Guide · AI Act / 2024/1689
GUIDE TO THE
AI ACT
What the Artificial Intelligence Act requires after the changes of July 2026 — who, what and from when. With links to the official text and no copied paragraphs.
What the AI Act regulates and what it does not
The Artificial Intelligence Act — Regulation (EU) 2024/1689 — is product regulation, not a code of ethics. It sorts AI systems by what they are used for and what risk that creates, not by the technology inside them. The definition of an AI system in Article 3(1) is deliberately broad: a machine-based system that infers, from the input it receives, how to generate outputs such as predictions, content, recommendations or decisions.
The regulation entered into force on 1 August 2024, but it becomes applicable in stages and the individual chapters start at different dates. The prohibited practices have applied since February 2025, the obligations of providers of general-purpose AI models since August 2025, the transparency obligations from August 2026, and the obligations for high-risk systems were pushed back in 2026 — which is the subject of the very next section.
What falls outside the regulation: systems placed on the market, put into service or used exclusively for military, defence or national security purposes (Article 2(3)); research and development activity prior to placing on the market, with the exception of testing in real world conditions (Article 2(8)); purely personal non-professional activity of a natural person (Article 2(10)); and systems released under free and open-source licences, unless they are placed on the market as high-risk or fall under Article 5 or 50 (Article 2(12)).
The AI Act does not replace the GDPR or the Czech Cybersecurity Act. It runs alongside them, and in a specific deployment the obligations add up rather than cancel each other out. For the protection of personal data the regulation says so expressly in Article 2(7); for cybersecurity regulation it follows from the fact that the regulation does not limit it in any way and aims at something else — at the product, not at the operation of a service.
What Regulation (EU) 2026/1744 changed, and why most articles carry the wrong timeline
On 8 July 2026 Regulation (EU) 2026/1744 was adopted — the digital omnibus package on artificial intelligence. It was published on 24 July 2026 and entered into force on the third day following publication, i.e. on 27 July 2026. It amends the AI Act, the Machinery Regulation and the basic regulation on civil aviation.
The practical consequence for the reader: a substantial part of the Czech content on the AI Act was written before it and therefore carries an invalid timeline. If a text tells you that the obligations for high-risk systems start on 2 August 2026, it was written before the omnibus. The four changes with the greatest practical impact are these:
- Deadlines for high-risk systems pushed back. Chapter III Sections 1, 2 and 3 — classification, technical requirements and the obligations of operators — apply to Annex III systems (Article 6(2)) from 2 December 2027 instead of 2 August 2026, and to systems embedded in Annex I products (Article 6(1)) from 2 August 2028 instead of 2 August 2027. Sections 4 and 5 of Chapter III — notified bodies, harmonised standards, conformity assessment and registration — were not postponed.
- Article 4 on AI literacy softened. The original wording required providers and deployers to take measures to ensure a sufficient level of AI literacy. The new wording speaks of measures to promote the improvement of AI literacy and expressly adds that neither of them has to guarantee any specific level for any individual.
- The notion of a safety component narrowed. The new definition in Article 3(14) ties the safety function to the intended purpose set by the provider. The new paragraphs 1a to 1c of Article 6 take out of the safety-component category systems used solely for user support, performance optimisation, service efficiency, automation, convenience or quality control, where that has no bearing on safety. At the same time, a system whose failure or malfunctioning would endanger health and safety is a safety component.
- Two new prohibitions. Points (ba) and (bb) were added to Article 5(1) — systems generating or manipulating intimate imagery of an identifiable person without their consent, and material depicting child sexual abuse. The new paragraphs 1a and 1b specify when the prohibition covers placing on the market and when it covers use. They apply from 2 December 2026, later than the other prohibitions.
The omnibus changed other things covered further down in this guide as well: it extended the exclusive competence of the European AI Office (Article 75), added Article 4a on the processing of special categories of personal data for the detection and correction of bias, introduced in Article 42 a presumption that the cybersecurity requirements are met for systems covered by the Cyber Resilience Act, clarified Article 25 on roles along the value chain and supplemented the penalty provisions in Article 99.
The four risk levels
The AI Act does not have one set of obligations for everything. It splits systems into four tiers, and each tier has different rules, including different dates. Classifying the specific tool is therefore the first thing worth doing — without it the obligations cannot be worked out at all.
