find out which obligations apply to you.
What is the EU AI Act?
The EU AI Act (Regulation (EU) 2024/1689) is the EU's first general regulation of artificial intelligence. It entered into force on 1 August 2024 and its obligations apply in stages. Regulation (EU) 2026/1744 (the “Digital Omnibus on AI”, effective from 27 July 2026) postponed the deadlines for high-risk systems; since 2 August 2026 the transparency obligations and the remaining parts of the Act outside the high-risk area have applied.
Together with the law firm of Mgr. Barbora Surmanová we offer a complete solution: technical and process compliance plus the legal documentation.
AI Act timeline
- 2 Feb 2025in force
Ban on unacceptable practices (Art. 5: social scoring, manipulative techniques) and the duty of AI literacy for staff (Art. 4).
- 2 Aug 2025in force
Obligations for providers of general-purpose AI models (GPAI), national supervisory authorities, governance.
- 2 Aug 2026new
Transparency under Art. 50: informing people that they are interacting with AI, labelling deepfakes, machine-readable marking of AI-generated content; application of the rest of the Act except high-risk systems.
- 2 Dec 2026next
New prohibitions (so-called nudifier apps, child sexual abuse material) and the end of the transition period for content marking by generative systems placed on the market before 2 August 2026.
- 2 Dec 2027next
High-risk systems under Annex III (HR, education, credit, critical infrastructure).
- 2 Aug 2028next
High-risk systems under Annex I (AI embedded in regulated products).
Where we are today: August 2026. Timeline under Regulation (EU) 2026/1744 (Digital Omnibus on AI).
Penalties: Up to €35 million or 7 % of worldwide turnover for prohibited practices, €15 million or 3 % for breaches of other obligations, and €7.5 million or 1 % for supplying incorrect information to the authorities.
Risk categories of AI systems
The AI Act classifies AI systems into four risk categories
Unacceptable risk
Biometric surveillance, social scoring
Prohibited since February 2025High risk
HR systems, education, critical infrastructure
Strict requirements from 2 Dec 2027 (Annex III) and 2 Aug 2028 (Annex I)Limited risk
Chatbots, deepfake generators
Transparency towards users since August 2026Minimal risk
Recommender systems, spam filters
Voluntary codes of conductDoes the AI Act apply to you?
- Do your staff use ChatGPT, Copilot or other AI tools at work? Then the AI literacy obligation applies (Art. 4).
- Do you use AI in recruitment, staff appraisals or credit scoring? That is probably a high-risk system.
- Does a chatbot talk to your customers, or do you generate AI content? Transparency obligations apply (Art. 50).
- Do you develop or sell AI solutions? You are a provider with your own set of obligations.
- Do you know which AI tools are actually used in your company and who approved them? Without an inventory, the obligations cannot be met.
How we can help
Risk assessment
Classification of your AI systems by AI Act risk category: prohibited, high, limited and minimal risk.
Compliance plan
An action plan for meeting the requirements: documentation, transparency, human oversight, data governance.
Documentation
Technical documentation, declarations of conformity and system records as required by the AI Act.
AI literacy training
AI literacy training for staff, mandatory for every business using AI since 2 February 2025.
AI Act assessment
Find out which AI systems you use, which risk category they fall into and what you need to do. Initial consultation free of charge.