01AI literacy for your staff
Article 4. You must take measures so that everyone who operates or relies on an AI system on your behalf has a sufficient level of AI literacy: what the system does, where it fails and when to step in. Since the Digital Omnibus this is a duty of effort, judged on the measures you take: role-based training, written instructions, a named contact. Keep records of the training; they are your evidence.
Applies now
02Prohibited practices
Article 5. Ten practices are banned outright, among them manipulative or deceptive techniques that cause harm, exploiting vulnerable groups, social scoring, emotion recognition in the workplace and in schools, and untargeted scraping of facial images. Two bans on generating non-consensual intimate content and child abuse material were added by the Digital Omnibus and apply from 2 December 2026.
Applies nowTwo new bans from 2 December 2026
03Tell people they are talking to AI
Article 50(1). Chatbots, voice agents and avatars must make clear at the first interaction that they are AI, unless it is obvious to a reasonably attentive person. The design duty sits with the provider; as the deployer you must run the system so that the disclosure actually reaches your customers, and if you rebrand or substantially modify the tool, the provider duty becomes yours. A discreet line in the footer is not enough: the disclosure has to be clear, distinguishable and accessible.
Applies now
04Mark and label generated content
Article 50(2) and 50(4). Providers must give generated text, images, audio and video a machine-readable mark, and deployers must visibly label deepfakes and AI-written text published on matters of public interest without human review; artistic works and text under editorial responsibility have their own exceptions. Systems that were already on the market get until 2 December 2026 for the machine-readable marking.
Applies now
05Emotion recognition and biometrics
Article 50(3) and Article 5. If a system reads emotions or sorts people by biometric traits, the people concerned must be informed and their personal data handled under GDPR. In the workplace and in education, emotion recognition is banned altogether, except for medical or safety reasons.
Applies now
06Human oversight of high-risk systems
Articles 14 and 26. For high-risk uses such as recruitment and HR decisions, credit scoring, insurance pricing, education and access to essential services, a competent and trained person must be able to understand the output, monitor it, and override or stop the system. Deployers keep the logs for at least six months, follow the provider's instructions and inform workers before use. The Digital Omnibus set these duties for 2 December 2027 for stand-alone systems and 2 August 2028 for AI built into regulated products; the preparation takes most of that time.
From 2 December 2027
07Where your data lives
The AI Act does not prescribe a hosting location. GDPR restricts moving personal data outside the EU, and prompts, transcripts and CRM records in sales, service and HR almost always contain personal data. EU-hosted models and storage, a processing agreement that rules out training on your data, and a data protection impact assessment where the risk warrants it, are the controls we recommend: they avoid transfer assessments for that data and answer the questions that enterprise clients and tenders ask first.
Applies now
08Records that prove it
An inventory of every AI system, including the ones inside your SaaS tools, with its role and risk class, instructions of use, training records, logs, incident notes and the assessments you performed. When a client, an auditor or the market surveillance authority asks, the answer is a document, not a meeting.
Applies now