aistack
Book consultation →
← All articles
AI Regulation

The EU AI Act: a complete guide to Europe’s AI rules for companies

Why it passed, what it actually requires, and what it means for your company. A current overview, including the deferral of the high-risk rules that took effect this week.

July 2026·17 min read·Milan Janoštík·
AI ActRegulationGovernance
Editorial infographic: a central four-tier risk pyramid with an amber apex, two blue bands and a green base, and on the left a stream of AI systems flowing through a classification gate.

European AI regulation has stopped being a conference topic and become binding law. The AI Act rolls out in stages from 2025 onward, and this week the rules shifted again: on 27 July 2026 the Digital Omnibus package took effect and pushed several deadlines back. Most of what you will find on the Czech internet today is therefore out of date. Our ambition is to offer the most complete and most practical guide to the AI Act on the Czech market: what you need to know as a company owner and as the person actually rolling AI out, and how to get ready without drowning in legal text.

Why the AI Act was written at all

The European Union chose a different path from the rest of the world. Rather than waiting to see how AI settles, it decided to write the rules up front and make them the same across all 27 states. The first goal is a single market: a company that meets the rules in Czechia meets them in Germany or France too, because one regulation applies, not 27 national laws. The second goal is trust. The rules are meant to give people confidence that AI deciding on their loan, their job or their healthcare was built responsibly and that you can trace who is accountable for the decision.

The AI Act does not build that confidence on what a model can do, but on what it is used for. A system that drafts an email and a system that decides whether you get hired are technically similar. The risk to a person is not. That distinction is the whole logic of the law.

Our ambition
The most complete AI Act guide on the market
This article is the first of three. We want it to be the most detailed yet still readable source on the AI Act for Czech companies: what the law asks, who it applies to, and how to actually become ready. The second part walks through implementation step by step; the third gives you a finished checklist and answers to the most common questions.

What the AI Act is: one regulation, four risk tiers

Formally it is Regulation (EU) 2024/1689. The word regulation matters: unlike a directive, it applies directly, without each state translating it into its own law. In Czechia the AI Act has therefore been in force in its own right since 1 August 2024; a national law only adds who supervises it and how fines are imposed. The whole structure rests on four tiers of risk.

Risk tierExamplesWhat it means
UnacceptableSocial scoring of citizens, manipulative techniques, emotion recognition at work and schoolBanned. You may not run such a system at all.
HighAI in hiring, credit scoring, insurance risk, critical infrastructureAllowed, but with the strictest duties (oversight, documentation, data quality).
LimitedChatbots, text and image generators, deepfakesA transparency duty: people must know they are dealing with AI or that AI made the content.
MinimalSpam filters, product recommendations, most everyday toolsNo special duties. The vast majority of business use sits here.

The pyramid has a wide base and a narrow top on purpose. The overwhelming majority of what companies do with AI sits at the bottom, in minimal risk. At the top, where the bans and the toughest rules live, is only a small slice of use. The first and most important task for any company is therefore to work out where in this pyramid each of its AI tools belongs.

Flow: incoming AI systems enter the classification gate and sort into the four risk tiers

The banned practices that already apply

At the top of the pyramid are practices Europe considers incompatible with fundamental rights. They have been banned since 2 February 2025, as the very first part of the law to take effect. This is not a future scenario; these rules apply today.

  • Social scoring, meaning rating people by behaviour and granting benefits or penalties across unrelated areas of life.
  • Systems that deliberately manipulate a person below the level of their awareness, or exploit a vulnerability such as age or health.
  • Emotion recognition in the workplace and in schools, save for narrow medical or safety exceptions.
  • Untargeted scraping of faces from the internet or cameras to build facial-recognition databases.

The Digital Omnibus, in force since 27 July 2026, added to this list. It newly bans tools that create intimate images of a person without their consent, and material that abuses children. Companies have until 2 December 2026 to bring their systems in line with this new prohibition.

High risk: where the rules really bite

High-risk systems are the core of the whole law. They are not banned, but they carry the most duties, because they decide things that change people’s lives. The law lists them in its Annex III, across eight areas.

  • Biometrics: recognising and categorising people by their face or other bodily features.
  • Critical infrastructure: managing the supply of energy, water or transport.
  • Education: admissions, grading students, monitoring exams.
  • Employment: selecting candidates, screening CVs, evaluating and allocating work to people.
  • Access to services: assessing creditworthiness for a loan, setting insurance risk, entitlement to benefits.
  • Law enforcement: risk assessment and AI used by police and the courts.
  • Migration and borders: assessing applications and managing border checks.
  • The administration of justice and democratic processes, such as vote counting.
An important exception
Not every Annex III system is automatically high-risk
If a system in one of those areas performs only a narrow supporting task and has no material effect on the decision about a person, it need not be high-risk. One line always holds, though: the moment a system profiles specific individuals, it counts as high-risk without exception.

The timeline: what applies when, and what just moved

The AI Act never switched on all at once. It rolls out in waves, and this is the most common source of confusion, because the dates changed in 2026. The original plan said the main wave of high-risk duties would begin on 2 August 2026. The Digital Omnibus package, adopted as Regulation (EU) 2026/1744 and in force since 27 July 2026, pushed that date back, just days before it was due to apply.

Feb 2025: bans + AI literacyAug 2025: GPAI + governance + finesAug 2026: transparency (Art. 50)Dec 2027: high-risk (Annex III)Aug 2028: high-risk inside products
What the Digital Omnibus changed (27 Jul 2026)
High-risk got more time, the rest did not
Duties for standalone high-risk systems under Annex III moved from August 2026 to 2 December 2027. Systems embedded in regulated products have until 2 August 2028. What did not move: the bans, AI literacy, the rules for large models, the fines, or transparency. The deferral is room to prepare, not a reason to do nothing.

