AI Act Ready

The AI Act became applicable on 2 August 2026

Find out what the EU AI Act actually requires of you.

Most guidance is written for enterprises with legal departments. This is a ten-question assessment for small and mid-sized companies that tells you which obligations apply to you today, which are already overdue, and which are still ahead of you.

Start the free assessmentNo account. Takes about three minutes.

Four dates, two of them already behind you

The July 2026 amendments moved the last two. They did not move the first two, which is the part most coverage got wrong.

  1. 2 February 2025

    Article 4: AI literacy

    Passed

    No transition period, no small-company exemption. In force for over a year.

  2. 2 August 2026

    Article 50: transparency

    In force

    Disclosure duties live, and national authorities gained full enforcement powers the same day.

  3. Today

    2 December 2027

    Annex III high-risk systems

    Deferred

    Recruitment, credit scoring, insurance pricing, biometrics. The date moved; the documentation did not.

  4. 2 August 2028

    Remaining high-risk obligations

    Deferred

    The rest of the high-risk regime, including systems embedded in regulated products.

What changed in 2026

The Digital Omnibus, Regulation (EU) 2026/1744, entered into force on 27 July 2026 and delayed the high-risk obligations everyone was preparing for. That created a widespread and mistaken impression that the AI Act had been postponed. It has not. The obligations that apply to ordinary companies are live now, and one of them has been live since early 2025.

Article 4

AI literacy

Overdue since 2 February 2025

Every organisation whose staff use AI systems must take measures supporting their AI literacy. Most companies have taken none, and it applies whether you build AI or merely use ChatGPT.

What it requires

Article 50

Transparency

Applies since 2 August 2026

Chatbots must disclose they are AI. Generated content must be machine-readable as artificial. Deepfakes must be labelled. National authorities gained full enforcement powers on the same date.

What it requires

Annex III

High-risk systems

Deferred to 2 December 2027

Recruitment, credit scoring, insurance pricing and biometrics carry the full high-risk stack. The July 2026 amendments moved the date, not the substance of what has to be documented.

What it requires

The obligation almost everyone has missed

Article 4 requires organisations to take measures supporting the AI literacy of staff who use AI systems. It applies to providers and deployers alike, which in practice means any company whose employees use ChatGPT, Copilot, Claude, or the AI features now embedded in ordinary business software.

It has been in force since 2 February 2025, with no transition period and no exemption for small companies, and national market surveillance authorities have been enforcing it since August 2026. The July 2026 amendments made the standard easier rather than harder: you no longer have to guarantee any particular level of competence, only show that you took measures.

Which turns the whole thing into a question of evidence, and evidence is inexpensive: a written policy, short role-appropriate training, and retained acknowledgements. That is precisely why having none of it is difficult to justify when an authority asks.

Check your position in three minutes

Ten questions on how your organisation uses AI. You get a plain-language breakdown of every obligation that applies, with article references and deadlines.

Begin the ten questions

Read the documents before you pay for them

This is the actual output of the generator, not a sample of it. Below is the opening of the AI Usage Policy as written for a small company whose staff use AI, running a chatbot and generating content. Your own answers change which documents appear and what they say.

Excerpt

AI Usage Policy

[Organisation name]: internal policy governing the use of AI systems

Satisfies the documented-policy element of the Article 4 AI literacy obligation and establishes the control environment a regulator will ask to see first.

1. Purpose and scope

This policy governs the use of artificial intelligence systems at [Organisation name]. It applies to every employee, contractor and temporary worker who uses an AI system in the course of their work, whether that system is procured by [Organisation name], embedded in software already in use, or accessed through a personal account for work purposes.

It exists to satisfy Article 4 of Regulation (EU) 2024/1689 (the AI Act), as replaced by Regulation (EU) 2026/1744, which requires organisations to take measures supporting the development of AI literacy among staff dealing with AI systems, and to establish a documented basis for the safe and lawful use of those systems.

2. Definitions

  • AI system: a machine-based system designed to operate with varying levels of autonomy that infers, from the input it receives, how to generate outputs such as predictions, content, recommendations or decisions.
  • Provider: a party that develops an AI system and places it on the market under its own name or trademark.
  • Deployer: a party using an AI system under its own authority in a professional capacity.
  • Personal data: as defined in Regulation (EU) 2016/679 (GDPR).

3. Permitted use

AI systems may be used to support work where the output is reviewed by a competent person before it is relied upon. The member of staff who uses an AI system remains accountable for the output as if they had produced it themselves.

  • Only tools recorded in the AI System Register may be used for work purposes.
  • A new tool must be recorded in the Register before first use.
  • Output must be checked for accuracy before it is sent externally, published, or used in a decision.

Generated alongside it

  • AI Literacy Training Record

    Article 4 asks what measures were taken, not what level of competence was reached. This record is the evidence that measures were taken, and is what an authority will request.

  • AI System Register

    The foundational evidence artefact. Almost every other obligation depends on having an accurate inventory, and it is usually the first thing requested.

  • Article 50 Transparency Notices

    Article 50 has been applicable since 2 August 2026. These disclosures are externally verifiable by anyone using your product, which makes them the most exposed obligation you currently carry.

4 documents, 21 numbered sections, with the article references and deadlines that apply to those answers.

Your organisation's name, the responsible person and the adoption date are filled in where the placeholders sit, on the page, before you buy anything.

See yours

What it costs

The assessment is free and complete in itself. If you want the paperwork that closes the gaps it finds, that is the paid half, and you see every document generated from your own answers before you decide.

Assessment

Free

Ten questions, about three minutes. Every obligation that applies to you, with article references and deadlines. No account and no card.

Take the assessment

Document pack

€349

  • AI Usage Policy
  • AI Literacy Training Record
  • AI System Register
  • Article 50 Transparency Notices

One payment, not a subscription, and it does not go stale: the documents are regenerated each time you open them, so later amendments reach you at no further cost. VAT added at checkout where it applies. A consultant's day rate for the same four documents starts well above this.