Note: This article is for informational purposes and practical summary only, and does not constitute legal advice.
If you own a business or manage a team, there is a high chance you have recently received alarmist emails or calls from various “AI compliance experts.” Their message is almost always the same: your company allegedly risks massive fines of up to €35 million if employees use tools like ChatGPT without purchasing a course or diploma from them.
In reality, we are witnessing a classic fear-based sales strategy built on convenient omissions. No one from the European Union is going to show up overnight and fine your company simply because you designed a promotional banner or drafted an email using ChatGPT.
Here is what European legislation actually requires, what has been postponed, what took effect on August 2, 2026, and what practical steps you need to take.
What Was Postponed and What Remains Active: The Real AI Act Timeline
Numerous headlines in the public space have claimed that the entire AI Act has been delayed. The reality is more nuanced: the European Union recognized that the market and regulatory bodies were not yet ready for the full implementation of its most complex requirements.
- High-Risk AI Systems: Through the Digital Omnibus amendment passed in July 2026, the timeline for the most demanding compliance requirements was moved to December 2027.
- Transparency (Article 50): Remains fully active and enforceable starting August 2, 2026.
Provider vs. Deployer: What Is Your Company’s Role?
Before worrying about compliance, you must answer a fundamental question: are you building the application, or are you merely using it?
- Deployer: If your team uses tools such as ChatGPT, Google Gemini, or Canva for graphics, copywriting, and daily communications, your status is generally that of a deployer. The vast majority of complex technical obligations under the AI Act fall exclusively on the technology provider.
- Provider: You only become a provider if you develop and commercialize your own AI application under your company’s brand.
The regulation classifies AI applications across a risk pyramid. At the base are minimal-risk systems (such as spam filters and video games), and at the apex are unacceptable-risk systems (prohibited practices).
The Prohibited Zone: What Practices Are Completely Banned?
The maximum fines of €35 million are strictly reserved for completely prohibited practices.
One easy way a company could inadvertently enter this prohibited zone is by deploying emotion recognition software in the workplace—tools designed to analyze employees’ facial expressions or voices to measure stress or engagement levels. The use of emotion recognition systems in the workplace has been banned since February 2025, subject only to very narrow, strictly defined exceptions for medical or safety reasons.

Article 50: The 4 Transparency Rules in Effect from August 2, 2026
Starting August 2, 2026, businesses must maintain transparency in their interactions with the public and end users. Here are the 4 specific scenarios to review:
1. Website Chatbots
If you run an automated chatbot on your website, users must be informed clearly and conspicuously that they are interacting with an artificial intelligence. Hiding this disclosure in small print within the Terms and Conditions is not compliant.
2. AI-Generated Media (Deepfakes and Realistic Simulations)
If you publish AI-generated images, videos, or audio recordings that resemble real people, places, or events and could reasonably be mistaken for authentic media, they must be clearly labeled.
- Example: Presenting a fictional, AI-generated building as your company’s physical headquarters requires explicit labeling.
- Exception: Content that is obviously artistic or fantastical (such as a dragon or a floating city) is not subject to this requirement.
3. AI-Generated Text on Topics of Public Interest
Articles or text generated via ChatGPT or similar tools that cover topics of public interest must be labeled accordingly.
- The Editorial Exception: If the text has undergone thorough review by a qualified human, passed through an editorial control process, and an individual or legal entity publicly assumes responsibility for the content, labeling it as “AI-generated” is no longer mandatory.
- What Constitutes Public Interest? A commercial blog post about the quietest car tires is generally not a matter of public interest. Conversely, an official notice regarding a product safety recall or new mandatory regulatory standards falls directly into the public interest category.
4. Emotion Analysis in Call Centers
If you employ automated systems to analyze emotional cues from customers’ voices in a call center environment, customers must be clearly informed prior to the start of the call.
Important Technical Distinction: If the software first transcribes the call and exclusively analyzes the resulting text transcript, it does not automatically fall under the emotion recognition classification of Article 50. However, standard legal frameworks (including GDPR) continue to apply in full.
