In brief
Under the EU AI Act, prohibited practices, AI literacy and Article 50 transparency already apply. The Digital Omnibus moved the high-risk obligations to 2 December 2027 (Annex III) and 2 August 2028 (Annex I). In Poland, complaints and fines start on 28 October 2026.
Key takeaways
- Regulation (EU) 2026/1744 (Digital Omnibus on AI) has been in force since 27 July 2026 and moved the high-risk obligations to 2 December 2027 (Annex III) and 2 August 2028 (Annex I).
- Article 50 transparency has applied since 2 August 2026; the Article 50(2) marking grace period runs to 2 December 2026 and covers only generative systems placed on the market before 2 August 2026.
- In Poland the AI authority KRiBSI handles complaints, inspections and fines from 28 October 2026; in Germany the AI market surveillance act (KI-MIG) has been in force since 29 July 2026, with the Bundesnetzagentur as the main market surveillance authority.
- The AI Act does not, as such, require an AI policy or an AI register, but without a list of systems and your role in each you cannot show which obligations apply to you.
Parts of the EU AI Act, Regulation (EU) 2024/1689, already apply. Prohibited practices and the AI literacy duty have applied since February 2025, Article 50 transparency since 2 August 2026, and national authorities in Poland and Germany are taking up enforcement this autumn. The Digital Omnibus moved only the high-risk deadlines. A company should now have a list of its AI systems with its role in each (provider or deployer), a check against the prohibitions and Article 50, and documented AI literacy measures. Our AI Act and ISO/IEC 42001 service starts with exactly that list.
What did the Digital Omnibus change?
Regulation (EU) 2026/1744, the Digital Omnibus on AI, has been in force since 27 July 2026. It kept the structure of the AI Act and postponed the heaviest obligations.
High-risk systems listed in Annex III, such as AI used in recruitment or credit scoring, now have until 2 December 2027. High-risk systems in products covered by the Annex I legislation have until 2 August 2028.
| From | What applies | Basis |
|---|---|---|
| 2 February 2025 | Prohibited practices (Article 5) and AI literacy (Article 4) | Article 113 AI Act |
| 2 August 2025 | Obligations for providers of general-purpose AI models | Article 113 AI Act |
| 2 August 2026 | Article 50 transparency | Article 113 AI Act |
| 28 October 2026 | Poland: inspections, complaints, individual opinions and fines by KRiBSI | Article 127 of the Polish act on AI systems |
| 2 December 2026 | Two new prohibitions (non-consensual intimate deep fakes, child sexual abuse material) and the end of the Article 50(2) grace period | Regulation (EU) 2026/1744 |
| 2 December 2027 | High-risk systems listed in Annex III | Article 113 AI Act as amended |
| 2 August 2028 | High-risk systems under Annex I | Article 113 AI Act as amended |
Watch out for older material: "high-risk AI from 2 August 2026" has been wrong since the Omnibus entered into force. The amending text is in the Official Journal of the EU.
Provider or deployer: which role does your company have?
The AI Act (Regulation (EU) 2024/1689) assigns obligations to providers and deployers of AI systems according to risk, so everything depends on your role.
A provider develops an AI system or has it developed and places it on the market or puts it into service under its own name or trademark (Article 3(3)). A deployer uses an AI system under its authority, except in a personal, non-professional activity (Article 3(4)).
Most companies are deployers: they use ChatGPT, Copilot or a vendor's chatbot. The role changes once you offer a system under your own brand.
For high-risk systems Article 25 is explicit: you become the provider if you put your name or trademark on the system, make a substantial modification to it, or change its intended purpose so that it becomes high-risk.
For each system, record:
- the system and its vendor, including AI features built into SaaS tools (CRM, office suite, help desk),
- your role: provider, deployer or both,
- the intended purpose and the input data, including personal data,
- the risk class with the reasoning and the date of the decision,
- the business owner responsible for the system.
Most of the entries will come from places where AI arrived without IT knowing. We explain where that comes from and what it risks in our piece on shadow AI, the AI tools used outside company control.
