Every company that uses AI
Do not use AI for prohibited practices (Art. 5), take AI literacy measures (Art. 4), and from 2 Aug 2026 label published deepfakes and inform people about emotion recognition (Art. 50(3) and (4)).
The EU regulation on artificial intelligence has been in force since 1 August 2024 and was amended in July 2026 by Regulation (EU) 2026/1744. Below: what it bans, when each obligation applies, what fines companies face and who enforces it, every figure with its article.
The AI Act is Regulation (EU) 2024/1689 of the European Parliament and of the Council, which sets rules for developing and using artificial intelligence across the EU. It applies directly, without national legislation, and covers companies that develop AI as well as those that only use it. The heaviest penalties are for prohibited practices, such as recognising employees’ emotions or social scoring: fines of up to EUR 35 million or 7 % of worldwide annual turnover.
Verified as of on EUR-Lex and in the Czech eKLEP legislative system. Prepared by CIAD.
Obligations depend on the purpose of use. Most of them fall on sectors where AI decides about people: recruitment and managing employees, lending and insurance, education and public services. E-commerce and marketing deal mainly with transparency and the ban on manipulation.
| Sector | What applies to you | High risk |
|---|---|---|
| E-commerce and customer service | Disclosure for a chatbot you developed or had developed under your name (Art. 50(1)), labelling of deepfakes in advertising (Art. 50(4)), the ban on harmful manipulation (Art. 5(1)(a) and (b)), AI literacy. | Usually not high-risk. |
| HR and recruitment agencies | Screening CVs and evaluating candidates and performance falls under Annex III point 4. Recognising the emotions of candidates and employees is already prohibited. | High-risk from 2 Dec 2027 (Art. 26). |
| Banks, insurers, lending | Creditworthiness assessment of natural persons and pricing of life and health insurance fall under Annex III point 5. In addition, a fundamental rights impact assessment (Art. 27). Supervision by the Czech National Bank under the draft act. | High-risk from 2 Dec 2027. |
| Marketing and agencies | Labelling of deepfakes (Art. 50(4)). AI-generated text must be labelled only on matters of public interest without editorial control. From 2 Dec 2026 intimate deepfakes are prohibited (Art. 5(1)(ba)). | Usually not high-risk. |
| AI developers and SaaS | Provider role: chatbot disclosure and machine-readable marking of outputs (Art. 50(1) and (2)), safeguards against prohibited outputs, and for high-risk uses conformity assessment, documentation, CE marking and registration. Relief for small and medium-sized enterprises. | Depends on the purpose of the product. |
| Manufacturers of regulated products | AI as a safety component of a product under Annex I, for example in medical devices, lifts or toys. | High-risk from 2 Aug 2028. |
| Schools and education | Admission, assessment of learning outcomes and proctoring of exams fall under Annex III point 3. Recognising students’ emotions is prohibited. | High-risk from 2 Dec 2027. |
| Municipalities and public authorities | Eligibility for benefits and public services falls under Annex III point 5. Fundamental rights impact assessment (Art. 27), registration. Legacy systems by 2 Aug 2030 at the latest. Under the Czech draft act, fines are capped at CZK 10 million. | High-risk from 2 Dec 2027. |
A general assistant such as ChatGPT is not high-risk in itself; its use becomes high-risk when, for example, it screens job applicants. The exception in Art. 6(3) and its limits are set out in Article 6 on EUR-Lex.
Obligations phase in. The prohibitions and AI literacy have applied since 2 February 2025, transparency since 2 August 2026. Amendment (EU) 2026/1744 postponed only the high-risk obligations, to 2 December 2027.
Prohibited practices under Art. 5 and the obligation to take AI literacy measures under Art. 4. From 2 Aug 2025 also the rules for general-purpose AI models and the penalty framework.
Art. 113(a) and (b)Disclosure for chatbots, labelling of deepfakes and informing people about emotion recognition under Art. 50. From 2 Dec 2026 two prohibitions are added (intimate deepfakes and child sexual abuse material) and older content generators must mark their outputs in a machine-readable way.
Art. 113, Art. 111(4)Obligations for high-risk uses under Annex III, for example recruitment or creditworthiness assessment. For AI in products under Annex I only from 2 Aug 2028.
Art. 113(c)Every date including legacy systems: when AI Act obligations apply.
Most companies only use AI. Above all they must avoid prohibited practices, take AI literacy measures and label deepfakes. More obligations come with high-risk use and with developing your own AI.
Do not use AI for prohibited practices (Art. 5), take AI literacy measures (Art. 4), and from 2 Aug 2026 label published deepfakes and inform people about emotion recognition (Art. 50(3) and (4)).