The Myth of “Mandatory” AI Literacy Certifications
Many commercial providers attempt to sell expensive courses by claiming that the law mandates certified diplomas for all employees.
The legislative framework is clear: companies are NOT obligated to obtain formal certifications or diplomas for every staff member.
For an SME using AI for copywriting, translations, or low-risk graphic design, an internal, proportionate approach is entirely sufficient:
- Draft a brief internal policy on acceptable AI tool usage.
- Conduct and document a short internal training session (a 15-minute briefing is often far more practical than a purchased certificate).
- Enforce strict rules against inputting personal data or confidential information (e.g., email addresses, passwords, national identification numbers, API keys) into unauthorized tools.
- Keep internal records of AI utilization (documenting who uses which tools and for what tasks).
- Require employees to fact-check any critical AI-generated output, mitigating the risk of model hallucinations.
What Are the Actual Fines, and What Has ANCOM Stated?
Citing a blanket €35 million fine misrepresents how sanctions are structured:
- €35 Million (or up to 7% of global turnover): Represents the statutory ceiling reserved exclusively for banned practices (unacceptable risk), not penalties for missing an internal certificate or omitting a disclosure tag.
- Transparency Violations Ceiling: Up to €15 million or 3% of global annual turnover.
- Principle of Proportionality: Any penalty must be strictly proportionate, taking into account the nature, gravity, duration of the infringement, resulting harm, and whether the non-compliance was intentional or negligent.
Furthermore, in Romania, ANCOM confirmed on July 24, 2026, that designated supervisory authorities cannot directly conduct inspections or issue administrative sanctions under the AI Act until the complete national enforcement architecture is formally enacted. While this does not waive existing obligations or exempt businesses from other active laws (such as GDPR or Consumer Protection regulations), it eliminates the risk of arbitrary, overnight enforcement audits.
A Practical 4-Step Checklist for Your Business
To ensure compliance without incurring unnecessary expenses, follow these internal steps:
- Inventory Your Tools: Maintain a simple register of all AI solutions used across your organization, identifying the users and specific use cases.
- Set Rules and Document Training: Establish clear, common-sense internal guidelines (covering privacy and output verification) and keep records of brief team briefings.
- Verify Transparency Elements: Confirm that public chatbots display clear notices, realistic synthetic media is labeled, public interest copy undergoes human editorial sign-off, and call center voice systems provide proper prior notification.
- Review Automated Decisions: Audit whether any AI systems are used in recruitment, performance evaluations, or other decisions that significantly affect individuals.
For the vast majority of small and medium-sized businesses, these measures can be managed entirely in-house by management or the IT department without requiring expensive external audits.
When All Is Said and Done…
Beyond the deadlines and technical criteria, the primary objective of these regulations is to establish accountability for AI-generated output and eliminate deceptive ambiguity.
Current models have become so sophisticated that distinguishing authentic content from synthetic simulations at a glance is increasingly difficult. In an environment where bad actors exist, baseline transparency rules are necessary to curb disinformation and manipulation.
While these measures inevitably place an administrative load on good-faith independent creators, developers, and small enterprises, the appropriate response is not panic or purchasing overpriced compliance packages. Instead, focus on establishing simple, transparent, and well-documented internal workflows early.
Useful Resources
- Labels: The European Commission provides a downloadable archive of standardized icons to label AI-generated content. Use is optional, but it serves as a practical reference: EU Icons for Labelling AI-Generated Content
- Action Plan: A structured 4-step PDF guide and checklist to help verify proper AI usage across your operations. Available here.
- AI Tool Inventory Register: A template PDF demonstrating how to log and monitor AI tool adoption internally to prevent “Shadow AI” (unauthorized software use) and maintain institutional transparency. Available here.
- Internal AI Training Protocol (Minutes Template): A sample PDF protocol to document internal employee training sessions and record mutual acknowledgement of company guidelines. Available here.
If you found this guide helpful, feel free to share it with colleagues and peers.





