Skip to content
SpeechToWork
100% local · GDPR-compliant without the cloud

EU AI Act summary: what businesses using AI need to do

The EU AI Act regulates how AI systems may be offered and used, and it applies to offices, law firms and practices that use ChatGPT, Copilot or a dictation assistant, not just to AI developers. This summary covers the timeline, the risk levels, AI literacy, deployer duties, fines and whether the EU AI Act applies to UK businesses. Last reviewed: September 2026.

Lawyer dictating in a law firm office with shelves of files
  • 2 Feb 2025the date from which the AI literacy duty in Art. 4 applies, including to deployers.
  • €35mor 7% of turnover: the maximum fine for prohibited practices, Art. 99.
  • 2 Dec 2027new deadline for high-risk AI under Annex III, Regulation (EU) 2026/1744.

The EU AI Act in brief

In short: If your business uses AI, it is a “deployer”. Since 2 February 2025, deployers must support AI literacy among their staff and must not use prohibited practices. Since 2 August 2026, transparency duties apply too. Strict high-risk duties, for example for AI used in recruitment, only apply from 2 December 2027. The GDPR applies on top.

The EU AI Act is Regulation (EU) 2024/1689 of 13 June 2024. As an EU regulation, it applies directly in every member state. It sorts AI systems by risk: the greater the danger to health, safety and fundamental rights, the stricter the rules.

Most duties fall on providers, the companies that develop AI systems and place them on the market. Businesses that only use AI are deployers. Their duties are fewer but concrete, and they are the focus of this guide.

In July 2026 the EU amended the Act for the first time: Regulation (EU) 2026/1744, the Digital Omnibus on AI, has been in force since 27 July 2026. It postpones the high-risk rules and rewords the AI literacy duty, so many older summaries are out of date.

EU AI Act timeline: what applies when?

The EU AI Act entered into force on 1 August 2024 and applies in stages (Art. 113, as amended by Regulation (EU) 2026/1744):

  1. Entry into force

    The AI Act enters into force 20 days after publication in the Official Journal (Art. 113). Its obligations apply in stages.

  2. Prohibitions and AI literacy

    The prohibited practices in Art. 5 and the AI literacy duty in Art. 4 apply, including to deployers.

  3. General-purpose AI models, authorities, penalties

    Obligations for providers of models such as those behind ChatGPT or Gemini (Chapter V), the governance structure and the penalty rules (Art. 99).

  4. Digital Omnibus in force

    Amending Regulation (EU) 2026/1744 postpones the high-risk rules and rewords Art. 4.

  5. General date of application

    The transparency obligations in Art. 50 apply. According to the European Commission, national authorities enforce AI literacy from this date.

  6. New prohibitions, end of grace period

    According to the Commission, the two new prohibitions added by the Omnibus take effect (see section 07). For AI systems already on the market before 2 August 2026, the four-month period for machine-readable marking under Art. 50(2) ends.

  7. Legacy general-purpose AI models

    Models placed on the market before 2 August 2025 must comply (Art. 111(3)).

  8. High-risk AI under Annex III

    For example recruitment, promotion, creditworthiness, education. Originally 2 August 2026.

  9. High-risk AI in products under Annex I

    AI as a safety component in products such as lifts, toys or medical devices. Originally 2 August 2027.

Only the high-risk rules were postponed. AI literacy, the prohibitions and the transparency duties were not. Whether high-risk duties matter for you is covered in section 07.

Does the EU AI Act apply to UK businesses?

It can. The UK has left the EU, but the AI Act reaches beyond EU borders. Under Art. 2(1) it applies to:

  • providers that place AI systems or models on the EU market or put them into service there, wherever they are established,
  • providers and deployers outside the EU where the output of the AI system is used in the EU,
  • deployers established or located in the EU, including UK companies’ EU branches.

So a UK firm that sells AI-based software to EU customers, or uses AI whose results are used in the EU, for example to assess applicants for a role in Dublin, needs to look at the Act. A UK office that only uses AI for its own work in the UK is generally not covered.

The UK’s own approach: as of September 2026, the UK has no AI Act and no government AI bill before Parliament. Since the 2023 white paper “A pro-innovation approach to AI regulation”, existing regulators apply existing law to AI within their remits. For personal data that means the UK GDPR and the Data Protection Act 2018, enforced by the ICO, which publishes guidance on AI and data protection. The rules on automated decision-making were changed by the Data (Use and Access) Act 2025.

