Insight
The EU AI Act: what actually applies from 2 August 2026
Two clocks are running, and most coverage conflates them. The transparency duties are live now; the high-risk ones moved. Only one of those affects the chatbot on your website this month.
Two clocks, not one
The reporting around the AI Act has been unhelpful because it treats the regulation as having a single switch-on date. It does not. Different obligations attach to different categories of system on different dates, and the two that matter to most businesses have diverged sharply.
The transparency obligations — the ones covering systems that interact with people, and content that has been generated or manipulated — apply from 2 August 2026. The obligations on high-risk systems, which carry the heavy documentation, data governance and human oversight requirements, have been pushed back, with the European Parliament voting to move standalone high-risk systems to December 2027 and sector-embedded ones later still.
The practical consequence is that a company with a customer-facing chatbot has a live obligation this month, while a company building a CV-screening tool has more time than it thought. Those are different projects with different urgency, and treating them as one programme is how budget gets spent in the wrong order.
What the transparency duties actually require
For a system that interacts with people, the requirement is that the person is made aware they are dealing with an AI system, unless that is obvious from the context. In practice this is much easier to satisfy than teams expect: a plain sentence at the start of the conversation does it. What does not satisfy it is a disclosure buried in a privacy policy nobody opens.
For generated or manipulated content — synthetic audio, image, video or text published to inform the public on matters of public interest — there are marking and disclosure duties. For most B2B marketing this is a narrower category than the panic suggests, but if you are publishing AI-generated imagery of things that look like real events or real people, it is squarely in scope.
Neither of these requires a compliance programme. They require a decision about wording and a change to an interface, which is a week of work rather than a quarter.
Where businesses wrongly assume they are out of scope
The most common misreading is "we did not build an AI system, we bought one." Obligations attach to deployers as well as providers. If you have configured a vendor chatbot and put it on your own site under your own brand, you are the one the customer is interacting with.
The second is jurisdictional. The Act reaches systems whose output is used in the Union, which catches a great many businesses that do not think of themselves as EU companies at all. A US firm serving European customers through a chatbot is not obviously outside it.
The third is the assumption that an internal tool is exempt because no customer sees it. Transparency duties are about people interacting with the system, and employees are people.
The part that is worth taking seriously
The high-risk category is where the real cost sits, and the delay is a reprieve rather than a cancellation. If a system makes or materially informs a decision about someone — creditworthiness, employment, access to a service, eligibility for something — it is worth establishing the classification now, while there is time to design for it.
This matters because retrofitting human oversight, logging, data governance documentation and technical files into a shipped system is dramatically more expensive than building with them in mind. The organisations that will struggle in 2027 are the ones that treat the delay as permission to stop thinking about it.
That classification is a question for your legal advisers rather than your agency. What we would do is make sure the architecture does not foreclose the answer — that decisions are logged, that a human can intervene, and that you can produce a record of why the system did what it did.
A realistic order of work
First, inventory. Which systems in the business interact with people or generate content, including the ones a single team adopted without telling anyone. This list is always longer than the first draft.
Second, the transparency fixes, because they are live now and cheap. Disclosure wording on any conversational interface, a review of what AI-generated content you publish and how it is marked.
Third, classification of anything that touches a decision about a person, done with advisers, and an architecture review of those systems against what the high-risk regime will require.
Fourth, supplier contracts. If a vendor supplies a system you deploy, what they will provide by way of documentation is a contractual question, and it is much easier to raise at renewal than in an enforcement conversation.
Questions
Does a simple FAQ chatbot need a disclosure?
If a person could reasonably think they were talking to a human, yes. A plain line at the start of the conversation satisfies it, and it costs nothing. Burying it in a policy document does not.
We bought our chatbot from a vendor — is it their problem?
Not only theirs. Obligations attach to deployers as well as providers, and the customer is interacting with your brand on your site. What documentation the vendor owes you is a contract question worth settling at renewal.
We are not an EU company. Does this reach us?
Potentially. The Act reaches systems whose output is used in the Union, which catches businesses serving European customers regardless of where they are incorporated. Confirm your position with advisers rather than assuming geography protects you.
The high-risk deadline moved — can we stop preparing?
That would be the expensive reading. Retrofitting logging, human oversight and technical documentation into a shipped system costs far more than designing for them. The delay is time to do it properly, not permission to skip it.
Do we need to label AI-written blog posts?
The marking duties centre on synthetic media and content informing the public on matters of public interest, which is narrower than most B2B marketing. Where you publish generated imagery that could be mistaken for real events or people, it is squarely in scope.
Where this sits in what we do
This article covers one decision inside a wider engagement. The solution page sets out how that engagement runs, what it includes and what it costs to find out.
- AI Customer Experience — A chatbot, a voice agent and a knowledge base that share one grounded source of truth — with citations, measured accuracy and a fast route to a human.
- Belgium's B2B e-invoicing mandate: the January 2026 big bang
- Poland's KSeF mandate: what clearance invoicing changes
- AI for custom customer care: what it can answer and what it must not
- When to build software instead of buying it
- All insight articles
Not sure which of your systems are in scope?
We will inventory what interacts with people or generates content, sort it by which clock it sits on, and tell you what is a week of work and what needs your lawyers.
Get in touch