2 August 2026, is the general date of application of the EU AI ACT. The actual subjects of complaints from August 2026 are Articles 5 and 50. This means that from 2 August 2026, everybody who believes that your AI-based software or device violates these articles has the right to file a complaint with the national AI market surveillance authority, which is obliged to take it into account. From 2 August 2026, this supervisory authority obtains all the necessary powers to start an investigation against your business: it can request access to documentation for the AI system you are using, demand corrective measures, significantly fine you, and even withdraw your product from the EU market. If you are a business developing or providing access to AI-enabled software and devices, you must know exactly what to do after 2 August 2026, in such scenarios.
What Happens After a Complaint Is Lodged Against Your AI System
The complaint is submitted to the national market surveillance authority. If this authority has sufficient reason to consider that your AI system presents a risk, it starts a formal evaluation (Article 79). And during this evaluation, the burden of proof lies on you.
EU AI ACT Article 5
For the prohibited practices of Article 5, you must show the authority how your system actually works, what data it uses and where this data comes from, and that it behaves in the way you declare. The form of this proof is a written assessment for each AI system (checked against all 8 prohibitions from Article 5, dated and signed), a description of how its engagement and dialogue mechanics work, an inventory of the data it uses, and test and monitoring records.
The most important part of this proof is the records. According to the guidelines of the Commission, when your system causes harm that you never intended, the same incident can be qualified as a prohibited practice or not, depending on whether you took safeguards and can demonstrate them. This means that if your chatbot caused harm to a user, but you can show the guardrails, the tests, and the monitoring you used to prevent it, the prohibition does not apply. If you cannot show them, it does.
EU AI ACT Article 50
For the content-marking and labelling obligations of Article 50, the authority first checks whether you follow the Code of Practice on Transparency of AI-Generated Content.
If you have not signed this Code, you must show that your own marking and disclosure measures achieve the same result, and the Commission expects a gap analysis comparing your measures with the measures of the Code. In this scenario, the authority will check you more closely: it can request additional information and additional access to test whether your marking actually works.
The chatbot disclosure and the emotion recognition notice rules from Article 50 are not covered by this Code: in this case, the authority checks your implementation directly.
Large fines for incomplete information
You must be very careful with the information you provide during the investigation: not only misleading or incorrect, but even incomplete information is a separate violation with a fine of up to €7.5 million or 1% of turnover.
If the authority finds your AI system non-compliant, you receive a maximum of 15 working days to correct the violation, withdraw the system, or recall it. In practice, this means that a transparency violation must be corrected, and a prohibited practice must be stopped. If you do not do this, the authority blocks the system on its national market and notifies all other EU member states. And the fine for the violation itself is added to this: up to €35 million or 7% of turnover for a prohibited practice, and up to €15 million or 3% for a transparency violation.
Whether you will actually be fined, and the amount of this fine, depends on the circumstances: quick correction of the violation and cooperation with the authority are taken into account in your favour (Article 99).
EU AI Act Compliance Checklist: What to Do Before 2 August 2026
To state that the EU AI Act does not apply to your business, you must answer several questions for each of your AI features: whether this feature is an AI system within the meaning of the official definition, whether it is available to users in the EU, whether its output is used in the EU, and whether it falls under Article 5 or Article 50. This check is performed system by system. This means that to reach the conclusion that the law does not apply to you, you in fact perform the same inventory, and the only question is whether you record its results.
You must record them, because a conclusion without documentation does not protect you: under Article 85, a complaint can be lodged even against a company that considers itself outside the scope of the law. If this happens, a documented negative scope assessment for each system is the only way to respond to the authority quickly.
The scope of the law can also change for your product over time. Your first client from the EU can appear, your feature can be repurposed (in this case Article 25(1)(c) makes you the provider of this feature), and your marketing department can describe the purpose of the product on the website in a new way. In each of these scenarios, your previous conclusion that the law does not apply to this product becomes outdated. If you do not update this list, nobody in your company will notice this change.
EU AI Act Inventory
The rules that apply from 2 August 2026 do not contain the obligation to keep an inventory of your AI systems: neither Article 5, nor Article 50, nor the guidelines of the Commission require such a list. But you need this list, for several reasons.
- You cannot check your systems against the eight prohibitions of Article 5 and implement the four transparency duties of Article 50 if you do not know which AI systems your company actually uses.
- When a complaint is lodged against your AI system, the burden of proof lies on you, and you receive a maximum of 15 working days to correct the violation. Within this period, you have no time to find out how many AI features your company runs and which model works behind each of them. This information must be collected in your inventory before the investigation starts.
- AI systems appear in a company not only through your own development plans. Your team can subscribe to an HR tool with emotion recognition, and your manager can connect a bot to customer calls, and in such scenarios your company starts violating the law without knowing about it. The inventory allows you to find such systems before the authority finds them.
- From 2 December 2027, high-risk AI systems must be registered in the public EU database, and the registration form requires information about each system. If you build this list now, you prepare this registration in advance.
The obligations of the EU AI Act apply to each AI system separately and depend on its intended purpose. This means that the unit of your inventory is one AI system with its intended purpose, and not the model behind this system.
Products that work on the same model can receive completely different legal outcomes under the EU AI Act. For example, three of your products can run on the same GPT-class API.
