Home / Blog / EU AI Act for small teams
Industry · GuideThe EU AI Act Is Live: What Small AI Product Owners Actually Have to Do
The next real deadline is August 2, 2026, and it is not the one most people are bracing for. Here's what lands that day, what moved to 2027, and the short list a small team has to work through.
Key takeaways
- August 2, 2026 starts the Article 50 transparency regime: disclose AI chat, deepfakes, and AI-written text on matters of public interest. Not the high-risk rules.
- The high-risk deadline moved. The Digital Omnibus on AI, Regulation (EU) 2026/1744, pushed standalone Annex III systems to December 2, 2027 and embedded ones to August 2, 2028.
- GPAI obligations have applied since August 2, 2025 and land on the model provider, not you; August 2, 2026 is when the AI Office can enforce them.
- Most small-team AI features are limited-risk or minimal-risk. Core duties: disclose AI use, label AI-generated content, document your provider chain.
- US HQ is not an exemption. But Article 99(6) caps SME fines at whichever is lower, the euro figure or the percentage: the reverse of the headline rule.
You're building a small AI feature — a chatbot, a summarizer, a smart search box. Then someone forwards you a legal-panic email about the EU AI Act.
Deep breath. For most small teams the to-do list is short. (Not legal advice: if your product touches high-risk territory, get a lawyer. We'll flag that line.)
Where we are on the timeline
Adopted in 2024, the Act phases in over several waves. The next is August 2, 2026, three days from this update, and it's where most published advice is wrong. That date is not the high-risk deadline any more, and it never was the GPAI start date. What begins is the Article 50 transparency regime plus the enforcement machinery. The Commission adopted its final Article 50 guidelines on July 20, 2026.
| Date | What applies | Yours? |
|---|---|---|
| Feb 2, 2025 | Prohibited practices (Art. 5); AI literacy (Art. 4) | Rarely. |
| Aug 2, 2025 | GPAI model obligations (Arts. 51–56); governance; penalties | Vendor-side. |
| Aug 2, 2026 | Article 50 transparency duties; AI Office enforcement over GPAI; market surveillance live | Yes. |
| Dec 2, 2026 | Art. 50(2) marking for generative systems shipped before Aug 2, 2026; new prohibition on AI-generated intimate imagery and CSAM | If you shipped generative. |
| Aug 2, 2027 | GPAI models placed on the market before Aug 2, 2025 must comply | Ask your vendor. |
| Dec 2, 2027 | High-risk duties, standalone Annex III (hiring, credit, education, essential services) | Those categories only. |
| Aug 2, 2028 | High-risk duties, Annex I embedded products (medical devices, machinery, vehicles) | Rarely. |
The Digital Omnibus moved the deadline you were worried about
The Digital Omnibus on AI was published in the Official Journal on July 24, 2026 as Regulation (EU) 2026/1744 and entered into force on July 27, 2026, after provisional agreement on May 6 and Member State confirmation on May 13. It:
- Moved standalone Annex III high-risk obligations from August 2, 2026 to December 2, 2027, sixteen months, and Annex I embedded high-risk to August 2, 2028.
- Added an Article 5 prohibition on AI generating non-consensual intimate imagery or CSAM where that output is a reasonably foreseeable and reproducible result, with a transitional period to December 2, 2026.
- Gave generative systems already on the market a four-month grace period on Article 50(2) marking.
- Extended simplified compliance to small mid-caps: under 750 employees, turnover €150 million or less, or total assets €129 million or less.
It did not move Article 50 (still August 2, 2026) or the GPAI rules (still August 2, 2025). Check the date on any guidance you read: anything written before May 2026 will tell you high-risk lands in August 2026.
The four risk tiers, and where your product probably sits
Your tier decides which of those dates is yours:
| Tier | What it covers | Your deadline |
|---|---|---|
| Prohibited | Social scoring, most real-time biometric ID in public spaces, emotion recognition at work or school, manipulative dark patterns; since the omnibus, AI generating non-consensual intimate imagery or CSAM | Banned since Feb 2, 2025; imagery, Dec 2, 2026. |
| High-risk | Recruitment, credit scoring, education grading, essential services, law enforcement (Annex III); medical devices, machinery, vehicles (Annex I) | Dec 2, 2027 (Annex III), Aug 2, 2028 (Annex I). |
| Limited-risk | Chatbots and voice agents, deepfakes, AI-generated media and public-interest text, emotion recognition, biometric categorisation | Article 50 transparency, Aug 2, 2026. |
| Minimal-risk | Everything else: spam filters, recommendations, autocomplete, search | Nothing mandatory. |
The must-do list, and the dates attached to it
Small SaaS teams almost always sit in the bottom two tiers. Items 1 and 2 are Article 50 duties that start applying on August 2, 2026; the rest is cheap groundwork.
