Almost everything written about the AI Act is addressed to the people building models. Almost every organisation we advise is on the other side of the line: it pays for a licence, and its people use the thing. For two years that felt like somebody else's regulation. It is not, it never was, and on 2 August 2026 the authorities that supervise it got their powers. Greece named its supervisor a few weeks before that. Here is the deployer's version.

First, the word that decides everything

The Act divides the world mainly into providers and deployers. A provider develops an AI system, or has one developed, and places it on the market under its own name. A deployer uses an AI system under its own authority in the course of a professional activity. If you bought a licence to an assistant, a transcription service, a CV-screening tool or an image generator and your staff use it at work, you are a deployer. There is no size exemption from the obligations below, and no sector exemption either.

One trap is worth naming early. If you take a general-purpose model, put your own name on the front of it and offer it to customers as your product, you have crossed the line and become a provider, with a much longer list. Several companies we have looked at did this by accident, through a white-labelled chatbot on a customer portal.

What the Digital Omnibus actually changed

You will have read that the AI Act was delayed. That is half true and the half matters.

The Digital Omnibus on AI was published in the Official Journal on 24 July 2026 and entered into force on 27 July, six days before the Act's original high-risk deadline. It deferred the application of obligations for stand-alone high-risk systems under Annex III from 2 August 2026 to 2 December 2027, and for AI embedded in products already covered by EU sectoral safety law under Annex I to 2 August 2028. It amended Article 6 so that systems used purely for non-safety aspects of user assistance, performance, optimisation, service efficiency or automation convenience are not treated as safety components. It kept a registration duty, in lighter form, for systems the provider has self-assessed as not high-risk. It added prohibitions on generating non-consensual intimate imagery and child sexual abuse material, and it simplified documentation for small and mid-cap companies.

What it did not do is push back the two obligations that actually land on an ordinary company. Those are literacy and transparency, and both were live on 2 August 2026.

Obligation one: AI literacy, Article 4

Article 4 has applied since 2 February 2025. It requires providers and deployers to take measures to ensure, as far as possible, a sufficient level of AI literacy among the staff and other people operating AI systems on their behalf, taking into account their technical knowledge, experience and the context of use.

The omnibus softened the wording from guaranteeing a level of literacy to taking measures that support its development. In plain terms it became an obligation of effort rather than of result, which is a genuine relief for anyone who was wondering how to prove that a colleague had understood something. What it did not become is optional. National market surveillance authorities gained formal powers to check compliance on 2 August 2026.

Two practical points people get wrong. First, Article 4 is not in the list of provisions that Article 99 makes directly fineable at EU level. That does not mean no consequence: member states may set national penalties for infringements the EU tiers do not cover, and in any proceeding about a bad AI outcome the absence of any literacy effort is the first thing a regulator or a claimant will point at. Second, there is no certificate, no mandated curriculum, no fixed number of hours and no EU-approved course that discharges the duty.

What satisfies it, in our experience, is something unglamorous: role-differentiated, proportionate and recorded. Managers and HR need to understand automation bias and how a person contests a decision. Anyone touching data needs to know where prompts go. Executives need to understand risk classification and who is accountable. An hour per role, a slide deck you actually wrote, an attendance list with dates, and a refresher when the tooling changes. We argued the wider case for doing this before adoption rather than after in Before You Adopt AI; Article 4 has now made the argument a legal one.

Obligation two: transparency, Article 50

Article 50 applies from 2 August 2026 and covers four situations. Two are provider duties: systems that interact directly with people must make the interaction disclosable, and systems generating synthetic audio, image, video or text must mark their output in a machine-readable way. Two are yours as a deployer.

  • Emotion recognition and biometric categorisation. If you operate such a system you must inform the people exposed to it. In an ordinary company this turns up in call-centre analytics and in some access-control products, often sold without either word being used in the brochure.
  • Deepfakes and AI-generated text. If you publish image, audio or video content that has been artificially generated or manipulated and constitutes a deepfake, you must disclose it. For text published to inform the public on matters of public interest, the same applies unless the content underwent human review and someone holds editorial responsibility for it.

Systems already on the market before 2 August 2026 that generate synthetic content have until 2 December 2026 to comply. Anything placed on the market from 2 August onwards had to comply from the start. Breaches of Article 50 sit in the Article 99 tier of up to fifteen million euro or three per cent of worldwide annual turnover, whichever is higher.

The cheap way to satisfy this is a labelling convention decided once and written into your content workflow, rather than a judgement call made by whoever is posting. We label our own machine-narrated audio and our AI-narrated video for exactly this reason, and it costs nothing once it is a habit.

Obligation three: find out whether anything you use is high-risk

The deadline moved to December 2027. The classification work did not, because you cannot plan for an obligation you have not discovered.

For a normal company that is not building medical devices, the Annex III category that bites is employment: systems used for recruitment, for screening or filtering applications, for evaluating candidates, and for decisions on promotion, termination, task allocation or monitoring performance. A CV-ranking feature inside a recruitment platform is the single most common high-risk system sitting unnoticed in a mid-sized European company. Credit scoring and certain insurance pricing are the next most common.

If you are a deployer of a high-risk system, your duties from December 2027 include using it in line with the instructions, assigning human oversight to people with the competence and authority to exercise it, making sure input data is relevant and sufficiently representative for the purpose, keeping the automatically generated logs, and informing workers and their representatives before putting such a system into use at work. None of that is achievable in the last month, which is the argument for doing the inventory now.

What Greece did, and who will knock

On 22 July 2026 Greece published Law 5321/2026, the national framework for applying the AI Act. Three things in it matter to you.

The Data Protection Authority is the central market surveillance authority, covering prohibited practices, high-risk systems and the transparency obligations. That is a consequential choice: the supervisor for your AI use is the same body that already supervises your personal-data processing, with the investigative habits that go with it. The telecommunications regulator is the notifying authority and hosts the coordination centre for the regulatory sandbox, including testing of high-risk systems in real-world conditions. Sector authorities retain competence in areas such as law enforcement, migration and asylum. The law also sets up a single complaints channel at the Data Protection Authority and brings reports of AI Act infringements under whistleblower protection.

A single complaints channel with whistleblower protection is worth pausing on. The most likely way your AI use becomes a regulator's business is not an inspection. It is an employee who was screened, monitored or scored by something nobody told them about.

The Monday-morning version

  1. Inventory. Every AI system in use, who owns it, what data goes in, whether the vendor is the provider and you the deployer. This is the same list you need for NIS2 supplier security and for any shadow-AI policy, so build it once.
  2. Classify. Prohibited, high-risk, transparency-triggering, or none of these. Write down the reasoning, not just the answer. The reasoning is what you will be asked for.
  3. Literacy. Role-differentiated, proportionate, recorded, with dates. Do it before you need to prove it.
  4. Labels. A written convention for disclosing synthetic content and for informing people subject to emotion recognition.
  5. An owner. One named person, reporting to the board, who holds the register and reviews it quarterly. The most common failure we see is not a wrong classification; it is a classification nobody has looked at since the tool changed.

The Act has been softened at the edges and it will probably be softened again. The direction has not changed, and the two obligations that reach every organisation are the two that were never postponed. If you use AI at work, the Act is already about you.


Sources: Regulation (EU) 2024/1689, as amended by the Digital Omnibus on AI (Official Journal, 24 July 2026; in force 27 July 2026); Article 4 and Article 50; Greek Law 5321/2026 on the national framework for the application of the AI Act (published 22 July 2026). Related reading: Before You Adopt AI: A Case for Literacy First and Shadow AI.