European AI regulation has stopped being a conference topic and become binding law. The AI Act rolls out in stages from 2025 onward, and this week the rules shifted again: on 27 July 2026 the Digital Omnibus package took effect and pushed several deadlines back. Most of what you will find on the Czech internet today is therefore out of date. Our ambition is to offer the most complete and most practical guide to the AI Act on the Czech market: what you need to know as a company owner and as the person actually rolling AI out, and how to get ready without drowning in legal text.
Why the AI Act was written at all
The European Union chose a different path from the rest of the world. Rather than waiting to see how AI settles, it decided to write the rules up front and make them the same across all 27 states. The first goal is a single market: a company that meets the rules in Czechia meets them in Germany or France too, because one regulation applies, not 27 national laws. The second goal is trust. The rules are meant to give people confidence that AI deciding on their loan, their job or their healthcare was built responsibly and that you can trace who is accountable for the decision.
The AI Act does not build that confidence on what a model can do, but on what it is used for. A system that drafts an email and a system that decides whether you get hired are technically similar. The risk to a person is not. That distinction is the whole logic of the law.
What the AI Act is: one regulation, four risk tiers
Formally it is Regulation (EU) 2024/1689. The word regulation matters: unlike a directive, it applies directly, without each state translating it into its own law. In Czechia the AI Act has therefore been in force in its own right since 1 August 2024; a national law only adds who supervises it and how fines are imposed. The whole structure rests on four tiers of risk.
| Risk tier | Examples | What it means |
|---|---|---|
| Unacceptable | Social scoring of citizens, manipulative techniques, emotion recognition at work and school | Banned. You may not run such a system at all. |
| High | AI in hiring, credit scoring, insurance risk, critical infrastructure | Allowed, but with the strictest duties (oversight, documentation, data quality). |
| Limited | Chatbots, text and image generators, deepfakes | A transparency duty: people must know they are dealing with AI or that AI made the content. |
| Minimal | Spam filters, product recommendations, most everyday tools | No special duties. The vast majority of business use sits here. |
The pyramid has a wide base and a narrow top on purpose. The overwhelming majority of what companies do with AI sits at the bottom, in minimal risk. At the top, where the bans and the toughest rules live, is only a small slice of use. The first and most important task for any company is therefore to work out where in this pyramid each of its AI tools belongs.
The banned practices that already apply
At the top of the pyramid are practices Europe considers incompatible with fundamental rights. They have been banned since 2 February 2025, as the very first part of the law to take effect. This is not a future scenario; these rules apply today.
- Social scoring, meaning rating people by behaviour and granting benefits or penalties across unrelated areas of life.
- Systems that deliberately manipulate a person below the level of their awareness, or exploit a vulnerability such as age or health.
- Emotion recognition in the workplace and in schools, save for narrow medical or safety exceptions.
- Untargeted scraping of faces from the internet or cameras to build facial-recognition databases.
The Digital Omnibus, in force since 27 July 2026, added to this list. It newly bans tools that create intimate images of a person without their consent, and material that abuses children. Companies have until 2 December 2026 to bring their systems in line with this new prohibition.
High risk: where the rules really bite
High-risk systems are the core of the whole law. They are not banned, but they carry the most duties, because they decide things that change people’s lives. The law lists them in its Annex III, across eight areas.
- Biometrics: recognising and categorising people by their face or other bodily features.
- Critical infrastructure: managing the supply of energy, water or transport.
- Education: admissions, grading students, monitoring exams.
- Employment: selecting candidates, screening CVs, evaluating and allocating work to people.
- Access to services: assessing creditworthiness for a loan, setting insurance risk, entitlement to benefits.
- Law enforcement: risk assessment and AI used by police and the courts.
- Migration and borders: assessing applications and managing border checks.
- The administration of justice and democratic processes, such as vote counting.
The timeline: what applies when, and what just moved
The AI Act never switched on all at once. It rolls out in waves, and this is the most common source of confusion, because the dates changed in 2026. The original plan said the main wave of high-risk duties would begin on 2 August 2026. The Digital Omnibus package, adopted as Regulation (EU) 2026/1744 and in force since 27 July 2026, pushed that date back, just days before it was due to apply.
