Back to the blog

Guide

The EU AI Act: what changes from 2 August 2026 and what to do

From 2 August 2026 the EU AI Act's transparency rules kick in. What to actually do if you use chatbots, generate content, or deploy AI agents in your business.

Written by Alice & Cesare

First, just a brief bit of context to understand what we're talking about.

What the AI Act is (in short)

The AI Act is the European regulation governing artificial intelligence. It's the first of its kind in the world and formally entered into force in August 2024, but it applies in stages: the various rules become operational at different times, spread out through 2027-2028.

The principle is this: not all AI is the same, so not all of it should be regulated in the same way. The regulation divides systems into four tiers, based on the risk they pose to people.

Unacceptable risk: prohibited.
Practices considered incompatible with fundamental rights, and that are simply banned:

  • assigning citizens a "social score" based on their behaviour
  • using subliminal or deceptive techniques to steer people's choices to their detriment
  • inferring the emotional state of employees in the workplace
  • identifying people through real-time facial recognition in public spaces (save for narrow exceptions).

High risk: heavily regulated.
Systems that affect important decisions in people's lives:

  • recruitment
  • access to credit
  • healthcare
  • education
  • critical infrastructure

Here the obligations are serious (documentation, risk management, human oversight), but they concern a minority of businesses.

Limited risk: transparency obligations.
In practice, this is where the vast majority of SMEs and professionals using:

  • chatbots
  • virtual assistants
  • tools to generate text and images

Here the main obligation is transparency: making it recognisable to users when they are interacting with an artificial intelligence system, or when a piece of content has been generated by AI.

Minimal risk: no obligations.
Spam filters, video games, most internal automations. No specific requirements.

A brake on innovation or a necessary safeguard?

The AI Act is the subject of serious criticism, and not just for convenience. The strongest criticism is that regulating such a young and versatile technology risks stifling it. Those who make this case observe that the obligations lengthen time to market and raise costs, with the greatest disadvantage falling precisely on startups and small businesses, the ones least able to afford dedicated legal departments. The fear is that Europe will end up with access to "second-best" solutions, while real innovation develops elsewhere, where the rules are lighter.

On the other side there's an equally concrete argument: systems that decide who gets a loan, who gets hired, or how critical infrastructure is managed cannot be black boxes without rules, and a minimum of transparency and accountability protects citizens from abuse and discrimination.


You can have your own view on which of the two voices weighs more; it's a legitimate and open debate. But from the standpoint of someone running or working in a business, the practical question is a different one: the law exists, it applies, and it can't be ignored. So how do I keep using AI with peace of mind? Let's try to answer that question in the rest of the article.

Where attention is really needed

For most businesses the requirements are modest, but two aspects deserve care: understanding precisely what your role is in the eyes of the law, and knowing exactly what kicks in and when. These are the two points where it's easiest to get confused, and they're exactly the ones we'll look at now.

An important distinction: are you a "deployer" or a "provider"?

The regulation uses two words worth learning, because they determine how many obligations you have.

The deployer (user) is whoever uses an AI system in their own activity. If you put a chatbot on your site, use a tool that generates marketing copy, or have an AI feature in your management software, you're a deployer. The obligations here are light.

The provider is whoever develops an AI system and places it on the market. The obligations are considerably heavier.

Almost all businesses instinctively place themselves among the deployers. And often that's correct. But there's a pitfall worth knowing about.

The distinction doesn't depend on who trained the model. If you take a third-party model (that is, the ones behind the best-known AI tools), integrate it into your product, customise it, and distribute it under your own brand, in several cases the regulation considers you a provider. This is exactly what happens when a software house builds an AI feature into a management system it then sells, or when a company brings to market an assistant based on external services.

How do you know? Ask yourself three questions: do you use the AI inside your own company, or do you sell it to clients? Do you distribute it under your own name? Are you modifying it substantially? If the three answers make you suspect you're a provider, it's time to consult an advisor. Clarifying your role before designing an AI feature costs far less than chasing it afterwards.

What actually kicks in on 2 August 2026

There's been quite a bit of noise here, because at the end of June 2026 the so-called Digital Omnibus was adopted, and the message that reached the market was "they've postponed the AI Act." That's not quite how it is: only one specific part has slipped, the rest is coming into force.

Postponed: most of the obligations on high-risk systems: the standalone ones (credit, insurance, infrastructure, recruitment) to 2 December 2027, and those embedded in products such as medical devices or machinery to 2 August 2028.

Not postponed: what kicks in on 2 August 2026: the transparency obligations (Article 50 of the regulation) and the full operation of the supervisory authorities, together with the accompanying penalty regime. In Italy, supervision is entrusted to the National Cybersecurity Agency.

In practice: the businesses affected by the postponed part are relatively few and generally already well structured. The businesses affected by the part that was not postponed are almost all of those that have a chatbot or generate content with AI. Which, in all likelihood, includes yours.

The practical list: what you need to do

Transparency comes down to four concrete situations. In all of them, the principle is the same: people have the right to know when they are interacting with an AI system or looking at content it has produced.

  • Disclose chatbots and assistants. If a user interacts with an AI system such as a support chatbot, a virtual assistant, or an agent that answers emails, they must know it. A clear notice, even a small one, at the start of the interaction is enough.
  • Label generated content. Images, videos, and audio produced or modified with AI must be flagged as such. Deepfakes in particular must always be declared.
  • Flag texts published without human review. If you publish, automatically and without genuine human review, AI-generated texts intended to inform the public on matters of general interest, the regulation sets specific transparency obligations. A key point is precisely human review: a text generated by AI but checked, corrected, and approved by a person is not treated the same way as content published automatically.
  • Inform in cases of emotion recognition or biometric categorisation. Less common, but present in some analytics and retail solutions: if you use them, the people concerned must be informed.


