FAQ · AI Act / 2024/1689

QUESTIONS ON THE AI ACT

Answers to what companies ask most often — training, corporate AI tools, marking of outputs, supervision in Czechia. With links into the official text.

Orientation, not a legal opinion The answers below are our reading of Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744. They are not a binding legal opinion. Every statement about a deadline or an obligation carries the article number so that it can be checked against the official text. CypherOn provides cybersecurity services and is not a law firm — for a binding assessment of a specific situation, turn to an attorney registered with the Czech Bar Association.

Basics and scope

Does the AI Act apply to an ordinary Czech company that develops no AI of its own?

Yes, but far more narrowly than is usually claimed. A company that only buys licences and uses them is a deployer for the purposes of the regulation (Article 3(4)), not a provider — the provider obligations, meaning conformity assessment, the technical documentation under Annex IV and registration in the EU database, do not apply to it.

In practice three things do: the prohibitions in Article 5, measures to promote the improvement of AI literacy under Article 4 and — where the company generates or publishes AI content — transparency under Article 50(3) and (4). A fourth set of obligations, under Article 26, is triggered only once a system falls into the high-risk category, typically in recruitment or worker management. What follows from each of them is set out in the guide section on companies that only use AI.

How many risk categories does the AI Act have and what applies in each?

Four tiers, each with a different set of obligations and a different date of application:

  • Unacceptable risk (Article 5) — prohibited practices, since 2 February 2025. This is not an obligation to document something, it is a ban.
  • High risk (Article 6) — the full set of Chapter III requirements, from 2 December 2027 and 2 August 2028 respectively.
  • Limited risk (Article 50) — transparency obligations, from 2 August 2026.
  • Minimal risk — everything else, which is most corporate use of AI. Article 4 and possibly Article 50 still apply, no documentation and no registration.

The tiers are not mutually exclusive: one tool can sit in minimal risk and still carry an obligation under Article 50 because it generates content. Which two routes lead into high risk, and what exceptions apply to the prohibitions, is described in the guide section on the four risk levels.

We are a small company or a start-up — is there any relief for us?

The substantive obligations do not change with size, but the regulation works with size in several places and the omnibus extended that:

  • Fines — for small and medium-sized enterprises, including start-ups, the lower of the two figures in the fine range applies rather than the higher one, and that holds in all three tiers (Article 99(6), covering paragraphs 3, 4 and 5). The new paragraph 6a added a comparable relief for small mid-cap companies, but only for paragraphs 4 and 5 — it does not extend to the top tier for the prohibitions in Article 5.
  • Technical documentation — after the amendment of Article 11(1), small and medium-sized enterprises and small mid-cap companies may provide the Annex IV elements in a simplified manner, on a form the Commission is to draw up for that purpose. Notified bodies have to accept it.
  • Quality management system — the amended Article 17(2) says expressly that implementation is to be proportionate to the size of the provider; the degree of rigour and the level of protection may not be lowered, however.

Definitions of both categories were added to Article 3 as points (14a) and (14b) — a small and medium-sized enterprise as defined in Commission Recommendation 2003/361/EC, a small mid-cap company as defined in Recommendation (EU) 2025/1099.

The Czech act in preparation is to add two further reliefs: for less serious breaches, the option of issuing a warning instead of immediately opening administrative offence proceedings, and lower fine ceilings. For now that is only a draft from the Ministry of Industry and Trade, not the state of the law — where the Czech act stands is tracked in the guide section on supervision and penalties.

What does the AI Act not cover at all?

The most frequently overlooked exclusions in Article 2:

  • Use exclusively for military, defence or national security purposes (paragraph 3).
  • Research, testing and development prior to being placed on the market — except testing in real-world conditions (paragraph 8).
  • Purely personal non-professional activity of a natural person (paragraph 10). An employee using AI at work does not belong here.
  • Systems released under a free and open-source licence (paragraph 12).

The open-source exception is narrower than it looks: it does not apply where the system is placed on the market as high-risk, and it covers neither the prohibited practices in Article 5 nor transparency under Article 50. The full scope of application is in the opening section of the guide.

Dates after the 2026 omnibus

We hear the AI Act deadlines have moved. What exactly changed?

