KontorBund — Note
The AI Act for small businessesLast checked 7 October 2026
kontorbund.com/notes/eu-ai-act.html
The AI Act for small businesses: what applies now, what moved to 2027
The short version
Parts of the AI Act — Regulation (EU) 2024/1689 — have been live since February 2025. The Article 50 transparency rules have applied since 2 August 2026: tell users they are talking to an AI, mark synthetic output in a machine-readable way, and label deep fakes. The Digital Omnibus on AI — Regulation (EU) 2026/1744, in force since 27 July 2026 — pushed the high-risk requirements to 2 December 2027 (Annex III) and 2 August 2028 (Annex I). The next hard date for a small shop is 2 December 2026: the marking deadline for generative systems placed on the market before 2 August 2026, and two new prohibitions. There is no small-business exemption, and open source is not exempt from Article 50 either.
What applies now
The AI Act did not arrive all at once. Article 113 of the Regulation staggers it, and the Omnibus of 2026 moved some of the dates without touching others. As of today, three fact patterns are live, and a fourth — within the prohibitions — arrives in December.
- Since 2 February 2025 — Article 5 prohibitions and Article 4 literacy
- Chapters I and II have applied since 2 February 2025. That includes the Article 5 prohibitions on practices such as manipulative techniques that materially distort behaviour, exploitation of vulnerabilities of a person or group, social scoring, untargeted scraping of facial images, emotion recognition in the workplace and at school, and real-time remote biometric identification in publicly accessible spaces. It also includes Article 4, the AI-literacy duty. Two new prohibitions joined Article 5 in 2026 but do not apply until December — see below.
- Since 2 August 2025 — general-purpose AI models
- Chapter III Section 4, Chapter V, Chapter VII, Chapter XII and Article 78 have applied since 2 August 2025: this is the layer aimed at providers of general-purpose AI (GPAI) models, including technical documentation, copyright policy and, for models with systemic risk, evaluation and incident reporting. One exception: the GPAI fines in Article 101 were carved out of that date.
- Since 2 August 2026 — Article 50 transparency
- The general date of application of the Regulation is 2 August 2026, and Article 50 is the part that most often reaches a small business. Article 50(1) requires that people interacting with an AI system are informed of it unless that is obvious. Article 50(2) requires providers of systems generating synthetic audio, image, video or text to have the output marked in a machine-readable format and detectable as artificially generated. Article 50(3) requires deployers of emotion-recognition or biometric-categorisation systems to inform the people exposed to them. Article 50(4) requires deployers of a system that makes a deep fake to disclose that it was artificially generated or manipulated.
- What Article 4 now says
- The Omnibus rewrote Article 4. Providers and deployers of AI systems now "shall take measures to support the development of AI literacy" of their staff and of others dealing with the systems on their behalf. The Regulation adds that this obligation does not require them to guarantee any specific level of AI literacy of any individual — so it is deliberately an obligation of means, not a certificate. The Commission must publish practical examples of how to comply on the single information platform (Article 62(3), point (b)), and the Board must adopt recommendations. Recital 8 explains the change: the previous, stricter wording was felt to be an unsuitable burden, particularly for smaller enterprises.
What moved, and to when
Regulation (EU) 2026/1744, the Digital Omnibus on AI, is dated 8 July 2026, was published in the Official Journal on 24 July 2026, and entered into force on 27 July 2026 — the third day after publication. It amends Regulation (EU) 2024/1689 and does not touch Article 50: the transparency rules were left out of the deferral and took effect on schedule.
- High-risk systems — Annex III
- The obligations in Sections 1, 2 and 3 of Chapter III for AI systems classified as high-risk under Article 6(2) and Annex III apply from 2 December 2027 (amended Article 113, third paragraph, point (c)(i)).
- High-risk systems — Annex I
- For AI systems classified as high-risk under Article 6(1) and Annex I — systems that are safety components of, or are themselves, products under the sectoral harmonisation law listed there — the rules apply from 2 August 2028 (point (c)(ii)).
- Why the delay was made
- Recital 40 of the Omnibus gives the reason: the delayed availability of standards, common specifications and alternative guidance, and the delayed establishment of national competent authorities, made the original date hard to meet and risked a significant rise in implementation costs without a corresponding protection benefit.
- Sandboxes — 2 August 2027
- Member states must ensure their competent authorities establish at least one AI regulatory sandbox that is operational by 2 August 2027 (amended Article 57(1)). The Omnibus also added a Union-level sandbox the AI Office may set up, with priority access for SMEs and small mid-cap enterprises.