- Unacceptable risk (Article 5). Prohibited practices, applicable since 2 February 2025. Two prohibitions are the most relevant for ordinary companies: the ban on inferring emotions of natural persons in the workplace and in education institutions (paragraph 1, point (f)), from which the regulation allows an exception only where the use is intended to be put in place or into the market for medical or safety reasons, and the ban on biometric categorisation inferring race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation (point (g)). Point (g) has an exception of its own too — it does not cover labelling or filtering of lawfully acquired biometric datasets, nor categorisation of biometric data in the area of law enforcement.
- High risk (Article 6). Two routes. Either the system is a safety component of a product covered by Annex I that is subject to third-party conformity assessment, or it is one of the use cases listed in Annex III — among them recruitment and worker management, access to education, creditworthiness assessment, risk pricing in life and health insurance, and the operation of critical infrastructure. The full regime of requirements and obligations, from 2 December 2027 and 2 August 2028 respectively.
- Limited risk (Article 50). Not a lighter version of high risk but a separate set of transparency obligations. Applicable from 2 August 2026, and it catches companies that develop nothing themselves.
- Minimal risk. Everything else — and that is most corporate use of AI. What remains from the regulation is Article 4 and possibly Article 50. Nothing more. For this category the regulation prescribes no documentation and no registration.
The exception in point (g) is aimed at work with lawfully acquired datasets and at the area of law enforcement; it does not reach ordinary commercial deployments, typically a tool in HR or in marketing. Article 6(3) then makes it possible to document that an Annex III system does not present a significant risk — where it performs a narrow procedural task, improves the result of a previously completed human activity, detects patterns in decision-making or performs a preparatory task. This calls for a documented assessment before placing on the market and registration under Article 49(2). Where the system performs profiling of natural persons, the exception can never be used.
Roles: provider, deployer, importer, distributor
Obligations do not fall on the company as such but on the role you hold in relation to a specific system. You can be the deployer of one tool and the provider of another. The regulation uses the roles consistently — where an obligation says “provider”, it does not concern the deployer, and vice versa.
The umbrella term is operator (Article 3(8)): a provider, product manufacturer, deployer, authorised representative, importer or distributor. It appears mainly in the provisions on supervision and penalties, so where the regulation speaks of an operator it means any of the above.
- Provider (Article 3(3)) — develops an AI system or a general-purpose AI model, or has one developed, and places it on the market or puts it into service under its own name or trademark, whether for payment or free of charge.
- Deployer (Article 3(4)) — uses an AI system under its own authority, except where used in the course of a personal non-professional activity. This is the role of most Czech companies.
- Importer (Article 3(6)) — established in the Union, places on the market a system bearing the name or trademark of a person established in a third country.
- Distributor (Article 3(7)) — is in the supply chain, makes a system available on the Union market and is neither the provider nor the importer.
The role is determined for a specific system, not for the company. It pays to write it into the tool inventory: one role, one owner and one risk classification per tool. Without that you cannot even answer who has to report what for which tool.
When a deployer becomes a provider
The most practical and most frequently overlooked part of the regulation for Czech companies. Under Article 25(1), a distributor, importer, deployer or other third party becomes the provider of a high-risk system — with all the obligations under Article 16 — in the three situations set out below.
When that happens, the original provider ceases under Article 25(2) to be the provider of that system. Here the omnibus spelled out what exactly the original provider has to give the new one: technical documentation sufficient to assess compliance with the requirements of Article 16, information on known limitations and failure modes, and targeted technical access, including access for testing and validation. There is an exception — where the original provider clearly stated that its system was not to be turned into a high-risk one, the duty to cooperate and hand over documentation does not apply to it.
The omnibus also added a penalty: an infringement of Article 25(2) and (4) is now listed in Article 99(4), point (da), i.e. in the tier of up to EUR 15 million or 3 % of total worldwide annual turnover, whichever is higher.
- You put your name or trademark on a high-risk system that is already on the market or in service (Article 25(1)(a)). Typically a white-label deployment or resale under your own brand.
- You make a substantial modification to a high-risk system already on the market in such a way that it remains high-risk (point (b)).
- You change the intended purpose of a system — including a system built on a general-purpose AI model — that was not high-risk, so that it becomes high-risk under Article 6 (point (c)).
