WOODLANDS ADVISORY
All articles
AI Governance· 9 min

The EU AI Act after 2 August: what applies now, what has been postponed and what managing directors of mid-sized companies should do

Risk classes, labelling duties under Article 50, AI literacy and the postponement of high-risk obligations by the Digital Omnibus: the state of the AI Act in autumn 2026, explained for decision-makers in mid-sized companies.

2 August 2026 was announced as the big deadline of the AI Act. Then the Digital Omnibus arrived and postponed the high-risk obligations by more than a year. Many companies have read this as "we still have time". That is only half true: the transparency obligations have applied since August, and the question of whether your AI applications fall into a high-risk class needs an answer long before December 2027.

Over the past four weeks we have looked closely at what decision-makers in Germany search for around AI regulation. The pattern is clear. The questions are rarely about principles and almost always concrete: Which risk classes exist? Do I have to label AI content? What has been mandatory since 2 August? Do my employees need an AI licence? How do I make sure our AI systems comply with the regulation?

This article answers these questions in the order in which they become relevant for a mid-sized company.


The state of play in autumn 2026

Since / fromWhat applies
2 February 2025Prohibited AI practices (Art. 5) and the AI literacy obligation (Art. 4)
2 August 2025Obligations for providers of general-purpose AI models (GPAI)
27 July 2026Digital Omnibus on the AI Act (Regulation (EU) 2026/1744) enters into force
2 August 2026Transparency obligations under Art. 50: chatbots, deepfakes, AI-generated text on matters of public interest, emotion recognition
2 December 2026Transition period for machine-readable marking (Art. 50(2)) for systems already on the market before August; new prohibition of non-consensual intimate imagery
2 December 2027High-risk AI under Annex III (including employment, creditworthiness, education, critical infrastructure)
2 August 2028High-risk AI as a safety component of regulated products (Annex I, for example machinery)

The key message: what was postponed is the high-risk regime, not the regulation. The transparency obligations have applied unchanged since 2 August.


The four risk classes and why classification depends on the use case, not the technology

The AI Act is risk-based. What matters is not which model you use but what you use it for. The same language model can be an uncritical writing assistant in one company and a high-risk system in another.

1. Prohibited practices (Art. 5). These include manipulative techniques, social scoring, emotion recognition in the workplace and in education (with narrow exceptions) and certain biometric methods. Rarely relevant for a typical mid-sized company, but a point to check explicitly in any HR or analytics tool you buy in.

2. High-risk AI (Art. 6 with Annexes I and III). This is where the real work lies. For mid-sized companies the most relevant areas are:

  • Employment and HR: AI that filters or scores applications, contributes to decisions on promotion, task allocation or dismissal, or monitors performance and behaviour.
  • Access to essential services: creditworthiness assessment of natural persons, risk assessment and pricing in life and health insurance.
  • Education and training: admission, assessment of learning outcomes, exam proctoring.
  • Critical infrastructure: AI as a safety component in energy, water, transport or digital infrastructure.
  • Products under Annex I: AI as a safety component in machinery or medical devices, for example.

The exception in Art. 6(3) matters: a system in an Annex III area is not high-risk if it only performs a narrow procedural task, improves the result of a previously completed human activity, or merely prepares a decision without replacing it. The exception never applies where the system performs profiling of natural persons. Anyone relying on it must document that assessment. The Commission published draft guidelines on classification in May 2026.

3. Limited risk with transparency obligations (Art. 50). Chatbots, AI-generated content, deepfakes. More on this below, because this is the part that applies today.

4. Minimal risk. The bulk of everyday applications, such as spam filters, translation or internal writing assistance. No specific obligations under the regulation, although data protection, employment law and information security still apply.

A note on AI agents: agents that carry out actions on their own are not a separate risk class. An agent that pre-codes invoices generally remains minimal risk. An agent that pre-sorts applications and sends rejections is operating in high-risk territory. What matters is which decisions the agent influences and whether a person approves before execution.


Labelling under Article 50: what has applied since 2 August

Searches for "AI labelling obligation", "Art. 50 AI Act" and "EU label AI generated" show that this is where uncertainty is greatest. Article 50 distinguishes between providers (whoever develops an AI system or places it on the market under their own name) and deployers (whoever uses it under their own authority in a professional context). Most mid-sized companies are mainly deployers, but quickly become providers themselves, for instance with their own chatbot on the website.

Obligations of providers

  • Chatbots and assistants (para. 1): people must be told that they are interacting with an AI, unless this is obvious.
  • Machine-readable marking (para. 2): synthetic audio, image, video and text content must be technically detectable as AI-generated. For systems already on the market before 2 August 2026, a transition period runs until 2 December 2026.

Obligations of deployers

  • Deepfakes (para. 4, first subparagraph): anyone who generates or manipulates image, audio or video content resembling real people, places or events must disclose that it is artificially generated. Lighter rules apply to evidently artistic or satirical works.
  • AI-generated text on matters of public interest (para. 4, second subparagraph): published text intended to inform the public must be recognisable as AI-generated, unless it has undergone editorial review and a person or organisation holds editorial responsibility.
  • Emotion recognition and biometric categorisation (para. 3): the people affected must be informed.

