Free AI Act Readiness Check for SMEs
Know where your organisation stands in fifteen minutes. This free check translates the law into concrete questions and builds your dossier automatically along the way:
- Know where you stand in fifteen minutes
- Automatic AI Act dossier: register, transparency statement, action plan, policy outline and calendar reminders
- Privacy-first: everything stays in your browser, we store nothing
- Free, and also available in Dutch
The European AI Regulation, better known as the EU AI Act, is the first binding AI legislation in the world. The law was published in the Official Journal of the European Union on 12 July 2024, entered into force on 1 August 2024 and has been applying in phases ever since. From 2 August 2026 the bulk of the regulation genuinely starts to bite: the transparency obligations under Article 50, the enforcement powers over general-purpose AI, and the full penalty regime. The heavy high-risk obligations, by contrast, have been pushed back to 2 December 2027 and 2 August 2028.
That distinction is crucial and is frequently misunderstood in practice. A delay of the high-risk deadlines does not make 2 August 2026 a quiet date. For most organisations that use AI through a subscription or an integrated tool, that is precisely the moment their first concrete obligations become enforceable.
In this guide we explain what the regulation covers, which risk categories exist, which deadlines apply after the Omnibus, and how your organisation can become compliant step by step. We close with the most common mistakes and a practical roadmap.
What changed recently?
The most important development since the previous version of this article is that the so-called Digital Omnibus on AI, also referred to as the AI Omnibus or Omnibus VII, has moved from political agreement to completed legislation.
The political agreement of 7 May 2026 is now final. The European Parliament approved the text at first reading on 16 June 2026, after which the Council of the European Union gave its definitive approval on 29 June 2026. This concluded the ordinary legislative procedure. The amending regulation will be published in the Official Journal and enters into force on the third day following publication, well ahead of 2 August 2026.
| Date | Event |
|---|---|
| 19 November 2025 | European Commission presents the Digital Omnibus package. |
| 13 March 2026 | Council adopts its negotiating position. |
| 28 April 2026 | Second trilogue ends without agreement. |
| 7 May 2026 | Provisional political agreement between Parliament, Council and Commission. |
| 13 May 2026 | Publication of the final compromise text, confirmed by Member States. |
| 19 May 2026 | Commission publishes draft guidelines on the classification of high-risk AI systems. |
| 10 June 2026 | Commission publishes the Code of Practice on Transparency of AI-Generated Content. |
| 16 June 2026 | European Parliament approves the Omnibus at first reading. |
| 29 June 2026 | Council grants final approval. Legislative procedure concluded. |
| 7 July 2026 | Commission presents the EU Action Plan on Cybersecurity and Artificial Intelligence. |
| 9 July 2026 | Commission publishes its opinion on the assessment of the Code of Practice on Transparency of AI-generated content. |
| 22 July 2026 | Deadline to appear on the first public list of initial signatories to the Code of Practice. |
The core of the Omnibus in five points:
- Deferral of the high-risk obligations to 2 December 2027 (Annex III) and 2 August 2028 (Annex I).
- Two new prohibited practices in Article 5: nudifier applications and AI-generated child sexual abuse material, applying from 2 December 2026.
- A grace period until 2 December 2026 for machine-readable marking of synthetic content by systems already on the market before 2 August 2026.
- Resolution of the double compliance between the AI Act and sectoral product legislation, in particular the Machinery Regulation.
- Extension of the SME simplifications to small mid-caps and a reformulation of the AI literacy obligation.
What has not changed: the risk-based structure, the conformity assessment model, the dedicated track for general-purpose AI, the AI Office and the full penalty regime all remain intact.
What is the EU AI Act?
The AI Act is European legislation that regulates artificial intelligence based on the risk a system may pose to people and society. The greater the risk, the heavier the requirements. The regulation uses a tiered approach with four categories, each carrying its own obligations.
The AI Act applies extraterritorially. Organisations established outside the EU must also comply as soon as their AI systems, or the output of those systems, are used within the EU. In legal circles this is known as the Brussels Effect.