Regulation (EU) 2026/1744 (the digital omnibus on AI) entered into force on 27 July 2026 and, by amending Article 113, moved two dates:

  • Chapter III Sections 1, 2 and 3 for systems under Article 6(2) and Annex III apply from 2 December 2027 instead of 2 August 2026.
  • The same provisions for systems under Article 6(1) and Annex I, meaning those embedded in regulated products, apply from 2 August 2028 instead of 2 August 2027.

Nothing else moved — the general date of application of 2 August 2026 including transparency under Article 50, the prohibitions in Article 5 (since 2 February 2025) and the obligations for general-purpose AI models (since 2 August 2025) all stand. The other omnibus changes and the whole timeline including the original dates are covered in the guide section on the omnibus.

We found an article saying the high-risk obligations start on 2 August 2026. Is that a mistake?

Under the wording in force as of the validity date of this page, yes. 2 August 2026 was the correct date for Annex III systems until the omnibus moved it to 2 December 2027.

A practical test for spotting such a text: if it does not mention Regulation (EU) 2026/1744 and at the same time speaks of high-risk obligations from August 2026, it was written before the end of July 2026 and its timeline is out of date. Individual statements in it may still be correct — the postponement touched the deadlines, not the substance of most requirements.

We recommend not relying on secondary sources and checking dates directly in Article 113 of the consolidated text of the AI Act. Regulation (EU) 2026/1744 itself has only four articles — the new dates are in its Article 1, point 40, which amends Article 113 of the AI Act.

We have documentation in progress under the old wording. Do we have to rewrite it?

There is no need to throw it away. The omnibus changed deadlines and part of the definitions, not the logic of the regulation. The points worth checking are these:

  • The classification of systems you treated as safety components. The new definition in Article 3(14) and the new paragraphs 1a to 1c in Article 6 take some of them out of the category — exactly which ones, and on what condition, is in the guide.
  • Internal materials on AI literacy. If they are built on having to demonstrate a level of knowledge for specific individuals, the wording no longer matches Article 4.
  • Deadlines in project plans. For Annex III systems you have roughly 16 months more.
  • The cybersecurity part for high-risk systems. Where the system falls under the Cyber Resilience Act, the new Article 42(3) makes it possible not to address it separately under Article 15.

We use AI, we do not develop it

Does the AI Act require us to train staff? We are being offered mandatory training.

Not in the form in which it is being offered. Article 4 was replaced by the omnibus and the new wording requires only “measures to promote the improvement of AI literacy”, proportionate to the technical knowledge, experience and education of the people concerned and to the context in which the tool is used.

The decisive part is the last sentence of paragraph 1, which was not in the original wording: the obligation “does not require providers or deployers to guarantee any specific level of AI literacy of any individual”. The regulation therefore prescribes no certificate, no test and no number of hours, and there is no level you would have to demonstrate for a particular employee.

What is an obligation: to adopt measures and to be able to show that you adopted them. Training is one option, not the only one — rules for using the tools, guidance inside the tool itself or internal documentation work just as well. Under the new Article 4(2), the Commission is to publish practical examples of compliance on the single information platform.

If a vendor tells you the AI Act requires staff training with a demonstrated level, they are arguing from wording that ceased to apply on 27 July 2026. What exactly the omnibus changed in Article 4 is in the guide section on the omnibus.

What may and may not an employee put into ChatGPT, Copilot or Claude?

The AI Act does not answer this question — it does not govern what data you put into a tool. The answer follows from other rules and from the contract with the provider:

  • GDPR — entering personal data into a tool is processing. You need a legal basis, clarity about the role of the provider (processor or separate controller), a processing agreement, transfers outside the EU sorted out and an entry in the record of processing activities.
  • Act No. 264/2025 Coll., if you are a regulated entity — the AI tool is an asset and its provider is an ICT service supplier, with everything supply chain risk management entails.
  • Trade secrets and contractual confidentiality obligations towards clients. This tends to bite earlier than GDPR: customer data under an NDA do not become lawful input just because nobody is named in them.
  • The terms of the specific licence. The crucial difference is between the consumer and the business variant of the same tool, mainly in whether inputs are used for training and how long they are retained. The decision can only be based on the terms of the version you actually have, not on the product name.

The practical output of this is usually a one-page rule: a list of approved tools, the categories of data that must not go into them, and who approves a new tool. The same document then normally doubles as evidence of the measures under Article 4.

We deliberately do not offer a ready-made template. The rule makes sense only if it matches the tools that actually run in the company and the data that flow into them; borrowed wording creates the impression of a discharged obligation, misses the real operation and proves nothing in an inspection. What is reusable is the structure and examples of wording, not a document to sign.