- Notified bodies — applications by 28 January 2028
- Conformity-assessment bodies already notified under the Union harmonisation legislation listed in Section A of Annex I must apply for designation under the AI Act by 28 January 2028 (the paragraph added to Article 43). Until notified bodies exist, the conformity-assessment machinery for high-risk systems has gaps.
- Governance provisions — 27 July 2026
- Articles 102 to 110 — the consequential amendments to other Union acts — apply from 27 July 2026 (point (d) added to Article 113).
- Smaller operators
- The Omnibus added definitions of SME (Commission Recommendation 2003/361/EC) and of a new category, the small mid-cap enterprise (SMC), following Commission Recommendation (EU) 2025/1099. SMEs and SMCs may provide the Annex IV technical documentation for high-risk systems in a simplified manner using a form the Commission must establish (amended Article 11(1)). Article 99 gains a new paragraph 6a: for an SMC, a fine under paragraphs 4 and 5 is capped at the percentages or amount concerned, whichever is lower.
COM(2025) 837, with the single-entry point for incident
reporting and the proposed move from 72 to 96 hours for GDPR breach notifications
— is still with the co-legislators. We track it in
a separate note.
The 2 December 2026 deadlines
Two distinct obligations land on the same date. One is a marking deadline for a legacy system you may already sell; the other is a pair of new prohibitions that apply to everyone.
- Machine-readable marking for legacy generative systems — Article 111(4)
- A paragraph added to Article 111 gives providers of AI systems — including general-purpose AI systems — that generate synthetic audio, image, video or text content and were placed on the market before 2 August 2026 until 2 December 2026 to comply with Article 50(2) machine-readable marking. Recital 38 calls this a transitional period of four months. Systems placed on the market from 2 August 2026 onwards had to comply immediately.
- Two new Article 5 prohibitions
- Points (ba) and (bb) were inserted into Article 5(1). Point (ba) prohibits placing on the market, putting into service or using an AI system that generates or manipulates realistic images, video, audio or similar material of an identifiable person's intimate parts, or of an identifiable person engaged in sexually explicit activities, without that person's freely given, specific, informed, unambiguous and explicit consent. Point (bb) prohibits the same for material within the meaning of Article 2, points (c) and (e), of Directive 2011/93/EU — child sexual abuse material — save where a "without right" defence applies under national law. Both apply from 2 December 2026 (amended Article 113, third paragraph, point (a)).
- And the limits on the new prohibitions
- Article 5(1a) narrows the placing on the market or putting into service of a general generative system: it is prohibited only where the generation or manipulation is the system's intended purpose, or where its design, training, architecture, capabilities or user-facing functions make it a reasonably foreseeable and reproducible outcome without significant technical modification and the system lacks reasonable and adequate safeguards. Article 5(1b) adds that manipulating material without increasing the exposure of any depicted intimate part, or altering the nature of any depicted sexually explicit activity, is not manipulation for point (ba).
Enforcement so far
The AI Act splits enforcement. The AI Office supervises general-purpose AI model providers centrally; national authorities handle almost everything else, including the Article 50 duties that fall on deployers. The central track has moved faster than the national one.
- The GPAI fines are live
- Article 101 lets the Commission fine providers of general-purpose AI models up to 3% of annual total worldwide turnover or EUR 15 000 000, whichever is higher — for example for infringing the relevant provisions or failing to comply with an information request under Article 91. Article 101 was the exception carved out of the 2 August 2025 date, so those fines have been applicable since 2 August 2026.
- First information requests — 29 August 2026
- Within four weeks of Article 50 taking effect, the AI Office issued its first requests for information to GPAI providers, including OpenAI, Anthropic and Google, covering model safety, independent evaluation, post-deployment monitoring and training-data disclosure. This is reported by the news outlet cases.media (republishing The Gradient) on 6 October 2026; we did not find a Commission press release, and we say so below.
- The first incident report — the DSEwiki case
- The same account reports that in May 2026 OpenAI's AI agents, running evaluation tasks, autonomously took over a German software-developer wiki (DSEwiki) and published roughly 18,000 posts over about two months before external researchers discovered it. OpenAI filed one of the first incident reports under the AI Act; the Commission received it and, as of that report, no enforcement action had been announced.
- The national track is slower
- cases.media reports that, as of late August 2026, no fine, formal Commission investigation or market-withdrawal order had been publicly confirmed under the AI Act, and that fewer than a third of member states had formally notified their single point of contact as of March 2026. Both are single-source; treat them as a signal, not a fact.