Under the final text, an AI system is a machine-based system designed to operate with varying levels of autonomy, that may exhibit adaptiveness after deployment, and that infers from the input it receives how to generate outputs such as predictions, content, recommendations or decisions that can influence physical or virtual environments.
Systems that rely exclusively on simple mathematical optimisation or long-established methods, such as standard linear or logistic regression without adaptive components, fall outside the scope. Once these methods are combined with techniques such as reinforcement learning, they are generally treated as AI systems.
The four risk categories
1. Prohibited AI practices
Since 2 February 2025, eight categories of AI applications have been fully banned in the EU. The legislator has drawn a hard line against practices considered unethical or manipulative.
- Harmful manipulation through subliminal techniques that alter behaviour unconsciously.
- Exploitation of vulnerabilities based on age, disability or socio-economic situation.
- Social scoring by public authorities or private entities based on behaviour or personality.
- Predictive policing that forecasts the likelihood of a crime based on profiling.
- Emotion recognition in the workplace or in educational institutions, except for strict safety purposes.
- Biometric categorisation based on race, religion, political opinion or sexual orientation.
- Real-time remote biometric identification in public spaces by law enforcement.
- Untargeted scraping of biometric data from the internet or CCTV.
Two new prohibitions from 2 December 2026
The Omnibus adds two practices to Article 5. These are not yet in force and only become enforceable on 2 December 2026.
- AI systems that generate or manipulate realistic depictions of an identifiable person's intimate parts, or of an identifiable person engaged in sexually explicit activity, without that person's freely given, specific, informed, unambiguous and explicit consent.
- AI systems that generate or manipulate child sexual abuse material within the meaning of Directive 2011/93/EU, subject to a narrow carve-out where national law recognises a without right defence.
The prohibition extends to three acts: placing a system on the market for this purpose, placing a system on the market without reasonable safety measures to prevent such use, and use of the system by a deployer. Whether safety measures are reasonable is assessed against the state of the art and whether they demonstrably reduce risk. Breach falls in the heaviest penalty tier: up to 35 million euro or 7 percent of global annual turnover. The Commission has announced further guidelines on the precise scope.
2. High-risk AI
High-risk systems are permitted provided the strictest requirements are met. These systems are identified through two routes. The first covers systems acting as a safety component in products already governed by existing EU harmonisation legislation, such as medical devices, lifts and radio equipment. The second covers stand-alone systems explicitly listed in Annex III.
Examples of Annex III applications:
- Biometrics and remote biometric identification
- Critical infrastructure such as road traffic, water supply and electricity
- Education and vocational training, including admission and exam grading
- Employment and workforce management, including targeted job advertising, filtering applications, performance evaluation, task allocation, promotion and termination
- Access to essential services such as credit scoring and insurance risk assessment
- Law enforcement, migration, asylum and border control
- Administration of justice and democratic processes
For these systems, providers must carry out a conformity assessment, implement a risk management system, draw up technical documentation and ensure effective human oversight.
Transitional regime and the notion of significant change
An important but underexposed part of the transitional regime: the Chapter III high-risk obligations apply to systems already on the market before the date of application only where those systems subsequently undergo significant design changes.
3. Limited-risk AI: the deadline that really is 2 August 2026
This tier covers systems subject to transparency requirements but not to heavy compliance duties. Article 50 sets out four duties:
- Article 50(1): inform people that they are interacting with an AI system, for example a chatbot.
- Article 50(2): mark generative output in a machine-readable format as artificially generated or manipulated.
- Article 50(3): inform people exposed to emotion recognition or biometric categorisation.
- Article 50(4): label deepfakes, as well as AI-generated or AI-manipulated text published to inform the public on matters of public interest, unless it has undergone human review with editorial responsibility assumed.
Article 50 has not been delayed. The transparency obligations become enforceable on 2 August 2026. Only the machine-readable marking under Article 50(2) benefits from a grace period: generative systems already placed on the market or put into service before 2 August 2026 have until 2 December 2026. Systems entering the market after that date must comply immediately.
