Skip to main content
12 min readNorvalda

EU AI Act for Small Business: What Actually Applies After August 2026 — and What Got Postponed

Half the guides online still say “high-risk obligations start August 2026.” That is no longer true. The Digital Omnibus moved those deadlines to December 2027 and August 2028 — but the transparency rules for chatbots and AI content entered into force on 2 August 2026. Here is the calm, sourced breakdown of what a small company actually has to do now.

Short answer first. If you run a small business in the EU, the EU AI Act requirements that apply to you in 2026 are narrower than most articles suggest: the transparency rules of Article 50 — including the duty to tell people they are talking to a chatbot — entered into application on 2 August 2026, while the heavy high-risk obligations were postponed to 2 December 2027 and 2 August 2028 by the Digital Omnibus (Regulation (EU) 2026/1744). The bans on certain AI practices and the AI literacy duty have already applied since 2 February 2025.

Why the confusion? Because the timeline changed mid-year. The AI Act (Regulation (EU) 2024/1689) originally said the bulk of the regulation “shall apply from 2 August 2026.” Then, on 24 July 2026, the EU published the Digital Omnibus on AI — Regulation (EU) 2026/1744 — which entered into force on 27 July 2026 and moved the high-risk deadlines. A large share of the guides you will find in search were written before that date and still claim high-risk obligations started in August 2026. They did not. This article walks through what is actually in force, with every date checked against EUR-Lex and the AI Act Explorer. One caveat up front: we are an implementation studio, not a law firm — for anything that affects your legal position, verify the interpretation with your lawyer.

EU AI Act deadlines in 2026: what applies now, what was postponed

  • 2 February 2025 — already in force: prohibited AI practices (Article 5) and the AI literacy obligation (Article 4), per Article 113(a)
  • 2 August 2025 — already in force: rules for general-purpose AI (GPAI) model providers, governance, and the penalties chapter (except Article 101), per Article 113(b)
  • 2 August 2026 — in force now: the general application date, including Article 50 transparency (chatbot disclosure, marking of AI-generated content); from this date the AI Office and national authorities are responsible for supervision and enforcement
  • 2 December 2026 — end of the transitional period for machine-readable marking of synthetic content for systems already placed on the market before 2 August 2026; also the stated application date for the two new prohibitions added by the Omnibus (non-consensual intimate imagery and CSAM)
  • 2 December 2027 — postponed: high-risk obligations for AI systems classified under Article 6(2) and Annex III (previously 2 August 2026)
  • 2 August 2028 — postponed: high-risk obligations for AI systems classified under Article 6(1) and Annex I

The postponement wording comes directly from Regulation (EU) 2026/1744 on EUR-Lex: the application date of Chapter III Sections 1, 2 and 3 “is set to 2 December 2027 for AI systems classified as high-risk pursuant to Article 6(2) and Annex III, and to 2 August 2028 for AI systems classified as high-risk pursuant to Article 6(1) and Annex I.” These are fixed dates. The earlier proposal to tie the deadlines to the readiness of technical standards — a conditional trigger — did not make it into the final text.

Deployer or provider: the first question for any small business under the AI Act

Before you read a single obligation, work out which role you play, because the AI Act assigns duties by role, not by company size. Article 3 defines both.

“Provider (Article 3(3)): a natural or legal person, public authority, agency or other body that develops an AI system or a general-purpose AI model or that has an AI system or a general-purpose AI model developed and places it on the market or puts the AI system into service under its own name or trademark, whether for payment or free of charge.”

“Deployer (Article 3(4)): a natural or legal person, public authority, agency or other body using an AI system under its authority except where the AI system is used in the course of a personal non-professional activity.”

Most small companies are deployers: you use ChatGPT, a CRM with AI scoring, a chatbot built on someone else's model, an invoice-processing tool. Deployer obligations are substantially lighter than provider obligations. The line can blur — for example, if you take a model and put a system on the market under your own brand — and in those borderline cases the classification genuinely matters, so have your lawyer confirm which side of the line you are on.