Which EU AI Act obligations already apply today?
Three groups of obligations concern almost every company, and the Omnibus did not postpone any of them.
- Prohibited practices (Article 5), since 2 February 2025. These include manipulative techniques, social scoring, and emotion recognition in the workplace and in education, except for medical or safety reasons.
- AI literacy (Article 4), since 2 February 2025. As amended by the Omnibus, providers and deployers take measures to support the AI literacy of their staff and of other people who operate AI systems on their behalf. The duty does not require them to guarantee any specific level of AI literacy of any individual.
- Transparency (Article 50), since 2 August 2026. Details below.
Article 50: who informs whom, and what gets marked
- Providers must design chatbots and voice assistants so that people know they are interacting with an AI system, unless that is obvious (Article 50(1)).
- Providers of systems that generate text, images, audio or video must mark the output in a machine-readable format (Article 50(2)).
- Deployers of emotion recognition or biometric categorization systems must inform the people exposed to them (Article 50(3)).
- Deployers must disclose deep fakes and AI-generated text published to inform the public on matters of public interest, unless the text went through human review or editorial control and someone holds editorial responsibility for it (Article 50(4)).
The information must be given at the latest at the first interaction or exposure (Article 50(5)). The Commission's guidelines on the Article 50 transparency obligations and the voluntary code of practice on marking and labeling AI-generated content give practical examples.
For Article 4, the evidence is a training plan matched to roles and a record of who completed what and when. A ban on AI tools is not a control: people still use them, only out of sight. We look at the pitfalls of AI in development teams in our article on the ethical dilemmas of AI in software development.
Who enforces the AI Act in Poland and Germany?
Enforcement is national: KRiBSI in Poland, the Bundesnetzagentur (with BaFin for finance) in Germany.
The fines themselves are set in Article 99 of the AI Act: up to EUR 35 million or 7% of worldwide annual turnover for prohibited practices, up to EUR 15 million or 3% for most other obligations, and up to EUR 7.5 million or 1% for incorrect information to authorities. Whichever is higher applies; for SMEs, whichever is lower (Article 99(6)).
Poland: KRiBSI from 28 October 2026
Poland's act on AI systems of 3 July 2026 (Dz.U. 2026 poz. 1003) has been in force since 11 August 2026. Under its Article 127(2), the chapters on inspections, proceedings and complaints, settlements and fines, and the individual opinions (Articles 8-18), apply from 28 October 2026.
The authority is the Komisja Rozwoju i Bezpieczeństwa Sztucznej Inteligencji (KRiBSI, Commission for the Development and Security of Artificial Intelligence), the market surveillance authority and single point of contact under Article 70 of the AI Act. surveillance authority and single point of contact under Article 70 of the AI Act.
- Complaints (Article 59). Any natural or legal person, or an organizational unit without legal personality, can file one electronically, describing the system, the facts and why they see a breach.
- Proceedings (Articles 60-61). They must end within 6 months of service of the decision opening them; KRiBSI may issue a warning before then.
- Fines (Article 104). Imposed by KRiBSI within the Article 99 limits, converted from euro at the National Bank of Poland's average rate of 28 January of each year.
- Individual opinions (Articles 8-17). A company in scope, or one planning to be, can ask about a concrete case. The fee is PLN 150, the answer comes within 30 days (60 in particularly complex cases), and a company that follows the opinion cannot be penalized for doing so.
Germany: the KI-MIG and the Bundesnetzagentur
Germany's implementing act for the AI Act is the KI-MIG (KI-Marktüberwachungs-und-Innovationsförderungs-Gesetz, the act on AI market surveillance and innovation), published in BGBl. 2026 I Nr. 223 and in force since 29 July 2026.
The Bundesnetzagentur is the market surveillance authority unless the act assigns another one (section 2(1)); BaFin covers AI systems directly linked to regulated financial activities (section 2(3)). Complaints go to a central complaints office at the Bundesnetzagentur (section 8).
