Table of contents
- What is the AI Act and Who Do the New EU Regulations Apply To?
- Provider or Deployer? Your Role in the New Ecosystem
- Timeline Update: When Does the AI Act Apply After the Latest Revision?
- The Tech Grey Area: A Silent Threat in Your Company
- How to Safely Implement Modern AI Systems?
- Virtual Assistants, E-commerce, and Transparency: What Does Article 50 Say?
- The Obligation to Develop Digital Competencies: How to Build “AI Literacy”?
- Penalties for Non-compliance: How Much Can It Cost You?
- How to Prepare Your Company for EU Regulations in 7 Steps
- FAQ – Frequently Asked Questions
- How Can FOTC Help Your Company?
Did you know that in an average company employing up to 200 people, employees use an average of 10–12 artificial intelligence tools on their own, while the board of directors knows about only three or four? This clearly shows that organizations often lose control over new technologies. The AI Act, the European Union’s landmark regulation on artificial intelligence, is designed to bring order to this market. In mid-2026, a package of amendments came into force, significantly changing business obligations. Let’s explore how to legally implement these solutions in your company and what this means in practice.
What is the AI Act and Who Do the New EU Regulations Apply To?
The AI Act is the world’s first comprehensive framework that classifies artificial intelligence systems based on the level of risk they pose. The document introduces specific safety, transparency, and oversight rules that apply to global corporations and smaller enterprises alike. The regulations affect anyone who designs, provides, imports, or simply uses AI systems within the European Union. That is why the AI Act is currently one of the most critical regulatory frameworks for entrepreneurs.
Important note for businesses operating in Europe: The AI Act is a regulation, meaning it is fully binding and directly applicable. Companies cannot afford to wait for separate national legislation—preparations to implement the new organizational frameworks must begin immediately.
Provider or Deployer? Your Role in the New Ecosystem
To prepare for the new rules, you must first define your role:
Provider: A company that develops an AI model or application and places it on the market. Deployer: An organization that simply uses an off-the-shelf AI tool in its processes—for example, for recruitment or data analysis.
The majority of traditional businesses act as deployers. However, this does not exempt them from complying with strict security and transparency requirements. The scenario can also become complex if you modify a third-party solution and offer it under your own brand.
Timeline Update: When Does the AI Act Apply After the Latest Revision?
The timeline for when the AI Act becomes enforceable has recently changed. The package of amendments adopted in mid-2026 (the Digital Omnibus on AI) shifted several key deadlines, giving businesses valuable time to adjust operationally to the new legal frameworks.
Here is the updated schedule for the roll-out of key changes:
- August 2024 – The original entry into force of the AI Act.
- Mid-2026 – Introduction of the Digital Omnibus on AI amendments, providing more flexibility for implementation.
- December 2026 – The final deadline to implement AI content labeling (digital watermarking) and an absolute ban on—and market withdrawal of—systems that violate fundamental human rights (such as tools generating intimate content without consent).
- December 2027 – The new deadline to comply with requirements for high-risk standalone software systems (e.g., credit scoring systems, HR algorithms supporting recruitment processes).
- August 2028 – The new deadline to comply with requirements for high-risk systems embedded in physical products that are already subject to EU safety standards (e.g., machinery, medical devices).
The Tech Grey Area: A Silent Threat in Your Company
Many managers are still unaware of the hidden software operating within their organization. This phenomenon, known as Shadow AI, occurs when employees use free, public text generators or browser extensions without the knowledge or approval of the IT department. Inputting sensitive corporate data, client lists, or source code into an unsecured public assistant exposes the organization to severe breaches of GDPR and the AI Act itself.
Employees Use Dozens of Tools, While You Only Know About Three
Team members often look for shortcuts. Our analysis indicates that while management might have approved only a few official tools, a typical mid-sized company often has over a dozen different AI assistants running in the background. This lack of control presents a massive risk. If you do not know what software your team is using, you cannot assess algorithmic risk—which is the very foundation of the new EU regulations.
How to Safely Implement Modern AI Systems?
The solution lies in adopting verified, enterprise-grade business tools. Systems like Google Workspace with its built-in Gemini assistant ensure that company data is never used to train public models. In Poland and wider Europe, organizations are also increasingly opting for on-premise systems installed locally on the company’s own servers. Such infrastructure provides total control over information, making it ideal for voice bots or clinical medical assistants.
Virtual Assistants, E-commerce, and Transparency: What Does Article 50 Say?
The e-commerce industry must pay close attention to Article 50 of the regulation, as it directly covers chatbots and virtual assistants. Customers have the right to know whom they are interacting with. Transparency builds trust in online trade, and EU regulations are turning this market best practice into hard law.
The Obligation to Inform Customers: You Are Talking to a Machine
The most critical change is the requirement to inform users of their interaction with an AI system right at the start of the first interaction. An online store’s chatbot must clearly state in its greeting that it is not a human being. Legal experts emphasize that a brief mention buried deep within the store’s Terms & Conditions is absolutely insufficient.