1. Disclose when users are interacting with AI, by August 2, 2026
- Article 50(1) puts this on the provider: if a user could reasonably think they're talking to a human, the system has to make clear they aren't. "You're chatting with an AI assistant. Type agent to reach a human" is the entire fix for a support bot; it covers voice agents too.
- There's a narrow carve-out where the AI nature is obvious to a reasonably well-informed person. Don't lean on it.
2. Label AI-generated content, by August 2 or December 2, 2026
- Article 50(4) is human-facing: deployers publishing deepfakes, or AI-generated text published to inform the public on matters of public interest, must disclose it. From August 2, 2026, no grace period.
- Article 50(2) is machine-readable: providers of generative systems must mark synthetic audio, image, video and text as artificially generated, in practice via provenance metadata such as C2PA. If your feature was on the market before August 2, 2026, you have until December 2, 2026. Nothing generated before August 2, 2026 needs retroactive labelling.
- Article 50(3): running emotion recognition or biometric categorisation means telling the people whose biometric data it processes. Also August 2, 2026.
3. Document your data sources and provider chain
Know which foundation model you're using, from which provider and on which terms, and keep a one-page note on what data goes in and comes out. If you fine-tune, record the training data source.
4. Confirm your foundation-model vendor's compliance posture
- GPAI obligations (transparency, copyright compliance, systemic-risk assessment) land on the model provider, not on you, and have applied since August 2, 2025. What's new on August 2, 2026 is teeth: the AI Office can investigate providers, order mitigations and levy fines.
- Models placed on the market before August 2, 2025 have until August 2, 2027. If you depend on an older one, ask your vendor where it sits; if you're weighing a swap, start with our honest comparison of the 2026 models.
- Self-hosting is different: you may be closer to "provider" than you think.
5. Have a takedown and appeal flow
Not an Article 50 duty, but users need a way to flag AI outputs that harm them. An email address and a documented process counts.
Nobody gets fined for plain-English "you're talking to AI" copy. The risk is pretending it's a human, or drifting into a high-risk use case you didn't realize was one.
The one thing that trips small teams up
Context drift is the biggest way a limited-risk product becomes a high-risk problem. An internal support chatbot is disclosed, limited-risk, fine — until ops starts feeding it resumes to pre-screen applicants. That's a recruitment use case, Annex III territory, and you'd have until December 2, 2027 to build the technical documentation, risk management, human oversight, conformity assessment and EU registration it now needs. Sixteen extra months is a planning window, not a reprieve.
Fines, and the part everyone quotes wrong
From Article 99:
- Up to €35 million or 7% of global annual turnover for prohibited-AI violations.
- Up to €15 million or 3% for most other breaches, including the Article 50 transparency duties and the GPAI obligations.
- Up to €7.5 million or 1% for supplying incorrect information to regulators.
Almost every summary adds "whichever is higher" and stops. That's Article 99(2), the rule for large undertakings. Article 99(6) caps each fine for SMEs, including start-ups, at the percentage or the amount, whichever is lower. A startup with €2 million in turnover facing a top-tier violation is looking at 7% of €2 million — €140,000, not €35 million. Still bad. Not company-ending.
The practical risk for a five-person team isn't a fine anyway. It's an inquiry that eats weeks, and an EU customer contract you can't sign. The Act is becoming procurement-desk table stakes.
Where people go wrong (and when to call a pro)
If you've already done serious GDPR work you're most of the way there: the AI Act layers on top of GDPR rather than replacing it. If you're shipping your first agent, how to build your first AI agent pairs well: "what is this agent allowed to decide?" is the AI Act question in different clothes.
Frequently asked questions
Does the EU AI Act apply to my US-based startup?
What risk tier is my product likely in?
What are the minimum things a small team must do before August 2, 2026?
How bad are the fines really for a startup?
Shipping AI into Europe?
Let us pressure-test your AI Act posture before a customer does.
Article 50 starts applying on August 2, 2026. Ghostwire Systems helps small teams get the disclosure, labelling, and provider chain right the first time.