In force since February 2025: prohibited practices and AI literacy

Two things have applied to everyone since 2 February 2025. First, Article 5 bans certain AI practices outright: subliminal or manipulative techniques; exploiting vulnerabilities related to age, disability or social and economic situation; social scoring; predicting criminality based solely on profiling; untargeted scraping of facial images from the internet or CCTV to build recognition databases; emotion recognition in workplaces and education (with narrow medical and safety exceptions); biometric categorisation by protected characteristics; and real-time remote biometric identification in public spaces for law enforcement, with narrow exceptions.

For a typical 5–50 person company, the practical takeaway is short: if any tool you use does emotion recognition on employees or scores people socially, that is not a compliance task — it is a stop-using-it task. Most SMB tooling is nowhere near this list, but you only know that after you have listed what you actually use.

Second, Article 4 requires both providers and deployers to “take measures to support the development of AI literacy” among staff who work with AI systems, taking into account their technical knowledge and the context of use. The regulation does not prescribe a specific training format or certification level. Notably, the Omnibus amendment added a paragraph committing the Commission and member states to support compliance “particularly for SMEs, including publishing practical compliance examples” — worth watching for official templates.

In force since August 2025: GPAI rules — your vendor's homework, your questions to ask

Since 2 August 2025, providers of general-purpose AI models carry their own obligations under Article 53: technical documentation for the AI Office and national authorities (Annex XI); documentation for downstream developers (Annex XII); a policy for complying with EU copyright law, including the text-and-data-mining opt-out under Article 4(3) of Directive 2019/790; and a public summary of training data based on the AI Office template. Free and open-source models with openly available parameters are exempt from the first two duties, unless the model poses systemic risk.

None of this is your obligation as a small deployer — but it is your due-diligence checklist when choosing a vendor. Before signing with an AI tool provider, ask: can you show your Annex XII downstream documentation? Do you publish a training data summary? What is your copyright policy? A vendor who cannot answer in 2026 is a vendor taking risks you will inherit operationally, if not legally.

New since 2 August 2026: Article 50 transparency — the chatbot disclosure requirement

This is the part of the AI Act that touches the largest number of ordinary websites, and it is in force now. Article 50(1) requires providers to ensure that people know they are interacting with an AI system, “unless this is obvious from the point of view of a natural person who is reasonably well-informed.” The information must be given “at the latest at the time of the first interaction or exposure.” The European Commission puts it plainly: when using AI systems such as chatbots, humans should be made aware that they are interacting with a machine.

Article 50(2) covers synthetic content: providers of systems that generate synthetic audio, images, video or text must ensure outputs are “marked in a machine-readable format and detectable as artificially generated or manipulated,” with solutions “effective, interoperable, robust and reliable as far as this is technically feasible.” Assistive editing functions that do not substantially alter the input are excepted. One transitional nuance from the Omnibus: recital 38 of Regulation 2026/1744 grants a four-month transitional period for providers whose systems were already on the market before 2 August 2026 — which runs to 2 December 2026. New systems must comply immediately.

Articles 50(3)–(4) address deployers directly: deepfakes — content that is “artificially generated or manipulated” — must be disclosed, with lighter treatment for artistic and satirical works; AI-generated text published on matters of public interest is exempt from disclosure where a human carries editorial responsibility; and if you use emotion recognition or biometric categorisation, you must inform the people concerned and comply with GDPR.

Practically, for a small business this means three things: your website chatbot needs a clear “you are chatting with an AI assistant” disclosure at first contact; if you publish AI-generated imagery or video of real people, label it; and if you buy a chatbot or content tool, the machine-readable marking is your provider's job — but checking that they do it is yours.

The Digital Omnibus (Regulation 2026/1744): what was postponed — and what the postponement does not mean

The Digital Omnibus on AI — formally, Regulation (EU) 2026/1744 of 8 July 2026, amending Regulations (EU) 2024/1689, (EU) 2018/1139 and (EU) 2023/1230, published in the Official Journal on 24 July 2026 and in force from 27 July 2026 — did two headline things. It moved the high-risk application dates: Annex III systems (the Article 6(2) list — think recruitment screening, credit scoring, essential services) to 2 December 2027, and Annex I systems (Article 6(1), AI embedded in regulated products) to 2 August 2028. And it added two new prohibitions to Article 5(1): generating or manipulating realistic intimate images of an identifiable person without their “freely-given, specific, informed, unambiguous and explicit consent” (point ba), and child sexual abuse material as defined by Directive 2011/93/EU (point bb) — both subject to a transitional period until 2 December 2026.