Point (c) is a trap you can fall into without a single line of your own code. Build a tool on top of a general-purpose model that screens CVs or scores creditworthiness and you become the provider of a high-risk system, even though all you wrote was a system prompt and an API call. The boundaries can be clarified in advance — we handle it as a risk assessment of AI tools before deployment, because once the tool is live the change of intended purpose is a done deal.
A company that only uses AI: Copilot, ChatGPT, Claude
The most common situation in the Czech Republic and the biggest source of confusion. A company buys Microsoft 365 Copilot, ChatGPT or Claude licences and staff use them at work. In the eyes of the AI Act such a company is a deployer, not a provider. It carries out no conformity assessment, issues no declaration of conformity, keeps no technical documentation under Annex IV and registers nothing in the EU database.
The obligations of providers of general-purpose AI models under Chapter V do not concern you either — since 2 August 2025 they have applied to whoever develops the model and places it on the market. A model is considered to carry systemic risk where the cumulative amount of computation used for its training exceeded 10^25 floating point operations (Article 51(2)), or on the basis of a Commission decision. Tracking that and meeting the follow-on obligations is the business of the model provider, not yours.
What the regulation really does put on a deployer is four things:
- The prohibitions in Article 5, applicable since 2 February 2025. In practice: you must not deploy a tool that infers the emotions of employees — sentiment analysis of contact centre calls, engagement scores from cameras, rating candidates by their facial expressions — unless there is a medical or safety reason. This is the most common real breach we come across at Czech companies, and it usually comes bundled inside an HR module or an analytics tool that nobody has read.
- Article 4 — AI literacy. You are to take measures to promote the improvement of AI literacy among staff and other persons dealing with the operation and use of AI systems on your behalf, taking into account their knowledge, training and the context of use. You do not have to guarantee a particular level for a particular person — the new wording expressly rules that out.
- Article 50(3) and (4) — transparency on the deployer side. If you generate a deep fake or publish AI text for the purpose of informing the public on matters of public interest, you have to disclose it. If you deploy emotion recognition or biometric categorisation where these are not prohibited, you have to inform the persons concerned that the system is in operation. From 2 August 2026.
- Article 26 — obligations for high-risk systems. Only once you deploy an Annex III system, typically in recruitment, worker management or client assessment. From 2 December 2027. For some deployers a fundamental rights impact assessment under Article 27 comes on top of that.
The greatest real risk in this scenario is not in the regulation at all. It lies in what data staff put into the tools and which tools they procure outside IT — and those can only be traced from technical sources, never from a questionnaire. We do the AI usage policy and the assessment of the tools already running in the company as one step, among other things because that policy is the easiest way to evidence the measures under Article 4 — but only where it describes the tools and the data the company actually has. Wording lifted from elsewhere has no such link and evidences nothing in an inspection.
Labelling AI outputs under Article 50
Chapter IV applies from 2 August 2026 and it is the part of the regulation that reaches the largest number of entities. It requires no conformity assessment and no technical documentation. What it requires is that it be apparent that AI is involved.
The obligations are split by role. Under paragraph 1 the provider ensures that systems intended to interact directly with people are designed so that a person can tell they are dealing with an AI system — unless that is obvious. Under paragraph 2 it ensures that the outputs of systems generating synthetic audio, image, video or text are marked in a machine-readable format and detectable as artificially generated; the regulation speaks of effective, interoperable, robust and reliable technical solutions.
The deployer has two obligations. Under paragraph 4 it discloses, for a deep fake, that the content has been artificially generated or manipulated, and the same goes for AI text published for the purpose of informing the public on matters of public interest. Under paragraph 3 it informs persons exposed to emotion recognition or biometric categorisation that the system is in operation — where such use is not outright prohibited by Article 5.
Here the omnibus introduced a transitional period. Under the new Article 111(4), providers of systems generating synthetic audio, image, video or text that were placed on the market before 2 August 2026 are to take the steps necessary to comply with Article 50(2) by 2 December 2026.
- Exception in paragraph 2: it does not apply to the extent that the systems perform an assistive function for standard editing or do not substantially alter the input data provided by the deployer or the semantics thereof.
