Back to blog
AI Act

The EU AI Act for mid-sized companies: what you need in place now

One part of the AI Act starts to bite on 2 August 2026. The part most companies feared was postponed by seventeen months, one week ago. Here is the difference.

Radical AI Team31 July 20269 min read
EU flags outside the European Commission's Berlaymont building in Brussels

On Sunday 2 August 2026, part of the EU AI Act starts to apply in a way that a mid-sized company has to act on. Another part, most likely the part you were worried about, was postponed by seventeen months last week.

That postponement is no longer a rumour or a proposal. Regulation (EU) 2026/1744, the Digital Omnibus on AI, appeared in the Official Journal on 24 July 2026 and entered into force on 27 July. That was two days ago. Almost every explainer you will find today is older than that, which means it is wrong on at least one point.

This page sets out what actually applies to a company of fifty to three hundred and fifty people, what has moved, and what you can still do this week. It is not legal advice, but it does give you the dates and the article numbers to go on.

A warehouse employee reading output from a system on a tablet. Most companies meet the AI Act as a deployer, not as a builder.A warehouse employee reading output from a system on a tablet. Most companies meet the AI Act as a deployer, not as a builder.

The short version

For the overwhelming majority of companies in this size bracket it comes down to three things:

  1. You need to know where AI is running in your organisation. Not because an article demands that list in so many words, but because you cannot assess any of the other obligations without it.
  2. From 2 August 2026 you have to tell people when they are dealing with AI. That is Article 50, and it was not postponed.
  3. The people working with those systems need to understand enough about them. That is Article 4, in force since February 2025, and supervised from 2 August.

The heavy obligations, the conformity assessments and the technical documentation for high-risk systems, do not apply to most companies in this category, and have moved to 2 December 2027 in any case.

What exactly moved

The Omnibus replaces the original date of 2 August 2026 for high-risk systems with fixed new dates. One detail matters: Parliament and Council dropped the proposed mechanism that would have tied the delay to the availability of standards, and put hard dates in its place. So there is no standards process you need to track.

WhenWhat appliesChanged?
2 February 2025Prohibited AI practices (Article 5) and AI literacy (Article 4)No, already in force
2 August 2025Rules for general-purpose AI models, governance, penaltiesNo, already in force
2 August 2026Transparency obligations (Article 50) plus supervision and enforcement by national authoritiesNo, unchanged
2 December 2026New prohibitions on non-consensual intimate imagery and child sexual abuse material. Also the end of the grace period for watermarking systems already on the market on 2 AugustNew
2 December 2027High-risk systems under Annex III, the stand-alone applicationsMoved from 2 August 2026
2 August 2028High-risk AI embedded in regulated products, Annex IMoved from 2 August 2027

The row to remember is the one in bold. Everything around it has either been postponed or has applied for a long time.

The distinction that decides everything: do you build it or use it

The AI Act puts by far the most obligations on the provider, the party placing an AI system on the market or putting it into service under its own name. A fraction sits with the deployer, the party using the system inside its own organisation.

A wholesaler rolling out Copilot, a logistics company switching on a planning module from its TMS vendor, a construction firm summarising quotes: all deployers. The obligations resting on them are limited and workable.

The flip happens in two situations, both easier to reach than people assume. Put a system on the market under your own brand and you become a provider. Modify an existing system so substantially that its intended purpose changes, and the same applies. An off-the-shelf chatbot trained only on your own documentation usually remains a bought-in system. A model you fine-tune yourself and then offer to your customers does not.

The question is not how advanced it is. The question is whose name it goes out under.

When you are high-risk after all

High-risk sounds like something for hospitals and power stations, which is exactly why companies wave it away too quickly. Annex III lists eight areas, and two of them occur routinely in an ordinary company of this size.

The first is recruitment and workforce management. The regulation names systems used for the recruitment or selection of people, in particular to place targeted job advertisements, to analyse and filter job applications, and to evaluate candidates. Alongside that, systems making decisions on terms of employment, promotion or termination. If applications are pre-sorted automatically, you are in this category, even where the final choice rests with a human.

The second is access to essential services, including creditworthiness assessment and risk pricing in insurance. If you run customer acceptance on a scoring model, this is relevant.

One thing to hold on to: high-risk does not mean prohibited. It means a heavier regime, with a risk assessment, documentation, logging and documented human oversight. And, as of last week, with a start date of 2 December 2027 rather than next week. That is the seventeen months of slack you were handed, and it is enough time to do it properly instead of in a panic.

The trap here is not the requirements but the assumption. Almost every company this size does something with job applications. If your instinctive answer to whether you use AI in hiring is no, check which features your ATS vendor switched on over the past year first.

Article 50: the one real deadline on 2 August

Article 50 covers transparency, and it is unusually concrete. Four elements matter to an ordinary company.

People must know they are talking to a machine. A system interacting directly with people has to make that clear, unless it is obvious to someone reasonably well-informed and observant. A chat window on your site presenting itself as a colleague does not meet that bar.

Generated content must be marked in a machine-readable way. That is primarily an obligation on the provider of the generative system, not on you as a user. It is, however, a concrete question to put to your vendor.