What the postponement does not mean: it is not a rollback. The prohibitions apply. AI literacy applies. Article 50 transparency applies. From 2 August 2026 the AI Office and member state authorities hold full supervision and enforcement powers — the AI Office can request technical documentation, evaluate models, require corrective measures and issue fines. The deferral buys time only for the high-risk chapters, and the sensible way to use that time is to know, by late 2027, whether anything you run falls under Annex III. If it does, Article 26 already tells you what is coming: competent human oversight, use according to the provider's instructions, relevant input data, incident monitoring and reporting, log retention of at least six months, and informing affected workers.

On penalties, one calm factual note. Article 99 sets maximums: up to €35 million or 7% of worldwide turnover for prohibited practices, up to €15 million or 3% for most other obligations including Article 50, up to €7.5 million or 1% for supplying incorrect information — and the penalties chapter has applied since 2 August 2025. The detail small businesses rarely hear: Article 99(6) caps fines for SMEs and startups at whichever of the two amounts is lower. The point of compliance here is not fear; it is that the transparency duties are cheap to meet and expensive to ignore.

What of this is NOT about you: an honest filter

A regulation this large invites over-compliance, and over-compliance is wasted money. So, honestly:

  • The high-risk chapters (Chapter III Sections 1–3, Article 26 duties) do not apply to anyone yet — Annex III from 2 December 2027, Annex I from 2 August 2028. If a consultant is selling you urgent high-risk conformity work in 2026, ask them to cite the post-Omnibus dates.
  • GPAI provider obligations (Article 53) belong to the companies building foundation models — not to you for merely using their tools.
  • Machine-readable marking of synthetic content under Article 50(2) is a provider obligation. Your job as a deployer is disclosure of deepfakes and AI text in public-interest publishing, per Article 50(3)–(4).
  • If you use no chatbot, generate no synthetic content, and run no AI in decisions about people, your current obligations reduce to two: do not use tools that fall under Article 5 prohibitions, and support AI literacy for staff who work with AI.
  • Nothing in the Act requires you to stop using AI, register your ChatGPT account, or hire a compliance officer. There is no SME exemption from the rules that do apply — but there are SME softenings: the fine cap in Article 99(6) and the Commission's commitment to publish practical compliance examples for SMEs.

A practical checklist: what a small business can do in one week

  • Day 1–2. AI inventory. List every AI tool in use — chatbots, content generators, CRM scoring, transcription, automations — and note which business process each one touches. This is the foundation for everything else.
  • Day 2–3. Assign roles. For each tool, mark whether you are a deployer (using someone else's system) or arguably a provider (offering it under your own brand). Flag borderline cases for a lawyer.
  • Day 3. Screen against Article 5. Check the inventory against the prohibited practices list — emotion recognition on staff, social scoring, biometric categorisation. Anything that matches gets switched off, not documented.
  • Day 3–4. Fix chatbot disclosure. Ensure every chatbot on your site tells users it is an AI at the first interaction, and label published deepfake-style AI content. This is the Article 50 duty that is live right now.
  • Day 4–5. Question your vendors. Send your AI tool providers the Article 53 questions: downstream documentation, training data summary, copyright policy, machine-readable marking of outputs — and note their answers.
  • Day 5. Contract check. Note which vendor contracts say nothing about AI obligations, and put AI clauses on the renewal agenda — with your lawyer, not from a blog template.
  • Day 5–7. AI literacy session. Run a short internal briefing: what tools you use, what they may and may not be used for, what Article 50 disclosure looks like in your channels. Document that it happened.
  • Ongoing. Put two dates in the calendar: 2 December 2026 (marking transition ends; new prohibitions apply) and 2 December 2027 (Annex III high-risk obligations begin) — and revisit the inventory before each.

What this means for your chatbot and automations

If you are building a new chatbot now, build the disclosure in from day one — a first-message identification, a visible AI label, and a log of what the bot says — rather than retrofitting it later. If your AI processes touch sensitive data, this is also a reasonable moment to weigh an on-premise LLM, where the model runs on your infrastructure and data control questions get simpler. And because the rules are still moving — the Omnibus proved that — someone should own the job of keeping your setup current.

