There is a bit of confusion around the AI Act right now: some deadlines have moved, the obligations arrive in waves, and a small business with a website chatbot faces something quite different in practice than a corporation with a compliance team. The facts, though, are firm — the delay of the obligations for high-risk systems under Annex III to 2 December 2027 is binding law (Regulation (EU) 2026/1744, in force since 27 July 2026), and the rest of the AI Act keeps running. In a few minutes on this page you will know what the Regulation means for a small, mid-sized and large company — and what is worth addressing right now.
What did the delay not touch at all? Mandatory AI literacy for staff (Article 4) has applied since February 2025. Transparency — a chatbot must disclose that it is AI (Article 50) — applies from 2 August 2026. And neither GDPR Article 22 nor Section 316 of the Czech Labour Code has any delay.
The question for a CTO reads differently than the one for a lawyer: What exactly did your AI agent read yesterday? Where did that data go? And which version of the rules allowed it? If the answer doesn't exist in a log but only in the head of the person who built the agent, you have an unaudited channel into your company data — regardless of any deadline.
This page brings companies' obligations under the AI Act together in one place: what applies when, how to recognise a high-risk system, and how the obligations are evidenced in practice.
We will walk through where your AI stands against the Regulation. Concrete and to the point.
Book a consultation →Regulation (EU) 2024/1689 does not take effect all at once — it arrives in waves, and the delay under Regulation (EU) 2026/1744 has reshuffled them. For an ordinary company adopting and using AI, three dates remain. The Regulation calls such a company the deployer, and this page uses that term throughout.
| Date | What applies | Who it concerns |
|---|---|---|
| 2 Feb 2025 | Prohibited AI practices banned (Article 5) and mandatory AI literacy for staff (Article 4) | Every company that uses AI |
| 2 Aug 2026 | Transparency (Article 50): a chatbot informs users that it is AI; labelling of synthetic content* | Anyone offering a chatbot to users; providers of generative systems (content labelling) |
| 2 Dec 2027 | High-risk systems under Annex III + deployer obligations (Article 26) — moved from the original 2 Aug 2026 | HR tools, scoring, evaluation of individuals |
What can it cost? Breaches of deployer or transparency obligations carry fines of up to EUR 15 million or 3% of worldwide annual turnover — whichever is higher (Article 99). The top band — up to EUR 35 million or 7% — is reserved for prohibited practices under Article 5. For small and medium-sized enterprises, the lower of the two amounts applies.
On the Czech side, the Ministry of Industry and Trade (MPO) is the lead ministry and the Czech Telecommunication Office (ČTÚ) is proposed as the main market surveillance authority. The Czech AI adaptation act is in the legislative process — it is not yet in force.
The obligations in the AI Act do not depend on the size of your company but on what your system does. Size changes something else: the impact, and the capacity you have to deal with it. You will most likely recognise yourself in one of these three situations.
A chatbot on the website and a team that uses AI tools. From August 2026, the chatbot must disclose that it is AI (Article 50). Employees need role-appropriate AI literacy (Article 4) — that already applies today. For fines, small and medium-sized enterprises pay the lower of the two amounts (Article 99(6)). No panic: two concrete things, both manageable. And if you were to deploy a tool that evaluates people, the same applies to you as to the mid-sized company next door.
An internal assistant over company data, the first HR automation on the table. Classification decides: as soon as a system evaluates people — sorts CVs, scores performance, influences promotion — it heads into the high-risk category (Annex III). Walk through the three questions below. GDPR Article 22 and Section 316 of the Czech Labour Code already apply today. Logs and human oversight only concern high-risk systems from 12/2027 — but the architecture that can carry them is built now.
Several AI systems in production, procurement audits from customers, your own DPO or compliance team. Governance decides: a single audit trail across systems, and evidence you do not have to reconstruct retroactively during an audit. And an AI strategy instead of patches.
Most internal assistants are not high-risk. But the line is not drawn by the technology — it is drawn by what the system does with people.
Two details that get underestimated in practice. First: the exemptions under Article 6(3) (narrow procedural task, preparatory activity) must be assessed and documented by the provider before the system is placed on the market — not by you as the deployer. Second, the Article 25(1) trap: if you substantially modify a high-risk system, or change a system’s intended purpose so that it becomes high-risk, you become the provider yourself — with all the obligations. This also applies to an agent built on top of a general-purpose model. Internal development can drift into this situation unnoticed.
The exact boundary will be further clarified by European Commission guidelines; the assessment is always case by case.
Not sure where your system falls? Classification is an hour of work — and it determines which obligations await you.
Let's walk through the classification →Companies’ obligations under the AI Act have a practical translation: what evidence you produce when someone asks. Just mind the scope. The obligations under Article 26 apply only to high-risk systems and take effect on 2 December 2027. Article 4 already applies today. And Article 50 from August 2026 — for anyone operating a chatbot or generating content.
Every AI deployment today passes through three gates: past the board and legal counsel, past your customer's procurement — and sometimes past a regulator.
At all three, the same thing decides: can you prove who, what, when, and under which version of the logic? A company that pulls the answer out of an audit trail in an hour passes the gates faster than a company that spends a week reconstructing it from a developer’s memory.
That is the difference between “it works” and “you can prove it”. An internal prototype can be technically excellent — but the audit infrastructure beneath it is not a weekend project. It is a discipline of its own: signed versions of rules, records where a silent subsequent change leaves a trace (tamper-evident), exports for the auditor, tests that hold the whole thing together. Your team should be building the product; this is a layer that makes sense to bring in ready-made.
