Skip to content
ORTHODROMECONSULTING
Regulatory brief

EU AI Act: what a company that only uses AI must do

You have not built any artificial intelligence, but your teams use it every day. The regulation still applies to you. Here is what, since when, and in what order to deal with it.

Updated 04 August 2026

This resource provides general information, accurate as of the date shown. It does not constitute legal advice and does not replace analysis by a qualified professional in light of your situation.

We built nothing. Does the AI Act still apply to us?

Yes, as soon as you use an AI system professionally. Regulation (EU) 2024/1689 separates the provider, who develops the system and places it on the market under its own name, from the deployer, who uses it "under its authority", except for personal, non-professional use (Article 3(4)). A conversational assistant, CV screening, an agent answering your customers: you are a deployer.

Good news: most of the burden sits with the provider. Your obligations are few — but real, and several already in force.

The role is assessed system by system: rebrand, substantially modify, or repurpose a high-risk system, and you become its provider (Article 25).

What actually applies since 2 August 2026?

The timeline changed a week before the deadline. Much of what ran in the spring is now wrong.

Since 2 February 2025: prohibited practices (Article 5) and AI literacy (Article 4).

Since 2 August 2025: general-purpose AI models, governance, penalties (Articles 99 and 100, except 101).

Since 2 August 2026: the rest of the regulation (Article 113), including transparency (Article 50).

But the Digital Omnibus on AI — Regulation (EU) 2026/1744 of 8 July 2026, in the Official Journal on 24 July, in force since 27 July — postponed high risk: 2 December 2027 for Annex III, 2 August 2028 for AI embedded in already regulated products (Annex I).

What remains for you: prohibitions, literacy, transparency.

AI literacy (Article 4): what is actually required?

Proportionate measures so your teams understand the tools they handle. Nothing more.

Article 4 has applied since 2 February 2025, rewritten by the omnibus with effect from 27 July 2026: take measures to support the development of AI literacy — without, the text specifies, guaranteeing any given level for any given person. An obligation of means.

No set format, no minimum hours, no certificate, no accredited body. An offer selling a certified course as a legal requirement describes a text that does not exist.

What counts: measures proportionate to the context and the people, and a record — what was circulated, when, to whom. A two-page briefing people actually read beats a training plan that never starts.

Which uses are simply prohibited?

Article 5 has banned eight categories of practice since 2 February 2025. Three can reach an ordinary company with no bad intent.

Inferring emotions at work or in education (Article 5(1)(f)), outside medical or safety purposes — what "engagement analysis" and "motivation scoring" features sell in video interviews or contact centres.

Social scoring (Article 5(1)(c)): rating people on their social behaviour, then treating them detrimentally in a context unrelated to the data collected.

Building facial recognition databases by untargeted scraping of images online or from CCTV (Article 5(1)(e)).

The only block with the top penalty ceiling, and the only one documentation cannot repair: a prohibited use is stopped.

Do we have to label AI-generated content?

Yes, in three cases, since 2 August 2026 (Article 50).

Emotion recognition or biometric categorisation: you inform the people exposed of how it operates (paragraph 3).

A deepfake — generated image, audio, or video resembling real people, places, or events: you disclose that it is artificial (paragraph 4), with a narrow exception for artistic, satirical, or fictional works.

AI-generated text published to inform the public on matters of public interest: you disclose it, unless it underwent human editorial review and someone holds editorial responsibility (paragraph 4).

The "you are talking to a machine" notice sits with the provider (paragraph 1) — but check your interface: it is what your customer sees. Machine-readable marking only becomes enforceable on 2 December 2026 for systems already on the market: your provider's duty, but the proof of where a piece of content came from.

Are our HR or scoring tools "high-risk"?

Possibly. The deferral changes the date, not the answer.

Of the eight areas in Annex III, three cross everyday SME operations: employment and worker management (candidate screening, task allocation, performance evaluation), access to essential services (creditworthiness, life and health insurance pricing), education and vocational training.

If one of your tools falls there, the deployer obligations of Article 26 — use in line with the instructions, human oversight by competent people with real authority, monitoring of operation, log retention, prior information of affected workers — take effect on 2 December 2027.

Two reasons not to wait: these obligations shape how the tool is chosen and configured — after deployment, what looms is a replacement, not an adjustment — and the GDPR, for its part, already applies in full.

What is the real exposure, and who enforces it?

Article 99 sets three ceilings: 35 million euros or 7 % of worldwide turnover (prohibited practices); 15 million euros or 3 % (other infringements, including Article 50); 7.5 million euros or 1 % (incorrect information supplied to authorities). The applicable cap: the higher of the two — except for SMEs and start-ups, where it is the lower one (Article 99(6)). Your exposure is capped by a percentage of turnover, not by the 35 million euros in the headlines.

Article 4 carries no dedicated fine (Article 99(4)). It is still binding: a failure surfaces elsewhere — an employment dispute, a customer complaint, an insurance questionnaire, a supplier audit.

In France, enforcement is spread across some fifteen sectoral authorities — the CNIL, the DGCCRF, and Arcom foremost, with the DGCCRF coordinating (scheme published by the Directorate General for Enterprise, 9 September 2025). Its formalisation in national law is late; that suspends nothing, as the regulation applies directly.

Where should we start?

One thing is genuinely urgent: knowing what you use. Four steps.

Inventory. Every AI system, including those nobody approved: the assistant open in a browser tab, the summariser on by default, the extension a team installed in a hurry. The longest step, and the only one no template replaces.

Qualify the role, system by system: deployer almost everywhere, provider if you rebrand a tool or change its intended purpose.

Classify. Prohibited: stop now. Annex III: December 2027, but revisit tool choices today. Transparency: enforceable now. Everything else — the bulk of it — comes down to literacy and your own rules.

Record. A reasoned, dated decision beats a perfect policy nobody follows. It is what a customer, an insurer, or an authority will read.

The inventory, along the way, usually reveals more tools than expected — and less high-risk AI than feared.

How we handle this

Mapping and classifying usage is part of the framing work, not a separate engagement: you cannot decide where AI creates value without knowing where it already is.

This does not replace your legal counsel: we document, we classify against the text, and we flag what a lawyer must decide.

Frequently asked questions

Does the AI Act really apply to small and mid-sized companies?
Yes. No headcount or turnover threshold exempts you: the text scales by role and risk, not by size. The one concession: your fine is capped at the lower of the two amounts (Article 99(6)).
Is using a generative assistant at work prohibited?
No. There is no blanket ban: the regulation prohibits specific uses (Article 5), requires certain disclosures (Article 50), and asks for literacy (Article 4). The real daily risk: data protection and trade secrets — whatever goes into a prompt leaves your information system.
Do we need certified AI training for our staff?
No. Article 4 is an obligation of means — its rewrite by Regulation (EU) 2026/1744 confirms it: no format, no duration, no certification. What counts is proportionality, and a record of what was done.
Does the December 2027 deferral give us breathing room?
No. It only covers high-risk systems (Annexes III and I). Prohibitions and literacy have applied since February 2025, transparency since 2 August 2026.
Is our vendor liable instead of us?
No. A contract can organise recourse between you; it does not transfer the regulatory burden. Your vendor's documentation still conditions your compliance: ask for it before signing.
Are we in scope if we are established outside the EU?
Yes, wherever the output produced by the system is used in the Union (Article 2). Where your head office sits is not enough to place you outside the text.

Sources

So where do you start?

Describe your situation: you get a heading, a scope and a quote in return. No commitment.

Reply within 48 business hours · No commitment · Confidential