AI ACT · REGULATION (EU) 2024/1689

AI Act

The EU regulation on artificial intelligence has been in force since 1 August 2024 and was amended in July 2026 by Regulation (EU) 2026/1744. Below: what it bans, when each obligation applies, what fines companies face and who enforces it, every figure with its article.

Regulation
(EU) 2024/1689
Amendment
(EU) 2026/1744
Verified
22 Sep 2026

What is the AI Act?

The AI Act is Regulation (EU) 2024/1689 of the European Parliament and of the Council, which sets rules for developing and using artificial intelligence across the EU. It applies directly, without national legislation, and covers companies that develop AI as well as those that only use it. The heaviest penalties are for prohibited practices, such as recognising employees’ emotions or social scoring: fines of up to EUR 35 million or 7 % of worldwide annual turnover.

What it is
Regulation (EU) 2024/1689, the Artificial Intelligence Act. Directly applicable across the EU, in force since 1 August 2024, amended in July 2026 by Regulation (EU) 2026/1744.
Who it covers
Companies and public bodies that develop AI and those that only use it, including companies outside the EU when the output is used in the EU. It does not cover purely personal use, systems used exclusively for military and defence purposes, or systems developed solely for scientific research and development (Art. 2).
Who enforces it in Czechia
The Czech act designating the supervisory authorities has not been adopted yet; the government has not discussed the draft submitted on 26 June 2026. Under the draft, supervision will be shared by the Czech Telecommunication Office (ČTÚ), the Czech National Bank (ČNB) and the Office for Personal Data Protection (ÚOOÚ). The obligations of the regulation apply directly regardless.

Verified as of on EUR-Lex and in the Czech eKLEP legislative system. Prepared by CIAD.

Does it apply to your company?

Obligations depend on the purpose of use. Most of them fall on sectors where AI decides about people: recruitment and managing employees, lending and insurance, education and public services. E-commerce and marketing deal mainly with transparency and the ban on manipulation.

SectorWhat applies to youHigh risk
E-commerce and customer serviceDisclosure for a chatbot you developed or had developed under your name (Art. 50(1)), labelling of deepfakes in advertising (Art. 50(4)), the ban on harmful manipulation (Art. 5(1)(a) and (b)), AI literacy.Usually not high-risk.
HR and recruitment agenciesScreening CVs and evaluating candidates and performance falls under Annex III point 4. Recognising the emotions of candidates and employees is already prohibited.High-risk from 2 Dec 2027 (Art. 26).
Banks, insurers, lendingCreditworthiness assessment of natural persons and pricing of life and health insurance fall under Annex III point 5. In addition, a fundamental rights impact assessment (Art. 27). Supervision by the Czech National Bank under the draft act.High-risk from 2 Dec 2027.
Marketing and agenciesLabelling of deepfakes (Art. 50(4)). AI-generated text must be labelled only on matters of public interest without editorial control. From 2 Dec 2026 intimate deepfakes are prohibited (Art. 5(1)(ba)).Usually not high-risk.
AI developers and SaaSProvider role: chatbot disclosure and machine-readable marking of outputs (Art. 50(1) and (2)), safeguards against prohibited outputs, and for high-risk uses conformity assessment, documentation, CE marking and registration. Relief for small and medium-sized enterprises.Depends on the purpose of the product.
Manufacturers of regulated productsAI as a safety component of a product under Annex I, for example in medical devices, lifts or toys.High-risk from 2 Aug 2028.
Schools and educationAdmission, assessment of learning outcomes and proctoring of exams fall under Annex III point 3. Recognising students’ emotions is prohibited.High-risk from 2 Dec 2027.
Municipalities and public authoritiesEligibility for benefits and public services falls under Annex III point 5. Fundamental rights impact assessment (Art. 27), registration. Legacy systems by 2 Aug 2030 at the latest. Under the Czech draft act, fines are capped at CZK 10 million.High-risk from 2 Dec 2027.