The window until December 2027 is a head start. Whoever solves auditability now keeps deploying in 2027 — while others start catching up on documentation.
The audit infrastructure is one layer. We build the whole stack — from strategy through development to day-to-day operations — and auditability belongs in it from the start, not as an afterthought.
A consultation on where AI helps you first — and where to start.
Discuss what makes sense for you →Sentinel is a security and audit layer for enterprise AI (MCP servers). It is built to the standards of record-keeping, human oversight and robustness that the AI Act expects — with proof in code and tests.
Every security incident has a card with an evidence chain (append-only hash chain). A record cannot be silently deleted or overwritten — any damage to the chain is visible at every verification; it is a tamper-evident record, and an external anchor for a full tamper-proof mode is on the roadmap. Every incident records the version of the rules that made the decision — and if a model were deciding, its version too. The auditor downloads a complete export including the chain's integrity status.
An incident is never closed by a machine — every closure requires a named person with a justification. Blocking and unblocking a user is confirmed by an authorised person with two-factor authentication (TOTP); today in observe mode — see below. The AI component is advisory by construction: it recommends, never enforces — and it is not yet running in production.
Telemetry carries metadata only: hashes, sizes, timestamps. Never the content of your documents. Raw data is kept for 90 days; after that only aggregates remain.
No score, ranking or leaderboard of individuals is ever sent to the client — you technically cannot build an employee performance measurement tool out of it. This boundary is held not by a document, but by code and tests.
The honest status: the first deployment runs in observe mode — Sentinel records and evaluates, it does not enforce. Enforcement is the next phase, conditional among other things on confirmation that you have informed your workers. The compliance dossier is generated directly from the code and rests on more than 1,000 test declarations; the audit trail is designed according to the draft of prEN ISO/IEC 24970. Architecturally, Sentinel is an SDK embedded in your MCP server with a control plane outside the request path — no extra proxy between you and your data.
Deployer obligations cannot be bought. What can be bought are the tools and evidence you defend them with.
| We deliver | Stays with you |
|---|---|
| An audit layer with append-only records (a silent change leaves a trace — tamper-evident) and exports for the auditor | Informing workers and their representatives before deployment |
| Human oversight mechanisms (2FA confirmation, human-only incident closure) — today in observe mode | Appointing a competent person who actually carries out the oversight |
| Decision reconstruction: the version of the rules for every incident — and if a model were deciding, its version too | The DPIA with your DPO |
| Templates: information notice, DPIA skeleton, runbook — they require review by your lawyer | Log retention of at least 6 months (Article 26(6)) and training under Article 4 |
You are not buying compliance — no vendor can secure that for you. You are buying the tools and evidence you defend it with.
Yes. From 2 August 2026, a system intended to interact with people must inform them that it is AI (Article 50(1)). The only exemption applies where this is obvious to a reasonably well-informed person.
No. The delay — enacted as Regulation (EU) 2026/1744, in force since 27 July 2026 — covers only high-risk systems under Annex III (now 2 December 2027); AI in regulated products (Annex I) moves to 2 August 2028. AI literacy (Article 4) has applied since February 2025, transparency (Article 50) applies from August 2026, and GDPR Article 22 applies with no delay.
If it analyses and filters job applications, evaluates performance, or influences promotion or termination, it falls under Annex III point 4. Exemptions under Article 6(3) exist, but they must be documented by the provider before the system is placed on the market — and they do not apply to the profiling of individuals.
Article 4 has required, since 2 February 2025, a sufficient level of AI literacy of everyone who works with AI in the company — with regard to their role. According to the Commission's interpretation (non-binding Q&A, May 2025), relying on the instructions for use, or merely circulating them, is not enough; training appropriate to the role and context is expected.
For breaches of deployer or transparency obligations, up to EUR 15 million or 3% of worldwide annual turnover (Article 99). The top band of EUR 35 million / 7% applies only to prohibited practices under Article 5. For SMEs, the lower of the two amounts applies.
No. The adaptation act is in the legislative process; the Ministry of Industry and Trade (MPO) is the lead ministry and the Czech Telecommunication Office (ČTÚ) is proposed as the main market surveillance authority. The Regulation's penalty framework has been applicable since 2 August 2025, but real enforcement in the Czech Republic presupposes the adoption of the adaptation act.
The legal statements are based on the text of the Regulation and clearly marked Commission interpretations, not on blogs.
Primary source: Regulation (EU) 2024/1689 (the “Artificial Intelligence Act”), EUR-Lex CELEX 32024R1689. Deadline delay: Regulation (EU) 2026/1744 (Digital Omnibus on AI), published in the Official Journal on 24 July 2026, in force since 27 July 2026. Czech adaptation act: the MPO bill in the legislative process.
A consultation with a concrete output: a list of what your company must prove, and what it already has in place.
Find out where you stand →Status as of 28 July 2026. Based on Regulation (EU) 2024/1689 (EUR-Lex CELEX 32024R1689) and on the deadline delay under Regulation (EU) 2026/1744 (Digital Omnibus on AI), published in the Official Journal on 24 July 2026 and in force since 27 July 2026. The Czech AI adaptation act is in the legislative process; the boundaries of high-risk systems will be further clarified by European Commission guidelines. The information presented here may change. This page is not legal advice. Consult a lawyer on your company’s specific obligations; the document templates we deliver require review by your legal department.