FAQ · AI Act / 2024/1689
Answers to what companies ask most often — training, corporate AI tools, marking of outputs, supervision in Czechia. With links into the official text.
Orientation, not a legal opinion The answers below are our reading of Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744. They are not a binding legal opinion. Every statement about a deadline or an obligation carries the article number so that it can be checked against the official text. CypherOn provides cybersecurity services and is not a law firm — for a binding assessment of a specific situation, turn to an attorney registered with the Czech Bar Association.
Yes, but far more narrowly than is usually claimed. A company that only buys licences and uses them is a deployer for the purposes of the regulation (Article 3(4)), not a provider — the provider obligations, meaning conformity assessment, the technical documentation under Annex IV and registration in the EU database, do not apply to it.
In practice three things do: the prohibitions in Article 5, measures to promote the improvement of AI literacy under Article 4 and — where the company generates or publishes AI content — transparency under Article 50(3) and (4). A fourth set of obligations, under Article 26, is triggered only once a system falls into the high-risk category, typically in recruitment or worker management. What follows from each of them is set out in the guide section on companies that only use AI.
Four tiers, each with a different set of obligations and a different date of application:
The tiers are not mutually exclusive: one tool can sit in minimal risk and still carry an obligation under Article 50 because it generates content. Which two routes lead into high risk, and what exceptions apply to the prohibitions, is described in the guide section on the four risk levels.
The substantive obligations do not change with size, but the regulation works with size in several places and the omnibus extended that:
Definitions of both categories were added to Article 3 as points (14a) and (14b) — a small and medium-sized enterprise as defined in Commission Recommendation 2003/361/EC, a small mid-cap company as defined in Recommendation (EU) 2025/1099.
The Czech act in preparation is to add two further reliefs: for less serious breaches, the option of issuing a warning instead of immediately opening administrative offence proceedings, and lower fine ceilings. For now that is only a draft from the Ministry of Industry and Trade, not the state of the law — where the Czech act stands is tracked in the guide section on supervision and penalties.
The most frequently overlooked exclusions in Article 2:
The open-source exception is narrower than it looks: it does not apply where the system is placed on the market as high-risk, and it covers neither the prohibited practices in Article 5 nor transparency under Article 50. The full scope of application is in the opening section of the guide.
Regulation (EU) 2026/1744 (the digital omnibus on AI) entered into force on 27 July 2026 and, by amending Article 113, moved two dates:
Nothing else moved — the general date of application of 2 August 2026 including transparency under Article 50, the prohibitions in Article 5 (since 2 February 2025) and the obligations for general-purpose AI models (since 2 August 2025) all stand. The other omnibus changes and the whole timeline including the original dates are covered in the guide section on the omnibus.
Under the wording in force as of the validity date of this page, yes. 2 August 2026 was the correct date for Annex III systems until the omnibus moved it to 2 December 2027.
A practical test for spotting such a text: if it does not mention Regulation (EU) 2026/1744 and at the same time speaks of high-risk obligations from August 2026, it was written before the end of July 2026 and its timeline is out of date. Individual statements in it may still be correct — the postponement touched the deadlines, not the substance of most requirements.
We recommend not relying on secondary sources and checking dates directly in Article 113 of the consolidated text of the AI Act. Regulation (EU) 2026/1744 itself has only four articles — the new dates are in its Article 1, point 40, which amends Article 113 of the AI Act.
There is no need to throw it away. The omnibus changed deadlines and part of the definitions, not the logic of the regulation. The points worth checking are these:
Not in the form in which it is being offered. Article 4 was replaced by the omnibus and the new wording requires only “measures to promote the improvement of AI literacy”, proportionate to the technical knowledge, experience and education of the people concerned and to the context in which the tool is used.
The decisive part is the last sentence of paragraph 1, which was not in the original wording: the obligation “does not require providers or deployers to guarantee any specific level of AI literacy of any individual”. The regulation therefore prescribes no certificate, no test and no number of hours, and there is no level you would have to demonstrate for a particular employee.
What is an obligation: to adopt measures and to be able to show that you adopted them. Training is one option, not the only one — rules for using the tools, guidance inside the tool itself or internal documentation work just as well. Under the new Article 4(2), the Commission is to publish practical examples of compliance on the single information platform.