When do we stop being a user and become a provider with all the obligations?

In three situations under Article 25(1): you put your name or trademark on a high-risk system (point (a)), you make a substantial modification to it (point (b)), or you change the intended purpose of a system in such a way that it becomes high-risk (point (c)). In all three, the provider obligations under Article 16 pass to you.

In practice the third situation is the most common, because it needs no development of your own. Building an internal tool for screening CVs or assessing creditworthiness on top of a purchased general-purpose model is enough to put you in the provider role — a system prompt and an API connection will do it.

What the omnibus added — what documentation the original provider has to hand over, and why a breach of Article 25 now sits in the 15 million euro or 3 % of turnover tier — is covered in the guide section on the deployer taking over the provider role.

Can we deploy a tool that evaluates the mood of employees or candidates?

As a rule, no. Article 5(1)(f) prohibits placing on the market, putting into service for this specific purpose, or using AI systems to infer emotions of a natural person in the areas of workplace and education institutions; the only exception is use for medical or safety reasons. The prohibition has applied since 2 February 2025 and sits in the top fine tier — up to 35 million euro or 7 % of total worldwide annual turnover.

It catches things that are routinely sold as analytics: sentiment scoring of contact centre calls, measuring employee engagement from camera footage, evaluating the facial expressions or voice of a candidate during an interview.

Alongside it, point (g) prohibits biometric categorisation of people in order to deduce their race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation. The exception in that point is aimed at lawfully acquired biometric datasets and at the area of law enforcement, so it does not reach a corporate tool — the scope of both prohibitions is in the guide.

The breach usually comes packaged in a module of an HR system or an analytics tool whose feature description nobody read. Checking already deployed tools against Article 5 is therefore the first thing we do in such a situation — it is quick, and it is the only tier where the issue is not documentation but a ban.

Do we have to report or register anything if we only use AI?

No. Registration in the EU database under Article 49 attaches to providers of high-risk systems, or to a provider who documents under Article 6(4) that its Annex III system is not high-risk. A deployer in the position of an ordinary user registers nothing and has no ongoing reporting duty towards the authority.

A registration duty appears only if you deploy a high-risk system as a public authority, or if you become a provider under Article 25.

Do note, though, that an incident in an AI tool may be reportable under other rules — under Act No. 264/2025 Coll. if it affects a regulated service, or under GDPR if it was a personal data breach. The AI Act does not disapply those deadlines, and it is practical to have one process that covers both sides.

Marking AI content under Article 50

From when do we have to mark AI outputs and what does it cover?

Chapter IV, meaning Article 50, applies from 2 August 2026. The obligations split by role:

  • Provider — with systems interacting directly with people it has to be apparent that this is AI (paragraph 1), and the outputs of generated audio, image, video or text have to be marked in a machine-readable format (paragraph 2).
  • Deployer — for deep fakes and for AI text published to inform the public on matters of public interest, it discloses that the content was generated or manipulated by AI (paragraph 4), and with emotion recognition or biometric categorisation it informs the people exposed to it (paragraph 3).

Paragraph 5 adds what the information has to look like: clear, distinguishable, accessible and provided at the latest at the time of the first interaction or exposure. As a practical example, the Czech Telecommunication Office mentions labels such as “AI generated” for fully generated content and “AI modified” for content edited with AI. The conditions attaching to the individual paragraphs are covered in the guide section on marking under Article 50.

Our chatbot has been running for two years. Is there a transitional period for us?

For the machine-readable marking duty under Article 50(2), yes. Providers of generative systems placed on the market before 2 August 2026 have until 2 December 2026 under the new Article 111(4).

This transitional rule is aimed at paragraph 2, meaning at providers. The deployer obligations under paragraph 4 and the rules on how to inform under paragraph 5 apply from 2 August 2026 with no delay. So be careful: if you are both the provider and the deployer of your own tool, the transitional period does not cover everything.

What counts as sufficient marking? Is a sentence in the terms of use enough?

It is not. The duty under paragraph 2 speaks of marking in a machine-readable format that is detectable as artificially generated — a property of the output, not a line in documentation. The duty under paragraph 4 concerns what a person will see, and paragraph 5 adds the requirement of clarity, distinguishability and timing no later than the first interaction or exposure.