Notices must be clearly visible, given at the latest at the first interaction, and accessible. The Commission published guidelines on Article 50 in July 2026. Infringements can be fined up to 15 million euros or 3 % of worldwide annual turnover; for smaller companies the lower of the two amounts is the ceiling.

What this means in practice:

  • The website chatbot needs a visible notice when the conversation starts.
  • AI-generated product images showing photorealistic people should be labelled.
  • A specialist article drafted with AI, then reviewed and approved by a responsible person, generally falls under the editorial exception. This assumes the review actually takes place and can be traced.
  • Internal use without publication does not trigger the deployer obligations under para. 4.

AI literacy under Article 4: do we need an AI licence?

There is no statutory AI licence. Since February 2025, Article 4 has required providers and deployers to ensure AI literacy among their staff. The Digital Omnibus has softened this obligation: companies must take measures to support the development of AI literacy, but need not guarantee a specific level.

That is relief, not an all-clear. After an incident, the first question will be how employees were prepared to work with AI. A short, role-specific training, a clear AI policy and a record of who received what and when are achievable with modest effort.


Why December 2027 is closer than it sounds

Moving the Annex III obligations to 2 December 2027 buys time, but less than the calendar suggests. Anyone operating a high-risk system will need, among other things:

  • a classification of every relevant AI use with a documented rationale,
  • human oversight that actually works within the process (Art. 14 and 26), not only on paper,
  • logging and retention of logs,
  • information for employees and their representatives before workplace deployment,
  • for certain uses, such as creditworthiness or insurance assessment, a fundamental rights impact assessment (Art. 27),
  • contracts with providers that deliver the necessary information and evidence.

Many of these points depend on suppliers, works councils and budget cycles. Whoever starts in autumn 2027 will be negotiating under time pressure. Then there is supervision: in Germany, the Federal Network Agency (Bundesnetzagentur) is to become the central market surveillance authority and complaints office. The Bundestag passed the implementing act (KI-MIG) in June 2026.


Five steps worth taking now

1. Build an AI inventory. Which AI systems are in use, whether bought in, built in-house or embedded as a feature in existing software? The biggest gap is almost always shadow AI: tools that business units use without approval.

2. Classify every use. Prohibited, high-risk, subject to transparency obligations, or minimal. Where you rely on the exception in Art. 6(3), record the rationale in writing.

3. Close the transparency gaps now. Chatbot notices, labelling of synthetic media, a clear approval process for AI-assisted publications. These are modest changes with immediate effect.

4. An AI policy that is actually lived. Not another policy PDF, but a few clear rules: which tools are permitted, which data must not go in, who approves results, how incidents are reported. Add training that fits the role and the tool.

5. Build control in before execution. With AI agents in particular, logging after the fact is not enough. Separate identities and permissions for agents, approval thresholds for consequential actions and a person who confirms critical decisions: this not only meets future supervisory requirements but prevents errors before they create costs.


Frequently asked questions

Which risk classes does the EU AI Act define? Four: prohibited practices, high-risk AI, AI with transparency obligations and minimal-risk AI. Classification follows the purpose of use, not the technology.

Does the high-risk regime already apply? No. Following the Digital Omnibus, the obligations for Annex III systems apply from 2 December 2027 and for Annex I products from 2 August 2028.

Do I have to label AI-generated content? Yes for deepfakes and for published AI-generated text on matters of public interest, unless it has undergone editorial review with clear responsibility. Technical marking is the responsibility of the providers of the AI systems.

Does a website chatbot have to be identifiable as AI? Yes, since 2 August 2026, unless this is already obvious to users.

Do employees need an AI licence? No. Companies must support the development of AI literacy. A certificate is not required, but a documented training concept makes sense.

Who supervises the AI Act in Germany? The Federal Network Agency is intended to be the central market surveillance authority and complaints office; sectoral supervisors such as BaFin remain responsible for their areas.


How Woodlands supports you

We connect regulation and implementation: from the AI inventory and the classification of your use cases to guardrails that actually take effect in your processes. Model-neutral, staffed with senior practitioners and with the aim that the result is not just a document but controlled use of AI.

If you would like to know where your company stands on risk classes, labelling and AI literacy, let us discuss it in confidence.

Book an initial consultation free of charge →

This article reflects the position as of 28 September 2026 and does not replace legal advice in an individual case.


Sources

  1. Regulation (EU) 2024/1689 (AI Act), Art. 4, 5, 6, 14, 26, 27, 50, 99 and Annex III
  2. European Commission: AI Omnibus enters into force
  3. NicFab: Digital Omnibus on AI: Regulation (EU) 2026/1744 Is Published in the Official Journal
  4. Gibson Dunn: EU AI Act Omnibus Agreement: Postponed High-Risk Deadlines and Other Key Changes
  5. Mayer Brown: EU AI Act News: Digital Omnibus on AI, New Guidance on Risk Classification, GPAI, and Transparency Obligations
  6. Jones Walker: Yes, August 2 Still Matters
  7. zerodox: KI-Verordnung: Was seit 2.8.2026 gilt (Art. 50)
  8. Cortina Consult: KI-Aufsicht Bundesnetzagentur: Das KI-MIG im Überblick

Share this article

LinkedInX · Twitter
Woodlands Advisory

Let us discuss your specific situation.

20 minutes. Confidential. Non-binding.

Schedule initial consultation →← Back to all articles