Practical guide · Reg. EU 2024/1689

AI Act compliance: what companies must do (and the documents to prove it)

The European AI Regulation is not just for big tech: anyone using AI systems — a website chatbot, a CV-screening tool, generative AI at the office — has duties of their own, some already applicable. The near-term deadline is 2 August 2026: the Article 50 transparency duties.

The dates that matter

2 February 2025Prohibited practices (Art. 5) and staff AI literacy (Art. 4): ALREADY APPLICABLE.
2 August 2025Rules on general-purpose AI models (GPAI) and governance.
2 August 2026Article 50 transparency (chatbots, generated content, deepfakes): THE KEY DEADLINE, confirmed by the Digital Omnibus.
2 December 2026Article 50(2) transparency for GPAI models generating synthetic content: deferred by the Digital Omnibus.
2 December 2027Obligations for Annex III stand-alone high-risk systems: deferred from 2 August 2026.
2 August 2028High-risk AI embedded in regulated products (Annex I): deferred from 2 August 2027.

Update: the Digital Omnibus package moved the dates

For two years 2 August 2026 was presented as the start of the high-risk obligations. It no longer is: Annex III moved to 2 December 2027 and Annex I to 2 August 2028. The Article 50 transparency duties, by contrast, are confirmed for 2 August 2026. Many articles still circulate the old calendar.

The 7 compliance documents

AI Act accountability is proven with documents. These are the ones a company or public body should have — all generated in minutes with DPO Workspace, in Italian and English:

  • AI systems register — The inventory: which systems you use, in what role, purpose and human oversight.
  • Risk classification — Prohibited / high-risk / transparency / minimal, with the resulting duties.
  • Transparency notice (Art. 50) — For chatbots, AI-generated content and deepfakes. Mandatory from 2/8/2026.
  • Corporate AI use policy — Authorised tools, data that must not be entered, human review of outputs.
  • FRIA (Art. 27) — Fundamental rights impact assessment for high-risk deployers.
  • AI training register (Art. 4) — Evidence of staff literacy: who, when, on what.
  • AI officer designation — The organisational role holding together register, classifications and training.

AI Act section in the document generator

All 10 templates are in the DPO Workspace generator: fill in a guided wizard and download the document as PDF or Word. The risk classification computes the outcome from your answers.

Try it free

Where to start, in practice

  1. Inventory the AI systems in use (including the 'department tools' nobody declared).
  2. Classify each system's risk: prohibited, high-risk, transparency, minimal.
  3. Adopt an internal policy and train staff (Art. 4: already mandatory).
  4. Prepare the Art. 50 notices before August 2026.
  5. For high-risk: human oversight, logs and, where required, a FRIA.

Frequently asked questions

Does the AI Act apply to SMEs that only use ChatGPT or similar tools?

Yes: those who use AI systems (deployers) have their own duties, starting with staff AI literacy (Art. 4, already applicable) and transparency (Art. 50, from 2 August 2026). The heaviest duties concern high-risk systems and apply from 2 December 2027.

What kicks in on 2 August 2026?

The Article 50 transparency duties: disclosing chatbots, AI-generated content and deepfakes. NOT the high-risk framework, which the Digital Omnibus package deferred to 2 December 2027 (Annex III stand-alone systems) and 2 August 2028 (Annex I, AI embedded in regulated products). Prohibited practices and AI literacy have applied since 2 February 2025.

Did the Digital Omnibus remove any obligations?

No. It moved the dates, not the substance: conformity assessment, technical documentation, quality management system, CE marking, EU database registration, human oversight and the FRIA are unchanged. Treating the deferral as a reason not to start means facing the same work with less time.

Which documents evidence compliance?

At minimum: an AI systems register, a risk classification per system, an internal AI use policy, a training register (Art. 4) and, where applicable, the Art. 50 transparency notice and the Art. 27 FRIA. All available in the DPO Workspace generator.

Do the AI Act and the GDPR overlap?

They complement each other: when an AI system processes personal data, the GDPR continues to apply (legal basis, notices, DPIA). The AI Act FRIA can build on an existing DPIA.

Be ready for August 2026

AI register, classification, transparency, policy, FRIA and training: all in one platform.

Start free