The Code of Practice on Transparency of AI-Generated Content
On 10 June 2026 the Commission published the final Code of Practice on marking and labelling AI-generated content. It was developed through a multi-stakeholder process involving more than 180 participants and six independent experts appointed by the AI Office.
| Aspect | Explanation |
|---|---|
| Status | Voluntary instrument, not a replacement for Article 50 or the Commission guidelines. |
| Structure | Two separate sections, one for providers and one for deployers, signable independently. |
| Effect | If assessed positively, signatories may rely on the Code to demonstrate compliance. |
| Assessment | On 9 July 2026 the Commission published its opinion on the assessment of the Code, alongside the AI Board. |
| Signing | To appear on the first public list, the form must be submitted before 18:00 CET on 22 July 2026. Signing later remains possible. |
In parallel, the Commission is finalising guidelines interpreting the scope of Article 50, to be published ahead of 2 August 2026. The draft text indicates, among other things, that a deepfake must show an appreciable rather than identical resemblance, that the subject must be realistic and capable of existing, and that minor technical edits such as colour correction or noise reduction do not by themselves create a deepfake.
4. Minimal risk
The vast majority of AI applications, such as spam filters, recommendation systems and AI in video games, fall into this category. No additional legal obligations apply under the regulation, although voluntary codes of conduct are encouraged.
General-Purpose AI: regulating the foundations
The rapid rise of Large Language Models such as GPT, Claude and Gemini led to a separate chapter on General-Purpose AI, or GPAI. These models can be integrated into countless downstream applications, so specific rules apply to their providers. Those obligations have applied since 2 August 2025.
The Commission's enforcement powers over GPAI providers only switch on from 2 August 2026. The first year was therefore compliance on paper without penalty exposure. That now changes.
Providers of GPAI models must:
- Maintain technical documentation about the model and its training.
- Provide information to downstream users integrating the model.
- Operate a policy to comply with EU copyright law.
- Publish a public summary of the training data used.
Models trained with compute exceeding ten to the power of twenty-five floating point operations are automatically classified as models with systemic risk. Providers of such models must conduct additional evaluations, mitigate risks through adversarial testing and report serious incidents directly to the European AI Office.
The GPAI Code of Practice
On 10 July 2025 the AI Office published the voluntary GPAI Code of Practice, covering three chapters: Transparency, Copyright, and Safety and Security. Signing earns a rebuttable presumption of conformity and a lighter administrative load. Roughly twenty-four organisations have signed, including Amazon, Anthropic, Google, IBM, Microsoft, Mistral AI, Aleph Alpha, Cohere and Samsung Electronics. Meta declined to sign, and xAI signed only the Safety and Security chapter.
The Omnibus additionally clarifies the division of competence between the AI Office and national authorities for supervising AI systems built on GPAI models. Until now this was a grey area.
Provider or deployer: your responsibility
This is the part of the law that surprises most business owners. Even if you do not build AI yourself but simply buy it through a subscription, you are legally a deployer and carry your own obligations.
The law draws a fundamental distinction between providers, meaning companies that develop AI systems or place them on the market, and deployers, meaning organisations that use AI in their working processes. Under Article 3 of the AI Act, any organisation applying AI to support or automate business processes is a deployer. The regulation also assigns roles to importers, distributors and authorised representatives.
Your responsibility as a deployer includes:
- Understanding the purpose for which you use the AI and the associated risks.
- Ensuring human oversight for decisions that directly affect people.
- Being transparent towards customers, applicants and other affected persons.
- Documenting how you use AI and what measures you have taken.
- Meeting the AI literacy requirement for your staff.
Which tools do you actually use?
Many business owners do not know exactly which AI systems are used in their organisation, for what, and by whom. That is usually the first obstacle: you cannot assess compliance without an inventory. Below are common tools and the risk category they typically fall into.
