Skip to content
Back to the blog
6 min read

The AI Act in your company: what applies since August, and what moved to 2027

For two years the AI Act conversation was mostly about high-risk systems, and those have just been pushed back by more than a year. Meanwhile, on 2 August 2026, the rules that reach an ordinary company with a website chatbot or images from a generator started to apply. On 11 August a Polish act came into force that gives those rules a national supervisor.

RegulationAI ActGuide

What applies since 2 August

Article 50 of the AI Act sets out transparency duties. For a typical company three situations matter. First, an AI system that talks directly to people has to be designed so the person knows they are dealing with AI. The exception covers cases where this is obvious to a reasonably well informed, observant person. A chatbot called "Anna" with a smiling avatar is unlikely to qualify.

Second, if you publish an image, audio or video that is a deep fake, meaning it realistically shows people, places or events that never happened, you have to disclose that it was generated or manipulated. In clearly artistic, satirical or fictional work a light mention that does not spoil the piece is enough.

Third, AI generated text published to inform the public on matters of public interest has to be labelled too. That duty falls away when the text has been through human review and a person or company holds editorial responsibility for it. A company post drafted with a model, then read and corrected by the person who signs it, falls within that exception.

All of this has to be shown clearly and at the latest at the first interaction or first exposure to the content. A clause in terms of service nobody opens does not meet that bar.

A separate duty, machine readable marking of generated content, sits with the providers of generative systems: the companies that build the generator, not those that use it. For systems placed on the market before 2 August 2026 the Digital Omnibus provides a transition period until 2 December 2026. Beyond that transition period, the Omnibus did not move the Article 50 duties and left them largely as they were.

A Polish supervisor: KRiBSI

The Polish Act on AI systems (Dz.U. 2026 item 1003) was signed on 24 July, promulgated on 27 July and has been in force since 11 August. It creates the Commission for the Development and Security of Artificial Intelligence, KRiBSI, as Poland's AI market surveillance authority. The Sejm, with the Senate's consent, has two months to appoint its chair, and according to Kancelaria Macura the full Commission should start work in November 2026.

The date that matters most to a business is 28 October 2026. That is when the chapters on inspections, proceedings before the Commission and penalties take effect. From then any person, company or organisation can file a complaint with KRiBSI, electronically, describing the system and what they believe breaks the rules. A customer who did not know they were chatting with a bot gets a concrete address.

The Commission imposes fines under the AI Act's own rules. In the regulation's text, breaching the Article 50 duties can cost up to EUR 15 million or 3% of worldwide annual turnover, whichever is higher. For small and medium firms the lower of the two applies. Those are ceilings, and the Polish act lets the Commission cut a fine by 10 to 50% if the firm carries out the steps set out in the Commission's earlier warning within three months of receiving the fine decision.

Individual opinions also start on 28 October. For PLN 150 you can ask the Commission how the rules apply to a specific system, including one you are only planning. It has 30 days to answer, 60 in particularly complex cases. If it misses the deadline, the position set out in your request stands, and an opinion once issued binds the Commission in that matter.

What moved, and why you can breathe

The Digital Omnibus, Regulation (EU) 2026/1744, was published in the Official Journal on 24 July and entered into force on 27 July. It moves the high-risk deadlines. Standalone systems listed in Annex III, including those used in employment and education, such as CV screening, have to comply from 2 December 2027. Systems embedded in regulated products under Annex I follow from 2 August 2028.

The European Commission also says some relief previously reserved for SMEs now extends to small mid-cap companies, and access to regulatory sandboxes widens. Under the political agreement reached in May, as reported by Gibson Dunn, the deadline for member states to set sandboxes up is to move to 2 August 2027.

A free sandbox for SMEs

The chapter on the regulatory sandbox has applied since 11 August. KRiBSI picks participants through a call, and participation lasts 6 to 12 months. During that time a company tests its system under the Commission's supervision and gets help reaching AI Act compliance, and in justified cases permission to depart from some provisions. Micro, small and medium firms take part free of charge. Other companies pay a fee the act caps at four times the minimum wage, with the exact amount to be set by a regulation of the digital affairs minister.

The sandbox makes sense if you are building your own system that might fall into the high-risk category. For a customer service chatbot, a label and tidy records are enough.

Calendar

  1. 012 August 2026: AI Act Article 50 transparency duties
  2. 0211 August 2026: Polish act in force, including the sandbox rules
  3. 0328 October 2026: complaints, inspections and fines before KRiBSI, individual opinions
  4. 042 December 2026: content marking for generators placed on the market before 2 August 2026
  5. 052 December 2027: Annex III high-risk systems
  6. 062 August 2028: Annex I high-risk systems

What to do this quarter

Most of the work belongs before 28 October, because from that day any ambiguity can turn into a complaint.

This quarter's list

  1. 01Label the chatbot as AI in its first message, for example: "I am an AI assistant. You can ask for a person at any time."
  2. 02Go through images, video and audio from generators. Anything that realistically shows people or events that never happened gets an AI generated label.
  3. 03Set a rule for text: every AI assisted text is read and edited by a person who is accountable for it. The text labelling duty then does not apply.
  4. 04Ask your generator vendors how they mark content and whether they will be ready by 2 December 2026.
  5. 05List every AI system in the company: what it does, who provides it, whether it talks to customers, whether it touches hiring or assessing people.
  6. 06If a system touches employment or education, plan for the high-risk requirements before December 2027.
  7. 07If you are building your own AI system, check the terms of the KRiBSI sandbox call. For SMEs participation is free.

This piece lays out dates and duties; it is not legal advice. Check with your lawyer for your specific case, especially where the line between provider and user of a system falls for you. After 28 October a KRiBSI individual opinion for PLN 150 is a second route.

Sources

  1. 01EUR‑Lex, Regulation (EU) 2024/1689 (AI Act), Official Journal Lpublished 12 July 2024
  2. 02Dziennik Ustaw 2026 poz. 1003, Ustawa o systemach sztucznej inteligencjipublished 27 July 2026
  3. 03Gibson Dunn, EU AI Act Omnibus Agreement: Postponed High‑Risk Deadlines and Other Key Changespublished 27 May 2026
  4. 04European Commission, AI Omnibus enters into forcepublished 27 July 2026
  5. 05Hunton, EU Digital Omnibus on AI Enters Into Forcepublished 28 July 2026
  6. 06Kancelaria Macura, Ustawa o systemach sztucznej inteligencji podpisanapublished 28 July 2026
  7. 07Rzeczpospolita, Ustawa o AI weszła już w życie. Od października będzie można się na nią poskarżyćpublished 11 August 2026

Keep reading

6 min read

Jev: a model that returns a decision, not a sentence

TypeSafe AI released a model on 15 September that writes no text at all. It hands back a chosen option and a probability, costs $0.042 per million input tokens, and charges nothing for output. Here is what survives once the marketing is subtracted.

Read
7 min read

Agent skills: why five beat a hundred

With five skills in the pool, 29.6% of the skills an agent actually uses are the right one; with a hundred, 3.3%. And in August a public skills registry served clones that stole SSH keys. Four rules for a team working with agents.

Read

Show us the process that costs your team the most time

Describe it in a few sentences. We’ll tell you whether it can be improved, roughly what that would cost, and whether it needs AI at all.