- Exception in paragraph 4 for evidently artistic, creative, satirical and fictional works or programmes — the obligation narrows to disclosing the existence of such generated content in an appropriate manner that does not hamper the display or enjoyment of the work.
- Exception in paragraph 4 for AI text that has undergone a process of human review or editorial control and for the publication of which a natural or legal person holds editorial responsibility.
- Under paragraph 5 the information is provided clearly and distinguishably at the latest at the time of the first interaction or exposure, and it has to meet the applicable accessibility requirements.
On 10 June 2026 the Commission published a voluntary code of practice on the transparency of AI-generated content covering Article 50(2), (4) and (5), and alongside it guidelines on Article 50. The code is voluntary and does not replace the legal obligation — that follows from the regulation. Signing up to the code is, however, intended as a way of demonstrating compliance, and in Article 50(7) the omnibus adjusted how the Commission assesses the adequacy of the code.
The cybersecurity layer: what is in the regulation and what is missing from it
Article 15 requires high-risk systems to achieve an appropriate level of accuracy, robustness and cybersecurity throughout their lifecycle. Paragraph 4 adds a duty to address feedback loops in systems that continue to learn after being placed on the market.
Paragraph 5 is unusually concrete for a regulation: the technical solutions are to include measures to prevent, detect, respond to, resolve and control attacks trying to manipulate the training data set (data poisoning) or the pre-trained components used in training (model poisoning), inputs designed to cause the model to make a mistake (adversarial examples, model evasion), confidentiality attacks and model flaws.
Here the omnibus added a practical shortcut. The new Article 42(3) provides that a high-risk system falling within the scope of the Cyber Resilience Act (CRA, Regulation (EU) 2024/2847) and meeting the conditions of its Article 12(1) is deemed to comply with the cybersecurity requirements of Article 15. Whoever deals with the CRA does not deal with this part twice.
What you will not find in the regulation, on the other hand: prompt injection, data exfiltration through model outputs and tools procured outside IT. They are not named there. Prompt injection can be brought under the general duty in Article 15(5) — resilience against attempts by unauthorised third parties to alter the use, outputs or performance of the system by exploiting its vulnerabilities — but the regulation gives no guidance on it, and the duty applies to high-risk systems only. The taxonomy therefore has to come from elsewhere, typically from the OWASP Top 10 for large language model applications.
- For tools you merely use, the risk does not turn into your obligation under Article 15, but it stays with you as a risk under Act No. 264/2025 Coll. — an AI tool is an asset and its supplier is an ICT service supplier, with everything that entails under both the lower and the higher set of obligations.
- Putting personal data into a tool is processing under the GDPR. The AI Act does not deal with that; the new Article 4a covers only the narrow case of processing special categories of data for the detection and correction of bias, and under hard conditions — pseudonymisation, strict control and documentation of access, a ban on transmission to other parties, deletion once the bias has been corrected, and a justification of necessity in the records of processing activities.
- Article 27(4), as amended by the omnibus, allows a fundamental rights impact assessment to refer to, or to take over, the relevant parts of a data protection impact assessment under Article 35 of the GDPR. Two sets of documentation therefore do not have to be written from scratch twice.
- Providers of high-risk systems under the exclusive competence of the European AI Office report serious incidents to that Office, not to the national authority (new Article 75(1a)). The Office then passes the information on to the national market surveillance authority.
A practical view: when AI is being rolled out, the weak spot is usually what flows into the tool, not the model itself. It can be assessed with the same logic as any other ICT supplier — what data, where to, for how long, who has access to it, what happens to it during training, how you get it back and what remains after the contract ends. We do this as a data security assessment for AI adoption, and the overlap with the Czech Cybersecurity Act follows on from it.
Supervision in the Czech Republic and penalties
Supervision in the Czech Republic is split between several authorities and is to be settled definitively by the act on artificial intelligence, which as at the validity date of this page is not in the Collection of Laws. The draft from the Ministry of Industry and Trade, which is responsible for implementation, envisages the Czech Telecommunication Office as the single point of contact, the Czech National Bank and the Office for Personal Data Protection in their respective sectors, the Czech Office for Standards, Metrology and Testing as the notifying authority, and the Public Defender of Rights on questions of human rights protection. The draft also includes a national regulatory sandbox.