The EU AI Act risk levels

The European Commission describes four levels of risk:

LevelExamplesConsequence
Unacceptable riskSocial scoring, emotion recognition in the workplace, exploiting vulnerabilitiesProhibited (Art. 5)
High riskRecruitment, evaluating employees, creditworthiness, access to education (Annex III), AI in regulated products (Annex I)Strict duties for providers, Art. 26 for deployers
Transparency riskChatbots, AI-generated images, deepfakes, emotion recognition outside the banLabel and inform (Art. 50)
Minimal riskSpell checkers, spam filters, dictation, writing assistants in the officeNo specific duties, but AI literacy (Art. 4)

Separately, the Act regulates general-purpose AI models (Art. 51 onwards), the large language models. Those duties fall on their providers, not on you as a user. Most office tools are minimal or transparency risk, but the classification depends on the use, not the tool. The same chatbot that drafts emails becomes high risk if it is used to shortlist job applicants.

Who counts as a deployer?

Under Art. 3(4), a deployer is any natural or legal person, public authority, agency or other body using an AI system under its authority, except for personal, non-professional activity.

  • A law firm whose staff draft letters with an AI assistant is a deployer.
  • A practice that dictates clinical letters with AI speech recognition is a deployer.
  • A builder who writes quotes with ChatGPT is a deployer, even on a free account, once it is used for work.

Be careful with your own changes: if you market a high-risk system under your own name, modify it substantially or change the purpose of an ordinary AI system so that it becomes high risk, Art. 25(1) makes you a provider with all the duties that come with it. An example is a general chatbot deliberately used to pre-screen job applications.

AI literacy under Article 4

Article 4 is the duty that affects almost every business, because it applies to all deployers regardless of risk. Since the Omnibus, providers and deployers must “take measures to support the development of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf”, taking into account their knowledge, experience, education and the context.

Before, Article 4 required a “sufficient level” of AI literacy. It is now a duty to act rather than a guaranteed result, but it has not been removed. The European Commission’s questions and answers say:

  • No certificate is required. An internal record of training and guidance is enough.
  • There is no fixed format. The approach should fit the role, the systems used and what staff already know.
  • It also applies if staff only use ChatGPT or similar tools. They should know the risks, such as made-up answers (hallucinations).
  • National market surveillance authorities enforce it, according to the Commission from 2 August 2026.

Art. 99 sets no specific fine for Article 4, but authorities can enforce it. Useful AI literacy training for an office covers what AI can and cannot do, which tools are allowed, which data must not go in, how to check results and who to ask.

Duties under Articles 50 and 26, and the bans in Article 5

Transparency under Art. 50 (since 2 August 2026)

Some transparency duties fall on providers: chatbots must be recognisable as AI (para. 1) and generated content must be marked in a machine-readable way (para. 2). Deployers must act themselves when they:

  • use emotion recognition or biometric categorisation: the people exposed must be informed (para. 3),
  • create deepfakes, realistic images, video or audio of people, places or events: they must disclose that the content is artificially generated (para. 4),
  • publish AI-generated text to inform the public on matters of public interest: this must also be disclosed, unless a person has reviewed it and holds editorial responsibility (para. 4).

The information must be clear at the latest at the first interaction (para. 5). An email you drafted with AI and read yourself does not need a label.

High-risk AI: duties under Art. 26 (from 2 December 2027)

If you use a high-risk system, such as software that filters applications or evaluates staff, you must among other things:

  • use it in line with the provider’s instructions (para. 1),
  • assign human oversight to people with the necessary competence, training and authority (para. 2),
  • where you control the input data, make sure it is relevant to the purpose (para. 4),
  • monitor operation and report risks or serious incidents to the provider (para. 5),
  • keep automatically generated logs for at least six months (para. 6),
  • inform workers’ representatives and affected workers before using it at work (para. 7),
  • inform people about whom the system makes or supports decisions (para. 11).

Public bodies and some businesses, for example in credit scoring and life and health insurance, must also carry out a fundamental rights impact assessment (Art. 27).

Prohibited practices under Art. 5 (since 2 February 2025)

Banned are, among others, AI systems that manipulate people subliminally or exploit vulnerabilities due to age, disability or social situation, social scoring, untargeted scraping of facial images from the internet or CCTV for facial recognition databases, and biometric categorisation by traits such as religion or sexual orientation.

For employers, Art. 5(1)(f) matters most: emotion recognition in the workplace and in education is banned, except for medical or safety reasons. Software that reads staff mood from voice or face during customer calls falls under it. The Omnibus adds two bans: AI that creates realistic intimate images of people without consent, and AI that creates child sexual abuse material.

EU AI Act fines

The Act sets maximum amounts; member states lay down the details. The penalty rules have applied since 2 August 2025.

InfringementMaximum fine
Prohibited practices (Art. 5)€35 million or 7% of total worldwide annual turnover for the preceding year, whichever is higher (Art. 99(3))
Deployer duties (Art. 26), transparency (Art. 50) and other operator duties€15 million or 3% of worldwide annual turnover (Art. 99(4))
Incorrect, incomplete or misleading information to authorities€7.5 million or 1% of worldwide annual turnover (Art. 99(5))

For small and medium-sized enterprises, including start-ups, the lower of the two amounts applies (Art. 99(6)). Authorities consider, among other things, the nature, gravity and duration of the infringement, intent or negligence and the size of the business. GDPR fines can come on top.

The EU AI Act and the GDPR: both apply

The AI Act does not replace data protection law. Art. 2(7) makes clear that the GDPR is unaffected. As soon as personal data goes into an AI tool, you still need:

  • a lawful basis under Art. 6 GDPR, plus Art. 9 for health data,
  • a data processing agreement under Art. 28 if a provider processes the data,
  • an assessment of transfers to third countries such as the US (Chapter V),
  • a data protection impact assessment under Art. 35 where required. For high-risk AI, Art. 26(9) of the AI Act refers to it directly.

Put simply: the AI Act asks whether and how an AI system may be used, the GDPR asks what happens to the data in it. In the UK, the UK GDPR plays that role. What to look for in a tool is explained in our guides on GDPR-compliant AI and whether ChatGPT is GDPR compliant.

Common problems in the office

In small businesses, compliance rarely fails on the legal text, but on everyday work:

  • Shadow AI: staff use personal accounts for chatbots, translators or transcription services without anyone knowing. What nobody knows about cannot be trained, classified or checked for data protection.
  • No overview: nobody can say which tools are in use, which contain AI and what they are used for. Without that list, you can neither train nor classify.
  • Providers change models and terms: cloud services swap models, add features and update their terms and privacy notices. A review from a year ago may no longer fit.
  • Client data in chatbots: a client’s email is quickly pasted in to draft a reply. Personal data, often confidential client information, then ends up with an outside provider.

EU AI Act checklist for deployers

These steps cover the duties that apply to most offices today:

  1. List your AI tools: every program and service with AI, who uses it and what for, including free accounts and browser extensions.
  2. Classify: for each use, check whether it is prohibited (Art. 5), high risk (Annex III, for example HR decisions) or covered by Art. 50.
  3. Stop anything prohibited: for example emotion recognition in staff conversations.
  4. Set rules: a short AI policy covering allowed tools, forbidden data, checking results and labelling under Art. 50.
  5. Train and record: build AI literacy under Art. 4 to fit each role and keep a record of who learned what and when.
  6. Check data protection: lawful basis, processing agreements, international transfers, a DPIA where needed.
  7. Prepare for high risk: if it applies, implement the Art. 26 duties by 2 December 2027 and involve staff representatives early.
  8. Review regularly: new tools, changed provider terms and further guidance from the Commission and national authorities.

What a local AI assistant makes easier, and what it does not

SpeechToWork is an AI assistant that runs entirely on your own Windows computer: speech recognition and the language model work there, and dictations, emails, documents and recordings do not go to any provider. That mainly simplifies the data protection side: for your content there is no processor, no transfer to the US and no training on your data. The model does not change overnight, because it sits on your computer as a file. More in our guide to local AI.

To be honest: a local program does not take the AI Act off your hands. If your business in the EU uses SpeechToWork, it is still a deployer of an AI system. The AI literacy duty under Art. 4 applies all the same, the program belongs on your tool list, and if you used it for a high-risk task, that purpose would count. For everyday office work such as dictating, drafting, summarising and taking minutes, no further duties arise.