If a vendor tells you the AI Act requires staff training with a demonstrated level, they are arguing from wording that ceased to apply on 27 July 2026. What exactly the omnibus changed in Article 4 is in the guide section on the omnibus.
The AI Act does not answer this question — it does not govern what data you put into a tool. The answer follows from other rules and from the contract with the provider:
The practical output of this is usually a one-page rule: a list of approved tools, the categories of data that must not go into them, and who approves a new tool. The same document then normally doubles as evidence of the measures under Article 4.
We deliberately do not offer a ready-made template. The rule makes sense only if it matches the tools that actually run in the company and the data that flow into them; borrowed wording creates the impression of a discharged obligation, misses the real operation and proves nothing in an inspection. What is reusable is the structure and examples of wording, not a document to sign.
In three situations under Article 25(1): you put your name or trademark on a high-risk system (point (a)), you make a substantial modification to it (point (b)), or you change the intended purpose of a system in such a way that it becomes high-risk (point (c)). In all three, the provider obligations under Article 16 pass to you.
In practice the third situation is the most common, because it needs no development of your own. Building an internal tool for screening CVs or assessing creditworthiness on top of a purchased general-purpose model is enough to put you in the provider role — a system prompt and an API connection will do it.
What the omnibus added — what documentation the original provider has to hand over, and why a breach of Article 25 now sits in the 15 million euro or 3 % of turnover tier — is covered in the guide section on the deployer taking over the provider role.
As a rule, no. Article 5(1)(f) prohibits placing on the market, putting into service for this specific purpose, or using AI systems to infer emotions of a natural person in the areas of workplace and education institutions; the only exception is use for medical or safety reasons. The prohibition has applied since 2 February 2025 and sits in the top fine tier — up to 35 million euro or 7 % of total worldwide annual turnover.
It catches things that are routinely sold as analytics: sentiment scoring of contact centre calls, measuring employee engagement from camera footage, evaluating the facial expressions or voice of a candidate during an interview.
Alongside it, point (g) prohibits biometric categorisation of people in order to deduce their race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation. The exception in that point is aimed at lawfully acquired biometric datasets and at the area of law enforcement, so it does not reach a corporate tool — the scope of both prohibitions is in the guide.
The breach usually comes packaged in a module of an HR system or an analytics tool whose feature description nobody read. Checking already deployed tools against Article 5 is therefore the first thing we do in such a situation — it is quick, and it is the only tier where the issue is not documentation but a ban.
No. Registration in the EU database under Article 49 attaches to providers of high-risk systems, or to a provider who documents under Article 6(4) that its Annex III system is not high-risk. A deployer in the position of an ordinary user registers nothing and has no ongoing reporting duty towards the authority.
A registration duty appears only if you deploy a high-risk system as a public authority, or if you become a provider under Article 25.
Do note, though, that an incident in an AI tool may be reportable under other rules — under Act No. 264/2025 Coll. if it affects a regulated service, or under GDPR if it was a personal data breach. The AI Act does not disapply those deadlines, and it is practical to have one process that covers both sides.
Chapter IV, meaning Article 50, applies from 2 August 2026. The obligations split by role:
Paragraph 5 adds what the information has to look like: clear, distinguishable, accessible and provided at the latest at the time of the first interaction or exposure. As a practical example, the Czech Telecommunication Office mentions labels such as “AI generated” for fully generated content and “AI modified” for content edited with AI. The conditions attaching to the individual paragraphs are covered in the guide section on marking under Article 50.
For the machine-readable marking duty under Article 50(2), yes. Providers of generative systems placed on the market before 2 August 2026 have until 2 December 2026 under the new Article 111(4).
This transitional rule is aimed at paragraph 2, meaning at providers. The deployer obligations under paragraph 4 and the rules on how to inform under paragraph 5 apply from 2 August 2026 with no delay. So be careful: if you are both the provider and the deployer of your own tool, the transitional period does not cover everything.
It is not. The duty under paragraph 2 speaks of marking in a machine-readable format that is detectable as artificially generated — a property of the output, not a line in documentation. The duty under paragraph 4 concerns what a person will see, and paragraph 5 adds the requirement of clarity, distinguishability and timing no later than the first interaction or exposure.
The most concrete description available of what counts as sufficient is the code of practice on transparency of AI-generated content, published by the Commission on 10 June 2026, and the guidelines on Article 50 issued alongside it. The code is voluntary and does not replace the obligation under the regulation; its role in demonstrating compliance is described in the guide.