The most concrete description available of what counts as sufficient is the code of practice on transparency of AI-generated content, published by the Commission on 10 June 2026, and the guidelines on Article 50 issued alongside it. The code is voluntary and does not replace the obligation under the regulation; its role in demonstrating compliance is described in the guide.

When is marking not required?

The exceptions are in Article 50 itself and they are narrower than they are usually read:

  • Under paragraph 2, for systems performing an assistive function for standard editing that do not substantially alter the input data or their semantics. Proofreading belongs here, rewriting a text into a new shape does not.
  • Under paragraph 4, for evidently artistic, creative, satirical and fictional works or programmes, and for AI text that has undergone human review or editorial control and for which someone holds editorial responsibility.
  • Across the paragraphs, for use authorised by law to detect, prevent, investigate or prosecute criminal offences.

The precise scope of the first two exceptions — with artistic work the obligation is only narrowed, not removed — is in the guide section on Article 50. In its press release of 31 July 2026, the Czech Telecommunication Office recommends assessing for each specific activity whether it falls under one of the exceptions, and reading Article 50 together with the Commission guidelines.

Security, overlap with other rules and supervision

Does the AI Act address prompt injection and data leaking through model outputs?

Not by name. The closest is Article 15, which requires an appropriate level of accuracy, robustness and cybersecurity for high-risk systems; its paragraph 5 lists attacks on training data and on the model, inputs designed to make the model err, and confidentiality attacks. The full list from paragraph 5 is in the guide.

Prompt injection fits under paragraph 5 through the general wording on resilience against attempts by unauthorised third parties to alter the use, outputs or performance of the system by exploiting its vulnerabilities. The regulation offers no guidance on it, however, and the whole of Article 15 applies only to high-risk systems — for an ordinary corporate deployment nothing follows from it.

The taxonomy therefore has to come from elsewhere. The most widely used one is the OWASP Top 10 for Large Language Model Applications, which does name prompt injection, data leakage through outputs and excessive agency. It is not a legal rule, but as a basis for assessing the risks of a specific deployment it is more usable than Article 15.

How do we deal with tools employees obtained outside IT?

The AI Act does not address this problem at all, and it is still the biggest risk in the whole topic in practice. The company answers for the processing of personal data and for the protection of trade secrets even with a tool it does not know about.

What works: map the tools from technical sources — proxy or SASE logs, DNS queries, the list of OAuth applications connected to the corporate tenant, and corporate card statements. A questionnaire does not work, because it asks the people who are going around the rule.

The other half of the solution is having an approved option that is actually usable. If the corporate tool is worse or slower than the consumer version, a ban will not stop the workaround.

An inventory of tools is useful for the regulation itself as well: without a list showing the role, the owner and the risk classification for each tool, you cannot even answer whether Article 50 concerns you. Why this scenario is riskier than the regulation itself is covered in the guide section on companies that only use AI.

How does the AI Act relate to the Czech Cybersecurity Act, NIS2 and GDPR?

They run alongside each other and the obligations add up. Each rule targets something different:

  • The AI Act regulates the AI system as a product — what properties it has to have and who answers for them.
  • Act No. 264/2025 Coll. (the Czech transposition of NIS2) regulates the operation of a regulated service. From its perspective the AI tool is an asset and its provider an ICT service supplier, with everything supply chain risk management and incident reporting entail.
  • GDPR regulates the processing of personal data. Article 2(7) of the AI Act expressly confirms that GDPR is not affected by it.

The omnibus reduced duplicated documentation in two places: under Article 27(4) the fundamental rights impact assessment may build on parts of the data protection impact assessment under Article 35 GDPR, and the new Article 42(3) recognises compliance with the cybersecurity requirements of Article 15 for systems covered by the Cyber Resilience Act. The conditions for both are in the guide.

The new Article 4a inserted by the omnibus, by contrast, is narrow — it covers only special category data used to detect and correct bias in a model, and even that under hard conditions. It is not a general permission to process special category data for training, and in itself it creates no obligation to detect bias.

What penalties are we facing?

Article 99 has three tiers. In each of them the higher of the two figures applies — a fixed amount, or a percentage of worldwide turnover for the preceding financial year:

  • Up to 35 million euro or 7 % — non-compliance with the prohibitions in Article 5.
  • Up to 15 million euro or 3 % — breach of the ordinary obligations, whether in the role of provider, importer, distributor or deployer, including transparency under Article 50.
  • Up to 7.5 million euro or 1 % — incorrect, incomplete or misleading information supplied to notified bodies or competent authorities.