The same draft envisages two forms of relief for smaller businesses: for a less serious infringement it should be possible to issue a warning instead of opening administrative proceedings straight away, and a lower ceiling for fines is to be set. Both are so far the intention of the drafter, not the law in force — as long as the act is not in the Collection of Laws, nothing can be derived from it. In a press release of 31 July 2026 the Czech Telecommunication Office states that supervision of the obligations under Article 50 will be exercised in the Czech Republic by market surveillance authorities and that it will be one of them — it speaks about itself in the future tense, which is consistent with the act not having been adopted.
Over part of the systems the European AI Office has exclusive competence. Through the new Article 75(1) the omnibus extended it to AI systems built on general-purpose AI models where the model and the system come from the same provider or from providers within the same undertaking, and to systems forming part of very large online platforms or search engines under the Digital Services Act. For deployers this exclusive competence applies only where they are at the same time providers or part of the same undertaking — an ordinary company that merely uses such a system is supervised by the national authority.
The penalty tiers are set by Article 99 and there are three of them. In all of them the higher of the fixed amount and the percentage of total worldwide annual turnover for the preceding financial year applies. Two adjustments by size of undertaking and a special regime for providers of general-purpose AI models go with the tiers:
- Up to EUR 35 million or 7 %. Non-compliance with the prohibitions in Article 5.
- Up to EUR 15 million or 3 %. The other obligations of operators and notified bodies — among them the obligations of providers under Article 16, of importers under Article 23, of distributors under Article 24, of deployers under Article 26, transparency under Article 50 and, newly, Article 25(2) and (4).
- Up to EUR 7.5 million or 1 %. Supplying incorrect, incomplete or misleading information to notified bodies or competent authorities.
- Adjustment by size. For SMEs including start-ups, Article 99(6) applies the lower of the two values, in relation to paragraphs 3, 4 and 5. Through the new paragraph 6a the omnibus introduced comparable relief for small mid-cap enterprises, but only in relation to paragraphs 4 and 5 — so it does not apply to the highest tier for the prohibitions in Article 5 (paragraph 3). To Article 99(1) the omnibus added that Member States are to take into account the interests and the economic viability of both categories.
- General-purpose AI models. Fines on their providers are imposed by the Commission itself under Article 101 — up to 3 % or EUR 15 million. That provision applies from 2 August 2026.
Chapter XII on penalties applies from 2 August 2025, but the specific rules and procedures are laid down by the Member States under Article 99(1). Until the Czech implementing act takes effect, the national procedural framework for imposing fines is missing. That leaves the obligations under the regulation itself untouched — the regulation is directly applicable and stands regardless of the state of the Czech act.
Timeline of application after the omnibus
The dates follow the wording of Article 113 of the AI Act as amended by Regulation (EU) 2026/1744. Where a deadline moved, the original date is given as well, so that the change is visible.
1 Aug 2024
The AI Act entered into force. The obligations themselves start in stages under Article 113.
2 Feb 2025
Chapters I and II: scope, definitions, Article 4 on AI literacy and the prohibited practices under Article 5.
2 Aug 2025
Chapter III Section 4 (notifying authorities and notified bodies), Chapter V (general-purpose AI models), Chapter VII (governance) and Chapter XII (penalties), with the exception of Article 101. Also Article 78.
27 Jul 2026
Regulation (EU) 2026/1744 entered into force. From that day the new wording of Article 4, the new definition of a safety component in Article 3(14) and the new paragraphs 1a to 1c of Article 6 apply. The omnibus also moved Regulation (EU) 2023/1230 on machinery from Section A of Annex I to Section B (point 21); for systems embedded in products covered by the legislation in Section B, only Article 6(1), the new Article 60a and Articles 102 to 112 apply from the regulation.
2 Aug 2026
The general date of application for the rest of the regulation — including Chapter IV, i.e. the transparency obligations under Article 50, Chapter III Section 5 (conformity assessment, registration), Article 6(5) and Article 101.
2 Dec 2026
The new prohibitions under Article 5(1), points (ba) and (bb), and paragraphs 1a and 1b — systems generating non-consensual intimate material and material depicting child sexual abuse. At the same time the end of the transitional period for providers of generative systems placed on the market before 2 Aug 2026, who have to comply with Article 50(2) by that date (Article 111(4)).
