On 2 August 2026, national authorities across the EU began enforcing the AI Act. In the weeks since, two opposite errors have spread through the business world at roughly equal speed. The first: "this is a law for Big Tech; it does not concern us." The second: "everything AI-related is now regulated; safest to do nothing." Both are wrong, both are expensive, and both dissolve under an hour of reading the regulation as it actually stands — including the amendments that Regulation (EU) 2026/1744, the Digital Omnibus on AI, made to it on 27 July 2026.
This piece sets out what applies to a company that uses AI — at any size, in any sector — what has been deferred, and what the sensible minimum response looks like. It is written for the person who has to defend the decision internally, whether that person runs the company or runs its compliance function.
The timeline, stripped of noise
The AI Act entered into force on 1 August 2024 and applies in phases. Five dates matter for a company that deploys AI rather than builds it, and two of them were rewritten this summer.
2 February 2025. The prohibitions on unacceptable-risk practices took effect — social scoring, manipulative systems that cause harm, untargeted scraping for facial recognition databases. Very few companies of any kind touch these. The same date activated something almost every company does touch: Article 4, the AI literacy obligation.
2 August 2026. Governance became real. National market surveillance authorities began supervising compliance, with the penalty framework behind them. For companies whose AI use is not high-risk — the large majority — the practical effect is that the literacy duty moved from "in force but unsupervised" to "in force and enforceable."
2 December 2026. Article 50's transparency duties — telling people when they are dealing with an AI system, and marking AI-generated content as such — were left on their original timeline. This is the date still ahead in that article: Article 50(2) reaches systems that were already on the market. If a model answers your customers or drafts content you publish, that is the part of the regulation to read, and it was not postponed.
2 December 2027, then 2 August 2028. The obligations for high-risk systems — AI used in hiring decisions, credit scoring, critical infrastructure, and the other Annex III categories — were deferred by Regulation (EU) 2026/1744, the Digital Omnibus on AI, published in the Official Journal on 24 July 2026 and in force since 27 July. Stand-alone Annex III systems move from 2 August 2026 to 2 December 2027. High-risk AI embedded in products already regulated under Annex I moves to 2 August 2028.
The deferral is where the confusion breeds. Much of the business press reported it as "the AI Act delayed," and many companies concluded the whole file could wait. It cannot. The delay applies to the high-risk chapter specifically. Article 4 and Article 50 were not moved, the enforcement machinery stood up in August regardless, and the same amending regulation added a further prohibited practice to Article 5.
Article 4: the obligation nearly everyone actually has
Article 4 requires providers and deployers of AI systems to take measures supporting a sufficient level of AI literacy among their staff and anyone operating AI systems on their behalf — contractors included. "Deployer" is the word to sit with. If your team uses a chatbot to draft offers, an AI feature inside the CRM, or a transcription tool in meetings, your company deploys AI within the meaning of the regulation. There is no size threshold beneath which the duty disappears.
The Digital Omnibus reworded this duty without postponing it: the obligation shifted from ensuring a sufficient level of literacy to supporting its development — an obligation of effort rather than of result. That is genuine relief. It is not exemption, and Article 4 keeps its original timeline: while the chapter everyone read about was moving to 2027, the literacy obligation stayed exactly where it was — and since August it has had a supervisor. An obligation of effort still requires demonstrable effort. An authority that asks what measures you have taken expects an answer better than silence.
The regulation's own answer to "how much is enough" is proportionality: the measures should match how the systems are used and who is affected. For a ten-person firm that means less paperwork than for a corporation with a dozen AI-touching departments — but the shape of the work is identical at every scale, and it is unglamorous:
An inventory.
A list of the AI systems actually in use — including the unofficial ones. (MIT's 2025 research found employees at over 90% of surveyed firms using personal AI tools regardless of company policy; pretending otherwise inventories a fiction.)
A short written policy.
What may be used, for what, with what data. One page that exists beats ten that are planned.
Role-appropriate training, documented.
The regulation and the Commission's guidance both stress proportionality: what staff need to understand depends on how they use the systems and who is affected. A half-day for most staff, more for whoever manages customer-facing AI. Keep the attendance record; the documentation is half the point.
None of this requires a law firm. All of it requires someone to actually do it, and most companies have not: the obligation has been live since February 2025, and surveys throughout the period found the majority of European firms unaware it existed.
What most companies can safely not do
Compliance advice in this market has an incentive problem: fear sells retainers. So, for balance, here is what the regulation does not require of a typical deployer today — small, large, or in between.
It does not require conformity assessments, CE-marking, or quality-management systems — those attach to high-risk systems and, primarily, to their providers, on the deferred timeline. It does not prohibit using general-purpose AI tools in ordinary business workflows. It does not require an "AI officer." And using AI to automate an internal process — invoice intake, order confirmation, report generation — sits, in almost every configuration, in the minimal-risk category where Article 4 and ordinary data-protection law are the whole of the matter.
One caution earns its place: the risk category follows the use, not the tool. The same language model that drafts product descriptions at minimal risk becomes a high-risk deployment the day it screens job applications. If automation plans touch hiring, creditworthiness, or access to essential services, 2 December 2027 belongs in the project plan now — systems built this year should not need rebuilding the year the rules land.
Why this is an operations question, not a legal one
The companies treating the AI Act purely as a legal exposure are missing what the inventory exercise tends to reveal. Listing where AI is actually used — officially and unofficially — is the same exercise as mapping which processes people are quietly trying to fix themselves. Shadow AI use is a map of unmet automation demand, drawn by your own staff. The regulation, whatever else it does, forces a company to look at that map.
Our view, stated plainly: the sensible response to the AI Act for any company whose AI use is not high-risk is one inventory, one page of policy, one documented training, and a diary note for the high-risk timeline. For most organisations that is days of effort, not months — and it scales with the company, not against it. The alternative responses — ignoring it, or freezing all AI adoption in its name — both cost more, and the second one costs the most, because it concedes the efficiency gains to competitors while purchasing no legal safety in return.
Sources: Regulation (EU) 2024/1689 (AI Act), as amended by Regulation (EU) 2026/1744 (Digital Omnibus on AI) — published in the Official Journal on 24 July 2026, in force 27 July 2026; European Commission, "AI Act — Shaping Europe's digital future" (application timeline); MIT NANDA, "The GenAI Divide" (2025) on shadow AI usage. Regulatory references are to obligations in force at the time of writing; this article is analysis, not legal advice.



