AI in practice · 10 min read

Does the EU AI Act apply to you? What businesses really need to do now

By · werkflow.studio · Published

short answer

For the vast majority of businesses little changes, and the little that does is manageable. Three points work as a map. First: almost no ordinary business is a “high-risk” case, and even the few exceptions have until the end of 2027. Second: AI content that goes out into the world needs an honest notice (a chatbot says it is an AI, deceptively real AI images must be labelled). Third: your team should be able to handle AI, and that belongs in writing. The regulation does not require a mandatory certificate, a dedicated AI officer or knowledge tests. Do not let the scaremongering around the deadline unsettle you.

What happened on 2 August 2026

Around the August deadline a small market of banners and compliance panic texts is running hot. Most of it does not hold up against the wording of the regulation. So here is the answer calmly and in order.

The European AI Act entered into force on 1 August 2024 and applies in stages:

  • Since 2 February 2025: prohibited practices and the AI-literacy obligation (Art. 4).
  • Since 2 August 2025: rules for the large AI models, the supervisory structures and the penalty framework.
  • From 2 August 2026: the regulation applies in principle and becomes enforceable by authorities. The market surveillance authorities take up supervision; in Germany this is the Bundesnetzagentur with its coordination and competence centre for AI supervision (under the AI Market Surveillance and Innovation Promotion Act, KI-MIG for short).

The big high-risk deadline has been postponed

2 August 2026 was originally meant to be the big deadline for high-risk systems too. A few weeks beforehand came the turn. With the Digital Omnibus Regulation (EU) 2026/1744 of 8 July 2026, the EU postponed the obligations for stand-alone high-risk systems to 2 December 2027, so by a good 16 months. The set of obligations itself has not changed. Only the active review by the Bundesnetzagentur is delayed.

That leaves a short, clear list for an ordinary business. But one step at a time.

The first question: am I even “high-risk”?

“High-risk” sounds threatening and is narrowly defined in law. Annex III lists eight areas of use:

  • Biometrics (remote identification, categorisation, emotion recognition)
  • Critical infrastructure (water, gas, electricity, transport)
  • Education and vocational training
  • Employment and staff management
  • Access to essential services (creditworthiness, insurance)
  • Law enforcement
  • Migration, asylum and border control
  • Administration of justice and democratic processes

For ordinary businesses only staff management really counts

For a typical mid-sized company, a trade business or an engineering office, practically one area is relevant: staff management (number 4). Anyone using AI that pre-sorts applications, scores candidates or helps decide on performance and promotion is operating in the high-risk area. That is the trap businesses fall into without noticing, because such functions run along quietly in many HR tools today.

Everything else an ordinary business does with AI does not fall under Annex III. Drafting a quote from measurement notes, turning a voice memo into minutes, sorting the inbox, pre-formulating a report: none of it is high-risk. As a rule of thumb: whoever operates a high-risk system usually notices it from the subject matter. Whoever is unsure is, as a rule, not operating one.

A short self-check brings clarity

A short self-check brings clarity. To read them here, these are the three core questions:

  • Do we use AI in one of the eight areas? In practice this almost always means: does an AI decide about people at our company, above all in staff selection or lending?
  • Does the system make the decision or substantially prepare it? A tool that only delivers text building blocks, whose result a human then assesses, is something different from a system that automatically sorts candidates out.
  • Do we know what our tools do in the background? Many HR and office programs have retrofitted AI functions. An honest inventory uncovers that.
self-check

Check it yourself in two minutes

The interactive check walks you through these questions (plus one on AI use in your team) and shows at the end what concretely applies to you. Nothing is stored, everything runs in your browser.

Start the self-check

Nothing is stored or sent. The check runs entirely in your browser.

What an ordinary business has to do from now on

Three clear noes mean: no high-risk case. And even a yes buys time until the end of 2027, thanks to the postponement, to prepare calmly.

Two obligations apply to everyone who uses AI professionally, regardless of high-risk status. They are the actual core of what changed on 2 August.

1. Label AI content (Art. 50)

This is the practically most important change for ordinary businesses. Anyone using AI that becomes visible to the outside must disclose it. What matters is separating two levels, because one of them is not the business's job at all.

The chatbot on the website makes clear that an AI is answering, unless that is obvious anyway. One sentence is enough.

For AI images, video and audio there are two separate obligations:

  • The machine-readable marking (metadata, watermark) must be built in by the provider of the AI system, so OpenAI, Anthropic and the like themselves. For the business this only means: do not deliberately remove this marking. You do not have to add it yourself.
  • The visible labelling is the business's job, but only for so-called deepfakes. The term is narrowly framed in law: content that noticeably resembles real people, objects, places or events and could falsely appear genuine.

Does every AI image have to be labelled?

No. The trigger is not whether people are shown, but whether the image looks like a real photograph. A photorealistic image of an object such as a computer, or of a group of people, can fall under it, even with no recognisable faces. A clearly recognisable illustration, a pictogram, an icon, a diagram or an obviously stylised image does not. As a line:

If the image looks like a real photo, it needs a notice. If you can tell it is AI, none is needed.

The exact reach is not yet settled in law

An honest caveat: because the definition also covers objects and places, some lawyers read it very broadly. This is not yet settled with legal certainty. Labelling when in doubt is the safe and, in any case, likeable path, and a small notice costs nothing.