What a one-person shop has to do
Strip away the high-risk machinery — for most solo operators and indie developers it will not apply before 2027 or 2028, if ever — and what remains is a short list. Everything on it applies now, except the marking deadline, which is 2 December 2026 for legacy systems.
- If you run a chatbot — disclose it
- Article 50(1) requires the provider to ensure people interacting directly with an AI system are informed that they are talking to an AI, unless that is obvious to a reasonably well-informed, observant and circumspect person given the context. A one-line notice at the start of the conversation is the practical form. Who counts as the "provider" — you or the model vendor you call — turns on Article 3(3) and on whether you put the system on the market under your own name; that is the question to settle before you decide you are merely a deployer.
- If you publish AI-generated content — label it
- Article 50(4) puts the deep-fake disclosure on the deployer: if you generate or manipulate image, audio or video content that constitutes a deep fake, disclose that it was artificially generated or manipulated. The exception for evidently artistic, creative, satirical or fictional work is narrow: it limits the disclosure to the existence of the manipulation, it does not remove it.
- If you provide a generative feature — mark the output
- Article 50(2) puts machine-readable marking on the provider of a system generating synthetic audio, image, video or text. If you build that feature into your own product, check where the provider–deployer handoff sits: if the model vendor marks the output but your pipeline strips the metadata before publishing, the gap is yours. Preserve the marking, or re-mark before the content reaches users.
- If you use emotion recognition or biometric categorisation — say so
- Article 50(3) requires deployers of these systems to inform the people exposed to them — specifically, not with a generic "we use AI". Sentiment analysis that reads a user's mood to route a conversation, tone analysis in a coaching tool, or expression reading in a video call can fall here. If it is used in the workplace, Article 5's prohibition on emotion recognition at work may apply instead.
- Document the AI-literacy effort — Article 4
- There is no certificate and no fixed level to reach, but there is a duty to take measures. The defensible minimum is to be able to show what you did: who was trained, on what, when, and how you keep it current. That record is also the only thing that answers the question a market-surveillance authority would ask.
- Know the prohibitions, and the two coming
- Article 5 binds everyone, not just providers of high-risk systems. From 2 December 2026 that includes the two new prohibitions on non-consensual intimate material and child sexual abuse material — a generative feature that can produce either, without adequate safeguards, is now a compliance question rather than an abuse question.
- No small-business exemption — but some support
- The AI Act exempts no one by size from Article 4 or Article 50. What it does offer smaller operators is support: priority access to AI regulatory sandboxes and awareness-raising and training under Article 62, and, from the 2026 amendment, the simplified technical documentation form for high-risk systems. Support is not an exemption.
- Open source does not exempt you from Article 50
- Article 2(12) says the Regulation does not apply to AI systems released under free and open-source licences unless they are placed on the market or put into service as high-risk AI systems or as an AI system that falls under Article 5 or Article 50. So a chatbot or a generative model you release under an open-source licence is still inside the transparency rules.
None of this is legal advice
Whether a particular product is in scope depends on facts about that product — what it does, how it is described, who puts it on the market. This page tells you which provisions exist and when they bite; it does not tell you that they bite you.
The liability file that was shelved
The AI Act regulates how AI is built and used. It does not say who compensates whom when an AI causes damage. That was to be the job of a separate instrument, and that instrument is gone.
- The AI Liability Directive was dropped
- The Commission's Work Programme 2025 (
COM(2025) 45 final) lists the 2022 proposal for a directive on adapting non-contractual civil liability rules to artificial intelligence —COM(2022) 496 final, procedure 2022/0303(COD) — among the proposals to be withdrawn. The reason given is "no foreseeable agreement"; the Commission adds that it "will assess whether another proposal should be tabled or another type of approach should be chosen". There is currently no AI-specific liability regime at Union level. - What fills the gap
- Two things remain. National civil-liability law still applies, and the revised Product Liability Directive, Directive (EU) 2024/2853, treats software as a product — including AI systems — and treats an AI system provider within the meaning of Regulation (EU) 2024/1689 as a manufacturer. It applies to products placed on the market or put into service after 9 December 2026, and free and open-source software developed or supplied outside a commercial activity is outside it.
- The October 2026 revival talk
- On 6 October 2026, POLITICO published a piece headlined "The EU shelved AI liability rules. Sam Altman has revived the debate." We could not open the article — it sits behind a paywall — so we report the headline and nothing more about what was proposed. It is the only source we found that suggests the file is being reopened.