Transparency: the rule that reaches almost everyone
While high risk touches a minority of companies, the transparency duty under Article 50 reaches almost anyone deploying AI toward customers today. It applies from 2 August 2026 and says three simple things. When a person chats with a bot, they must know it is a machine and not a live agent. When a company publishes text, an image or a video made by AI, it must be recognisable and machine-marked. And if you deploy a system that recognises emotions or sorts people by biometrics, you must inform the people affected.
There is a small grace period for marking AI-generated content: systems already on the market before August 2026 have until 2 December 2026 to add machine-readable marking. New systems must mark from day one.
AI literacy: the duty people forget
Article 4 sets a duty most companies overlook, even though it has applied since February 2025. Anyone deploying or supplying AI must ensure that the people working with it have sufficient AI literacy: that they understand what the tool does, where its limits are, and when not to take its output as settled fact. This is not a certificate or a template course. It is demonstrable care that your people use AI with judgement.
Provider or deployer: which side you are on
The AI Act distinguishes roles, and this single question matters most. A provider is whoever develops an AI system and places it on the market under their own name. A deployer is whoever uses a finished system in their company. The vast majority of Czech companies are deployers: they take a finished tool and run it on their data. And a deployer’s duties are markedly lighter than a provider’s.
- Risk and quality management across the system’s whole life
- Technical documentation and operating records
- Conformity assessment, CE marking, entry in the EU database
- Responsibility for robustness, accuracy and cybersecurity
- Use the system according to the provider’s instructions
- Ensure human oversight and monitor operation
- Keep logs and inform the people affected
- In some cases, assess the impact on fundamental rights
There is one catch. If you re-label a finished system with your own name, change it substantially, or deploy it for a high-risk purpose it was not meant for, Article 25 can turn you into a provider, with all of a provider’s duties. The line between the roles is therefore not only about who wrote the software, but about how you handle it.
Large models and tools like Claude: who carries what
General-purpose AI (GPAI), the large language models today’s assistants are built on, is a chapter of its own. Their makers have their own duties: to supply technical documentation, to respect copyright, and to publish a summary of the data the model was trained on. The most capable models above a compute threshold (10^25 operations in training) carry extra duties around systemic risk.
For an ordinary company there is good news worth stating plainly. When you use an assistant built on a large model over your own company data, you are a deployer, not the model’s maker. The GPAI provider’s duties rest with whoever built the model, not with you. Your concern is different: how you deploy the model, what data you let it reach, and how you keep a person in charge of it.
Penalties: why this is not just paperwork
The law has teeth, and the penalties are graded by severity. They have applied since August 2025.
The percentages are of worldwide annual turnover, and for large companies the higher of the two amounts applies. For small and medium businesses and startups the law takes the lower of the two, so that a fine does not wipe out smaller players. Enforcement for banned practices and large models is already running; supervision of high risk starts with its deferred dates.
What this means for an ordinary Czech company
Put together, the sober conclusion for a typical Czech company is this. Most of what you do with AI falls into minimal risk and carries no special duties. Two things reach almost everyone, though: transparency toward customers and AI literacy for your people. And if you use AI in hiring, in assessing creditworthiness or in insurance, you move into high risk, where duties pile up, even with the deadline now pushed to the end of 2027.
How to be AI Act ready, and where we come in
Readiness for the AI Act is not about one tool you buy and are done. It is about how your AI is built. Whose infrastructure it runs on. Who sees which data. Whether every action leaves a traceable record. Whether a person keeps the final word on sensitive decisions. These are exactly the foundations we build, because underneath the paperwork the AI Act is really talking about technical architecture.
- Running on your own cloud infrastructure means control over your data and certainty that nothing is stored in someone else’s cache.
- Access through an MCP server that carries a specific user’s identity gives you permission control and a record of every query.
- A person in the loop on final decisions satisfies the human-oversight requirement.
- One governed space with one audit trail gives the traceability and accountability the law asks for.
Let us say it straight: no tool by itself makes you compliant with the AI Act, because compliance is largely a matter of process and people. But infrastructure built the right way removes most of the friction: the audit trail appears on its own, permissions stay under control, data stays with you. In the next two parts of the series we show how to do this step by step, and give you a finished readiness checklist.
The AI Act does not stop you from using AI smartly. It asks that smart use be traceable and accountable, things a well-run company would want anyway. If you would like to see what this would look like in your case, write to us. A short call is enough for us to say what makes sense and what does not.