A general assistant such as ChatGPT is not high-risk in itself; its use becomes high-risk when, for example, it screens job applicants. The exception in Art. 6(3) and its limits are set out in Article 6 on EUR-Lex.

When does it apply?

Obligations phase in. The prohibitions and AI literacy have applied since 2 February 2025, transparency since 2 August 2026. Amendment (EU) 2026/1744 postponed only the high-risk obligations, to 2 December 2027.

  1. Already applies

    Prohibitions and AI literacy

    Prohibited practices under Art. 5 and the obligation to take AI literacy measures under Art. 4. From 2 Aug 2025 also the rules for general-purpose AI models and the penalty framework.

    Art. 113(a) and (b)
  2. Already applies

    Transparency

    Disclosure for chatbots, labelling of deepfakes and informing people about emotion recognition under Art. 50. From 2 Dec 2026 two prohibitions are added (intimate deepfakes and child sexual abuse material) and older content generators must mark their outputs in a machine-readable way.

    Art. 113, Art. 111(4)
  3. Postponed by the amendment

    High-risk systems

    Obligations for high-risk uses under Annex III, for example recruitment or creditworthiness assessment. For AI in products under Annex I only from 2 Aug 2028.

    Art. 113(c)

Every date including legacy systems: when AI Act obligations apply.

What does your company have to do?

Most companies only use AI. Above all they must avoid prohibited practices, take AI literacy measures and label deepfakes. More obligations come with high-risk use and with developing your own AI.

Every company that uses AI

Do not use AI for prohibited practices (Art. 5), take AI literacy measures (Art. 4), and from 2 Aug 2026 label published deepfakes and inform people about emotion recognition (Art. 50(3) and (4)).

A company with a high-risk use

From 2 Dec 2027 the deployer obligations under Art. 26: use in line with the instructions, human oversight, control of input data, logs kept for at least six months, informing employees and affected people.

A company that develops AI or sells it under its own name

Chatbot disclosure and machine-readable marking of generator outputs (Art. 50(1) and (2)). For high-risk systems the requirements of Art. 9 to 15, conformity assessment, CE marking and registration. A company also becomes a provider when it substantially modifies a high-risk system or places it on the market under its own name (Art. 25).

What you must never do

  • Subliminal, manipulative or deceptive techniques that materially distort a person’s decision-making and cause, or are reasonably likely to cause, significant harm to them or others.
  • Exploiting vulnerabilities due to age, disability or a social or economic situation, causing actual or likely significant harm.
  • Social scoring that leads to detrimental treatment in an unrelated context or treatment that is disproportionate. Applies to companies and public authorities alike.
  • Assessing the risk that a person will commit a criminal offence based solely on profiling or personality traits.
  • Facial recognition databases built from untargeted scraping of images from the internet or CCTV.
  • Inferring emotions in the workplace and in education institutions, except for medical or safety reasons.
  • Biometric categorisation by race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation.
  • Real-time remote biometric identification in publicly accessible spaces for law enforcement, outside narrow exceptions.
  • From 2 Dec 2026: realistic intimate images of an identifiable person without their consent, and child sexual abuse material.

The binding text is Article 5 on EUR-Lex.

What to have ready before an inspection

  • An inventory of AI tools: who uses them, for what, with which data and in which role the company acts.
  • A check that no tool serves a prohibited practice.
  • AI literacy measures by role and a record of them. No certificate is required.
  • Disclosure for your own chatbots and labelling of deepfakes.
  • Classification of high-risk uses and a plan to comply by 2 Dec 2027.
  • Supplier contracts that secure the instructions for use and the information you need.
  • A named person responsible for keeping the records.

How the Article 4 measure translates into training by role: AI training for companies and the Article 4 obligation. The binding text of the transparency rules: Article 50 on EUR-Lex.

What are the fines and for what?

Article 99 sets three fine caps. For companies the higher of the two amounts applies, for small and medium-sized enterprises the lower. Besides a fine, an authority can order corrective action, prohibit use of the system or withdraw it from the market.

