Moviwa

What does the EU AI Act require of you in 2026?

9 min read · Reviewed in September 2026

In short

Regulation (EU) 2024/1689 has required AI literacy training since February 2025 and transparency about AI use since August 2026. The Digital Omnibus pushed high-risk obligations to 2027 and 2028, but touched neither of the first two. If your company merely uses AI, nothing has been delayed for you.

The confusion running through the market

Over the summer of 2026 you could read in a lot of places that "the AI Act has been delayed". That is only partly true, and the part that is not true is precisely the part that affects most companies.

Regulation (EU) 2026/1744, known as the Digital Omnibus and in force since 27 July 2026, postponed the obligations for high-risk AI systems: Annex III ones to 2 December 2027 and Annex I ones to 2 August 2028. Annex III covers uses with a direct impact on people — CV screening, creditworthiness assessment, biometrics, education, critical infrastructure, law enforcement.

What was postponed, then, is exactly what almost no small or mid-sized company was doing. What remains fully in force is what that same company does every Tuesday: drafting with AI, summarising reports, analysing documents, handling customers with an assistant.

The two obligations that do apply to you today

Article 4 · AI literacy

In force since 2 February 2025.

It requires providers and deployers to take measures to ensure their staff — and anyone operating AI systems on their behalf — have a sufficient level of AI literacy for the systems they use, taking into account their prior knowledge, the context of use, and the people the systems are used on.

Three points that are routinely missed:

  • You are the "deployer". You do not have to build AI to have the obligation: using it professionally is enough. This is the part that surprises most companies.
  • It is not a generic course. The level has to suit the context: somebody handling customer data needs different training from somebody writing marketing copy.
  • You have to be able to demonstrate it. The regulation talks about taking measures. A measure that leaves no documentary trace is indistinguishable from one never taken, and the trace is what gets audited.

The Omnibus softened the wording — take measures that support literacy, rather than guarantee a specific level — but it neither removed nor postponed the article.

Article 50 · Transparency

In force since 2 August 2026.

It imposes disclosure duties by system type:

  • Conversational systems. If a system is designed to interact directly with people, the user has to know they are talking to an AI, and know it at the first interaction, unless it is obvious from the context.
  • Synthetic content. Text, images, audio and video generated or manipulated by AI must be marked in a machine-readable format and be detectable as artificially generated. It is a technical obligation, not a visual notice.
  • Deepfakes and informational content. Deepfakes must be labelled as generated or manipulated, and content published to inform the public requires disclosure where it was generated or altered with AI.
  • Emotion recognition and biometric categorisation. People exposed to these systems have to be told.

The practical consequence is uncomfortable: to know where Article 50 applies to you, you need to know which AI tools are genuinely in use across your organisation and for what. A company without that inventory cannot claim it complies, nor that the article does not apply.

And if those prompts carry data about people, the obligation overlaps with the GDPR, which requires a legal basis and a processor agreement for that same disclosure.

The full timeline, updated

DateWhat happensStatus
1 August 2024Regulation (EU) 2024/1689 enters into forceDone
2 February 2025Prohibited practices and AI literacy (Art. 4)In force
2 August 2025General-purpose models, governance and the penalty regimeIn force
2 August 2026Transparency (Art. 50) and market surveillanceIn force
2 December 2027Annex III high-risk systemsPostponed by the Digital Omnibus
2 August 2028Annex I high-risk systemsPostponed by the Digital Omnibus

Organising all of this with a management system, rather than with a folder of loose documents, is exactly what ISO 42001 proposes.

How does Moviwa help?

The regulation asks for two things a company cannot improvise on the day an inspection arrives: evidence of what it does and knowledge of what is happening inside.

  • A real inventory of AI tools. Moviwa detects and catalogues which generative AI services each team uses. Without that catalogue you cannot determine where the Article 50 duties apply, nor justify that they do not.

  • Policy applied at the point of use. What company policy forbids, the platform blocks in the browser, with the notice reaching the employee in the moment — which is when a rule turns into behaviour.

  • An exportable log. A history of the risk activity detected, with date, policy applied and outcome. For Article 4 that is the half usually missing: the measure was taken, but left no trace. Here the evidence accumulates on its own instead of being reconstructed.

  • A board-level dashboard. Exposure level and how it is moving, in the format a governance decision gets documented in.

  • What Moviwa does not do. It does not mark your generated content in a machine-readable format. That obligation sits with the system generating the content. Moviwa tells you where it applies to you; it does not replace it.

See the plans

Fines

InfringementMaximum
Prohibited practices (Art. 5)€35 million or 7% of total worldwide annual turnover
Breach of the remaining obligations, including Article 50 transparency€15 million or 3% of total worldwide annual turnover
Incorrect or misleading information to authorities€7.5 million or 1.5% of total worldwide annual turnover

The higher figure applies, and the percentage is calculated on the group's worldwide turnover. The penalty regime has been in force since August 2025 and the Digital Omnibus did not change it.

Checklist: six steps before your next audit

  1. 1

    Take inventory. Which AI tools are in use, in which teams and for which tasks. Measured, not surveyed.

  2. 2

    Classify. Mark the ones that interact with people or generate publishable content: those are what trigger Article 50.

  3. 3

    Train and certify. Training proportionate to the role, with a named certificate per person. Keep the certificates where an auditor can see them.

  4. 4

    Write the AI use policy and turn it into a technical control. A policy that only lives on the intranet generates no evidence.

  5. 5

    Document. A log of activity, incidents and exceptions, with date and outcome.

  6. 6

    Review the timeline every quarter. This one has moved twice in eighteen months. Assign a named owner.

Frequently asked questions

Does the AI Act delay mean I can wait?
Not if your company merely uses AI. What was postponed are the obligations for Annex III and Annex I high-risk systems. Article 4 literacy and Article 50 transparency are fully in force.
Does the regulation apply to me if I only use ChatGPT or Copilot?
Yes, as a deployer. The literacy obligation does not distinguish between building and using. And if the system interacts with customers or generates content you publish, the transparency duties apply too.
What counts as “AI literacy” for Article 4?
The regulation sets no syllabus and no number of hours. It sets an outcome: that the person understands the capabilities, limits and risks of the AI they use, in their working context. What gets audited is that the measure was taken and that you can prove it.
We are a Spanish company: does it apply the same way?
Yes. It is a European regulation with direct effect, needing no national transposition. What does depend on Spain is the supervisory authority and the enforcement procedure.
What if my AI provider already complies?
Your provider meeting its obligations does not transfer yours. Training your staff and controlling what gets sent to those tools remain your responsibility.

Official sources

Do you know where Article 50 applies to you?

The answer starts with knowing which AI tools are in use across your organisation this week. Almost nobody does, and it is the first question of any audit.

No commitment · 15 minutes · No card

Related frameworks

Moviwa implements the technical and organisational controls these frameworks require, and produces the evidence to demonstrate them. Moviwa is not certified against these standards and does not certify your organisation: compliance remains your company's responsibility.

This content is informational and does not constitute legal advice. For decisions about your organisation's compliance, consult your legal adviser.