Home / Blog / EU AI Act for small teams

Industry · Guide

The EU AI Act Is Live: What Small AI Product Owners Actually Have to Do

The next real deadline is August 2, 2026, and it is not the one most people are bracing for. Here's what lands that day, what moved to 2027, and the short list a small team has to work through.

Industry · Guide

Key takeaways

  • August 2, 2026 starts the Article 50 transparency regime: disclose AI chat, deepfakes, and AI-written text on matters of public interest. Not the high-risk rules.
  • The high-risk deadline moved. The Digital Omnibus on AI, Regulation (EU) 2026/1744, pushed standalone Annex III systems to December 2, 2027 and embedded ones to August 2, 2028.
  • GPAI obligations have applied since August 2, 2025 and land on the model provider, not you; August 2, 2026 is when the AI Office can enforce them.
  • Most small-team AI features are limited-risk or minimal-risk. Core duties: disclose AI use, label AI-generated content, document your provider chain.
  • US HQ is not an exemption. But Article 99(6) caps SME fines at whichever is lower, the euro figure or the percentage: the reverse of the headline rule.

You're building a small AI feature — a chatbot, a summarizer, a smart search box. Then someone forwards you a legal-panic email about the EU AI Act.

Deep breath. For most small teams the to-do list is short. (Not legal advice: if your product touches high-risk territory, get a lawyer. We'll flag that line.)

Where we are on the timeline

Adopted in 2024, the Act phases in over several waves. The next is August 2, 2026, three days from this update, and it's where most published advice is wrong. That date is not the high-risk deadline any more, and it never was the GPAI start date. What begins is the Article 50 transparency regime plus the enforcement machinery. The Commission adopted its final Article 50 guidelines on July 20, 2026.

DateWhat appliesYours?
Feb 2, 2025Prohibited practices (Art. 5); AI literacy (Art. 4)Rarely.
Aug 2, 2025GPAI model obligations (Arts. 51–56); governance; penaltiesVendor-side.
Aug 2, 2026Article 50 transparency duties; AI Office enforcement over GPAI; market surveillance liveYes.
Dec 2, 2026Art. 50(2) marking for generative systems shipped before Aug 2, 2026; new prohibition on AI-generated intimate imagery and CSAMIf you shipped generative.
Aug 2, 2027GPAI models placed on the market before Aug 2, 2025 must complyAsk your vendor.
Dec 2, 2027High-risk duties, standalone Annex III (hiring, credit, education, essential services)Those categories only.
Aug 2, 2028High-risk duties, Annex I embedded products (medical devices, machinery, vehicles)Rarely.

The Digital Omnibus moved the deadline you were worried about

The Digital Omnibus on AI was published in the Official Journal on July 24, 2026 as Regulation (EU) 2026/1744 and entered into force on July 27, 2026, after provisional agreement on May 6 and Member State confirmation on May 13. It:

  • Moved standalone Annex III high-risk obligations from August 2, 2026 to December 2, 2027, sixteen months, and Annex I embedded high-risk to August 2, 2028.
  • Added an Article 5 prohibition on AI generating non-consensual intimate imagery or CSAM where that output is a reasonably foreseeable and reproducible result, with a transitional period to December 2, 2026.
  • Gave generative systems already on the market a four-month grace period on Article 50(2) marking.
  • Extended simplified compliance to small mid-caps: under 750 employees, turnover €150 million or less, or total assets €129 million or less.

It did not move Article 50 (still August 2, 2026) or the GPAI rules (still August 2, 2025). Check the date on any guidance you read: anything written before May 2026 will tell you high-risk lands in August 2026.

The four risk tiers, and where your product probably sits

Your tier decides which of those dates is yours:

TierWhat it coversYour deadline
ProhibitedSocial scoring, most real-time biometric ID in public spaces, emotion recognition at work or school, manipulative dark patterns; since the omnibus, AI generating non-consensual intimate imagery or CSAMBanned since Feb 2, 2025; imagery, Dec 2, 2026.
High-riskRecruitment, credit scoring, education grading, essential services, law enforcement (Annex III); medical devices, machinery, vehicles (Annex I)Dec 2, 2027 (Annex III), Aug 2, 2028 (Annex I).
Limited-riskChatbots and voice agents, deepfakes, AI-generated media and public-interest text, emotion recognition, biometric categorisationArticle 50 transparency, Aug 2, 2026.
Minimal-riskEverything else: spam filters, recommendations, autocomplete, searchNothing mandatory.
Classify by use case, not by tech. "Summarize customer feedback" and "rank job applicants" land on different rows, with deadlines sixteen months apart.

The must-do list, and the dates attached to it

Small SaaS teams almost always sit in the bottom two tiers. Items 1 and 2 are Article 50 duties that start applying on August 2, 2026; the rest is cheap groundwork.

1. Disclose when users are interacting with AI, by August 2, 2026

  • Article 50(1) puts this on the provider: if a user could reasonably think they're talking to a human, the system has to make clear they aren't. "You're chatting with an AI assistant. Type agent to reach a human" is the entire fix for a support bot; it covers voice agents too.
  • There's a narrow carve-out where the AI nature is obvious to a reasonably well-informed person. Don't lean on it.

