Artificial intelligence

EU AI Act: What Czech Companies Need to Know in 2026

A guide to EU AI Act requirements for small and medium-sized businesses after the Digital Omnibus

Mgr. Jaroslav Surman 15 January 2026 8 min read

The EU AI Act (Regulation (EU) 2024/1689 of the European Parliament and of the Council) is the world's first comprehensive regulation of artificial intelligence. It entered into force on 1 August 2024, and its provisions become binding in stages. In July 2026 the timetable was substantially changed by the amendment known as the Digital Omnibus on AI (Regulation (EU) 2026/1744, in force since 27 July 2026): it postponed the obligations for high-risk systems, softened the AI literacy duty and extended the deadline for national sandboxes. For Czech companies this means concrete obligations with clear deadlines. In this article we explain exactly what the AI Act requires as of August 2026, who is affected and what steps to take today.

The Four Risk Categories: Where Does Your Company Stand?

The AI Act sorts AI systems into four risk categories. The scope of your obligations depends on where your system falls.

Prohibited Practices (Unacceptable Risk)

Article 5 of the Regulation lists practices the EU considers incompatible with fundamental rights: social scoring (by public authorities and companies alike), manipulative techniques exploiting people's vulnerabilities, real-time biometric identification in public spaces (with narrow exceptions for law enforcement) and emotion recognition in the workplace and in schools. These practices have been banned since 2 February 2025. From 2 December 2026 further prohibitions are added, in particular AI systems designed to create non-consensual intimate imagery (so-called nudifier apps) and child sexual abuse material. If you use anything of the kind, you must stop immediately.

High-Risk AI Systems

This category covers AI used in areas such as recruitment (automated CV screening, candidate assessment), access to financial services (credit scoring), critical infrastructure, education and public administration (Annex III), as well as AI used as a safety component of regulated products such as machinery or medical devices (Annex I). The strictest requirements apply to these systems: conformity assessment, technical documentation, a risk management system, data governance, human oversight and ongoing monitoring. Full application of these requirements was postponed by Regulation (EU) 2026/1744: to 2 December 2027 for stand-alone high-risk systems under Annex III, and to 2 August 2028 for AI embedded in regulated products under Annex I.

Limited Risk (Transparency Obligations)

Chatbots, image and text generators and systems producing deepfakes fall under Article 50. The main obligation is transparency: users must know they are communicating with AI, deepfakes must be labelled and AI-generated content must carry machine-readable marking. These obligations have applied since 2 August 2026 and also concern companies that deploy a customer-service chatbot on their website. For generative systems placed on the market before 2 August 2026, a transitional period for machine-readable marking of content runs until 2 December 2026.

Minimal Risk

Most everyday AI applications (spam filters, e-shop recommendation engines, automatic text correction) fall into the minimal-risk category. No specific obligations apply to them, but the EU encourages voluntary adherence to codes of conduct.

The Timetable After the Digital Omnibus: What Applies When

The AI Act does not apply all at once but in waves. The current timetable looks like this.

2 February 2025: prohibition of unacceptable-risk practices (Article 5) and the AI literacy obligation (Article 4): companies must take measures to support AI knowledge among staff who work with AI. After the 2026/1744 amendment there is no longer any need to guarantee a specific level of knowledge for every individual, but the measures must be demonstrable.

2 August 2025: obligations for providers of general-purpose AI (GPAI) models, the governance rules (the European AI Office, national authorities) and most of the penalty provisions.

2 August 2026: transparency obligations under Article 50 and the remainder of the Regulation except the high-risk obligations; from this date providers of GPAI models can also be fined (Article 101). Since 3 August 2026 national market surveillance authorities supervise compliance.

2 December 2026: new prohibitions (nudifier apps, child abuse material) and the end of the transitional period for content marking by generative systems placed on the market before 2 August 2026.

