The AI Act applies: five situations from the working day and what to do now.
The transparency rules of the EU AI Act have applied since 2 August. The strictest duties were pushed back by 16 months shortly before. Five cases from everyday business, each with one clear instruction.
Since 2 August a new part of the EU AI Act has applied. It deals with one question only: When do you have to tell your customers that a machine was involved?
Six days earlier the EU took the pressure off somewhere else. On 27 July the Digital Omnibus came into force. It pushes the strict rules for sensitive uses back by 16 months. Anyone who read only about that now thinks the AI Act is off the table. That holds for the difficult part alone.
Almost everyone is affected. According to the Bitkom study, 41 per cent of German companies with 20 or more employees use AI, and another 48 per cent are planning to. It is most widespread in customer contact and in marketing.
For an ordinary business almost everything comes down to three sentences.
First: If a machine talks to your customers, tell them.
Second: If an AI image looks real, say that it came out of a computer.
Third: If somebody reads your texts before they go out, you need no label at all.
Five cases cover what comes up in an ordinary business.
The dates
What applies when
Four dates, two of them have passed. Click through.
2 February 2025 in force for a year and a half
The prohibited practices take effect, emotion recognition on employees among them. At the same time the duty begins to train your own people in the use of AI.
As of 5 August 2026. The bar only shows the order, it measures nothing.
1. Texts, proposals and newsletters
The most common use and at the same time the most harmless. Article 50 paragraph 4 asks for a label only on AI texts that inform the public about matters of public interest.
A proposal to a customer is not covered. Nor is a marketing email. A newsletter about changes in the law or a blog post about the state of your industry is.
You can spare yourself that distinction, because one exception applies almost every time: If a person has checked the content and somebody takes responsibility for it, no label is needed. In its FAQ on Article 50 the Commission makes clear that a look at the spelling is not enough. There has to be someone who owns the content and is allowed to change it.
What to do: Decide who reads every text before it goes out. That settles the whole area, whatever you write about.
2. Images for advertising and social media
Marketing and communication is the second largest area of use in the Bitkom study. The deepfake rule in Article 50 paragraph 4 applies here. It covers image, audio and video content that resembles something existing and looks authentic.
The clear case: A car dealer cuts out a real vehicle and places it in front of a backdrop it never stood in. The vehicle exists, the scene does not.
The disputed case is the completely invented face used as a model. According to the Commission's explanatory notes, content has to resemble something that really exists. An invented face does not meet that. One law firm reads the same text differently. In advertising the argument usually settles itself anyway, because the model holds a real product or stands in a real shop.
Ordinary image editing is not meant by this. Brightening the sky or cloning out a bin does not make a deepfake. Drawings, cartoons and obviously impossible scenes need no label either.
What to do: Label every image that looks real. The notice belongs on the image itself, not in the legal notice.
3. Chatbot and phone AI
Customer contact is by far the largest area of AI use in the Bitkom study. Article 50 paragraph 1 requires that people learn when they are talking or writing to a machine.
One sentence in the greeting is enough: „You are chatting with an AI assistant." On a phone greeting the notice belongs at the start, not at the end.
There is an exception for cases where everyone notices anyway. Do not rely on it. The Commission reads it narrowly in its guidelines of 20 July 2026. A name like „Your assistant" is not enough for it.
Strictly speaking the provider of the system is responsible, not you as its customer. Only the notice is missing on your website. Your customers ask you about it.
What to do: Open your own chat window. If the notice is missing, ask the provider for it.
4. Pre-sorting job applications
In HR only 14 per cent of AI users run such systems, according to Bitkom. It is the case with the strictest rules, though.
Annex III of the regulation counts software that evaluates or pre-sorts applications among the high-risk systems. That brings a risk assessment, technical documentation, logging and human oversight able to override the result.
These duties were meant to apply from 2 August. On 27 July the Digital Omnibus moved them to 2 December 2027, and to 2 August 2028 for AI inside products that are already regulated.
