Noxtrack

AI Act

The AI Act in brief, for companies of ten to fifty people

There are two kinds of reporting about the AI Act. One says everything has been postponed. The other says you risk fines in the millions. Both are only half right.

This page sets out what applies now if you run a company of roughly ten to fifty people that uses AI or builds something with it.

Where things stand

What changed, and what didn't

The AI Act is Regulation (EU) 2024/1689 and entered into force on 1 August 2024. Its rules apply in phases.

On 24 July 2026 the Digital Omnibus on AI appeared in the Official Journal as Regulation (EU) 2026/1744, in force since 27 July 2026. That amendment postpones the heavy obligations for high-risk systems. The postponement is law in force, no longer a proposal.

What it did not postpone: the prohibited practices, the AI literacy requirement, the rules for general-purpose AI models, and the transparency obligations that have applied since 2 August 2026.

The dates at a glance

  1. 2 Feb 2025Prohibited practices and AI literacyApplies now
  2. 2 Aug 2025Rules for general-purpose AI modelsApplies now
  3. 2 Aug 2026Transparency obligationsApplies now
  4. 2 Dec 2026Two new prohibitions; end of the transition period for markingComing up
  5. 2 Dec 2027Stand-alone high-risk systemsPostponed
  6. 2 Aug 2028High-risk AI in regulated productsPostponed
What applies to you now

Four subjects, one of which is new

The first three have applied for a while. Transparency is the point that arrived in August 2026 and that raises the most questions.

Since 2 February 2025

AI literacy

Employees working with AI have to understand what they are using and what the risks are. There is no prescribed course and no certificate. What counts is being able to show it: who was trained, on what, and when. Enforcement on this point has been possible since August 2026.

Since 2 February 2025

Prohibited practices

A short list of applications that are simply not allowed, including emotion recognition in the workplace and scoring people on social behaviour. For most companies this doesn't come up, but it is worth checking whether a supplier has something like it built into a product. The highest fines sit here: up to 35 million euro or 7 percent of worldwide annual turnover. From 2 December 2026 a further prohibition applies to nudify applications and to AI-generated child sexual abuse material.

Since 2 August 2025

General-purpose AI models

Obligations for the providers of the models themselves, such as OpenAI, Anthropic and Google. If you use their models, those obligations sit with them and not with you.

Since 2 August 2026

Transparency

This is the part that is new now. In brief:

  • If a chatbot talks to people, it has to be clear that it isn't a human, unless that is obvious from the context.
  • If you use AI to generate images, audio or video that imitates a real situation, you have to disclose it.
  • If you deploy emotion recognition or biometric categorisation, you have to inform the people concerned.
  • Systems that produce synthetic content have to mark it in a machine-readable way. For systems already on the market before 2 August 2026 there is a transition period until 2 December 2026.

Fines up to 15 million euro or 3 percent of worldwide annual turnover

What is often misrepresented: it does not say you have to put a label under every AI-written text. The full explanation is in Do you have to say you used AI?

What has been postponed

The heavy obligations have been pushed back

The obligations for high-risk systems. Think of AI in recruitment, in education, in lending and in critical infrastructure.

2 Dec 2027

Stand-alone high-risk systems (annex III), moved from 2 August 2026.

2 Aug 2028

High-risk AI embedded in regulated products (annex I).

Dec 2030

Systems already in use before 2 August 2026 keep their original deadline.

If you don't fall into this category, the postponement isn't about you and nothing changes for you.

What this means in practice

Four things, and none of them calls for a compliance department

None of these points takes a project of months. Point one does take most companies the most effort.

  1. Visibility of what is used

    Know which AI is being used in your company and what for.

  2. Knowledge among your people

    Make sure the people using it know what they are doing, and record that.

  3. Checking what you publish

    Check where your chatbot, your generated imagery and your publications stand against the transparency rules.

  4. Agreements with suppliers

    Sort out the data processing agreements with your AI suppliers, because as soon as personal data goes in, the GDPR applies too.

Point one is where most companies come unstuck, not because it is hard but because it is accurate today and no longer accurate in three months. That is what Seeing which AI tools your people actually use is about.

Download

Start with an empty register

An empty register is easier to finish than a blank page. This template gives you the columns.

AI register template

The fields you need to record your AI systems, as a spreadsheet with one filled-in example row. You get it straight away.

You get the template straight away. After that we send the occasional message about Noxtrack; you can unsubscribe from any email. See the privacy statement.

Frequently asked questions

What you probably want to know

Question not listed? Email hello@noxtrack.com.

Since 2 August 2026 most of the AI Act applies. For most companies of ten to fifty people it is not about high-risk systems, but about knowing what you use and being transparent about it. What applies to you exactly depends on your role and your use case; that is a legal question we do not answer for you. The block above sets out what is expected.

Sources

  • Regulation (EU) 2024/1689, the AI Act
  • Regulation (EU) 2026/1744, the Digital Omnibus on AI, Official Journal 24 July 2026
  • European Commission, statement on the entry into force of the AI Omnibus, 27 July 2026

This is an explanation, not legal advice.