To these are added two things often forgotten, but already in force for some time: AI literacy among staff (you and your team must have a basic competence regarding the systems you use) and compliance with the absolute prohibitions seen above.

There's finally a deadline to mark on the calendar: on 2 December 2026 the obligation for machine-readable labelling comes in (a kind of watermark in the file's metadata) for content generated by systems already on the market. It's a technical requirement: a visible label isn't enough, the marker has to sit inside the file.

The good news, as those who build these systems point out, is that almost all of these interventions are resolved with easy changes inside the product, not by producing reams of paperwork: a small notice in the interface, a label, a point where a person approves before publication, a log of decisions. These are things that, once you know where to put your hands, get sorted out quickly.


And AI agents?

AI agents (systems that don't just respond or generate text, but receive an objective and complete tasks autonomously, using external tools as well) deserve a separate discussion, because more and more businesses are adopting them.

The AI Act doesn't name them explicitly, but the definition of "AI system" is broad enough to encompass them, and the Commission has confirmed this. The important thing to understand is this: the level of risk depends on what the agent does, not on the fact that it's autonomous.

An agent that manages an internal workflow (routing tickets, reconciling invoices, preparing reports, or coordinating activities) in most cases doesn't fall among high-risk systems: so it's mainly the transparency obligations that will continue to apply. That same agent becomes high risk the moment its action touches sensitive decisions about people: filtering job applications, assessing creditworthiness, managing access to essential services. The practical rule: if it acts on data and processes it's generally limited risk; if it acts on decisions concerning people (employment, credit, rights, safety) it's almost certainly high risk.

If you build or use agents, three precautions keep you covered. Keep a human in the loop for the decisions that matter: the agent can work on its own on low-impact things, but important choices must be reviewable and stoppable by a person. Keep track of what it does with logs that make it possible to reconstruct why it reached a given decision. And if you use an agent developed by a third party in a sensitive context, get clear instructions from the provider on what the system can and can't do.

One last useful note: a simple rule-based automation, which always runs the same steps without adapting, usually doesn't even fall within the definition of an AI system. The dividing line is the capacity to adapt and choose, not the mere fact of being automated.

Final checklist

For most businesses the path can be very simple:

  • Map where you have AI in your systems, including the chatbot installed two years ago and the CMS's text-generation plugin. The real map is almost always broader than the perceived one.
  • Clarify your role (deployer or provider, see above) for each system. When in doubt, consult an advisor.
  • Close the transparency gaps: notice on chatbots, label on generated content, indication on texts published without review.
  • Check the logs: if tomorrow you had to explain how a system arrived at a decision, could you?
  • Train the team on using AI: it's the obligation most often forgotten.
  • Mark 2 December 2026 for machine-readable labelling

Compliance costs far less when you build it into the design rather than chasing it after a complaint. And for a business that uses AI transparently and sensibly, this set of rules comes down to a few well-made changes.

*

*

*

This article is for informational purposes and does not constitute legal advice. For the risk classification of your specific systems and for cases that border on the high-risk area, consult a specialised advisor. The deadlines cited are current as of mid-2026 and may be further amended: always verify the most recent state of the law.

Frequently asked questions

I only have a chatbot on my website. Do I really need to do anything before 2 August 2026?

Yes, but it's simple. The only real requirement is transparency: the user must understand they're writing to an artificial intelligence system and not to a person. A clear notice at the start of the conversation is enough. There's no paperwork, no registers, no filings: it's an interface change, not a compliance project.

I use ChatGPT (or similar tools) to generate text and images. Am I a "provider" with heavy obligations?

Almost certainly not. If you use these tools as they are, within your own business, you're simply a user (deployer) and your obligations are limited to transparency: flagging AI-generated or AI-modified content, deepfakes in particular. You only become a "provider," with heavier obligations, if you integrate a model into your product, customise it substantially, and distribute it to clients under your own brand.

What do I actually risk if I don't comply?

From 2 August 2026 the supervisory authorities are fully operational (in Italy, the National Cybersecurity Agency) and can impose penalties. The amounts vary by severity: from modest sums for minor breaches up to significant percentages of global annual turnover for the most serious infringements, such as the use of prohibited practices. For an SME that simply closes its transparency gaps, though, the practical risk is low: these are precisely the easiest requirements to sort out.

I've read that the "Digital Omnibus" postponed everything. Is that true?

No, and it's a common misunderstanding. Only the part on high-risk systems has been postponed (to late 2027 and 2028). The transparency obligations set for 2 August 2026 remain confirmed. Those are exactly the ones that affect most SMEs, so the postponement doesn't change what you need to do now.

Do my internal automations (which follow fixed rules) fall under the AI Act?

Generally no. An automation that always runs the same steps without adapting usually doesn't even fall within the definition of an AI system. The dividing line is the capacity to adapt and "choose": that's what triggers the rules, not the mere fact that a process is automated.

What changes if I use an AI agent that filters candidates' CVs?

Quite a lot. In that case the agent affects a sensitive decision about people (access to employment) and almost certainly falls among high-risk systems, with obligations far more demanding than mere transparency. The practical rule is: if the AI acts on data and processes it's limited risk; if it acts on decisions touching people's employment, credit, rights, or safety, a dedicated assessment is needed before you proceed.

More articles