2 Dec 2027
Chapter III Sections 1, 2 and 3 for high-risk systems under Article 6(2) and Annex III. Originally 2 Aug 2026.
28 Jan 2028
The deadline by which notified bodies notified under the harmonisation legislation in Annex I Section A are to apply for designation under the AI Act (Article 43(3)).
2 Aug 2028
Chapter III Sections 1, 2 and 3 for high-risk systems under Article 6(1) and Annex I Section A, i.e. for systems embedded in regulated products. Originally 2 Aug 2027. For the legislation in Section B, where the omnibus also moved machinery, the substantive requirements are to be written into the sectoral act itself by that date through a delegated act — only a narrow list of provisions applies to them directly from the AI Act.
2 Aug 2030
The final deadline for providers and deployers of high-risk systems intended to be used by public authorities that were placed on the market before the date of application of Chapter III (Article 111(2)).
Official sources
This guide is informative. What is authoritative is the official text — every statement about a date or an obligation above carries an article number you can look up in these sources.
Regulation (EU) 2024/1689 — Artificial Intelligence Act ↗
The official English text on EUR-Lex. Note that this is the original text published on 12 July 2024 — the 2026 changes are in the regulation below and are not reflected in this text.
Regulation (EU) 2026/1744 — digital omnibus on AI ↗
Regulation of 8 July 2026, published on 24 July 2026, in force since 27 July 2026. The source of all the postponed dates, of the new wording of Article 4 and of the changes to Articles 1, 2, 3, 5, 6, 10, 11, 17, 25, 27, 28, 42, 43, 50, 75, 99, 111 and 113. The new dates are in Article 1(40), which amends Article 113 of the AI Act.
European Commission — regulatory framework for AI ↗
The Commission hub on the AI Act: the risk-based approach, the timeline, implementing acts and guidelines.
Code of practice on the transparency of AI-generated content ↗
A voluntary code published by the Commission on 10 June 2026 to Article 50(2), (4) and (5) — the most concrete description available of what counts as sufficient labelling of AI content.
Commission guidelines on the transparency obligations under Article 50 ↗
An interpretation of Article 50 for providers, deployers and competent authorities. It complements the code of practice.
European Commission — AI literacy and skills ↗
Under the new Article 4(2) the Commission is to publish practical examples of how the duty to promote the improvement of AI literacy is met. This is where the materials on that topic come together.
AI Act Service Desk (European Commission) ↗
The official contact point of the Commission for questions on the AI Act, including an interactive walk-through of the obligations by role.
Czech Telecommunication Office (ČTÚ) — artificial intelligence ↗
The page of the Czech Telecommunication Office on the AI Act, in Czech. Mind the currency date stated on the page — part of the information predates the completion of the legislative process.
ČTÚ — press release on 2 August 2026 and Article 50 (in Czech) ↗
Release of 31 July 2026. The source for the statement that ČTÚ acts as a market surveillance authority for the transparency obligations and that in some cases enforcement lies with the European AI Office.
Ministry of Industry and Trade — draft act on artificial intelligence (in Czech) ↗
Press release of 26 September 2025. The source for the split of supervision between ČTÚ, the Czech National Bank, the Office for Personal Data Protection, the Czech Office for Standards, Metrology and Testing and the Public Defender of Rights, for both forms of relief for smaller companies (a warning instead of immediate administrative proceedings, a lower ceiling for fines) and for the regulatory sandbox. It is a draft, not an act in force.
Ministry of Industry and Trade — rules for labelling AI content (in Czech) ↗
Press release of 8 July 2026. A Czech summary of the obligations under Article 50 from 2 August 2026 and of the omnibus transitional rule until 2 December 2026 for generative systems that were already on the market.
Act No. 264/2025 Coll. on cybersecurity (in Czech) ↗
The overlap discussed in the cybersecurity section. Our guide to the Czech Cybersecurity Act goes into it in detail.
OWASP Top 10 for Large Language Model Applications ↗
Not a legal act. It is the most widely used taxonomy of the vulnerabilities the AI Act does not name — prompt injection, data leakage through outputs, excessive agency of agents.
ENISA — artificial intelligence and cybersecurity ↗
Publications of the EU Agency for Cybersecurity on the security of AI systems. Technical context for Article 15.