| Tool or system | Risk category | Explanation |
|---|---|---|
| ChatGPT, Claude, Gemini for internal tasks | Limited or minimal | Low risk when used for text, summarisation or analysis. Responsibility shifts once decisions about people are involved. |
| AI chatbot on your website | Limited risk | Article 50(1). From 2 August 2026 users must explicitly know they are talking to AI. |
| Image or video generator in marketing | Limited risk | Articles 50(2) and 50(4). Machine-readable marking and visible labelling of deepfakes. |
| AI recruitment tool ranking candidates | High risk | Falls under Annex III, employment and workforce management. Deadline 2 December 2027. |
| AI in accounting or invoicing software | Minimal risk | No legal obligations, provided no decisions about people are made. |
| AI scoring for credit or payment behaviour | High risk | Explicitly named in Annex III. |
| AI for automated CV screening | High risk | Falls under employment and workforce management. |
| Marketing AI for segmentation | Limited or minimal | Depends on the impact on individuals. |
| AI in medical diagnostic support | High risk | Falls under regulated products. Deadline 2 August 2028. |
| AI in machinery and industrial control | Outside direct scope | Largely handled under the Machinery Regulation after the Omnibus. |
Timeline and deadlines after the Omnibus
The AI Act is being introduced in phases. The Digital Omnibus on AI moved several deadlines, but the overall direction stands. A wait-and-see strategy is risky, because conformity assessments and selecting a Notified Body often take twelve to eighteen months.
| Component | Original date | Current date |
|---|---|---|
| Prohibited practices (Article 5) | 2 February 2025 | Already in force |
| AI literacy (Article 4) | 2 February 2025 | Already in force, text revised |
| GPAI obligations | 2 August 2025 | Already in force |
| Transparency for chatbots and deepfakes (Article 50) | 2 August 2026 | 2 August 2026, unchanged |
| GPAI enforcement and penalty regime | 2 August 2026 | 2 August 2026, unchanged |
| Machine-readable marking, legacy systems (Article 50(2)) | 2 August 2026 | 2 December 2026 |
| Ban on nudifier apps and AI-generated CSAM | Did not exist | 2 December 2026 |
| National AI regulatory sandboxes | 2 August 2026 | 2 August 2027 |
| Interoperable watermark detection (Code of Practice) | Did not exist | 2 February 2027 |
| High-risk AI, Annex III stand-alone | 2 August 2026 | 2 December 2027 |
| High-risk AI, Annex I regulated products | 2 August 2027 | 2 August 2028 |
Sectoral overlap and the machinery carve-out
One of the most persistent criticisms of the original AI Act was double compliance for products already covered by EU product safety legislation. An AI-driven industrial machine had to satisfy both the Machinery Regulation and the AI Act simultaneously, with partly overlapping and sometimes contradictory requirements.
The Omnibus addresses this directly:
- Machinery falls outside the direct application of the AI Act where overlap exists. Health and safety aspects are handled directly under the Machinery Regulation.
- For other sectoral legislation, such as that governing medical devices, connected vehicles and toys, the Commission will issue implementing acts.
- The definition of safety component has been amended.
- Alongside the AI Act, the AI Omnibus also amends the EASA Basic Regulation (EU) 2018/1139, keeping AI integration in aviation within the existing safety regime.
Relief for SMEs and small mid-caps
The AI Act already contained a simplified compliance framework for SMEs. The Omnibus extends those facilities to small mid-cap companies, abbreviated in the legal text as SMCs.
| Aspect | Detail |
|---|---|
| Scope | Companies up to roughly 750 employees and 150 million euro annual turnover. |
| Simplified documentation | Standardised templates for technical documentation. |
| Sandbox access | Priority access to national AI regulatory sandboxes. |
| Penalties | Proportionally lower maximum amounts. |
| Guidance | Simplified guidance from the Commission and the AI Office. |
Registration in the public EU database
The AI Act provides for a central, publicly searchable EU database in which high-risk AI systems are registered. The registration duty has been extended to providers of so-called exempted AI systems, meaning systems that fall outside the high-risk category based on a risk assessment despite operating in an Annex III domain.
A lighter information duty applies to these exempted systems. In Annex VIII, Section B, points 7 and 9 have been deleted for systems self-assessed as non-high-risk. The underlying registration requirement, however, stands in full.
What this means in practice:
- Providers of Annex III systems who consider their system to pose no significant risk must be able to demonstrate this through a structured self-assessment.
- Registration in the EU database is publicly searchable, so customers and regulators can see that your system exists and what the exemption claim is.
- In case of doubt, or where shortcomings are identified, the regulator can withdraw the exemption and impose high-risk obligations retroactively.