Transparency: the rule that reaches almost everyone

While high risk touches a minority of companies, the transparency duty under Article 50 reaches almost anyone deploying AI toward customers today. It applies from 2 August 2026 and says three simple things. When a person chats with a bot, they must know it is a machine and not a live agent. When a company publishes text, an image or a video made by AI, it must be recognisable and machine-marked. And if you deploy a system that recognises emotions or sorts people by biometrics, you must inform the people affected.

There is a small grace period for marking AI-generated content: systems already on the market before August 2026 have until 2 December 2026 to add machine-readable marking. New systems must mark from day one.

AI literacy: the duty people forget

Article 4 sets a duty most companies overlook, even though it has applied since February 2025. Anyone deploying or supplying AI must ensure that the people working with it have sufficient AI literacy: that they understand what the tool does, where its limits are, and when not to take its output as settled fact. This is not a certificate or a template course. It is demonstrable care that your people use AI with judgement.

Provider or deployer: which side you are on

The AI Act distinguishes roles, and this single question matters most. A provider is whoever develops an AI system and places it on the market under their own name. A deployer is whoever uses a finished system in their company. The vast majority of Czech companies are deployers: they take a finished tool and run it on their data. And a deployer’s duties are markedly lighter than a provider’s.

Provider (of the system)
  • Risk and quality management across the system’s whole life
  • Technical documentation and operating records
  • Conformity assessment, CE marking, entry in the EU database
  • Responsibility for robustness, accuracy and cybersecurity
User, operator (deployer)
  • Use the system according to the provider’s instructions
  • Ensure human oversight and monitor operation
  • Keep logs and inform the people affected
  • In some cases, assess the impact on fundamental rights

There is one catch. If you re-label a finished system with your own name, change it substantially, or deploy it for a high-risk purpose it was not meant for, Article 25 can turn you into a provider, with all of a provider’s duties. The line between the roles is therefore not only about who wrote the software, but about how you handle it.

Large models and tools like Claude: who carries what

General-purpose AI (GPAI), the large language models today’s assistants are built on, is a chapter of its own. Their makers have their own duties: to supply technical documentation, to respect copyright, and to publish a summary of the data the model was trained on. The most capable models above a compute threshold (10^25 operations in training) carry extra duties around systemic risk.

For an ordinary company there is good news worth stating plainly. When you use an assistant built on a large model over your own company data, you are a deployer, not the model’s maker. The GPAI provider’s duties rest with whoever built the model, not with you. Your concern is different: how you deploy the model, what data you let it reach, and how you keep a person in charge of it.

Penalties: why this is not just paperwork

The law has teeth, and the penalties are graded by severity. They have applied since August 2025.

EUR 35M / 7%
for banned practices, the higher of the two amounts
EUR 15M / 3%
for breaching most other duties, including high risk
EUR 7.5M / 1%
for false or misleading information to authorities

The percentages are of worldwide annual turnover, and for large companies the higher of the two amounts applies. For small and medium businesses and startups the law takes the lower of the two, so that a fine does not wipe out smaller players. Enforcement for banned practices and large models is already running; supervision of high risk starts with its deferred dates.

What this means for an ordinary Czech company

Put together, the sober conclusion for a typical Czech company is this. Most of what you do with AI falls into minimal risk and carries no special duties. Two things reach almost everyone, though: transparency toward customers and AI literacy for your people. And if you use AI in hiring, in assessing creditworthiness or in insurance, you move into high risk, where duties pile up, even with the deadline now pushed to the end of 2027.

The Czech specifics
The national law is still only a draft
The AI Act applies directly in Czechia, but the accompanying AI law from the Ministry of Industry and Trade is, as of 28 July 2026, still in parliament awaiting its third reading, not yet passed. The draft names the Czech Telecommunication Office as the main supervisor, the Czech National Bank for finance, and the data-protection office for biometrics and personal data. It sets no fine levels of its own, follows the regulation, and is deliberately minimalist.

How to be AI Act ready, and where we come in

Readiness for the AI Act is not about one tool you buy and are done. It is about how your AI is built. Whose infrastructure it runs on. Who sees which data. Whether every action leaves a traceable record. Whether a person keeps the final word on sensitive decisions. These are exactly the foundations we build, because underneath the paperwork the AI Act is really talking about technical architecture.

  • Running on your own cloud infrastructure means control over your data and certainty that nothing is stored in someone else’s cache.
  • Access through an MCP server that carries a specific user’s identity gives you permission control and a record of every query.
  • A person in the loop on final decisions satisfies the human-oversight requirement.
  • One governed space with one audit trail gives the traceability and accountability the law asks for.

Let us say it straight: no tool by itself makes you compliant with the AI Act, because compliance is largely a matter of process and people. But infrastructure built the right way removes most of the friction: the audit trail appears on its own, permissions stay under control, data stays with you. In the next two parts of the series we show how to do this step by step, and give you a finished readiness checklist.

Where we fit
The foundations of readiness, plus help mapping the gaps
We build AI infrastructure on your cloud, with user identity, human oversight and one audit trail, the technical groundwork readiness stands on. And we can map with you where on the road to AI Act ready you currently are. No spin, no scaremongering about fines.

The AI Act does not stop you from using AI smartly. It asks that smart use be traceable and accountable, things a well-run company would want anyway. If you would like to see what this would look like in your case, write to us. A short call is enough for us to say what makes sense and what does not.