InfringementMaximum fineFor exampleProvision
Prohibited practicesEUR 35 million or 7 %Software evaluates the emotions of employees or candidates; a company refuses customers based on a score derived from their social media behaviour.Art. 99(3)
Obligations of operators and transparencyEUR 15 million or 3 %Your own chatbot does not disclose that it is AI; an unlabelled deepfake in advertising; from 2 Dec 2027 screening candidates without human oversight or selling a high-risk system without conformity assessment and CE marking.Art. 99(4)
Incorrect information to authoritiesEUR 7.5 million or 1 %Incorrect, incomplete or misleading answers to a request from an authority.Art. 99(5)
Providers of general-purpose AI modelsEUR 15 million or 3 %Applies only to model makers. The fine is imposed by the European Commission.Art. 101

Example: a large company with a turnover of EUR 1 billion risks up to EUR 70 million for a prohibited practice, a small company with a turnover of EUR 10 million up to EUR 700,000. The percentage is calculated from worldwide annual turnover for the preceding financial year. The regulation sets no separate fine for missing AI literacy.

Beyond fines and during an inspection

Corrective action, then a ban

If an authority finds non-compliance in a system presenting a risk, it requires corrective action within at most fifteen working days. If none follows, it prohibits or restricts placing the system on the market or putting it into service, or ensures its withdrawal. The request itself does not rule out a fine. Art. 79, Art. 83

What an authority may request

Documentation and, for high-risk systems, training and testing data. Source code only on a reasoned request, when it is necessary to assess conformity and other means have been exhausted. Art. 74(12) and (13)

What reduces a fine

The authority takes into account, among other things, cooperation, remediation, the measures in place and whether you reported the infringement yourself. It also considers fines for the same conduct under other laws, for example the GDPR. Art. 99(7)

Complaints

Anyone with grounds to believe an infringement has occurred may lodge a complaint with a market surveillance authority: a customer, an employee or another company. Art. 85

This page is not legal advice.

Frequently asked questions.

Does the AI Act apply to a company that only uses ChatGPT or Copilot?

Yes, but to a limited extent. The company must take AI literacy measures under Article 4, must not use AI for prohibited practices and must label published deepfakes. High risk depends on the purpose: if the tool is used, for example, to screen job applicants, that use falls under Annex III point 4 and under Art. 25(1)(c) the company becomes the provider of a high-risk system.

Does the AI Act apply to small companies?

Yes. The basic obligations do not depend on size. For small and medium-sized enterprises, however, the fine cap is the lower of the two amounts (Art. 99(6)), and smaller providers get relief, for example simplified technical documentation.

Is AI literacy training mandatory?

What is mandatory is taking measures to support AI literacy under Article 4. The regulation prescribes no format, length or certificate, and after the amendment it expressly does not require guaranteeing a particular level for each individual. Training with a record of attendance is the most common and best documented measure.

Does all AI-generated content have to be labelled?

No. Providers of generators must mark outputs in a machine-readable way. A company that publishes content must label deepfakes and text on matters of public interest unless it has undergone human editorial review for which someone holds editorial responsibility. Ordinary text reviewed by a person, for which the company is responsible, does not need an AI label under the AI Act.

Has anyone been fined under the AI Act yet?

As of 22 September 2026 we found no publicly known case of a fine imposed under the AI Act in the EU. The European Commission states that the enforcement powers of the AI Office and national authorities apply from 2 August 2026.

First find out what applies to you. Then document it.

Review your obligations

We go through how your company uses AI and tell you which AI Act obligations apply, from when, and how to document them.

AI training for companies

Hands-on work with the tools you use, on your own agenda. You leave with a syllabus, an attendance record and draft company rules, the evidence of measures under Art. 4.

AI system verification

Independent review of your tool inventory, prohibited practices, transparency and the classification of high-risk uses before 2 December 2027.

FIRST STEP

Find out what the AI Act means for you.

We go through how your company uses AI and tell you which obligations apply. You can also write to office@ciad.cz.