Emotion recognition and biometric categorisation must be disclosed to the people subjected to it. This is the provision you are most likely to hit in a selection process or on a shop floor.

Deepfakes and published AI-generated text must be identifiable as such. For published text there is an exception where human editorial review and editorial responsibility apply. Which is exactly why an editorial process is more than a quality measure.

The information has to be given at the latest at the first interaction, clearly and distinguishably, and accessibly for people with disabilities. Buried in the terms and conditions does not count.

Article 4: softened, not gone

The original text of Article 4 required providers and deployers to take measures to ensure, to their best extent, a sufficient level of AI literacy among their staff. The Omnibus softened that standard: where it had to produce a result, it is now an effort. You must support the development of AI literacy, not guarantee a measurable level per employee.

That is genuine relief, and at the same time less than it looks. The duty was not postponed and not repealed, and from 2 August 2026 national market surveillance authorities formally have the power to enforce it. The difference is that demonstrable policy and demonstrable effort now suffice, instead of an exam result per person.

In practice that is half a day of work: record who uses which systems, what those people have been told about them, and when. More on what AI literacy means in practice is on the definitions page.

What you may not do, and what it costs

One category is absolute. Article 5 prohibits a number of practices outright, regardless of company size or sector. The two that genuinely occur in an ordinary company: emotion recognition in the workplace and in education, and untargeted scraping of facial images to build a recognition database. Both have been prohibited since February 2025.

The fines are in Article 99, and the gap between categories is wide.

InfringementMaximum
Prohibited practice (Article 5)EUR 35 million or 7 percent of total worldwide annual turnover
Most other obligations, including Article 50EUR 15 million or 3 percent
Incorrect or misleading information to an authorityEUR 7.5 million or 1 percent

There is a rule for smaller companies worth reading carefully. Where large undertakings face the higher of the two figures, small and medium-sized enterprises face the lower of the two. On a turnover of forty million euro, an Article 50 infringement caps at 1.2 million instead of 15 million. Still not a number to ignore, but not the existential threat this regulation is often sold as either.

Making a list by hand. The inventory of where AI is already running is the one step nobody can do for you.Making a list by hand. The inventory of where AI is already running is the one step nobody can do for you.

What to do this week

Four steps, in this order, none of which needs a lawyer.

One: make the list. Everything with AI in it that runs in your organisation. Do not forget the features your vendor quietly switched on in software you have had for years. In most companies that is where the surprises are, not in the projects you started yourself.

Two: note the provider per line. In nearly every case that is your vendor and not you. Where it is not, or where you are unsure, put a question mark, and that shorter list is the one that goes to a lawyer. Usually it is one or two lines, not thirty.

Three: check Article 50 against the systems that talk to people. Customer service, hiring processes, the chat on your site. Does the system say it is a system? If not, that is a copy change, not a project.

Four: write down who decides. Not because the law demands it in this form, but because every obligation above eventually comes down to a person who can explain why a system does what it does. That is the core of a workable AI policy and of human on the loop: a person supervising and able to intervene, rather than someone handed a log file after the fact.

Where this goes wrong

Two patterns come up most often.

The first is the organisation that launches a compliance project for obligations that do not rest on it. It costs a quarter, produces a folder nobody opens, and mainly has the effect of stalling the real work. The high-risk obligations do not apply to most companies in this size bracket, and they are eighteen months away.

The second is the organisation that does nothing because it was postponed, and discovers a year later that dozens of systems are running that nobody knows about. The inventory is not compliance work. It is the same list you need in order to decide where AI actually earns you something, which is the reason to make it either way.

One more thing about this page

Outdated regulatory content does more harm than no content. This page describes the state of play on 29 July 2026 and links each claim to the source where you can check it yourself. The Omnibus is two days old and the national implementation in the Netherlands has not settled. Verify the dates again before basing a decision on them, and consult a lawyer for your own situation.

Frequently asked questions

Yes, but with far fewer obligations. As a deployer you mainly face Article 50 transparency from 2 August 2026, the Article 4 AI literacy duty, and the absolute prohibitions in Article 5. The heavy provider obligations sit with your vendor, unless you put a system on the market under your own name or change its intended purpose.

Sources

  1. Europese Commissie: de AI Omnibus treedt in werkingdigital-strategy.ec.europa.eu
  2. AI Act artikel 50: transparantieverplichtingen voor aanbieders en gebruiksverantwoordelijkenartificialintelligenceact.eu
  3. AI Act artikel 4: AI-geletterdheid, de oorspronkelijke tekstartificialintelligenceact.eu
  4. AI Act artikel 5: verboden AI-praktijkenartificialintelligenceact.eu
  5. AI Act artikel 99: sancties, boetebedragen en de MKB-uitzonderingartificialintelligenceact.eu
  6. AI Act bijlage III: de acht gebieden met hoog-risico AI, waaronder werving en selectieartificialintelligenceact.eu
  7. Gibson Dunn: de nieuwe data uit het Omnibus-akkoord, bijlage III naar 2 december 2027gibsondunn.com
Looking for AI talent?

Tell us what you need.

We respond within 24 hours, from a real human.

Get in touch