Do all businesses using AI have the same obligations?
No. The AI Act distinguishes between providers, deployers, importers and distributors. A company buying an off-the-shelf tool for its own operations will usually be a deployer. It may nevertheless become a provider if it markets the system under its own name, makes a substantial modification or changes the intended purpose in a legally relevant way.
The assessment must be performed per use case, not once for the entire organisation. The same business may be a deployer of an office assistant and a provider of an AI feature embedded in its own product. The same underlying model may be used for low-impact internal drafting and for a materially more sensitive process affecting applicants, employees or customers.
What actually started to apply on 2 August 2026?
For many businesses, Article 50 is the most immediate operational change. A person interacting directly with a chatbot or another relevant interactive AI system should be informed that they are dealing with AI unless this is obvious to a reasonably well-informed and observant person in the circumstances. The disclosure should be made no later than the first interaction, rather than being buried in lengthy terms.
A deployer generating or manipulating image, audio or video content that constitutes a deepfake must disclose that the material was artificially generated or manipulated. An evidently artistic, satirical or fictional work may use a less intrusive form of disclosure, but the exception does not eliminate transparency altogether.
There is also a specific rule for AI-generated or manipulated text published to inform the public on matters of public interest. Disclosure is generally required. An exception may apply where the text has undergone human review or editorial control and a natural or legal person assumes editorial responsibility. That exception should not be treated as a blanket exemption for every company post or marketing publication.
What did the AI Omnibus not postpone?
Regulation (EU) 2026/1744 did not postpone Article 50 transparency duties. It also did not suspend the prohibited practices already applicable since 2 February 2025, including certain manipulative uses, specified forms of social scoring and, as a rule, emotion recognition in workplaces and educational institutions. Additional prohibitions relating to systems generating non-consensual intimate content and child sexual abuse material will apply from 2 December 2026.
It is therefore inaccurate to say that “the AI Act has been delayed”. A significant, defined part of the timetable changed. Rules already in force may apply to businesses that do not develop foundation models and merely deploy third-party systems.
Which high-risk deadlines were postponed?
The main requirements for Annex III high-risk systems — including specified uses in employment, education, biometrics, critical infrastructure and access to essential services — will apply from 2 December 2027. The relevant high-risk rules for AI associated with products covered by EU legislation listed in Annex I will generally apply from 2 August 2028.
This is preparation time, not an exemption from analysis. A business procuring an applicant-screening, employee-evaluation or customer-scoring system should already examine its intended purpose, supplier documentation, human oversight, data quality, logging and contractual allocation of responsibility. A complex technology and procurement programme may not be feasible if left until shortly before the deadline.
How did the AI literacy obligation change?
Following the AI Omnibus, providers and deployers must take measures supporting the development of AI literacy among staff and other persons operating or using AI systems on their behalf. They are not required to guarantee one prescribed level of knowledge for every individual.
The legal requirement is to take context-appropriate measures. Their form should reflect the team’s experience, the use case and the people affected by the system. Short rules on approved tools may be proportionate for basic administrative use. An HR team using AI to screen applicants needs more detailed guidance, meaningful output review and an understanding of discrimination risk. A certificate from a generic course does not automatically demonstrate compliance.
How should an AI review begin?
Start with a register of use cases, not merely a supplier list. Record the purpose, business owner, users, affected persons, input data, use of outputs, provider and the point at which a human may intervene.
Then determine the company’s role and make an initial risk classification. Recruitment and workforce management, scoring, access to services, biometrics, safety functions and AI features embedded in customer products require particular attention.
Finally, check whether interfaces and publications require disclosures, whether staff measures support AI literacy, and whether contracts provide the information and rights needed for lawful use. This allows the business to separate immediate actions from milestones for 2 December 2026, 2027 and 2028.
What should be reviewed in supplier contracts and data flows?
The contract should reflect the parties’ actual roles. Review the intended use and limitations of the system, changes to the model or features, security, use of customer data for training, processing locations, subcontractors, incident support, access to documentation, termination and data export.
If the tool processes personal data on the company’s behalf, an Article 28 GDPR data processing agreement may be required. Where the provider independently determines why data are used, simply calling it a “processor” does not settle the qualification. Confidential information, customer data and rights in outputs also require separate treatment. For a sector-specific application, see Generative AI in a Polish marketing agency: rights, confidentiality and client data.
Where AI is embedded in a customer-facing product, the upstream supplier terms should be aligned with the company’s own SaaS agreement with a business customer. AI used in workforce processes also requires a separate employment and privacy review; the starting points are explained in Employee monitoring and business email in Poland.
How the issue appears in practice
Practical example — hypothetical scenario
A retail company deploys two tools from the same supplier. One helps staff draft product descriptions. The other ranks job applications and recommends candidates for interview. The company adopts a single policy stating that “a human always approves AI output”. It does not assess the ranking criteria, explain how recruiters may override recommendations or examine the information given to candidates. Product descriptions are also published without checking claims about composition or performance. The risk profiles are different. The recruitment tool may fall within Annex III and the high-risk duties scheduled for 2 December 2027; GDPR and employment rules apply before that date. The drafting tool is unlikely to be high-risk, but the company remains responsible for accurate customer information, confidentiality and output verification. The proper solution is to assess both uses separately. Recruitment needs a compliance roadmap, supplier documentation, oversight rules, data review and a challenge process. Product copy needs input restrictions, substantive verification and publication approval. A shared governance policy can connect the controls but cannot replace use-specific measures.
Matters to determine or verify before proceeding
- Which AI systems are actually used, including tools adopted without central procurement?
- What role does the company perform for each system, and has it changed the system’s intended purpose?
- Is the use prohibited, subject to Article 50, or potentially high-risk?
- Who is affected by the output, and does it influence decisions concerning applicants, staff or customers?
- Does an interface, deepfake or public-interest publication require clear disclosure?
- What personal or confidential data enter the tool, and may the supplier use them for further training?
- Which AI literacy measures are appropriate for each role?
- Does the supplier contract provide documentation, incident support, change control and a workable exit?
Key issues at a glance
| Issue | Key information |
|---|---|
| Transparency duties | Article 50 applies from 2 August 2026 and may require an AI interaction notice or labelling of specified content. |
| Annex III high-risk systems | Main obligations were postponed until 2 December 2027. |
| Annex I product-related systems | The relevant main deadline was postponed until 2 August 2028. |
| AI literacy | Organisations must take measures supporting literacy but need not guarantee one individual knowledge level. |
| Common generative AI tools | Use is not automatically high-risk, but transparency, GDPR, confidentiality and output-control duties may still apply. |
| Human oversight | Oversight must be operational: the responsible person must understand limitations and be able to reject or change the output. |
Legal basis
- Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence, in particular Articles 3–6, 50, 99, 111 and 113 and Annexes I and III.
- Regulation (EU) 2026/1744 of the European Parliament and of the Council of 8 July 2026 amending Regulation (EU) 2024/1689 and related legislation as regards simplification of AI rules.
- Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (GDPR), where the AI use involves personal data.
This article provides general information and does not constitute legal advice for a specific matter. The appropriate solution depends on the facts, documents and business objective.
Summary
After 2 August 2026, a business should neither ignore the AI Act nor apply the same extensive programme to every tool. It needs a use-case register, correct role and risk classification, transparency measures that already apply, and a roadmap for high-risk systems. I can audit AI use cases, update internal policies and supplier contracts, prepare transparency rules and build a practical 2026–2028 implementation plan.