Two things still apply today. Data protection law with its rules on automated decisions. And Article 4 of the regulation, which since February 2025 has required the people working with such programs to understand them. Missing know-how is named by 53 per cent of companies as their biggest obstacle.
What to do: Train the people involved and write down that the training took place. Put the rest in the calendar for spring 2027.
5. Measuring mood and emotions
Since 2 February 2025 Article 5 has prohibited the use of artificial intelligence to infer people's emotions in the workplace or in education. What is meant is software that reads from a voice on the phone how stressed or how motivated an employee sounds. It stays permitted only for medical reasons or for safety.
With customers it is different. Analysing how satisfied callers sound is allowed. Under Article 50 paragraph 3 the people concerned have to be informed. Data protection law applies on top.
What to do: Switch it off for employees. For customers, put it in the greeting and in the privacy notice.
What a breach costs
For the transparency obligations in Article 50 it is up to 15 million euros or three per cent of worldwide annual turnover, whichever is higher. For the prohibited practices in Article 5, up to 35 million or seven per cent.
For small and medium-sized companies and start-ups the lower of the two figures applies (Article 99). Enforcement sits with the national market surveillance authorities.
For Article 4, the training duty, the regulation provides no fine at all. The penalty catalogue does not list it. Anyone threatening you with one is not telling you the truth.
The next date is 2 December 2026
By then AI tools have to mark their output so that programs can detect it as machine-generated. The makers take care of that. You do not have to mark old content afterwards.
What to do: In December, ask the providers you use.
The main points in brief
- Since 2 August a chatbot or phone AI has to say that a machine is answering. AI images that look real need a notice.
- Texts are the easiest case. If a person reads them before publication and takes responsibility, no label is needed at all.
- Recruiting software counts as a high-risk system. Those duties have moved to 2 December 2027. Data protection and the training duty apply today.
- Emotion recognition on employees has been prohibited since February 2025, carrying the highest fine range in the whole regulation.
- The training duty itself carries no fine. Article 4 is not in the penalty catalogue.
- The next date is 2 December 2026. By then AI tools have to mark their output in a machine-readable way, and that is the makers' job.
All in all it is two sentences in a greeting, a notice on a few images and a decision about who proofreads texts. That is one morning's work. The rest of the regulation reaches most companies in 2027 at the earliest.
Poll
How far along is your company with the AI Act?
One answer per device, anonymous, no cookie. The result will appear in a later post.
Daniel Klantke · AI consulting for companies and founders · klantke.com/en/blog/eu-ai-act-what-companies-must-do-now
Sources
- Bitkom: Durchbruch bei Künstlicher Intelligenz. 41 per cent of German companies with 20 or more employees use AI, another 48 per cent are planning to. Largest areas customer contact and marketing, HR 14 per cent. 53 per cent name missing know-how as an obstacle. 604 companies surveyed.
- European Commission: Guidelines on the transparency obligations, adopted 20 July 2026. Narrow reading of the obviousness exception, the line around editorial control.
- European Commission: FAQ on Article 50. Three criteria for a deepfake, transition until 2 December 2026, no retroactive labelling of old content.
- Article 50 of the EU AI Act. Paragraph 1 interaction, paragraph 2 machine-readable marking, paragraph 3 emotion recognition, paragraph 4 deepfakes and texts of public interest.
- Article 5, point f. Emotion recognition in the workplace and in education prohibited, exception for medical and safety reasons. In force since 2 February 2025.
- Article 99. 15 million euros or three per cent for transparency breaches, 35 million or seven per cent for prohibited practices, the lower figure for SMEs.
- Lewis Silkin: The Digital Omnibus on AI enters into force today, 27 July 2026. Published in the Official Journal on 24 July, in force from 27 July, new deadlines 2 December 2027 and 2 August 2028, Article 50 unchanged.
- WBS Legal: Why almost every AI image will have to be labelled as a deepfake. The broad reading, based on the draft guidelines of 8 May 2026.