2. Label AI-generated content, by August 2 or December 2, 2026

  • Article 50(4) is human-facing: deployers publishing deepfakes, or AI-generated text published to inform the public on matters of public interest, must disclose it. From August 2, 2026, no grace period.
  • Article 50(2) is machine-readable: providers of generative systems must mark synthetic audio, image, video and text as artificially generated, in practice via provenance metadata such as C2PA. If your feature was on the market before August 2, 2026, you have until December 2, 2026. Nothing generated before August 2, 2026 needs retroactive labelling.
  • Article 50(3): running emotion recognition or biometric categorisation means telling the people whose biometric data it processes. Also August 2, 2026.

3. Document your data sources and provider chain

Know which foundation model you're using, from which provider and on which terms, and keep a one-page note on what data goes in and comes out. If you fine-tune, record the training data source.

4. Confirm your foundation-model vendor's compliance posture

  • GPAI obligations (transparency, copyright compliance, systemic-risk assessment) land on the model provider, not on you, and have applied since August 2, 2025. What's new on August 2, 2026 is teeth: the AI Office can investigate providers, order mitigations and levy fines.
  • Models placed on the market before August 2, 2025 have until August 2, 2027. If you depend on an older one, ask your vendor where it sits; if you're weighing a swap, start with our honest comparison of the 2026 models.
  • Self-hosting is different: you may be closer to "provider" than you think.

5. Have a takedown and appeal flow

Not an Article 50 duty, but users need a way to flag AI outputs that harm them. An email address and a documented process counts.

Nobody gets fined for plain-English "you're talking to AI" copy. The risk is pretending it's a human, or drifting into a high-risk use case you didn't realize was one.

The one thing that trips small teams up

Context drift is the biggest way a limited-risk product becomes a high-risk problem. An internal support chatbot is disclosed, limited-risk, fine — until ops starts feeding it resumes to pre-screen applicants. That's a recruitment use case, Annex III territory, and you'd have until December 2, 2027 to build the technical documentation, risk management, human oversight, conformity assessment and EU registration it now needs. Sixteen extra months is a planning window, not a reprieve.

Write down what your AI feature is for. A one-sentence intended-use statement — "this chatbot answers product questions; not hiring, lending, or medical decisions" — is the cheapest AI Act hygiene there is.

Fines, and the part everyone quotes wrong

From Article 99:

  • Up to €35 million or 7% of global annual turnover for prohibited-AI violations.
  • Up to €15 million or 3% for most other breaches, including the Article 50 transparency duties and the GPAI obligations.
  • Up to €7.5 million or 1% for supplying incorrect information to regulators.

Almost every summary adds "whichever is higher" and stops. That's Article 99(2), the rule for large undertakings. Article 99(6) caps each fine for SMEs, including start-ups, at the percentage or the amount, whichever is lower. A startup with €2 million in turnover facing a top-tier violation is looking at 7% of €2 million — €140,000, not €35 million. Still bad. Not company-ending.

The practical risk for a five-person team isn't a fine anyway. It's an inquiry that eats weeks, and an EU customer contract you can't sign. The Act is becoming procurement-desk table stakes.

Where people go wrong (and when to call a pro)

If you've already done serious GDPR work you're most of the way there: the AI Act layers on top of GDPR rather than replacing it. If you're shipping your first agent, how to build your first AI agent pairs well: "what is this agent allowed to decide?" is the AI Act question in different clothes.

The expensive mistakes: assuming a US HQ exempts you (it doesn't if EU users touch the output); skipping the AI-content label because "it's obvious"; planning against the old August 2026 high-risk date, or a nonexistent August 2026 GPAI start date; treating the December 2027 postponement as a cancellation; and treating your vendor's compliance as your own. The moment your product touches hiring, credit, education, healthcare, or safety-critical decisions, get a lawyer. For everything else the real value is classifying your specific use case and building a provider chain that survives a 40-question customer questionnaire — the work we do in our services engagements.

Frequently asked questions

Does the EU AI Act apply to my US-based startup?
Very possibly. The Act applies extraterritorially: if your AI system is placed on the EU market, or if its output is used inside the EU, you fall under it regardless of where your company is headquartered. A US HQ is not an exemption.
What risk tier is my product likely in?
Most small SaaS teams shipping AI features (a chatbot, a summarizer, a recommendation engine) land in limited-risk or minimal-risk. High-risk is reserved for specific uses like recruitment screening, credit scoring, education grading, and safety-critical systems. Classification depends on how the system is used, not just what it does.
What are the minimum things a small team must do before August 2, 2026?
Four things: tell users clearly when they're interacting with AI, label your AI-generated content, document your data sources and provider chain, and confirm your foundation-model vendor's compliance posture. The Article 50 human-facing disclosure duties start applying on August 2, 2026, so the first two are dated work. If your generative system was already on the market before that date, you have until December 2, 2026 to add machine-readable marking.
How bad are the fines really for a startup?
The headline numbers are serious: up to €35 million or 7% of global annual turnover for prohibited-AI violations, and up to €15 million or 3% for most other breaches including the Article 50 transparency duties. But Article 99(6) says that for SMEs, including start-ups, the fine is capped at the amount or the percentage, whichever is lower, the reverse of the rule applied to large companies. Your exposure is bounded by your own turnover. The point isn't panic; the low-effort disclosure and labelling work is genuinely worth doing.

Shipping AI into Europe?

Let us pressure-test your AI Act posture before a customer does.

Article 50 starts applying on August 2, 2026. Ghostwire Systems helps small teams get the disclosure, labelling, and provider chain right the first time.