How do you label it?

There is no prescribed logo or fixed wording. The law requires a notice that is clearly recognisable and distinguishable and appears at the latest on first perception (Art. 50(5)). In practice:

  • Image: a visible note on the content, for example “Created with AI” as a caption, as a corner in the image or as watermark text. Put the same note in the alt text so it is also perceivable accessibly.
  • Video: an on-screen note, ideally at the start and permanently or recurring.
  • Audio: an audible note at the start.

Transition period for existing tools

For tools already in use before 2 August 2026, a grace period for the technical marking applies until 2 December 2026.

2. Build and document AI literacy (Art. 4)

This obligation has applied since February 2025 and has been supervised since August 2026. In the summer of 2026 it even became milder: the Digital Omnibus softened the wording from “ensure” to “support the development of AI literacy”. What is required are appropriate, documented measures that fit the staff's role and the system in use. For an ordinary business that means four steps:

  • Know who uses AI for what. An honest inventory, including unofficial use. 77% of STEM professionals use AI tools without approval (SThree/YouGov 2025). This use also exists where no one sees it.
  • Set rules. Which data may go into which tool and which may not, who checks results before they leave the house.
  • Train by role. Accounting needs different knowledge than sales. Training built on people's real tasks fulfils the purpose and brings the actual benefit along the way.
  • Document. Who was trained when on which content, which rules apply. A certificate of participation with a content overview and a short set of rules is enough as a basis.

What the regulation expressly does not require

Three things appear often in marketing copy and are nowhere in the regulation: a mandatory certificate (there is no recognised “Art. 4 certification”), knowledge tests or exams, and an appointed AI officer.

3. Only for staff selection: high-risk preparation

Anyone who noticed at the question above that they use AI in staff selection has the more demanding high-risk obligations ahead (risk management, data quality, human oversight, logging). Thanks to the postponement there is time for this until 2 December 2027. That time should be used and not let slip.

And if I am an employee?

The regulation is addressed to companies, not to individual employees. Anyone who is employed does not have to fear an authority themselves. A few things still make everyday work easier and safer:

  • Know your employer's rules and use the approved tools.
  • Do not put sensitive or personal data into tools that are not approved for it.
  • Check AI results before they go to customers or colleagues. Responsibility for the content stays with the human.
  • Honestly label self-published AI content (images, texts that go outward) where the rules above require it.

Quiet use becomes recognised competence

For many the deadline is a good occasion to openly address their own, partly hidden AI use. Quiet use thus becomes recognised competence, and that is visibly worth more in the business.

The fines question, soberly considered

Panic texts love to display fines in the millions. The high rates apply to prohibited practices and serious breaches by large providers. For small and medium-sized enterprises the regulation expressly provides for proportionate, capped rates. The real risk of missing order lies elsewhere anyway: in faulty results that end up with the customer, and in sensitive data flowing into third-party tools. Both happen today already, with or without supervision.

My honest take

A comparison from everyday life: before someone drives a car, they get a licence. They learn the rules and practise safe handling until they can take part in traffic responsibly. No one considers that harassment; it makes the road more reliable for everyone. At its core the AI Act wants the same: a practised, responsible handling of a powerful tool. Whoever trains their people in it fulfils the obligation almost in passing.

The August deadline is therefore, for the vast majority, a good occasion to deal with a postponed topic. Knowing which tools in the business use AI, which data flows where, and who checks results before they go out, is work that pays off regardless of any regulation. Less rework, less risk, more reliable quality.

What to do now, concretely

Anyone who wants to act themselves goes in order: do the interactive self-check, set the labelling wherever AI content goes outward, and build and document AI literacy. For a small business this is doable over one or two afternoons.

When day-to-day work and core tasks come first, werkflow.studio takes on the work: an honest assessment of whether and where the business is affected at all, an inventory of AI use, the implementation of labelling, and complete evidence documentation. On request with training that works on real processes (quotes, minutes, inbox) and ends with a certificate of participation.

At the centre is a team that works faster and more reliably, long after the deadline is forgotten. Sometimes the honest answer is also: you are barely affected, a note on your website is enough.

Answered briefly

From when does the EU AI Act apply to my business?

The regulation has been enforceable by authorities since 2 August 2026; in Germany supervision lies with the Bundesnetzagentur. The more demanding obligations for stand-alone high-risk systems were postponed to 2 December 2027 by the Digital Omnibus.

Do I have to label every image created with AI?

No. Only content that looks like real photos or recordings (so-called deepfakes) needs labelling. Clearly recognisable illustrations, icons, diagrams or graphics do not. When in doubt, label it.

Does my business need an AI officer or a mandatory certificate?

No. Art. 4 requires appropriate, documented AI-literacy measures. The regulation does not prescribe a mandatory certificate, an appointed AI officer or knowledge tests.

Is my small business a high-risk case?

Almost never. For a typical business practically only staff management is relevant, for example when an AI pre-sorts applications or scores candidates. Everything else that is everyday does not fall under Annex III of the AI Act.

Sources

Factual status checked on 4 August 2026. Before reusing, check whether deadlines or interpretations have shifted.

Not a substitute for legal advice

This guide gives initial guidance and does not replace legal advice. It reflects the status of August 2026 (after the Digital Omnibus). For a binding assessment of your specific case, talk to us or your legal adviser.

Last updated: Author: