AI Act: Obligations and timetable applicable to businesses

AI Act for businesses : The European regulation on artificial intelligence doesn't just apply to companies that develop AI tools. A company can also fall under the AI ​​Act because it markets, imports, integrates, or uses an artificial intelligence system as part of its business activities. Since August 2, 2026, the core of the regulation has been applicable, but obligations and deadlines vary depending on the company's role and the risk level of the system in question.

By Morgan Jamet and Haia El Zufari, lawyers – ARST Avocats

This article is an expanded and updated version of our analysis originally published in Village de la Justice.

Does the AI ​​Act apply to all businesses?

Regulation (EU) 2024/1689 on artificial intelligence, known as the "AI Act", entered into force on 1 August 2024. Directly applicable in France, it was adjusted by Regulation (EU) 2026/1744, known as the "AI Omnibus", which entered into force on 27 July 2026.

Its scope does not depend on the size of the company, nor, in principle, on its sector. A micro-enterprise, a small or medium-sized enterprise (SME), an association, a professional practice, a mid-sized company, or a large corporation can therefore be affected. The right question is not simply: "Do we use AI?", but rather: "What role do we play with regard to each AI system, and what risks does its use present?"

AI Act for businesses: which companies are affected?

Company situation Qualification AI Act Concrete example
She uses AI in her business Deployer Generative assistant, contract analysis, content creation
It markets an AI under its own name or brand Supplier Application sorting software developed in-house or outsourced
It provides a generalist model General purpose AI model provider Large language model usable for multiple tasks
It introduces into the EU AI from a non-EU supplier Importer American or Asian solution resold in France
She resells AI without being a supplier or importer Distributer European reseller of AI solutions
It integrates security AI into a regulated product Manufacturer considered equivalent to supplier Medical device, toy, elevator or PPE incorporating AI

,companies need to precisely determine the role played by each of the systems used or marketed.

A single company can possess multiple qualities. For example, it can use a generative assistant as a deployment tool and market, under its own brand, another tool for which it becomes a supplier.

What obligations does the AI ​​Act impose on businesses?

The professional use of an AI system under the company's authority generally grants it the status of deployer. This does not mean that the occasional use of a writing assistant entails the same constraints as a system assessing the creditworthiness of individuals or selecting job candidates.

For everyday use, the primary challenges are generally the following:

  • identify the tools actually used, including uses not officially authorized;
  • train employees on their capabilities, limitations and risks;
  • eliminate prohibited practices;
  • comply with transparency obligations when the tool or content falls within the cases referred to in Article 50;
  • to articulate the AI ​​Act with the GDPR, confidentiality, trade secrets, intellectual property and internal security rules.

AI Act for businesses: what obligations apply in 2026?

1. Develop AI proficiency within the company

Since February 2, 2025, vendors and deployers have been required to take steps to support the development of sufficient AI proficiency among their staff and others using these systems on their behalf. Since the AI ​​Omnibus Directive of July 2026, companies are no longer required to guarantee a uniform level of proficiency for every individual; measures must be tailored to their knowledge, experience, training, and context of use.

In practice, a usage policy, targeted awareness-raising, accessible documentation and proportionate training constitute the first building blocks of a compliance system.

2. Do not use prohibited AI practices

The main prohibited practices have been in effect since February 2, 2025: harmful manipulation, exploitation of certain vulnerabilities, social rating, certain forms of predictive policing, non-targeted creation of facial recognition databases, recognition of emotions at work or in education except in exceptional circumstances, certain biometric categorizations and real-time remote biometric identification for repressive purposes except in strictly regulated cases.

Two additional bans from the AI ​​Omnibus will come into force on December 2, 2026. They concern systems used to generate or manipulate non-consensual intimate content or content depicting child sexual abuse.

3. Comply with transparency obligations

Since August 2, 2026, certain individuals must be informed that they are interacting with AI, unless this is clearly evident from the circumstances. Specific obligations also apply to emotion recognition, biometric categorization, deepfakes, and certain texts generated or manipulated by AI when published to inform the public on a matter of general interest.

What is the timeline for the AI ​​Act for businesses?

Date Main applicable rules
February 2, 2025 Mastering AI and the first prohibited practices
August 2, 2025 Governance and obligations relating to new general-purpose AI models
August 2, 2026 General application, transparency and control powers
December 2, 2026 Two new prohibited practices; certain transitional marking regimes
August 2, 2027 Compliance of general-purpose AI models already on the market before August 2, 2025
December 2, 2027 Obligations relating to high-risk systems covered by Annex III
August 2, 2028 Obligations relating to high-risk systems integrated into regulated products of Annex I

When is an AI system considered high risk?

Two main categories must be distinguished. First, certain sensitive uses listed in Annex III fall under the category of high risk: biometrics, critical infrastructure, education, employment, access to essential services, solvency, life and health insurance, law enforcement, migration, justice, and democratic processes. Second, certain systems integrated as security components in products subject to European regulations, such as medical devices, personal protective equipment, toys, or elevators, also fall under the category of high risk.

The operator deploying a high-risk system must, in particular, follow the supplier's instructions, organize effective human oversight, monitor its operation, maintain certain logs, inform the relevant parties in some cases, and cooperate with the authorities. Additional obligations may apply to employers, public bodies, public service providers, and credit or insurance companies.

Beware of reclassification as a supplier

A company that initially acts as a simple user, importer, or distributor can legally become a supplier of a high-risk AI system. This can occur when it affixes its name or trademark to the system, makes a substantial modification to it, or changes its intended use in such a way as to make it fall into the high-risk category.

The classification therefore does not depend solely on the contract or the commercial terminology chosen by the publisher. It results from the reality of the operations carried out.

How to prepare your company for AI Act compliance?

For companies affected by the AI ​​Act, the first step is to identify the tools actually used, including those adopted directly by employees.

A proportionate approach can be undertaken in seven steps:

  1. Map the AI ​​tools and models that are used, developed, integrated, or commercialized.
  2. Define the company's role for each system: deployer, supplier, importer, distributor, or manufacturer.
  3. Classify uses according to their level of risk and identify prohibited practices.
  4. Check the obligations already in place, including AI governance and transparency.
  5. To regulate usage through a charter, procedures and appropriate training.
  6. Audit contracts with publishers, integrators, subcontractors, clients and distributors.
  7. Organizing evidence of compliance: decisions, training, notices, controls, incidents and corrective actions.

AI Act and artificial intelligence contracts: which clauses should be checked?

The AI ​​Act assigns specific obligations to each operator, but contracts must enable their practical implementation. They should notably address the qualification of the parties, the authorized use of the system, the information and documentation to be provided, cooperation in the event of an audit or incident, system modifications, input and output data, cybersecurity, intellectual property, confidentiality, responsibilities, and reversibility conditions.

A clause cannot eliminate regulatory responsibility towards the authorities. However, it can allocate tasks, organize recourse between the parties, and reduce areas of operational uncertainty.

FAQ – AI Act and businesses

Does the AI ​​Act apply to SMEs and micro-enterprises?

Yes. Size does not preclude the application of the regulation. However, it may be taken into account in certain proportionality or simplification measures.

Can a company without an IT department be affected?

Yes. Simply using an AI system professionally can confer the status of a deployer.

Is the use of ChatGPT prohibited in a company?

No. The AI ​​Act does not prohibit the general use of a generative assistant. However, companies must regulate its use and comply with applicable rules, particularly regarding AI governance, transparency, data protection, and confidentiality.

When is the AI ​​Act applicable?

The general date is August 2, 2026, but some rules have been in effect since 2025 and the main obligations relating to high-risk systems have been postponed to December 2027 or August 2028.

What is the first action to take?

Create a map of AI tools and uses, including those adopted directly by employees, then qualify the role of the company and the level of risk of each use.

ARST Avocats will assist you

The law firm ARST Avocats assists companies in identifying their obligations under the AI ​​Act, mapping and qualifying their uses, drafting internal charters, training teams, and auditing and negotiating their contracts related to artificial intelligence.

Do you want to check if your company is affected or develop a compliance plan tailored to your practices? Contact us.

Subscribe to our newsletter

Receive the latest news and updates from our team.

 

See you soon!