The EU AI Act in 2026: what must your organisation have in place?

Updated · 4 min read · werqly editorial team

Short answer

For most organisations that use AI, three things apply now: prohibited AI practices have been banned since February 2025, you must support the AI literacy of your staff, and since 2 August 2026 transparency duties apply to chatbots and AI-generated content, among other things. The rules for high-risk AI, such as AI in recruitment, were postponed by the Digital Omnibus to 2 December 2027.

The AI Act timeline after the Digital Omnibus

The AI Act (Regulation (EU) 2024/1689) entered into force on 1 August 2024 and applies in stages. In 2026 that timeline was changed by the Digital Omnibus on AI (Regulation (EU) 2026/1744), which entered into force on 27 July 2026. The key dates now:

DateWhat applies
2 February 2025Prohibited AI practices; the AI literacy duty (Article 4)
2 August 2025Rules for providers of general-purpose AI models; governance and penalties
2 August 2026Transparency duties (Article 50), such as telling people they are talking to AI
2 December 2026End of the transition period for marking AI content by existing systems; new ban on AI that generates non-consensual intimate imagery or child sexual abuse material
2 December 2027High-risk AI under Annex III (including recruitment, education, credit scoring, critical infrastructure); previously 2 August 2026
2 August 2028High-risk AI in products under Annex I (for example medical devices); previously 2 August 2027

A delay is not a cancellation. The substance of the high-risk requirements largely stays the same; you only get more time.

Are you a provider or a deployer?

The AI Act places most duties on the provider: the party that develops an AI system and places it on the market. Most organisations are deployers: they use an AI system under their own authority, for their own work.

Note that you can become a provider without noticing. For example, if you put an AI system into service under your own name, or modify a system so that it becomes a high-risk application. If you build AI automations yourself on an open-weight model, have your role assessed.

What must you have in place as a deployer now?

  1. No prohibited practices. Think of emotion recognition at work or in education, social scoring and manipulative techniques. Check that none of your tools does this, not even as a side feature.
  2. AI literacy. Article 4 asks you to support the AI literacy of staff who work with AI. The Digital Omnibus softened this from an obligation to achieve a level into a duty to support, but the duty remains. In practice: training, an AI policy and guidance on what may and may not go into a model.
  3. Transparency. If customers or citizens talk to a chatbot, they must know it is AI. If you publish AI-generated text on matters of public interest, or images that look real, you generally have to disclose that.
  4. An AI register. Not mandatory for every deployer, but indispensable: which AI systems do you use, for what, with which data and at which risk level? Without that overview you cannot answer any of the other questions.
  5. Preparing for high risk. Do you use AI in recruitment, staff evaluation, access to education or credit scoring? From December 2027 this brings duties including human oversight, logging, keeping logs and informing the people concerned. Public bodies and certain other parties must then also carry out a fundamental rights impact assessment.

The AI Act comes on top of the GDPR, not instead of it

Many questions about AI at work are not AI Act questions but GDPR questions. May an employee put customer data into a chatbot? Do you have a data processing agreement? Is a DPIA needed? Those questions apply already, regardless of the risk level the AI Act assigns to an application. See Is ChatGPT GDPR-compliant? and Shadow AI.

What helps: AI you can account for

The common thread in the AI Act is accountability: knowing which AI runs, who uses it, and being able to show what happened. That is hard when AI is scattered across personal accounts and separate SaaS tools. It becomes easier when AI runs in one place that you manage yourself.

With private AI from werqly, the models run on a node of your own, and werqly AI Control records per prompt, model and automation who did what and when. You set the retention period yourself, and export the audit log to your SIEM. Model provenance is transparent: only open-weight models such as Llama, Mistral and Qwen. And you record the policy on how much insight the organisation has into use, so the DPO and works council can inspect it.

Frequently asked questions

Questions on this topic

Has the AI Act been postponed?

Partly. The Digital Omnibus on AI postponed the rules for high-risk AI: for Annex III applications to 2 December 2027 and for AI in products under Annex I to 2 August 2028. The prohibited practices, AI literacy and the transparency duties already apply.

Do I have to train my staff in AI?

Article 4 of the AI Act asks you to support the AI literacy of staff who work with AI. After the Digital Omnibus it is a duty to support, not a guaranteed level. Training, a clear AI policy and practical instructions are the usual way to meet it.

Is using ChatGPT in the office high-risk?

Usually not. A general chat assistant for writing is not a high-risk application. That changes if you use AI to select job applicants or evaluate staff, for example. Separately, the GDPR applies to the data you enter.

Who supervises the AI Act?

Each member state designates market surveillance authorities; at EU level the AI Office supervises general-purpose AI models. Which authority is competent for which application depends on the country, the sector and the product. Sector supervisors in finance and healthcare remain involved.

Sources

  1. AI Act — Regulation (EU) 2024/1689
  2. Digital Omnibus on AI — Regulation (EU) 2026/1744 (overview)
  3. Gibson Dunn — EU AI Act Omnibus Agreement: postponed high-risk deadlines
  4. White & Case — EU AI Omnibus enters into force, amending the AI Act

This article is general information, not legal advice. Rules and guidance change; check the sources listed or ask your lawyer or DPO if in doubt.

Calculator

Calculate your private AI costs.

Enter your work email and number of employees. We work out four setups for you straight away: in your own server room or in our datacentre, self-managed or with werqly Pro management. werqly is not a cheap AI subscription: you pay for your own hardware and full control.

  1. 1Enter your email and number of employees
  2. 2Compare four proposals
  3. 3Request a quote straight away

We email the calculation to this address and use it only to contact you about your request.