Sources

All statements were checked against these sources in September 2026:

Last reviewed: September 2026. This guide is not legal advice. Further Commission guidelines and the practice of national authorities may still change how the Act is interpreted.

An example

What you say. What appears.

You sayDear all, um, from Monday our rule is: no client data in ChatGPT, no, in any online chatbot. The AI Act training is on Thursday at ten, please all attend, thanks.
In your programDear all, From Monday our rule is: no client data in any online chatbot. The AI Act training is on Thursday at 10 am. Please all attend. Thanks
Your advantage

Why SpeechToWork fits this job.

Client data stays in-house

Dictations, emails and documents are processed on your computer, which takes the client data in chatbots problem out of everyday work.

A stable entry on your tool list

One program, a fixed model, no provider terms that change overnight. That makes classification and records easier.

Training is still your job

Art. 4 applies to SpeechToWork too: your staff should know what the AI can do and when to check its results.

Privacy

Local means local. No compromises.

Speech recognition and the language model are installed on your PC and run there. What you dictate ends up in your program and nowhere else. How the data flow works.

No upload

Audio and text stay on your computer. There is no server listening in and no AI provider in the background.

GDPR made simple

No third party processes your dictations. So there is no data processing agreement to sign and no international transfer to assess.

Works without internet

Once installed, SpeechToWork works offline. Only the licence check needs a connection.

Good to know

Frequently asked questions

What is the EU AI Act?

The EU AI Act is Regulation (EU) 2024/1689. It regulates AI systems in the EU according to risk: some practices are banned, high-risk AI faces strict duties, and chatbots and deepfakes must be transparent. It entered into force on 1 August 2024 and applies directly in every member state, in stages until 2028.

Does the EU AI Act apply to UK businesses?

It can. Under Art. 2, it applies to providers placing AI on the EU market wherever they are based, and to providers and deployers outside the EU where the AI output is used in the EU. A UK business using AI only for its own work in the UK is generally not covered.

What is the EU AI Act timeline?

In force since 1 August 2024. Bans and AI literacy since 2 February 2025, rules for general-purpose AI models since 2 August 2025, transparency duties since 2 August 2026. After the Digital Omnibus, high-risk rules under Annex III apply from 2 December 2027 and for AI in regulated products from 2 August 2028.

Do I have to train my staff under the EU AI Act?

Yes, if your business is covered. Article 4 requires deployers to take measures to support the AI literacy of their staff, since 2 February 2025. According to the European Commission, no certificate is needed and an internal record is enough. Training should fit the role and tools: capabilities, limits, allowed data and checking results.

What are the fines under the EU AI Act?

Up to €35 million or 7% of worldwide annual turnover for prohibited practices, up to €15 million or 3% for breaches of deployer or transparency duties, and up to €7.5 million or 1% for misleading information to authorities (Art. 99). For small and medium-sized enterprises, the lower of the two amounts applies.

Has the EU AI Act been delayed?

Partly. Regulation (EU) 2026/1744, the Digital Omnibus, moved the high-risk rules under Annex III from 2 August 2026 to 2 December 2027, and those for AI in products to 2 August 2028. AI literacy, the bans and the transparency duties were not delayed. The AI literacy duty was reworded, not removed.

Does a local AI assistant exempt me from the EU AI Act?

No. A business in the EU that uses a local assistant such as SpeechToWork for work is still a deployer and must support AI literacy. What gets simpler is data protection: content stays on your computer, with no processor and no international transfer. For everyday office work, no further AI Act duties arise.

Coming soon

Coming soon. Then try it for 14 days.

SpeechToWork is about to launch. As soon as the first version is ready, you can download it here: one click, one file, no form.

Coming soon

For Windows 10/11 (64-bit). The download will be available here as soon as it is ready.

  • All features, no payment details
  • Ends automatically, nothing to cancel
  • Your dictations never leave your computer, not even in the trial
  1. Download

    One installer for Windows, straight from our server.

  2. Install

    A double click is all it takes. No administrator rights needed.

  3. Choose “Try for 14 days”

    On first start: enter your name and business email, no payment method.

On first start, SpeechToWork downloads the language models once (4 to 6 GB). Already have a licence key? Enter it on first start. What is transferred in the process is explained in our privacy policy.

Coming soon