The exceptions are in Article 50 itself and they are narrower than they are usually read:
The precise scope of the first two exceptions — with artistic work the obligation is only narrowed, not removed — is in the guide section on Article 50. In its press release of 31 July 2026, the Czech Telecommunication Office recommends assessing for each specific activity whether it falls under one of the exceptions, and reading Article 50 together with the Commission guidelines.
Not by name. The closest is Article 15, which requires an appropriate level of accuracy, robustness and cybersecurity for high-risk systems; its paragraph 5 lists attacks on training data and on the model, inputs designed to make the model err, and confidentiality attacks. The full list from paragraph 5 is in the guide.
Prompt injection fits under paragraph 5 through the general wording on resilience against attempts by unauthorised third parties to alter the use, outputs or performance of the system by exploiting its vulnerabilities. The regulation offers no guidance on it, however, and the whole of Article 15 applies only to high-risk systems — for an ordinary corporate deployment nothing follows from it.
The taxonomy therefore has to come from elsewhere. The most widely used one is the OWASP Top 10 for Large Language Model Applications, which does name prompt injection, data leakage through outputs and excessive agency. It is not a legal rule, but as a basis for assessing the risks of a specific deployment it is more usable than Article 15.
The AI Act does not address this problem at all, and it is still the biggest risk in the whole topic in practice. The company answers for the processing of personal data and for the protection of trade secrets even with a tool it does not know about.
What works: map the tools from technical sources — proxy or SASE logs, DNS queries, the list of OAuth applications connected to the corporate tenant, and corporate card statements. A questionnaire does not work, because it asks the people who are going around the rule.
The other half of the solution is having an approved option that is actually usable. If the corporate tool is worse or slower than the consumer version, a ban will not stop the workaround.
An inventory of tools is useful for the regulation itself as well: without a list showing the role, the owner and the risk classification for each tool, you cannot even answer whether Article 50 concerns you. Why this scenario is riskier than the regulation itself is covered in the guide section on companies that only use AI.
They run alongside each other and the obligations add up. Each rule targets something different:
The omnibus reduced duplicated documentation in two places: under Article 27(4) the fundamental rights impact assessment may build on parts of the data protection impact assessment under Article 35 GDPR, and the new Article 42(3) recognises compliance with the cybersecurity requirements of Article 15 for systems covered by the Cyber Resilience Act. The conditions for both are in the guide.
The new Article 4a inserted by the omnibus, by contrast, is narrow — it covers only special category data used to detect and correct bias in a model, and even that under hard conditions. It is not a general permission to process special category data for training, and in itself it creates no obligation to detect bias.
Article 99 has three tiers. In each of them the higher of the two figures applies — a fixed amount, or a percentage of worldwide turnover for the preceding financial year:
For smaller undertakings the tiers are softened, and fines on providers of general-purpose AI models are imposed by the Commission itself under Article 101. The breakdown, including which specific articles fall into the middle tier, is in the guide section on supervision and penalties.
As of the validity date of this page, the Czech implementing act that is to settle supervision is not in the Collection of Laws. The regulation itself is directly applicable and the obligations apply regardless, but at national level the procedural framework for imposing fines under Article 99(1) is missing.
Under the draft from the Ministry of Industry and Trade, the single point of contact is to be the Czech Telecommunication Office, with the Czech National Bank and the Office for Personal Data Protection in their respective sectors, the Czech Office for Standards, Metrology and Testing as the notifying authority, and a role in human rights matters for the Public Defender of Rights. Until the act is passed this is a proposal, not a settled division — in its press release of 31 July 2026, the Czech Telecommunication Office describes itself as one of the bodies that will supervise Article 50.
For some systems built on general-purpose AI models and for very large online platforms, supervision sits directly with the European AI Office. That does not reach anyone who merely uses such a system — they stay under the national authority. The precise delimitation of its exclusive competence after the omnibus, and the state of the Czech act, are in the guide section on supervision and penalties.
The answers above are based on these sources. Every statement about a deadline or an obligation carries the article number, which can be looked up in them.
A specific situation
Most questions turn on three things: what the tool actually does, what data flow into it and which role you hold. Describe the situation and we will go through it with you.