- The first product analyses webcam footage and concludes which of your employees are unhappy. This product is a system for emotion recognition in the workplace, and Article 5 prohibits such systems. This prohibition applies in any case: informing the employees does not make this system legal.
- The second product answers your customers in a chat. This product is legal, but under Article 50 it is obliged to disclose to the users that they are speaking with AI.
- The third product classifies incoming emails as spam. This product is also an AI system within the meaning of the law, but no obligation of the law applies to it, because it does not fall under the prohibitions of Article 5, it does not fall under any high-risk category, and it does not speak with people and does not generate content for them, so it has no transparency duties under Article 50 either.
How to Make an Inventory of Your AI Systems
The first step is to collect the candidates for this inventory. To collect them, you must request three lists: the list of all products and features with generation, chat, recommendations, scoring or recognition from your product managers, the list of every place where your code calls the API of OpenAI, Anthropic, Google or your own models from your developers, and the list of every purchased SaaS product with AI features (support bots, HR screening, call analytics) from your procurement department, because for these purchased products you are the deployer.
The second step is to check every candidate against the official definition of an AI system. Whether your software legally qualifies as an AI system is determined according to the Commission's Guidelines on the definition of an artificial intelligence system (February 2025). According to these Guidelines, software that works on ordinary if-else rules and static formulas is not an AI system, and software that involves training or inference is an AI system.
The third step is to run every system through the official EU AI Act Compliance Checker on the Commission's AI Act Service Desk. You answer the questions about one system and receive the result: whether this system falls within the scope of the law, whether you are its provider or its deployer, and which articles and obligations apply to it. The Compliance Checker is free, and its result must be added to your records.
The fourth step is to put all these systems into a table with fixed columns. There is no official template for an internal inventory, but you do not need to invent the columns: you can take the structure of Annex VIII (the official list of fields that providers of high-risk systems submit to the EU database at registration) and reduce it to your needs. In this table, you must record the name of the system, its intended purpose, the model behind it, your role (provider or deployer), the availability of this system to users in the EU, the result of the screening against Article 5 with the date of this screening, the applicable duties of Article 50, the classification under Annex III, and the owner of the record with the date of the next review.
The fifth step is to assign an owner of this inventory and to establish one rule: a new AI feature must receive a new row in the table before its launch. If you do not establish this rule, your inventory stops corresponding to the actual state of your AI systems within a month.
EU AI Act Enforcement August 2026 News: What Applies and What Was Delayed
After 2 August 2026, the key provisions of the EU AI Act were expected to become fully applicable, meaning fines and penalties from €7.5 million to €35 million (or from 1% to 7% of global turnover).
And indeed, for AI systems the rules of Article 5 (the prohibited practices) and Article 50 (the transparency requirements) are in force as of 2 August 2026. This is the Act's enforcement start date. From that day, anyone who has grounds to believe that the AI you use breaks the EU AI Act rules can officially lodge a complaint against your business, and a national market surveillance authority can investigate your AI-based systems. And it doesn't matter where you're based: in the EU or, say, in the US. The Act applies to providers and deployers worldwide (lawyers call this its extraterritorial reach).
But the implementation timeline for high-risk AI systems is on pause: the deadline for Annex III systems (hiring, credit scoring, education and so on) was moved from 2 August 2026 to 2 December 2027. The European Commission proposed the delay as part of the Digital Omnibus on AI, and the Parliament and Council agreed.
The Omnibus also allowed a small concession for generative AI systems that were already on the market before 2 August 2026: the machine-readable marking duty of Article 50(2) doesn't have to be implemented until 2 December 2026.
Belitsoft offers AI consulting services and provides senior AI developers with expertise and experience in architecting, engineering, and maintaining AI systems fully compliant with the EU AI Act. Let's talk
Who Does the EU AI Act Apply To?
The EU AI Act applies not just to the companies that train the models, as many would like to believe. According to Article 2(1) of the AI Act, with the definitions in Article 3, the affected include providers, deployers, importers, distributors and product manufacturers.
- Providers: anyone who develops an AI system (or has it developed) and offers it in the EU under their own name or brand. And if you build a product on top of a third-party model, even by simply calling the OpenAI API, the letter of the law considers you a provider too (a "downstream provider").
- Deployers: companies and public authorities that use AI systems in the course of their business from an HR department running a screening tool to a bank using a chatbot.
- Importers and distributors of AI systems.
- Manufacturers that embed AI into their products: cars, medical devices, machinery.
And location doesn't matter: a US or Chinese company falls under the Act as soon as its AI product is available to users in the EU, or as soon as the output of its AI system is used in the EU.
AI Recruitment Tools under the EU AI Act: High-Risk Systems and Prohibited Practices
AI recruitment tools are applications that analyze and filter job applications, rank candidates against a job description, and score interview answers. Founders and HR directors buy them to handle large volumes of applications, and developers usually build them on top of a ranking model trained on the client's own hiring history. The EU AI Act (Regulation 2024/1689) treats many of such tools as high-risk (read as "they cannot be sold in the EU without bias testing, technical documentation, audit logs and registration in a public database"), and some of them are prohibited.
AI emotion recognition in video interviews
Owners of video interview products need to know which of their features can be sold in the EU at all.
The problem is not the use of AI in a video interview as such.
Most of the AI Act applies from December 2027, but the ban on emotion recognition in the workplace has been in force since 2 February 2025, with exceptions for medical and safety purposes only. There is no compliance path for a prohibited practice, and the penalty is up to €35 million or 7% of worldwide turnover.
Simple example: a retailer runs a first round of interviews for shop floor staff. The candidate answers five questions on camera, and the product returns two scores. The first one rates the content of the answers against the job description. The second one rates confidence and enthusiasm from the candidate's voice and face. The first score is high-risk and can be brought into compliance. The second one has to be taken out before a client in the EU can use the product.
The distinction matters because not every AI feature used in recruitment performs the same function. Scoring the content of an answer is one thing, but inferring confidence, enthusiasm or personality from a candidate's face and voice is another.
A feature must be removed if:
- the model scores facial expression, micro-expression or gaze;
- the model scores voice tone, pitch, pace or hesitation as a proxy for confidence, enthusiasm, honesty and so on;
- the product builds a "cultural fit", "engagement" or "personality" score on top of any of the above.
When a customer asks us to prepare a video interview product for the European market, we usually start by separating these scores from the rest of the pipeline. They are cheap to remove while the code is still in development.
Differences between decision support and automated decision making
With a decision support tool, the recruiter evaluates the data and makes the final decision. In an automated decision making system, the outcome is determined by the system without meaningful human involvement. A recruiter may formally approve the outcome, but does not independently assess each case.
Almost every AI screening product on the market is sold as the first one: adoption of AI resume screening among HR teams went from 26% in 2024 to 43% in 2025.
Speaking to the BBC about the screening tools, Kelly Trindel, Chief Responsible AI Officer at Workday, describes how the company sees the division of responsibility: "Workday AI does not make hiring decisions and is not designed to automatically reject candidates. Customers retain full control and human oversight throughout their hiring processes."
Laura Holden, an AI lawyer and founder of the Bonsai AI and legal consultancy who ran responsible AI programmes at Unilever and Diageo, describes what happens on a recruiter's desk. Providers market these products as decision support tools, but they're designed and sold in a way that encourages employers to reject large numbers of applicants on the basis of AI-generated scores. So in practice they work as automated decision making systems.
The GDPR defines profiling as the processing of personal data by automated means to evaluate certain personal aspects relating to a natural person. This includes aspects relating to work performance. This definition includes grading resumes, giving them grades from A to D, or ranking candidates by "suitability."
Profiling deals with the assessment of personal characteristics and not merely with the use of personal data.
Profiling is performed by an AI recruitment system automatically evaluating candidates' personal data and ranking them according to their suitability. Even if the final decision is officially approved by a recruiter, the system is therefore in the high-risk category.
The EU AI Act includes, under Annex III, systems that analyze and filter applications and assess candidates. They are classified as high-risk systems.
Article 6(3) provides for an exemption from the 'high-risk' category for some systems listed in Annex III where they do not pose a significant risk of harm to fundamental rights and perform one of four limited tasks. However, this exception does not apply if the system engages in profiling.
Deployer Obligations (Article 26): When Using Someone Else's AI Falls Under the Act
Article 26 is the checklist for deployers or companies that use someone else's high-risk AI system in the course of their business. If the system you use isn't high-risk, this list isn't about you: your duties as a deployer are in Article 50, and they apply from 2 August 2026. The Article 26 checklist, thanks to the Digital Omnibus, starts to apply only on 2 December 2027 (Annex III systems) or 2 August 2028 (AI embedded in regulated products).
As a deployer of a high-risk AI system, you must:
- Use the system according to the provider's instructions for use, backed by technical and organisational measures.
- Assign human oversight to people who have the competence, training and authority to actually intervene.
- Make sure the input data you feed into the system is relevant and representative for the system's purpose (to the extent you control that data).
- Monitor how the system operates. If you suspect the system presents a risk even when used by the book, inform the provider and the market surveillance authority and suspend the use. A serious incident must be reported immediately.
- Keep the logs the system generates for at least six months (when the logs are under your control).
- If you're an employer: inform the affected workers and their representatives before switching the system on at the workplace.
- If your AI makes or helps make decisions about people (the Annex III cases: hiring, credit, education and so on): tell those people that AI is being used on them.
- Use the provider's technical information for your own GDPR impact assessment, and cooperate with the authorities.
- If you're a public body: check that the system is registered in the EU database (if it isn't - don't use it). And if you're a public body, a bank, an insurer or a private provider of public services: run a fundamental rights impact assessment before the first use and notify the results to the authority (Article 27).
A deployer's obligations are light (Article 26). But Article 25(1) lists 3 actions that makes you a provider, with a provider's obligations:
- You offer someone else's high-risk system under your own name or brand. You buy a third-party credit scoring engine and sell it to your customers as "YourBank Score" (white-labelling), and now you're the provider of that system (unless your contract with the developer allocates the obligations differently).
- You significantly modify someone else's high-risk system, for example re-train it on your own data, and the result is still a high-risk system. The original provider's certification covered their version, not yours, so the modified system needs a provider of its own: you.
- You take a system that is not high-risk at all (including general-purpose AI like ChatGPT) and repurpose it so that it becomes high-risk. You integrate a general-purpose API into your candidate selection process. The system was just a chatbot, you turned it into an HR tool, and now you're the provider of a high-risk AI system.
According to Article 25(2), once this happens, the original provider is no longer considered the provider of that system. OpenAI won't be liable for your CV-screening tool built on their model.
As for banks and insurance companies, they already have internal control, monitoring and record-keeping systems in place under financial legislation (CRD, Solvency II and others), so they don't need to build a new control system for the AI Act duties to monitor the operation of the AI system and to retain logs: complying with their existing financial governance rules is deemed to fulfil these two duties (Articles 26(5) and 26(6)).
Provider Obligations Under the EU AI Act (Article 16)
Article 16 is the checklist for providers of high-risk AI systems. If your system is not high-risk, your duties are in Article 50. And thanks to the Digital Omnibus, high-risk providers now have time: these obligations start to apply on 2 December 2027 (Annex III systems) or 2 August 2028 (AI embedded in regulated products).
A provider of a high-risk AI system must:
- Make the system meet the technical requirements for high-risk AI: risk management, quality of training data, technical documentation, automatic logging, instructions for deployers, human oversight, accuracy, robustness and cybersecurity (Articles 8–15).
- Put its name (or trademark) and contact address on the system, its packaging or its documentation.
- Run a quality management system covering the whole lifecycle (Article 17).
- Keep the technical documentation for 10 years after the system reaches the market (Article 18).
- Keep the logs the system generates — for at least six months, when the logs are under its control (Article 19).
- Pass a conformity assessment before the system reaches the market, draw up an EU declaration of conformity and affix the CE marking (Articles 43, 47, 48).
- Register the system in the public EU database (Article 49).
- If the system misbehaves: take corrective action, withdraw or recall it, inform the authorities and the distribution chain (Article 20).
- Demonstrate the system's conformity when a national authority asks for it.
- Meet the EU accessibility requirements for people with disabilities.
EU AI Act Concessions for SMEs and Start-ups: What Applies in 2026 and What Comes Later
The EU AI Act's impact on startups and small businesses is softer: the law comes with lower fines, free regulatory sandboxes and simplified paperwork. Here is what an SME gets and when.
Who Counts as an SME Under the EU AI Act
An SME here means fewer than 250 employees and up to €50 million turnover (Recommendation 2003/361/EC). You must count the employees and the turnover of your parent and affiliated companies too: if your company belongs to a large group, you're not an SME.
EU AI Act Obligations and Timeline for SMEs and Startups: Key Dates
The compliance dates for SMEs are the same as for everyone else: the Act doesn't give small companies extra time.
Here is the timeline of obligations for providers, deployers and SMEs.
- The prohibited practices of Article 5 (in force since 2 February 2025).
- The transparency duties of Article 50 for providers and deployers (from 2 August 2026).
- The enforcement: anyone with grounds to believe you breach the Act can ask a national authority to investigate you (from 2 August 2026).
- Generative systems already on the market before 2 August 2026 have until 2 December 2026 to implement the machine-readable marking.
- High-risk AI systems: from 2 December 2027 for Annex III systems (hiring, credit scoring, education, etc.) and from 2 August 2028 for AI embedded in regulated products (medical devices, machinery, etc.).
Lower Fines for SMEs and Start-ups
For a breach of the prohibited practices of Article 5, a large company pays €35 million or 7% of global turnover, whichever is higher. SMEs and start-ups pay whichever is lower.
The same reversal applies to the €15 million or 3% for the transparency duties of Article 50, and to the €7.5 million or 1% for giving incorrect, incomplete or misleading information to the authority.
EU AI Act Regulatory Sandboxes: Free Priority Access for SMEs and Start-ups
From 2 August 2026, every member state must run at least one regulatory sandbox, and SMEs and start-ups get priority access to it, free of charge.
A sandbox means you agree a plan with the national authority and, for a limited time, develop and test your AI system under their supervision before it goes to market. What you get out of it:
- The compliance problems in your system are pointed out to you, with guidance on how to fix them before the system is on the market.
- No administrative fines are imposed for breaches of the Act, as long as you follow the sandbox plan and the authority's guidance in good faith.
- You get a written participation record. The authorities and certification bodies must take these documents into account positively.
Simplified Documentation and Reduced Fees
If you're an SME or a start-up, you get two concessions that start to apply on 2 December 2027 (Annex III systems) or 2 August 2028 (AI embedded in regulated products).
You may draw up the technical documentation for your high-risk system (Article 11, Annex IV) in a simplified form. There is no official form yet.
And the law says the conformity assessment fee has to be lower for an SME than for a large provider (though, as of July 2026, by how much is unknown).
By the way, the Digital Omnibus extends the simplified technical documentation and the lighter quality management system (Article 17) to small mid-cap companies below 750 employees and €150 million in turnover.
High-Risk Classification: How to Tell If Your AI System Is High-Risk (Annex III)
There are two ways your AI system can turn out to be high-risk (Article 6).
The first way is through product regulation. Your AI is a safety component of a product (or is itself a product) that already requires third-party certification under the EU product laws listed in Annex I: machinery, medical devices, toys, lifts, cars, aviation. If that's your case, the AI is high-risk — with the obligations starting on 2 August 2028.
The second way is Annex III: a closed list of eight areas where the use case itself makes the system high-risk, with the obligations starting on 2 December 2027. Check your product against the list:
- Biometrics: remote identification of people, categorisation by sensitive traits, emotion recognition (a simple "is this person who they claim to be" verification is excluded).
- Critical infrastructure: safety components for digital infrastructure, road traffic and the supply of water, gas, heating and electricity.
- Education: deciding admission, evaluating learning outcomes, assessing what level of education a person can access, catching cheaters during exams.
- Employment: recruitment and CV screening, targeted job ads, evaluating candidates, decisions on promotion and firing, allocating tasks, monitoring employees' performance and behaviour.
- Essential services: eligibility for public benefits and healthcare, credit scoring (fraud detection is excluded), pricing in life and health insurance, classifying and dispatching emergency calls.
- Law enforcement: assessing the risk of someone becoming a victim, polygraphs, evaluating the reliability of evidence, assessing the risk of offending, profiling in criminal proceedings.
- Migration and border control: risk assessments of travellers, examining asylum and visa applications, identifying people (verifying travel documents is excluded).
- Justice and democracy: helping judges research facts and apply the law, influencing elections and how people vote.
The risk class of your AI product does not depend on the technology inside it, but on the purpose you declare for it. If you offer your GPT-based tool as a writing assistant, it's low-risk. But if you offer the same tool for screening candidates, this is an employment use case from Annex III (recruitment and CV screening) and considers you the provider of a high-risk AI system, with the obligations starting on 2 December 2027.
There is an exemption (Article 6(3)): if your system only does auxiliary work and doesn't materially influence the decision (converts CVs into a table, polishes a letter a human has written, flags patterns for a human to re-check, prepares materials for a human decision), it doesn't count as high-risk. But the exemption doesn't apply if the system profiles people, and any scoring of a person counts as profiling.
If you decide under Article 6(3) that your system isn't high-risk, you must document that assessment before the system reaches the market and register the system in the public EU database (Article 49).
The List of Transparency Duties (Article 50)
Article 50 of the EU AI Act contains a list of 4 transparency duties that companies and public authorities must comply with when their AI-based software and devices talk to people, generate content or watch people. If caught violating them, they face fines of up to €15 million or 3% of their total worldwide annual turnover for the preceding financial year, whichever is higher (or whichever is lower for SMEs and start-ups).
In practice, market surveillance authorities will interpret Article 50 in line with the European Commission's Guidelines on transparency obligations.
Article 50 requires that all four disclosures must be made clearly at the first interaction or exposure:
- An AI system that talks to people must tell them they are talking to AI (unless this is obvious). This is the duty of the provider.
Examples of AI systems affected by these requirements according to the Commission guidelines on the interpretation of Article 50:
- AI voice assistant or chatbot speaks with users in customer support, complaints management, e-commerce, finance, healthcare, education or public services.
- AI hotline takes incident or fraud reports from people.
- Humanoid robot, cobot or AI companion interacts with people.
- AI avatar interacts with people in a virtual reality environment.
- AI bot speaks with people on social networks and media.
- Coding agent or other AI agent interacts with people directly, including in multi-agent architectures.
- Robotic companion pet looks and behaves so much like a real animal that people cannot tell whether they are interacting with AI.
- Realistic human-like avatar or voice speaks with users in VR or AR, where children, the elderly or people with disabilities cannot easily tell human from AI.
- Helpdesk chatbot on an online platform gives replies that users may take for human-written.
- Police chatbot on an official website lets people report criminal offences (crime-reporting systems are not covered by the law-enforcement exception).
- AI-powered telephone hotline of the police answers public inquiries.
- Fraud-reporting hotline of a bank or public authority collects reports of suspected financial crimes.
- Virtual assistant collects witness statements.
The guidelines also explain how exactly AI systems must disclose themselves.
Examples of disclosures that are enough according to the Commission guidelines:
- Chatbot starts the conversation by mentioning it's based on AI technology
- Provider places a label or banner "You are interacting with an AI system" in the interface
- Voice assistant says at the beginning of a session that it's powered by AI
- AI agent puts an AI label at the top of the email it generates
Examples of disclosures that are not enough:
- Company mentions AI only in its documentation, terms and conditions
- Provider embeds a machine-readable watermark or metadata that users cannot see during the interaction
- Company calls the bot simply an "assistant" or gives it a human name and photo
- Website shows a generic "Services on this website use AI" notice
- Company states only the underlying technology ("this system uses LLMs") without explaining that the user is speaking with AI
The AI system must also admit it's AI if a user asks about it or if the conversation suggests that the person believes they're speaking with a real person.
The Digital Omnibus on AI also allowed a delay until 2 December 2026 for the machine-readable marking duty (Article 50(2)), and only for generative systems already placed on the market before 2 August 2026. The other three transparency duties and all new systems get no delay: they must comply from 2 August 2026.
- An AI system that generates audio, images, video or text must mark its outputs in a machine-readable format, so the content is detectable as AI-generated. This is the duty of the provider.
Examples of AI systems affected by this requirement according to the Commission guidelines:
- Chatbot or general-purpose AI system writes texts: articles, emails, reports, marketing copy.
- Image generator creates pictures from a text prompt.
- Video generator creates clips, 3D content or virtual reality environments.
- Voice generator clones voices or turns text into speech.
- Music generator composes songs.
- Photo or video editor removes, replaces or inserts objects and people, or swaps faces.
- AI agent sends people content it has generated: emails, documents, presentations.
- App creates digital twins: virtual replicas of real people or objects.
- Tool mixes AI-generated fragments with human-created material.
This guideline also explains which changes to content require marking and which don't because they're simple edits.
Examples of changes that require marking:
- AI tool summarises text.
- AI tool paraphrases or rewrites text, changing its style, structure or meaning.
- AI tool removes, replaces or inserts objects or people in images and video, or replaces faces.
- AI tool synthesises realistic speech in a specific person's voice.
- AI tool generates realistic video of events that never happened.
- AI tool alters a person's body shape or skin colour in a picture.
- AI tool makes extreme colour and contrast changes that alter the meaning of the content.
- AI tool builds composite images or clips that change how people, objects or events are represented.
The marking requirement doesn't apply to source code, to outputs that only machines exchange with each other, or internal technical materials (such as engineering designs, technical specifications and documentation) to which only a pre-defined circle of professionals in your company and your client's company has access, and which are never shared outside.
If you build your AI product on a model from a third-party developer and that model already has a watermark, you may use that watermark instead of your own. However, if that watermark fails, the fine is yours. So you must check that it actually meets the four legal requirements (effective, interoperable, robust and reliable) and be able to show this if the authority asks.
If you wish to ensure that the regulatory authority accepts your marking, you may sign and follow the voluntary Code of Practice on Transparency of AI-Generated Content.
- People exposed to an emotion recognition or biometric categorisation system must be informed that the system is running on them. This is the duty of the deployer.
This duty covers any biometric categorisation, even one that isn't high-risk. If your camera simply estimates the age or gender of visitors, you must inform them. It doesn't matter whether the system works in real time or analyses recordings afterwards. And you must inform everyone exposed to the system, including children.
Examples of informing people according to the Commission guidelines:
- Computer game shows a pop-up before launch saying that the player's face is recorded to capture their emotions.
- Exhibition hall places a visible notice at each entrance saying that visitors' faces are captured to assign them to an age group.
The notice only needs to state the fact: the system is running on people. The AI Act doesn't ask you to explain why you process their data (the purposes, the legal basis and the rest are what your GDPR privacy notice must already cover), because GDPR applies in parallel with the AI Act.
Note that informing people doesn't make the system legal by itself. Emotion recognition at work and in education stays prohibited under Article 5 no matter what notices you put up.
- Deep fakes must be disclosed as artificially generated or manipulated (for evidently artistic and satirical works in a way that does not spoil the experience); the same applies to AI-generated text published to inform the public on matters of public interest (unless it has passed human editorial review and someone holds editorial responsibility). This is the duty of the deployer.
Examples where you must disclose the AI origin:
- AI generates a video of a celebrity influencer promoting a product.
- AI generates a realistic synthetic avatar of a company CEO congratulating employees on the corporate results.
- AI generates a product image for an ad or packaging that makes the product look better or different than it really is.
- AI simulates humans advertising a product in a teleshopping-style video.
- AI generates an image of celebrities implying their involvement in activities that never happened.
- AI-generated synthetic influencer tests a sponsored real product.
- AI generates realistic holocaust scenes that are shared on social media.
- Movie features de-aged actors or digital replicas of dead actors.
- AI generates music resembling the individual style of existing artists.
- AI-manipulated image places a politician in a scene that clearly mocks his policy decisions.
- Game imagery includes deep fake simulations of real people.
- AI generates a summary of an article about a town council decision, and the newspaper publishes it without editorial review.
- AI manipulates parts of a lifestyle article comparing the effects of diets on a disease.
- AI manipulates corporate reports with investor information on a listed company's website.
- AI generates a storm warning on a meteorological institute's social media profile.
- Website posts AI-generated articles on EU policy without any human review.
- Another AI reviews AI-generated articles, and a human editor only checks the grammar.
- Self-published AI-generated book on climate change goes to an e-commerce platform without any review.
The duty applies even if you had no intention to deceive anyone, and the disclosure must be visible or audible to people.
For evidently artistic, satirical or fictional works (a movie with digital replicas of actors, AI music in the style of a real artist, political satire, a game) you may disclose the AI origin in a way that doesn't spoil the work.
The List of Prohibited Practices (Article 5)
Article 5 of the EU AI Act contains a list of activities that companies and public authorities are banned from performing with AI-based software and devices. If caught, they face fines of up to €35 million or 7% of their total worldwide annual turnover for the preceding financial year, whichever is higher (for SMEs and start-ups — whichever is lower).
In practice, market surveillance authorities will interpret Article 5 in line with the European Commission's Guidelines on prohibited AI practices. This is a 134-page official interpretation that helps anyone understand what exactly the wording of Article 5 means in practice.
Article 5 lists 8 prohibited AI practices. Each point describes, in general terms, one category of prohibited practices without giving examples. In turn, the Commission's Guidelines give dozens of concrete examples of what is prohibited (we counted around 80).
Article 5 prohibits placing on the market, putting into service or using:
- an AI system that applies covert, manipulative or deceptive influence techniques to materially distort a person's behaviour so that they take decisions they would not otherwise have taken, causing (or having the potential to cause) significant harm to them or to others.
Examples:
- A game with a brain-computer interface covertly trains players' brains to reveal sensitive information from their neural data (bank details, intimate information).
- AI system plays background audio or shows images that imperceptibly alter a person's mood, increasing anxiety and mental distress.
- AI system creates highly persuasive messages tailored to a person's data and vulnerabilities.
- AI system learns manipulative techniques on its own (from manipulative patterns in its training data or by gaming reinforcement learning from human feedback) even if the provider never intended it.
- AI chatbot impersonates a person's friend or relative with a cloned voice to run scams.
- AI system recognises when it is being evaluated and temporarily hides its undesired behaviour, resuming it once the evaluation is over.
- Advertising chatbot flashes brief visual cues and embeds inaudible audio signals to push people into harmful purchasing decisions without their conscious awareness.
- Wellness chatbot gives users dangerous health advice.
- AI chatbot nudges users towards self-harm or violence against others.
- AI companion app uses anthropomorphic features and emotional cues to make users emotionally dependent on the service.
- Chatbot offers fraudulent products.
- AI system uses addictive design that fosters compulsive use, anxiety and depression.
- AI systems facilitate harassment, gender-based violence and sextortion: deepfake porn and blackmail with AI-generated images.
- AI-generated deepfakes impersonate real people to deceive them.
- an AI system that exploits people's vulnerabilities related to their age, disability or a specific social or economic situation to materially distort their behaviour, causing (or having the potential to cause) significant harm to them or to others.
Examples:
- AI-powered toy encourages children to complete increasingly risky challenges (climbing furniture, handling sharp objects) in exchange for digital rewards and virtual praise.
- Game analyses a child's behaviour to create personalised rewards through addictive reinforcement schedules and dopamine-like loops, driving compulsive play.
- AI system targets older people with deceptive personalised offers or scams, exploiting their reduced cognitive capacity.
- Assistive robot forces older persons to do certain activities against their free choice.
- Therapeutic chatbot for people with mental disabilities exploits their limited intellectual capacities to push them into buying expensive medical products.
- AI system identifies women and young girls with disabilities online and targets them with more effective grooming practices.
- Predictive algorithm targets people in low-income postcodes with advertisements for predatory financial products, exploiting their financial desperation.
- Provider or deployer knows its system unlawfully discriminates against people in a vulnerable socio-economic situation and likely causes them significant harm and takes no corrective measures.
- Personalised chatbot identifies the discontent of migrants and pushes them towards extremist views, including violence.
- AI system generates child sexual abuse material or develops strategies for grooming and sexually extorting children.
- AI system uses addictive reinforcement schedules to keep young users dependent on the service, causing anxiety, depression, eating disorders, self-harm and suicidal behaviour.
- Anthropomorphic AI simulates human-like emotional responses with children, fostering unhealthy emotional attachment and distorting their understanding of real human relationships.
- AI system targets older people with expensive medical treatments, unnecessary insurance policies or deceptive investment schemes.
- AI-enabled differential pricing exploits people's economic situation, charging lower-income consumers higher prices for the same insurance coverage.
- Emotion recognition system meant to support mentally disabled individuals manipulates them into buying ineffective and expensive products with "unrealistic mental health benefits".
- AI chatbot targets socially or economically disadvantaged groups with fear-based narratives, inciting them to violence against others.
- AI system targets older persons with insurance offers by exploiting their reduced cognitive capacity.
- AI system uses imperceptible images to steer choices; emotion recognition covertly detects when a consumer is most susceptible and offers products at higher prices in that moment.
- an AI system that scores or classifies people over time based on their social behaviour or personal characteristics (known, inferred or predicted), leading to worse treatment of them in contexts unrelated to where the data came from, or to treatment that is unjustified or disproportionate to their behaviour.
Examples:
- Credit scoring system produces a "probability value" on whether a person will repay a loan by predicting that they will behave the way other people with similar characteristics have behaved (banned when the score uses unrelated data or leads to disproportionate treatment).
- Partly automated surveillance system at refugee camps (cameras, motion sensors) evaluates migrants over time to assess whether they are at risk of absconding.
- Public authority assesses people's trustworthiness combining an AI score with human assessment, when the AI score plays a sufficiently important role in the final decision.
- Public authority obtains a person's creditworthiness score produced by a separate specialised company (outsourcing the score does not escape the prohibition).
- National tax authority selects tax returns for closer inspection using not only income and assets, but also taxpayers' social habits and internet connections.
- Social welfare agency estimates fraud risk of benefit recipients based on having a spouse of a certain nationality or ethnic origin, having an internet connection, behaviour on social platforms and performance at work.
- Public labour agency scores unemployed people for state employment support using marital status, health data on chronic diseases and addictions.
- Public agency profiles families to detect "children at risk", and children are taken away over minor transgressions like occasionally missed doctors' appointments or traffic fines.
- Municipality scores residents' trustworthiness and people are blacklisted and lose public benefits for not returning library books on time, leaving rubbish out on the wrong day or paying local taxes late.
- Tax authority profiles child-benefit recipients into "deliberate intent / gross negligence" categories using low income and dual nationality, with benefits cancelled and families driven into heavy debt.
- Public authority scores fraud risk in student housing grants using applicants' internet connections, family status and level of education.