2 August 2027: deadline for Member States to establish at least one national regulatory sandbox (moved from 2026).

2 December 2027: full obligations for high-risk systems under Annex III.

2 August 2028: obligations for high-risk AI in regulated products under Annex I.

What This Means for SMEs in the Czech Republic

Many business owners think the AI Act does not concern them because they "only use ChatGPT". That is a mistake. If you deploy an AI system in your company (as a so-called deployer), you have your own obligations under Article 26: to use a high-risk system in accordance with the provider's instructions, ensure human oversight, monitor operation, keep logs and inform employees and affected persons. These are not the developer's obligations, but they are just as enforceable. And regardless of risk category, every company whose staff work with AI is subject to the AI literacy duty under Article 4 and, since August 2026, the transparency obligations under Article 50.

For small and medium-sized enterprises the AI Act does provide relief: simplified technical documentation, lower fine ceilings and access to regulatory sandboxes. The deadline for Member States to establish a sandbox was moved by the amendment to 2 August 2027. The Czech sandbox is being prepared by the Czech Standardization Agency (it is to be free of charge for SMEs), and under the Czech AI act currently in preparation the supervisory authority is to be the Czech Telecommunication Office.

GPAI Models: Who Has Which Obligations?

The AI Act introduces a special regime for general-purpose AI models, i.e. the large language models behind ChatGPT, Copilot or Gemini. If you develop such a model, or substantially modify one and place it on the EU market as a provider, you must keep technical documentation on the model's training, comply with transparency rules and respect copyright in the training data; for models with systemic risk, further duties such as adversarial testing and reporting of serious incidents apply. Companies that merely use a GPAI model do not have these provider obligations, but they remain responsible for how they deploy it, in particular for data protection, transparency and any high-risk applications they build on top of it.

Penalties: The Amounts at Stake

Fines under the AI Act are tiered and can be substantial. Using a prohibited practice can attract a fine of up to 35 million euros or 7 % of worldwide annual turnover. Breaches of other obligations, including high-risk and transparency obligations, up to 15 million euros or 3 % of turnover. Supplying incorrect, incomplete or misleading information to supervisory authorities, up to 7.5 million euros or 1 % of worldwide annual turnover. For companies the higher of the two amounts applies; for SMEs and start-ups, the lower.

Self-Check: Five Questions for Your Company

Before you approach a consultant, answer five questions. First: do you know which AI tools are actually used in your company, including those employees have obtained themselves? Second: do you use AI in recruitment, employee evaluation, assessing clients' creditworthiness or any other area listed in Annex III? If so, you have until December 2027 to prepare for the high-risk regime. Third: does a chatbot communicate with your customers, or do you publish AI-generated content? Then the transparency obligations have applied to you since August 2026. Fourth: can you document how you support your employees' AI literacy (training, rules)? Fifth: do you have internal rules on who may use which AI tool and with what data? If you hesitated on any question, you know where to start.

What to Do Today: 5 Practical Steps

First, take an inventory of all AI systems used in your company, including those employees use without official approval (shadow AI). Second, classify each system into the relevant risk category. Third, provide AI literacy training for staff and management and document it (this obligation has applied since February 2025). Fourth, prepare an internal AI policy setting out rules for deploying and using AI, and add user disclosures wherever AI communicates externally. Fifth, have a professional AI Act assessment carried out to identify specific gaps and propose a remediation plan with the 2027 and 2028 deadlines in mind.

How We Can Help

At Surman s.r.o. we combine technical and legal expertise. Mgr. Jaroslav Surman is a certified ISO/IEC 42001 Lead Implementer with hands-on experience implementing AI in a corporate environment. We offer complete preparation for the AI Act: from risk assessment through system classification and documentation to staff training. In cooperation with the law office of Mgr. Barbora Surmanová we also cover the legal aspects that purely technical providers overlook.

Do not put off preparing for the AI Act. Contact us for a non-binding initial consultation and find out where your company stands. Find out more on our EU AI Act page.

Updated August 2026.

Mgr. Jaroslav Surman

court-certified translator, AI consultant

← Back to the blog

Have a question about a topic from the blog?

Get in touch directly. Whether legal, translation or AI, the initial consultation is always without obligation.