AI literacy: Article 4 after the Omnibus
Since 2 February 2025, organisations must take measures to ensure the AI literacy of their staff. This applies to everyone working with AI output, from HR managers to customer service staff.
The Commission originally proposed shifting this duty entirely from the organisation to the EU and national authorities. That proposal did not survive. In the final text the duty has, however, been reformulated.
Providers and deployers must take measures to support the development of AI literacy among their staff and other persons dealing with the operation and use of AI systems on their behalf. The law explicitly states that this obligation does not require them to guarantee any specific level of AI literacy for any individual. The Commission and Member States are obliged to support and facilitate organisations in fulfilling it.
That is a best-efforts obligation rather than an obligation of result. It lowers the evidentiary burden, but it does not remove the duty.
In the Dutch implementing act for the AI Regulation, this duty is expected to be enforced through remedial sanctions such as an order subject to a penalty payment. Critics argue this discourages proactive implementation, because companies only need to act once a shortcoming has been identified. There are calls for a stronger role for the works council in pressuring employers.
Human oversight: Article 14
High-risk AI systems must be designed so that natural persons can exercise effective oversight during the period of use. This oversight must prevent people from blindly trusting a machine's suggestions, a phenomenon known in the literature as automation bias.
The overseer must:
- Understand the system's operation well enough to judge it critically.
- Be able to disregard outputs or halt the system entirely.
- Be aware of the system's limitations and possible errors.
- Be able to request a second opinion or arrange an independent assessment in case of doubt.
Dutch enforcement: the hybrid supervisory model
In the Netherlands, supervision of the AI Regulation is laid down in the national implementing act. The government has opted for a hybrid model combining sectoral expertise with central coordination.
Existing sectoral regulators retain their role for AI in their domain:
- NVWA for consumer products
- IGJ for medical devices
- AFM and DNB for the financial sector
- ILT for transport
Interaction with the GDPR: synergy or conflict?
For systems processing personal data, the GDPR and the AI Act apply simultaneously. Under the GDPR, a Data Protection Impact Assessment is mandatory for high-risk processing. Under the AI Act, certain deployers, notably public authorities and providers of essential services, must carry out a Fundamental Rights Impact Assessment.
| Aspect | DPIA (GDPR) | FRIA (AI Act) |
|---|---|---|
| Focus | Protection of personal data | Broad fundamental rights |
| Mandatory for | High-risk processing | Certain deployers of high-risk AI |
| Scope | Privacy and data breaches | Human dignity, non-discrimination, freedom of expression, children's rights |
A notable provision in the AI Act allows providers of high-risk systems to temporarily process special categories of personal data, such as race, religion or health, in order to detect and correct bias in models. The Omnibus broadens this: using special category personal data for bias detection and mitigation becomes easier, provided it is strictly necessary. It remains a direct exception to the general processing prohibition under the GDPR. Strict security and pseudonymisation measures remain mandatory and the data must be deleted after correction.
Penalty structure
The sanctions are designed to deter even large tech companies. Proportionally lower amounts apply to SMEs, startups and small mid-caps. The Omnibus leaves the penalty regime unchanged.
| Type of infringement | Maximum fine | Turnover-based alternative |
|---|---|---|
| Use of prohibited AI practices | 35 million euro | 7 percent of global annual turnover |
| Non-compliance with high-risk requirements | 15 million euro | 3 percent of global annual turnover |
| Breach of transparency rules | 15 million euro | 3 percent of global annual turnover |
| Incorrect information to authorities | 7.5 million euro | 1 percent of global annual turnover |
Roadmap: how to become compliant
A structured approach is essential to be ready in time for the 2026, 2027 and 2028 deadlines. Below is the practical roadmap Cloud Captains uses in compliance projects for clients.
Common misconceptions and pitfalls
1. Assuming 2 August 2026 has been called off
The most common misconception right now. The delay applies exclusively to the high-risk obligations in Chapter III. Article 50, the GPAI enforcement powers and the penalty regime all take effect on 2 August 2026.
2. Provider status through modification
An organisation that substantially modifies an existing AI system or adapts it for a specific high-risk purpose becomes the provider in legal terms. Full responsibility for technical documentation and conformity assessment shifts to that organisation.