This is the kind of work we do at Norvalda: an automation audit at €1,490 covers the AI inventory and role-mapping step in five days; a website chatbot built with the disclosure pattern from the start runs €2,000–5,000 over 14–21 days; broader AI automation projects €3,000–8,000; local-AI setups from a €1,200 audit to €3,900 implementation with €390/month care; and an AI-ops retainer at €1,290/month keeps the moving parts maintained as rules and models change. We are implementers, not lawyers — where the Act needs legal interpretation for your specific case, we will say so and point you to counsel.

FAQ: EU AI Act small business requirements, in short

Does the EU AI Act apply to small businesses?

Yes. There is no SME exemption from the prohibitions (Article 5), AI literacy (Article 4) or transparency (Article 50). There are softenings: Article 99(6) caps SME fines at the lower of the two possible amounts, and the amended Article 4 commits the Commission and member states to support SME compliance, including publishing practical examples.

What is in force since 2 August 2026?

The general application date arrived: Article 50 transparency duties (chatbot disclosure, marking and disclosure of AI-generated content), and full supervision and enforcement powers for the AI Office and national authorities. High-risk obligations did not start on this date — they were postponed.

What exactly was postponed to December 2027?

Obligations for high-risk AI systems under Article 6(2) and Annex III — categories like recruitment and credit decisions — now apply from 2 December 2027. High-risk systems under Article 6(1) and Annex I follow on 2 August 2028. Both dates are fixed in Regulation (EU) 2026/1744, with no conditions attached.

Must a website chatbot say it is an AI?

Yes, since 2 August 2026. Article 50(1) requires that people know they are interacting with an AI system, at the latest at the first interaction, unless it is obvious to a reasonably well-informed person. In practice: a clear disclosure at the start of the conversation.

Does AI-generated content have to be marked, and from when?

Providers of generative systems must mark outputs in a machine-readable format from 2 August 2026; systems already on the market before that date have a transitional period that runs to 2 December 2026 under the Omnibus. Deployers must disclose deepfakes; AI-written text on matters of public interest is exempt where a human holds editorial responsibility.

What is a deployer, and how is it different from a provider?

A provider develops an AI system or model and places it on the market under its own name (Article 3(3)). A deployer uses an AI system under its authority in a professional context (Article 3(4)). Most small businesses are deployers, with substantially lighter duties. Borderline cases — such as white-labelling someone else's system — are worth a lawyer's opinion.

The honest summary: for most small companies, the AI Act in autumn 2026 is a week of tidy-up — an inventory, a chatbot disclosure, a vendor questionnaire, a staff briefing — plus two calendar entries for 2027. If you would rather have a second pair of eyes on the inventory, that is what we are here for. Either way, do the week of tidy-up: it is the cheapest compliance you will ever buy.

Sources

  • Regulation (EU) 2026/1744 (the Digital Omnibus on AI), EUR-Lex: eur-lex.europa.eu/eli/reg/2026/1744/oj/eng
  • AI Act, Article 113 — entry into application: artificialintelligenceact.eu/article/113/
  • AI Act, Article 50 — transparency obligations: artificialintelligenceact.eu/article/50/
  • AI Act, Article 5 — prohibited practices: artificialintelligenceact.eu/article/5/
  • AI Act, Article 4 — AI literacy: artificialintelligenceact.eu/article/4/
  • AI Act, Article 3 — definitions (provider, deployer): artificialintelligenceact.eu/article/3/
  • AI Act, Article 53 — GPAI provider obligations: artificialintelligenceact.eu/article/53/
  • AI Act, Article 26 — deployer obligations for high-risk systems: artificialintelligenceact.eu/article/26/
  • AI Act, Article 99 — penalties: artificialintelligenceact.eu/article/99/
  • European Commission — regulatory framework for AI: digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai
  • Gibson Dunn — analysis of the Omnibus agreement: gibsondunn.com/eu-ai-act-omnibus-agreement-postponed-high-risk-deadlines-and-other-key-changes/