The third part of the series is the shortest and most practical. It is not for reading front to back, but for going through and ticking off. First test quickly where your company stands with the AI Act, then find answers to the questions companies most often ask us about the regulation. The detailed explanation of each point is in the first two parts.
Quick test: does the AI Act apply to you?
The answer is almost always yes. The AI Act does not only concern companies that build AI. It concerns anyone who uses AI in their company, which means you too, if you have a chatbot, generate content, screen CVs, or let an assistant work over company data. So the question is not whether, but which of your systems fall where, and what you therefore have to do.
The readiness checklist
Go through the points below. The more of them you can tick with a clear conscience, the better placed you are. The points you cannot tick are your to-do list.
| Area | You are ready when you can say yes |
|---|---|
| Inventory | We have a list of every place AI runs in the company, including tools people switched on themselves |
| Risk classification | For each system we know whether it is minimal, limited or high risk |
| Your role | We know where we are only a user (deployer) and where we could become a provider |
| Transparency | Where AI talks to people or creates content, it is clearly marked |
| AI literacy | The people working with AI know what it can do, where the limits are, and when to verify output |
| Human oversight | On sensitive decisions AI prepares the material, but a person approves it |
| Audit trail | We can trace who asked what, with which data, and what the system answered |
| Your data | We know where our data sits while working with AI, and who can access it |
| Owner | A specific person in the company is accountable for AI and its compliance |
Frequently asked questions
Does the AI Act apply to a small company?
Yes. The AI Act does not distinguish by company size, but by what the AI is used for. A small company with a chatbot has the transparency duty just like a large one. The law does take smaller players into account on fines, though: for small and medium businesses and startups it takes the lower of the two possible amounts, not the higher.
Is anything in force already, or do we have time?
Part of the law applies today. The bans on the riskiest practices and the AI literacy duty have applied since February 2025. The rules for large models, the governance structure and the fines since August 2025. The transparency duty from August 2026. Only high risk is deferred. Anyone waiting for one big deadline has missed that most duties are already running.
We heard the deadlines moved. What does that mean?
In July 2026 the Digital Omnibus package took effect and deferred the duties for high-risk systems. Standalone Annex III systems have until 2 December 2027, and systems embedded in products until 2 August 2028. The other deadlines stayed. The deferral is room to prepare, not a signal to do nothing, because preparing for high risk takes months.
We use Claude over our data. Does that make us compliant?
No, and anyone claiming otherwise is not telling the truth. No single tool makes your company compliant with the AI Act, because compliance is largely about process and people: about classifying systems by risk, about training, about who owns what. What infrastructure built the right way does do is remove most of the technical friction. The audit trail appears on its own, permissions stay under your control, and data stays with you.
Are we a provider or a deployer?
Almost certainly a deployer, meaning a user. A provider is whoever develops an AI system and places it on the market under their own name. If you take finished tools and use them, you are a deployer and your duties are lighter. Watch out, though: if you re-label someone else’s system with your name, change it substantially, or deploy it for a high-risk purpose, you can become a provider with all of a provider’s duties.
What does high risk actually mean?
High risk means specific uses named in the law, where AI decides things that change people’s lives: hiring and evaluating employees, assessing creditworthiness for a loan, insurance risk, access to essential services, biometrics, critical infrastructure. One line always holds: the moment a system profiles specific individuals, it is high-risk without exception. Ordinary internal tools with no effect on people’s rights do not belong here.
Are we at risk of a fine?
Fines exist and they are high: up to 35 million euro or 7 percent of worldwide turnover for banned practices, less for other breaches. But they are not there to frighten. Supervision aims at real wrongdoing, not at a company that honestly labels AI content and keeps human oversight. The best defence against a fine is demonstrable readiness, not perfection.
Who supervises this in Czechia?
As of 28 July 2026 it is not yet settled. The AI Act applies directly in Czechia, but the accompanying law naming the supervisory authorities is still in parliament awaiting its third reading. The draft names the Czech Telecommunication Office as the main supervisor, the Czech National Bank for the financial sector, and the data-protection office for biometrics. Until the law passes, treat these roles as proposed, not confirmed.
Where should we start?
With the inventory and risk classification. There is no point dealing with oversight or documentation for a system you do not yet know someone in the company is using. Make the list, classify each system by risk, and focus on the handful that fall into transparency or high risk. The whole step-by-step process is in the second part of the series.
This part closes the series. The first part explains the whole AI Act, the second walks through implementation step by step, this one gives the quick test and the answers. If you want to see what readiness would look like specifically in your case, get in touch. We start from where you stand today.