Furthermore, if the software makes binding decisions—such as rejecting returns or complaints—the customer has the right to demand that the decision be reviewed by a human representative (the so-called human oversight requirement).
Content Labeling and Digital Watermarks from December 2026
Under the new law, appropriate content labeling, including the use of digital watermarks, becomes mandatory. Any artificial image, audio, video, or informational text must contain a machine-readable marker confirming its synthetic origin. Companies using systems deployed before the change in regulations have been granted an extension to adapt. This labeling system must be fully implemented by December 2, 2026.
The Obligation to Develop Digital Competencies (“AI Literacy”)
Developing your team’s skills is no longer just a trend—it is a legal requirement. According to Article 4 of the AI Act, employers must ensure AI Literacy, meaning they must actively educate their staff on the safe and conscious use of AI systems (this provision has been in effect since February 2025).
Furthermore, establishing AI usage policies is no longer solely the responsibility of the IT department; it requires close collaboration among Legal, HR, Compliance, and Security teams.
Penalties for Non-compliance: How Much Can It Cost You?
The penalties for violating the EU regulations are extremely severe, as supervisory authorities aim to rigorously deter misconduct. The regulation outlines three main tiers of financial sanctions:
- Up to €35 million or 7% of annual global turnover (whichever is higher) for using prohibited AI practices, such as subliminal manipulation or illegal social scoring systems.
- Up to €15 million or 3% of annual global turnover for non-compliance with high-risk system requirements and transparency obligations—such as failing to declare a virtual customer assistant.
- Up to €7.5 million or 1% of annual global turnover for supplying misleading information to supervisory authorities.
When determining fines, authorities may take into account whether the company had robust compliance procedures in place. Well-documented processes and swift responses to incidents can significantly mitigate final penalties.
How to Prepare Your Company for EU Regulations in 7 Steps
Adapting to the AI Act should be approached as the implementation of a new organizational framework. To streamline this transition, you can follow these 7 practical steps:
- Inventory: Create a complete list of all AI tools currently used within the company (including those in the “Shadow AI” grey area).
- Impact Assessment: Determine which of these systems directly affect business decisions, customers, or employees.
- Risk Classification: Check if any of the AI systems utilized could be classified as high-risk systems (e.g., those used in recruitment or candidate screening).
- Role & Supplier Verification: Confirm whether your company acts strictly as a “deployer,” and review/update your agreements with AI providers.
- Establish Human Oversight: Create clear protocols for human verification of machine-generated outputs.
- Training: Organize training sessions for all employees on the responsible use of AI tools and assign specific competency scopes within teams.
- Document Update: Draft clear AI policies and regularly update this ruleset, as the regulatory landscape remains highly dynamic.
Proactive management of new technologies will protect your company from fines, build trust with partners, and deliver a lasting competitive advantage.
FAQ – Frequently Asked Questions
Does the AI Act apply to small businesses? Yes. The size of the company is secondary—what matters is how the AI system is utilized. If a micro-business uses AI to screen job applicants, automate key decisions, or analyze customer profiles, it is subject to the provisions of the regulation.
How does the AI Act differ from GDPR? GDPR focuses strictly on the protection of personal data and privacy. The AI Act, on the other hand, regulates the safety and operational standards of the AI systems themselves, emphasizing transparency, fundamental rights, and the reliability of the systems.
Does my company have to stop using popular text generators? No, the AI Act does not ban AI. However, it demands caution. You should opt for secure, authorized business versions (where your inputs are kept confidential) and ensure that employees do not input sensitive corporate data into free, public generators.
Who is responsible for informing a customer that they are talking to a bot? This obligation falls on the company that deploys the tool for the end-user (the deployer). For instance, an online store must clearly inform users in its welcome message that they are interacting with a virtual assistant.
When must artificially generated images be labeled? Under the transparency rules, any visual, audio, or textual content of an informational nature created by AI must be marked in a machine-readable way (e.g., with a digital watermark). The deadline for adapting legacy systems is December 2, 2026.
How Can FOTC Help Your Company?
You don’t have to navigate the path to compliance alone. In addition to our industry workshops, the FOTC team offers comprehensive support to help organizations safely adapt to artificial intelligence:
- Unlocking Secure and Compliant Tools: We implement closed, fully managed environments. We can deploy Google Workspace with Gemini for your company (either as a new setup or an upgrade of your current plan), ensuring your data remains private and secure under the AI Act.
- Educating Your Team: We guide your team through the technology. Our experts will teach your staff how to use new AI assistants on a daily basis, in a way that is highly productive, legally compliant, and aligned with your internal security policies.
- Auditing Your Current Setup (AI Care): We will conduct an audit of the AI tools currently in use (often unconsciously as part of Shadow AI). We will identify security gaps and recommend optimized, compliant solutions to minimize legal risks.
Don’t wait for the first penalties to arrive. Contact our sales department or your dedicated Growth Manager to schedule a free consultation and learn how to legally and effectively unlock the potential of AI in your business.