For smaller undertakings the tiers are softened, and fines on providers of general-purpose AI models are imposed by the Commission itself under Article 101. The breakdown, including which specific articles fall into the middle tier, is in the guide section on supervision and penalties.

Who enforces the AI Act in the Czech Republic?

As of the validity date of this page, the Czech implementing act that is to settle supervision is not in the Collection of Laws. The regulation itself is directly applicable and the obligations apply regardless, but at national level the procedural framework for imposing fines under Article 99(1) is missing.

Under the draft from the Ministry of Industry and Trade, the single point of contact is to be the Czech Telecommunication Office, with the Czech National Bank and the Office for Personal Data Protection in their respective sectors, the Czech Office for Standards, Metrology and Testing as the notifying authority, and a role in human rights matters for the Public Defender of Rights. Until the act is passed this is a proposal, not a settled division — in its press release of 31 July 2026, the Czech Telecommunication Office describes itself as one of the bodies that will supervise Article 50.

For some systems built on general-purpose AI models and for very large online platforms, supervision sits directly with the European AI Office. That does not reach anyone who merely uses such a system — they stay under the national authority. The precise delimitation of its exclusive competence after the omnibus, and the state of the Czech act, are in the guide section on supervision and penalties.

Official sources

The answers above are based on these sources. Every statement about a deadline or an obligation carries the article number, which can be looked up in them.

Regulation (EU) 2024/1689 — Artificial Intelligence Act ↗ The official text published on 12 July 2024. The 2026 changes are not reflected in it — they are in the regulation below. Regulation (EU) 2026/1744 — digital omnibus on AI ↗ Regulation of 8 July 2026, published on 24 July 2026, in force since 27 July 2026. The source of the new wording of Article 4, the new definition of a safety component, the new paragraphs in Article 6 and the postponed dates in Article 113. European Commission — regulatory framework for AI ↗ The Commission hub on the AI Act: the risk-based approach, the timeline, implementing acts and guidelines. Commission guidelines on the transparency obligations under Article 50 ↗ Interpretation of Article 50 for providers, deployers and competent authorities. Code of practice on transparency of AI-generated content ↗ A voluntary code published by the Commission on 10 June 2026 on Article 50(2), (4) and (5). The source of the answer on what counts as sufficient marking. AI Act Service Desk (European Commission) ↗ The official Commission contact point for AI Act questions, including a walk-through of the obligations by role. Czech Telecommunication Office — press release on 2 August 2026 and Article 50 ↗ Release of 31 July 2026, in Czech. The source of the recommended three-step approach, of the “AI generated” and “AI modified” examples, and of the wording on the future supervisory role of the Office. Czech Telecommunication Office — Artificial intelligence ↗ The page of the Office on the AI Act, in Czech. It states itself that the AI Act requires a national implementing act for the institutional and penalty mechanisms. Ministry of Industry and Trade — draft act on artificial intelligence ↗ Press release of 26 September 2025, in Czech. The source of the split of supervision between the Czech Telecommunication Office, the Czech National Bank, the Office for Personal Data Protection, the Czech Office for Standards, Metrology and Testing and the Public Defender of Rights, of both reliefs for smaller companies (a warning instead of immediately opening administrative offence proceedings, lower fine ceilings) and of the regulatory sandbox. This is a draft, not an act in force. Ministry of Industry and Trade — rules on marking AI content ↗ Press release of 8 July 2026, in Czech. A summary of the Article 50 obligations from 2 August 2026 and of the omnibus transitional rule until 2 December 2026. Act No. 264/2025 Coll. on cybersecurity ↗ The overlap discussed in the security answers. Our guide to the Czech Cybersecurity Act covers it in detail. NÚKIB — guide to the secure use of AI in public administration ↗ Material of the Czech National Cyber and Information Security Agency on secure and responsible AI adoption. It targets public authorities, but the procedures transfer to companies. OWASP Top 10 for Large Language Model Applications ↗ Not a legal rule. It is the most widely used taxonomy of the vulnerabilities the AI Act does not name — prompt injection, data leakage through outputs, excessive agency of agents.
Content valid as of 8 August 2026

A specific situation

The general answer is short,
the one about your tool is not.

Most questions turn on three things: what the tool actually does, what data flow into it and which role you hold. Describe the situation and we will go through it with you.