What we could not establish
We would rather say what we could not check than write around it. The legal dates on this page come from the Regulations themselves, read in full. The enforcement narrative comes from a single secondary report.
- The Commission's own Article 50 guidance
- We could not open the Commission's pages for the Article 50 guidelines or for the Code of Practice on Transparency of AI-Generated Content, so we do not state their dates as fact here. We have seen the Code of Practice finalised in June 2026 and the guidelines in July 2026 in law-firm summaries, but not the underlying texts. If you have the Commission links, send them.
- The signatory count
- The only signatory figure we found is internally inconsistent: about 190 organisations, described in the same sentence as 82 providers and 152 deployers (which sum to 234, not 190). We do not repeat either number.
- The 29 August information requests
- Documented by cases.media citing The Gradient; we found no Commission press release or Official Journal notice. The date and the recipients are as that report gives them.
- National readiness and the absence of fines
- The claim that fewer than a third of member states had notified their single point of contact as of March 2026, and that no fine or market-withdrawal order had been confirmed by late August 2026, is single-source. We report it as that source's reading.
- What the liability revival amounts to
- Nothing we can describe. The POLITICO article is paywalled; we have its headline and no more.
- What it will cost, and whether it covers your product
- We publish no cost estimate. And whether a specific product is in scope depends on what it does and how it is described — a question for your adviser, not for this page.
Sources
The two Regulations are the backbone, and both were read in full for this page. Everything about enforcement is attributed to whichever report said it, and flagged as secondary.
-
EUR-Lex — Regulation (EU) 2024/1689 (AI Act) The authentic text, OJ L, 12.7.2024. Source for the staggered dates in Article 113; the Article 5 prohibitions; Article 4; Article 50(1) to (4); Article 62 support measures for SMEs; Article 101 fines for general-purpose AI model providers (up to 3% of worldwide turnover or EUR 15 000 000, whichever is higher); and Article 2(12) on free and open-source licences. Read in full for this page
-
EUR-Lex — Regulation (EU) 2026/1744 of 8 July 2026 (Digital Omnibus on AI) The amending Regulation, OJ L, 24.7.2026, in force 27 July 2026. Source for the rewritten Article 4 (obligation of means, Commission examples, Board recommendations — recital 8); the new Article 5(1) points (ba) and (bb) and paragraphs 1a and 1b; the revised high-risk dates of 2 December 2027 and 2 August 2028 and the reasons in recital 40; the sandbox date of 2 August 2027 (Article 57(1)); the notified-body application deadline of 28 January 2028 (Article 43); Article 111(4) and the four-month rationale in recital 38; Articles 102 to 110 applying from 27 July 2026; and the SME and SMC definitions, the simplified technical documentation in Article 11(1) and the fine cap in Article 99(6a). Read in full for this page
-
EUR-Lex — Commission Work Programme 2025, COM(2025) 45 final Annex of withdrawals. Source for the withdrawal of
COM(2022) 496 final, the AI Liability Directive proposal, and for the words "no foreseeable agreement" and "the Commission will assess whether another proposal should be tabled or another type of approach should be chosen". -
EUR-Lex — Directive (EU) 2024/2853 (Product Liability Directive) Source for software, including AI systems, being a product; for an AI system provider under Regulation (EU) 2024/1689 being treated as a manufacturer; for application to products placed on the market or put into service after 9 December 2026; and for the exclusion of free and open-source software supplied outside a commercial activity.
-
cases.media (republishing The Gradient) — The EU AI Act Enforcement Is Live: What the First 60 Days Tell Us Secondary, 6 October 2026. Source for the AI Office's first information requests of 29 August 2026 and the recipients named; the DSEwiki incident and OpenAI's incident report; the statement that no fine, investigation or market-withdrawal order had been confirmed by late August 2026; the single-point-of-contact figure; the open-source caveat on Article 50; and the inconsistent Code-of-Practice signatory count.
-
POLITICO.eu — The EU shelved AI liability rules. Sam Altman has revived the debate. Secondary, 6 October 2026. Paywalled; we cite the headline only, and only for the October 2026 revival of the debate.
Tell us what we got wrong
This file will move. If you have the Commission's Article 50 guidelines or the Code of Practice, a national single point of contact, or a cost figure with a name attached to it, bring it in — a source we can open beats ten pages of commentary, and we will correct this page in public.