Summary · cheatsheet · the AI Act after the omnibus

AI ACT SUMMARY

Regulation (EU) 2024/1689 as amended by 2026/1744 · categories, roles, deadlines, penalties · ready to print as PDF

← Back to the AI Act guide
Summary · cheatsheet · the AI Act after the omnibus
Regulation (EU) 2024/1689 as amended by 2026/1744 · categories, roles, deadlines, penalties · ready to print as PDF
Orientation document This document is a simplified, informative overview of Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744, not a binding legal opinion or a complete interpretation. CypherOn is not a law firm — for a legal opinion, turn to an attorney registered with the Czech Bar Association. The authoritative source is the official text on EUR-Lex; the 2026 changes are in Regulation 2026/1744 and are not reflected in the 2024 text.
Directly applicable regulation Regulation (EU) 2024/1689 as amended by 2026/1744 · categories, roles, deadlines, penalties · ready to print as PDF

What the Artificial Intelligence Act means for a company after the changes made by Regulation (EU) 2026/1744. Everything else turns on two questions: which risk category the tool falls into and which role you hold in relation to it. A reference for management and IT, not a legal interpretation.

Roles: whose obligation it is

The provider (Article 3(3)) develops the system or has it developed and places it on the market under its own name or trademark. The deployer (Article 3(4)) uses it under its own authority — and that is where most Czech companies stand, including those that have merely bought Copilot, ChatGPT or Claude licences. The role is determined for the tool, not for the company, and it changes: under Article 25(1) you become the provider of a high-risk system when you put your name or trademark on it, substantially modify it, or change its intended purpose so that it becomes high-risk. The last case takes not a single line of your own code — building a CV-screening tool on top of a general-purpose model is enough. The original provider then ceases to be the provider and hands over the documentation (paragraph 2).

The four risk levels and how to tell them apart

1. Unacceptable risk — prohibited (Article 5)

Prohibited practices, since 2 Feb 2025, regardless of role or company size. Two of them matter in practice: inferring emotions in the workplace and in education institutions (the only exception is medical or safety reasons) and biometric categorisation inferring race, political opinions, trade union membership, religion, sex life or sexual orientation. How to spot it: the tool rates mood, engagement or facial expressions; it tends to sit inside an HR or analytics module. From 2 Dec 2026 two further prohibitions added by the omnibus apply — generating intimate material without the consent of the person depicted, and material depicting child sexual abuse.

2. High risk (Article 6)

Two routes in: the system is a safety component of a product covered by Annex I that undergoes third-party conformity assessment, or it is a use case from Annex III — recruitment and worker management, education, creditworthiness, insurance, critical infrastructure. How to spot it: the tool has a say in decisions about people or about operational safety, not about texts and spreadsheets. The full Chapter III regime applies from 2 Dec 2027 (Annex III) and 2 Aug 2028 (Annex I, Section A) respectively. For Annex III, Article 6(3) allows you to document that no significant risk arises.

3. Limited risk — transparency (Article 50)

A separate set of obligations, not a lighter version of high risk, from 2 Aug 2026. How to spot it: the system interacts with people directly or generates synthetic audio, image, video or text — it has to be apparent that AI is involved. It also catches companies that develop nothing themselves: deep fakes and AI text published to inform the public are disclosed by the deployer (paragraph 4). Exceptions: assistive editing, artistic and satirical works, content that has undergone human review.

4. Minimal risk — everything else

Most corporate use of AI: summarising, drafting text, code, translation, searching documents. How to spot it: the tool is not caught by Article 5, is not in Annex III and is not a safety component. What remains is Article 4 and possibly Article 50 where it generates content. No documentation, no registration, no conformity assessment. The tiers are not mutually exclusive — even a minimal-risk tool can carry an obligation under Article 50.

What to do: obligations by role and category

Penalty tiers (Article 99)

Three tiers, and in each of them the higher of the fixed amount and the percentage of total worldwide annual turnover for the preceding financial year applies. EUR 35 million / 7 % — non-compliance with the prohibitions in Article 5. EUR 15 million / 3 % — the other obligations of operators and notified bodies, among them Articles 16, 23, 24, 26, 50 and, newly, Article 25(2) and (4). EUR 7.5 million / 1 % — incorrect, incomplete or misleading information given to notified bodies or authorities. For SMEs including start-ups, paragraph 6 applies the lower of the two values in all three tiers; the new paragraph 6a gives comparable relief to small mid-cap enterprises, but only in relation to paragraphs 4 and 5 — not to the prohibitions in Article 5. Fines on providers of general-purpose AI models are imposed by the Commission itself (Article 101, from 2 Aug 2026). Chapter XII applies from 2 Aug 2025, but the procedural rules are laid down by the Member States and the Czech act on artificial intelligence is not in the Collection of Laws yet. That leaves the obligations under the regulation untouched — they apply directly.

Dates of application after the omnibus

2 Feb 2025
Chapters I and II: scope, definitions, Article 4 on AI literacy and the prohibitions under Article 5.
2 Aug 2025
Chapter III Section 4 (notified bodies), Chapter V (general-purpose models), Chapter VII (governance) and Chapter XII (penalties) except Article 101.
27 Jul 2026
Omnibus 2026/1744 in force: the new wording of Article 4, the new definition of a safety component (Article 3(14)), paragraphs 1a to 1c in Article 6. Machinery (2023/1230) moved from Section A of Annex I to Section B — only Article 6(1), Article 60a and Articles 102 to 112 apply to Section B.
2 Aug 2026
The rest of the regulation: Chapter IV (Article 50), Chapter III Section 5 (conformity assessment and registration), Article 101.
2 Dec 2026
The new prohibitions under Article 5(1)(ba) and (bb); end of the deferral under Article 50(2).
2 Dec 2027
Chapter III Sections 1 to 3 for Annex III (Article 6(2)). Originally 2 Aug 2026.
2 Aug 2028
Chapter III Sections 1 to 3 for Annex I Section A (Article 6(1)). Originally 2 Aug 2027.

From an overview to your own list

Paper is generic.
Your list of tools is not.

The overview ends where practice starts: which AI tools are actually running in the company, who owns them, which role you hold in relation to them and what data flows into them. We go through it with you, and the output is a record you can keep working with.