Regulation (EU) 2024/1689 of the European Parliament and of the Council, known as the AI Act, entered into force on 1 August 2024, and its obligations are being phased in. The prohibitions on certain practices and the AI literacy requirement have applied since February 2025, the rules for general-purpose AI models since August 2025, and the transparency obligations, together with most of the remaining provisions, since 2 August 2026. Two new prohibitions apply from 2 December 2026. The rules for high-risk systems were postponed by Regulation (EU) 2026/1744, the Digital Omnibus on AI, which entered into force on 27 July 2026. For systems listed in Annex III, such as those used in recruitment or creditworthiness assessment, they apply from 2 December 2027; for systems that are part of products covered by Annex I, from 2 August 2028. Yet most Czech businesses have still not checked whether the regulation applies to them at all.
Many businesses assume that the AI Act only regulates those who develop artificial intelligence. It does not. The regulation also reaches so-called deployers, meaning businesses that merely use AI systems.
¶ Provider and deployer
The AI Act distinguishes two main roles. A provider develops an AI system or has it developed, and places it on the market under its own name. A deployer uses an AI system in the course of its professional activity.
If your company uses an AI tool to evaluate employees, score clients, automate credit decisions or screen CVs, it is a deployer, and it has obligations.
The roles can also overlap. A company that takes an open-source model, fine-tunes it on its own data and deploys it internally may become a provider, even if all it originally wanted was to "use" AI.
¶ Four risk categories: where your system falls
At the top are prohibited practices, AI systems that must not exist at all: social scoring of people (assessing them on their social behaviour in a way that leads to unjustified detrimental treatment), manipulative techniques exploiting people's vulnerabilities, emotion recognition in the workplace and in educational institutions (except for medical or safety reasons), and real-time remote biometric identification in publicly accessible spaces for the purposes of law enforcement. The last of these is subject to narrow exceptions, such as searching for abduction victims or the threat of a terrorist attack. These prohibitions have applied since February 2025. From 2 December 2026, Regulation (EU) 2026/1744 adds a ban on AI systems that create realistic intimate images, video or audio of identifiable people without the consent of the person concerned, and on systems that generate child sexual abuse material.
High risk covers AI systems used in areas where a wrong decision can seriously affect a person's life. They include recruitment and employee evaluation, creditworthiness assessment, access to education, critical infrastructure and medical devices. These systems face the strictest obligations, including risk management, documentation, human oversight and transparency. They only apply from 2 December 2027, and from 2 August 2028 for medical devices and other products covered by Annex I.
Limited risk concerns systems that interact with people, typically chatbots and content generators. The main obligation is transparency: users must know that they are communicating with AI or that content was generated by AI. These obligations have applied since 2 August 2026. Providers of generative AI systems placed on the market before 2 August 2026 have until 2 December 2026 to mark the content they generate in a machine-readable format.
Minimal risk covers most everyday applications, such as spam filters, recommendation engines in online shops or logistics optimisation. Beyond the general duty to support AI literacy among staff who work with AI (Article 4), the AI Act imposes no specific obligations here and encourages voluntary codes of conduct.
¶ What to do now
Based on our own practice, we recommend five steps.
Map the AI systems in your business. Most companies have no idea how many AI tools they actually use, because SaaS tools, cloud services and analytics platforms count too. Draw up an inventory: what each tool is, who supplies it, what it is for and what data it processes.
Classify the risk. Work out which category each system in the inventory falls into. If you are unsure, assume the higher category. Underestimating the risk costs more than being overly cautious.
Appoint a responsible person. The AI Act does not explicitly require an "AI compliance officer", but someone in the business must know which AI systems it uses and what obligations follow. In a smaller firm this can be the existing compliance manager or in-house counsel.
Prepare documentation. For high-risk systems, the technical documentation is drawn up by the provider. As a deployer, you must use the system in accordance with its instructions for use, keep the automatically generated logs for at least six months and inform the employees concerned in advance. A fundamental rights impact assessment must be carried out by public bodies, by private entities providing public services and by anyone using AI to assess the creditworthiness of individuals or for risk assessment and pricing in life and health insurance. These obligations apply from 2 December 2027. Even for lower-risk systems, it pays to record why and how the business deployed AI, if only in case of an inspection or a dispute.
Put human oversight in place. For high-risk systems, a person must have a genuine ability to intervene in the AI's decision-making. An automated decision that cannot be reviewed is a problem under both the AI Act and the GDPR.
¶ Why the AI Act is an opportunity
I often hear that the AI Act is yet another regulatory burden. In a sense, it is.
Preparing for it, however, shows a business how it really works. In practice, we see the process uncover inefficiencies, duplicated work and risks that management knew nothing about.
For businesses with international ambitions, complying with the AI Act will also be a competitive advantage. GDPR went the same way: those who took it seriously from the start are not scrambling to catch up today, while those who waited are still dealing with the problems.
The AI Act will be similar, and some of its obligations already apply. A company that prepares now will have a head start in December 2027, when the obligations for high-risk systems take effect, over those that only turn to the AI Act after their first inspection.
If you are unsure whether or how the AI Act applies to your business, get in touch. An audit of your AI systems takes days, not months, and ignoring the regulation can cost far more. If the AI Act also affects your supplier contracts, see Contract mistakes: five errors we see most often. Many of the obligations end up in data processing clauses and service agreements.
Using AI tools in your business and need to know whether and how the AI Act applies? In our risk prevention practice we audit your AI systems and set out how to meet the obligations that already apply and those arriving in December 2027. Get in touch.
¶ Frequently asked questions
Does the AI Act apply to a company that only uses AI?
Yes. The regulation also places obligations on deployers, meaning anyone who uses an AI system in a professional capacity, for example to evaluate employees, score clients or screen CVs.
Can we become an AI provider even if we did not develop the system ourselves?
Yes, that can happen. A company that takes an open-source model, fine-tunes it on its own data and deploys it internally may become a provider, even if it only meant to use AI.
Which AI practices are banned outright?
Among others, social scoring of people, meaning an assessment based on their social behaviour that leads to unjustified detrimental treatment; manipulative techniques that exploit people's vulnerabilities; emotion recognition in the workplace and in educational institutions (except for medical or safety reasons); and real-time remote biometric identification in publicly accessible spaces for the purposes of law enforcement, subject to narrow exceptions. These prohibitions have applied since February 2025. From 2 December 2026, a ban will be added on AI systems that create realistic intimate content depicting identifiable people without their consent, and on systems that generate child sexual abuse material.
What obligations does a business have if it uses a chatbot or a content generator?
Mainly transparency. Users must know they are communicating with AI or that content was AI-generated; the AI Act treats such systems as limited risk. These obligations have applied since 2 August 2026. Providers of generative AI systems placed on the market before 2 August 2026 have until 2 December 2026 to mark the content they generate in a machine-readable format.
Does the AI Act require a dedicated AI compliance officer?
No, the regulation does not explicitly require one. Someone in the organisation must still keep track of which AI systems are in use and what obligations follow; in a smaller firm this can be the existing compliance manager or in-house counsel. Since February 2025, the business must also take measures to support AI literacy among staff who work with AI.
What does the AI Act require for high-risk AI systems?
The provider must ensure risk management, technical documentation and automatic logging of the system's operation. The deployer must use the system in accordance with its instructions for use, assign human oversight to competent people, keep the automatically generated logs for at least six months and inform affected employees in advance. A fundamental rights impact assessment is required only from public bodies, private entities providing public services, and those using AI to assess the creditworthiness of individuals or for risk assessment and pricing in life and health insurance. These obligations apply from 2 December 2027, and from 2 August 2028 for products covered by Annex I.