Does the AI Act affect your company? Find out which obligations already apply, what the 2026 Digital Omnibus actually changes, and how to prepare step by step.

It’s 9 a.m. HR is using a platform that filters CVs with AI. Marketing has just generated ten LinkedIn images with AI. Customer service answers questions through a chatbot. Leadership uses ChatGPT to draft proposals.

None of these decisions looks especially significant. Yet each tool may be subject to different AI Act obligations — and many companies are not even aware of it.

According to Eurostat, 20% of EU companies with 10 or more employees already used AI technologies in 2025, up from 13.5% in 2024.

“The AI Act has been postponed”

You have probably seen that claim recently. Treating it as “we can do nothing yet” is a mistake.

The EU AI Regulation continues to apply in phases since 2024, and several obligations are already enforceable. The Digital Omnibus postponement only affects a specific part of the rules: certain high-risk AI systems listed in Annex III. The rest of the calendar remains unchanged.

In short

  • The AI Act (Regulation EU 2024/1689) regulates the development and use of AI by companies operating in Europe.
  • Obligations apply progressively between 2024 and 2028.
  • Some duties — prohibited practices, AI literacy and GPAI model rules — are already enforceable.
  • The 2026 Digital Omnibus only postpones certain high-risk obligations. The rest of the calendar stays.
  • The AI Act also affects companies that use AI tools daily, not only developers.
  • Fines can reach €35 million or 7% of worldwide annual turnover, depending on the infringement.
  • The first step is an AI inventory of the systems your company actually uses.

What the AI Act is

The AI Act is Regulation (EU) 2024/1689. It sets the legal framework for developing, placing on the market and using AI systems. It aims for safe, trustworthy AI while protecting fundamental rights and allowing innovation.

It entered into force on 1 August 2024, with obligations rolling out through 2028. Not every AI tool carries the same risk — so not every tool carries the same legal duties.

How the AI Act classifies AI systems

Category Allowed? Examples
Unacceptable risk Prohibited Social scoring, certain manipulative systems
High risk Allowed, with strict duties Recruitment, credit scoring, biometric identification
Limited risk Allowed, with transparency duties Chatbots, virtual assistants, AI-generated content
Minimal risk No AI Act-specific duties Spam filters, many low-risk everyday apps

Correct classification is the first compliance step. Without knowing which systems you use and their risk level, you cannot know which obligations apply.

Which companies are affected?

The Regulation distinguishes mainly between:

  • Provider: develops or places an AI system on the market.
  • Deployer: uses that system in a professional activity, even if a third party built it.

Most SMEs and freelancers are deployers: ChatGPT, Copilot, AI-enabled CRMs, recruitment platforms or marketing tools. A common mistake is assuming only the vendor must comply.

AI Act calendar: key dates

  • 1 August 2024: AI Act enters into force.
  • 2 February 2025: prohibited practices and AI literacy duties.
  • 2 August 2025: GPAI model obligations and part of the enforcement regime.
  • 2 August 2026: broader application, including Article 50 transparency duties.
  • 2 December 2027: Annex III high-risk systems (after the Digital Omnibus).
  • 2 August 2028: Annex I high-risk systems.

Waiting until 2027 because of the Omnibus headline is the wrong reading: much of the original calendar still applies now.

Sanctions

  • Up to €35 million or 7% of worldwide annual turnover for the most serious infringements.
  • Up to €15 million or 3% of worldwide annual turnover for other breaches.

In Spain, supervision sits with AESIA. Beyond fines, non-compliance can mean claims, reputational harm, contractual issues and barriers in tenders.

How a company can start complying

  1. Inventory every AI tool, including embedded AI features.
  2. Classify each system by risk level and applicable duties.
  3. Review transparency obligations for chatbots and AI-generated content.
  4. Train people who use AI (literacy is already required).
  5. Set up AI governance: policies, ownership and periodic review.

How Legal Stones’ AI Legal Assessment helps

Most companies do not have a pure legal problem — they have a visibility problem. The AI Legal Assessment maps your real AI use, classifies risk under the AI Act (and GDPR where relevant), and delivers a prioritised roadmap. Prefer a faster first step? Book the AI Act Quick Check.

FAQ

Has the AI Act been postponed?

Only partly. The Digital Omnibus delays certain Annex III/I high-risk duties. Prohibitions, literacy and GPAI rules largely keep their original path.

Does using ChatGPT mean I must comply?

Not automatically in every scenario, but professional use can trigger obligations depending on how and with which data you use it.

Do SMEs have to comply?

Yes. Size alone does not exempt you if you develop or deploy AI systems in your activity.

What should I do first?

Build an AI inventory, then classify each system.

Conclusion

The AI Act is already part of the European regulatory framework. The biggest risk is not using AI — it is not knowing how AI is being used. The best time to prepare is now.

Need to know how the AI Act affects your company? Request an AI Legal Assessment →

Free download

AI Act 2026 Guide (PDF)

Risk pyramid, updated calendar, sanctions and first steps for your company.

On submit, the download starts immediately and we also email you the PDF link.