- Government runs a comprehensive citizen rating across all areas of life (social interactions, online activity, purchasing habits, bill punctuality) and low scores restrict access to public services, raise loan rates and block travel, renting and jobs.
- Insurance company takes spending data from a bank (unrelated to life insurance eligibility) and uses it to refuse contracts or set higher premiums.
- Private credit agency decides whether a person gets a housing loan based on unrelated personal characteristics.
- an AI system that predicts the risk of a person committing a crime based solely on profiling them or assessing their personality traits.
Examples:
- Law enforcement authority predicts criminal behaviour (such as terrorism) solely from a person's age, nationality, address, type of car and marital status. People are deemed likely to commit crimes they have not committed based on personal characteristics alone.
- National tax authority reviews all tax returns to predict criminal tax offences solely on an AI-built profile using personality traits such as double nationality, place of birth, number of children and opaque inferred variables that are hard to verify.
- Police risk tool scores children and adolescents for "future violent and property offending" based on their relationships. A child is deemed higher-risk simply for having a sibling or friend with a high risk score and children end up registered, monitored and referred to youth "care" services.
- Private company, asked by a law enforcement authority, analyses masses of data from national registers, banking transactions, communications and geo-spatial data to predict which individuals are potential human-trafficking offenders.
- AI system links location-based crime data to a specific person and scores their criminal risk solely on profiling, including the fact that they live in a high-crime area.
- an AI system that creates or expands a facial recognition database through untargeted scraping of facial images from the internet or CCTV footage.
Examples:
- Scraping tool avoids collecting "everyone" at once and instead harvests faces group by group (all residents of one city today, another tomorrow) until the database covers everyone anyway.
- System legally searches for specific individuals but along the way harvests and stores the faces of everyone else it encounters.
- Scraping facial images from CCTV footage captured by surveillance cameras in airports, streets and parks.
- Facial recognition software company scrapes photos of faces from social media (Facebook, YouTube, Twitter, Venmo) with an automated image scraper, stores them with the source URL, geolocation and sometimes names, converts facial features into hashed mathematical representations and lets a user upload anyone's photo to find a match (business model of Clearview AI).
- an AI system that infers people's emotions in the workplace or in education institutions (except for medical or safety reasons).
Examples:
- AI system infers that an employee is unhappy, sad or angry towards customers from body gestures, a frown or the lack of a smile.
- AI system infers from voice and body gestures that a student is furious and about to become violent.
- AI system infers emotions from the way a person types, their facial expressions, body postures or movements.
- Call centre uses an AI system with webcams and voice recognition to track its employees' emotions, such as anger.
- AI system monitors the emotional tone of hybrid work teams from voice and imagery in video calls, even when the stated purpose is conflict prevention.
- AI emotion recognition system evaluates candidates during recruitment.
- AI emotion recognition system monitors employees during their probationary period.
- Supermarket uses AI-powered cameras to track its employees' emotions, such as happiness.
- Education institution requires students to use a language-learning app with AI emotion recognition.
- AI eye-tracking software at online exams detects not only cheating but also students' emotional arousal and anxiousness.
- Education institution uses an AI system to infer students' interest and attention.
- AI emotion recognition system assesses applicants during admission tests.
- AI system monitoring online lectures detects students' emotional arousal, anxiousness and interest.
- Education institution runs an AI emotion recognition system on both teachers and students.
- AI system detects burnout or depression at work or in education (the medical exception does not cover this).
- AI emotion recognition system assesses employees' or students' wellbeing, motivation and job or learning satisfaction (wellbeing does not count as a medical reason).
- Employer's AI-enabled wearables measure employees' anxiety or boredom (allowed only where stress poses a specific danger, such as operating dangerous machines or handling chemicals).
- an AI system that categorises individual people based on their biometric data (face, voice, etc.) to deduce or infer their race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation.
Examples:
- AI system categorises social media users by their assumed political orientation, analysing biometric data from the photos they have uploaded, to send them targeted political messages.
- AI system categorises social media users by their assumed sexual orientation from photos shared on the platform and serves them advertisements on that basis.
- AI system estimates people's attributes such as age, gender and ethnicity from bodily features (face, height, skin, eye and hair colour) or singles out individuals by a specific feature such as a scar under the right eye or a tattoo on the right hand (banned when this is used to infer the sensitive traits from the list).
- AI biometric system claims to be capable of deducing a person's race from their voice.
- AI biometric system claims to be capable of deducing a person's religious orientation from their tattoos or face.
The 8th point prohibits using (but not developing or selling) real-time remote biometric identification systems in publicly accessible spaces for law enforcement purposes (with narrow exceptions).
Examples:
- Police use a real-time facial recognition system to identify a shoplifter by comparing their face against criminal databases (theft is not among the three permitted objectives).
- Police at a busy festival screen everyone passing the entrances against a watchlist of wanted individuals with outstanding warrants, hoping to spot criminals in the crowd (untargeted "fishing" deployment is banned).
- Police run real-time facial recognition in the streets for general security, crime prevention and overcrowding concerns: constant, time-unlimited surveillance of everyone.
Rate this article
Recommended posts
Portfolio
Our Clients' Feedback
We have been working for over 10 years and they have become our long-term technology partner. Any software development, programming, or design needs we have had, Belitsoft company has always been able to handle this for us.
Founder from ZensAI (Microsoft)/ formerly Elearningforce