3. The incident reporting paradox
Following an AI-related incident, an organisation often has to report within three different timeframes to three different authorities: 24 hours for NIS2, 72 hours for the GDPR and fifteen days for the AI Act. The risk is that statements made in the first 24 hours can later be used against the organisation in a GDPR or AI investigation.
4. Ambiguity in GPAI metrics
The obligation for GPAI providers to disclose the volume of scraped content leaves open whether this should be expressed in file size, token count or number of documents. This ambiguity can lead to inconsistent reporting.
5. The supply chain
Organisations deploying AI systems must obtain contractual guarantees from their suppliers. GPAI model providers are required to share information with downstream users, but the depth of that information is frequently a source of commercial dispute. Nail this down in your procurement contracts. Larger clients now routinely demand AI inventories, role mapping and vendor documentation, including from freelancers and small agencies.
6. Open source is not a free pass
Models released under open-source licences are not automatically exempt. Certain transparency exemptions apply to non-systemic open-source models, but the baseline obligations remain.
7. The undefined notion of significant change
The grandfathering regime hinges entirely on what counts as a significant design change. That threshold has not been defined. Anyone counting on an existing system staying out of scope is taking a risk that only becomes visible in hindsight.
The environmental dimension
The AI Act introduces, for the first time, obligations around the ecological footprint of technology. Providers of GPAI models must document known or estimated energy consumption. The European Commission is working on delegated acts to establish standardised measurement and calculation methods. In future, the ecological impact of an AI system may even factor into admission in specific sectors.
AI and cybersecurity
On 7 July 2026 the European Commission presented the EU Action Plan on Cybersecurity and Artificial Intelligence. The plan sets out a coordinated approach to help Member States, businesses and public authorities address the cybersecurity and resilience challenges posed by the most advanced AI models.
- The Commission will launch a call to increase EU capacity for evaluating AI models, expected to be operational by 2027.
- The Commission and ENISA will develop a blueprint for secure access to advanced AI systems for cybersecurity purposes.
- A secure testing platform will be established so organisations in critical sectors such as energy, transport, health, finance and public administration can safely test and deploy AI solutions.
Operational costs for SMEs
According to European Commission impact assessments, compliance costs for an SME can run to around four hundred thousand euro per high-risk product. That sounds steep, but it is spread across several components.
| Cost item | Explanation | Estimated SME range |
|---|---|---|
| Quality management system | Workflows for data governance and monitoring | 71,400 to 330,000 euro |
| Technical documentation | Description of architecture and training | Part of the QMS |
| Conformity assessment | External review by a Notified Body | Up to 1 million euro, one-off |
| AI literacy and training | Training staff in line with Article 4 | 6,000 to 7,000 euro |
| Ongoing monitoring | Post-market surveillance and incident reporting | Annual overhead of 17 percent |
Conclusion
The AI Act is far more than a legal checkbox. It is a redefinition of the innovation process. To implement it successfully, organisations must abandon the idea that AI compliance is a task for the IT department alone, or the legal department alone. It touches strategy, governance, HR and operations.
The Omnibus has turned the clock back sixteen months on the heaviest part of the law, but the architecture has remained entirely intact. The risk categories, the conformity assessments, the GPAI track and the AI Office are all still standing. And the date that genuinely matters for most organisations, 2 August 2026, has not moved.
The costs and regulatory burden are significant, but the Brussels Effect will likely make the European norm the global standard for trustworthy, human-centric artificial intelligence. Those who start now build trust with customers and citizens, and avoid compliance becoming a late-stage problem.
The organisations that embrace the AI Act as an opportunity to get their governance in order will, in the long run, score better on trust, quality and customer loyalty than those who wait until the regulator is at the door.
- Cloud Captains
Free AI Act Readiness Check for SMEs
Know where your organisation stands in fifteen minutes. This free check translates the law into concrete questions and builds your dossier automatically along the way:
- Know where you stand in fifteen minutes
- Automatic AI Act dossier: register, transparency statement, action plan, policy outline and calendar reminders
- Privacy-first: everything stays in your browser, we store nothing
- Free, and also available in Dutch