Is your HR or credit-scoring AI a high-risk system?
Annex III point 4 covers AI for recruitment and selection: targeted job ads, analyzing and filtering applications, evaluating candidates. It also covers AI used to decide on promotion or termination, to allocate tasks, and to monitor and evaluate workers. Creditworthiness assessment and credit scoring of natural persons is high-risk too (point 5(b)).
Article 6(3) exempts a system that does not pose a significant risk, for example one that performs a narrow procedural task. The exemption never applies when the system profiles natural persons. A provider that considers an Annex III system not to be high-risk documents that assessment before placing it on the market (Article 6(4)).
From 2 December 2027, a deployer of a high-risk system must, among other things:
- use it according to the instructions for use and assign human oversight to people with the necessary competence and authority (Article 26(1)-(2)),
- keep the automatically generated logs under its control for at least 6 months (Article 26(6)),
- as an employer, inform workers' representatives and the affected workers before using it in the workplace (Article 26(7)),
- inform the people about whom the system makes or helps make decisions (Article 26(11)).
A fundamental rights impact assessment (Article 27) is required only from bodies governed by public law, private entities providing public services, and deployers of the systems in Annex III points 5(b) and (c): creditworthiness, and life and health insurance. A private employer using an HR tool does not have to carry one out, but must still inform its workers.
Does the AI Act require an AI policy and an AI register?
Not as such. The regulation does not oblige you to write an "AI policy" or keep an "AI register". Both are still the simplest evidence that you know which AI systems you use and in what role. Without a list of systems it is hard to answer a complaint or an authority's question properly.
A policy you cannot show in your systems stays on paper. Build the register from data: the application inventory, access logs for AI tools and vendor contracts.
Our AI governance and AI security page shows what that oversight looks like in practice. Where to start with the data side is covered in our article on data governance as the foundation for AI in your organization.
Checklist for the coming weeks
- List your AI systems, including those built into SaaS, with your role, the intended purpose and an owner.
- Compare the use cases with the Article 5 prohibitions and record a dated decision.
- Check chatbots, voice bots and published content against Article 50. If you provide a generative system placed on the market before 2 August 2026, marking is due by 2 December 2026.
- Prepare an AI literacy plan for the roles that use AI and record who completed what.
- Flag likely high-risk systems (HR, credit scoring) and plan the work up to 2 December 2027.
- Name the person who answers an authority's request, and the place where the evidence is kept.
- In Poland, consider asking KRiBSI for an individual opinion when a classification is unclear.
Where should you start?
With the list of systems and roles: every other step follows from it. In our AI Act and ISO/IEC 42001 work we establish your role for each AI system and what follows from it, then build one management system with owners and evidence around it. To find out where you stand before the national authorities start enforcing, get in touch.
Frequently asked questions
- Do the EU AI Act high-risk rules apply from 2 August 2026?
No. After the Digital Omnibus (Regulation (EU) 2026/1744), the obligations for Annex III systems apply from 2 December 2027 and for Annex I systems from 2 August 2028.
- Does using ChatGPT at work fall under the AI Act?
Yes. As a deployer, your company is responsible for AI literacy measures (Article 4) and for disclosing deep fakes and AI-generated text published on matters of public interest (Article 50(4)). The provider obligations for the model sit with the company that develops it.
- What are the fines under the EU AI Act?
Up to EUR 35 million or 7% of worldwide annual turnover for prohibited practices, up to EUR 15 million or 3% for most other obligations, and up to EUR 7.5 million or 1% for incorrect information (Article 99). For SMEs the lower of the two amounts applies.
- Does ISO/IEC 42001 certification mean AI Act compliance?
No. ISO/IEC 42001:2023 is an AI management system standard, but it is not a harmonized standard under the AI Act and gives no presumption of conformity. It helps organize roles, risks and evidence; the obligations for each system still have to be worked out separately.
- Do we need an AI policy?
The AI Act does not require one as such. A policy and a register of AI systems are still the simplest evidence that you know your systems, roles and obligations.