From 2 Dec 2027 the deployer obligations under Art. 26: use in line with the instructions, human oversight, control of input data, logs kept for at least six months, informing employees and affected people.
Chatbot disclosure and machine-readable marking of generator outputs (Art. 50(1) and (2)). For high-risk systems the requirements of Art. 9 to 15, conformity assessment, CE marking and registration. A company also becomes a provider when it substantially modifies a high-risk system or places it on the market under its own name (Art. 25).
The binding text is Article 5 on EUR-Lex.
How the Article 4 measure translates into training by role: AI training for companies and the Article 4 obligation. The binding text of the transparency rules: Article 50 on EUR-Lex.
Article 99 sets three fine caps. For companies the higher of the two amounts applies, for small and medium-sized enterprises the lower. Besides a fine, an authority can order corrective action, prohibit use of the system or withdraw it from the market.
| Infringement | Maximum fine | For example | Provision |
|---|---|---|---|
| Prohibited practices | EUR 35 million or 7 % | Software evaluates the emotions of employees or candidates; a company refuses customers based on a score derived from their social media behaviour. | Art. 99(3) |
| Obligations of operators and transparency | EUR 15 million or 3 % | Your own chatbot does not disclose that it is AI; an unlabelled deepfake in advertising; from 2 Dec 2027 screening candidates without human oversight or selling a high-risk system without conformity assessment and CE marking. | Art. 99(4) |
| Incorrect information to authorities | EUR 7.5 million or 1 % | Incorrect, incomplete or misleading answers to a request from an authority. | Art. 99(5) |
| Providers of general-purpose AI models | EUR 15 million or 3 % | Applies only to model makers. The fine is imposed by the European Commission. | Art. 101 |
Example: a large company with a turnover of EUR 1 billion risks up to EUR 70 million for a prohibited practice, a small company with a turnover of EUR 10 million up to EUR 700,000. The percentage is calculated from worldwide annual turnover for the preceding financial year. The regulation sets no separate fine for missing AI literacy.
If an authority finds non-compliance in a system presenting a risk, it requires corrective action within at most fifteen working days. If none follows, it prohibits or restricts placing the system on the market or putting it into service, or ensures its withdrawal. The request itself does not rule out a fine. Art. 79, Art. 83
Documentation and, for high-risk systems, training and testing data. Source code only on a reasoned request, when it is necessary to assess conformity and other means have been exhausted. Art. 74(12) and (13)
The authority takes into account, among other things, cooperation, remediation, the measures in place and whether you reported the infringement yourself. It also considers fines for the same conduct under other laws, for example the GDPR. Art. 99(7)
Anyone with grounds to believe an infringement has occurred may lodge a complaint with a market surveillance authority: a customer, an employee or another company. Art. 85
This page is not legal advice.
Yes, but to a limited extent. The company must take AI literacy measures under Article 4, must not use AI for prohibited practices and must label published deepfakes. High risk depends on the purpose: if the tool is used, for example, to screen job applicants, that use falls under Annex III point 4 and under Art. 25(1)(c) the company becomes the provider of a high-risk system.
Yes. The basic obligations do not depend on size. For small and medium-sized enterprises, however, the fine cap is the lower of the two amounts (Art. 99(6)), and smaller providers get relief, for example simplified technical documentation.
What is mandatory is taking measures to support AI literacy under Article 4. The regulation prescribes no format, length or certificate, and after the amendment it expressly does not require guaranteeing a particular level for each individual. Training with a record of attendance is the most common and best documented measure.
No. Providers of generators must mark outputs in a machine-readable way. A company that publishes content must label deepfakes and text on matters of public interest unless it has undergone human editorial review for which someone holds editorial responsibility. Ordinary text reviewed by a person, for which the company is responsible, does not need an AI label under the AI Act.
As of 22 September 2026 we found no publicly known case of a fine imposed under the AI Act in the EU. The European Commission states that the enforcement powers of the AI Office and national authorities apply from 2 August 2026.
We go through how your company uses AI and tell you which AI Act obligations apply, from when, and how to document them.
Hands-on work with the tools you use, on your own agenda. You leave with a syllabus, an attendance record and draft company rules, the evidence of measures under Art. 4.
Independent review of your tool inventory, prohibited practices, transparency and the classification of high-risk uses before 2 December 2027.
The figures are based on the consolidated text of the regulation on EUR-Lex and on materials of the European Commission and the Czech government. The consolidated text has no legal effect of its own; only the texts published in the Official Journal of the EU are binding. This page is not legal advice. Machine-readable version of this page: /en/ai-act.md.
We go through how your company uses AI and tell you which obligations apply. You can also write to office@ciad.cz.