Skip to content
Montevive

/ Blog /

News

Montevive

The AI Act: what it actually requires of your company, what moved, and what the fines really are

·Chema Robles·Inteligencia Artificial, Regulación
The AI Act: what it actually requires of your company, what moved, and what the fines really are

If someone on your team used ChatGPT this week, your company already has obligations under the AI Act, even if you have never written a line of code.

In June the EU approved a reform package that pushed part of the timeline back, and most of the coverage stopped at the headline: there is more time now. For a company using generative AI day to day, that is false. Almost none of your immediate obligations moved.

What the AI Act is

Regulation (EU) 2024/1689, known as the AI Act, is the world's first comprehensive law on artificial intelligence. Parliament and Council adopted it on 13 June 2024, it was published in the Official Journal on 12 July 2024, and it entered into force on 1 August that year. Because it is a regulation rather than a directive, it applies directly across all 27 Member States without each one having to transpose it.

It sorts any AI system into four tiers:

  • Unacceptable risk: banned outright, the Article 5 practices.
  • High risk: where the heavy obligations live, the Article 6 and Annex III systems such as recruitment, educational assessment, critical infrastructure and credit scoring.
  • Limited risk: transparency obligations.
  • Minimal risk: most uses, with no specific obligations.

It binds both those who build AI and those who use it inside the EU, whether or not the company is European.

If this is your first look at the regulation, we wrote an introduction to the AI Act and what it changes for companies when it came into force. This piece is the update: the timeline has changed since.

The timeline after the Digital Omnibus

On 19 November 2025 the European Commission proposed the reform package known as the Digital Omnibus on AI, document COM(2025) 836, with the stated aim of simplifying the Regulation's timeline.

Parliament approved the final text on 16 June 2026 and the Council gave its final green light on 29 June 2026.

What moved

Obligations for standalone high-risk systems under Annex III (employment, education, critical infrastructure, credit scoring, law enforcement) move from 2 August 2026 to 2 December 2027. Obligations for AI embedded in products already covered by other EU legislation (Annex I: medical devices, machinery, toys) move to 2 August 2028. The package also adds a new prohibition, on non-consensual intimate imagery generated by AI, effective 2 December 2026 regardless of whether a high-risk system is involved. Freshfields' article-by-article breakdown sets it out clearly.

What did not

Prohibited practices and the AI literacy obligation have applied since 2 February 2025, and the Digital Omnibus does not touch them. Obligations on providers of general-purpose models, such as ChatGPT, Claude and Gemini, have applied since 2 August 2025. And the Article 50 transparency obligations, the ones that actually bite for a company using generative AI, took effect on 2 August 2026 exactly as planned, with a short, specific extension only for the technical marking of content in systems already deployed before that date, running to 2 December 2026.

The delay is real, but it applies to a specific part of the Regulation, the Annex III and Annex I high-risk systems, not to the AI Act as a whole. If your company uses generative AI for customer support, drafting, analysis or internal help, almost none of your immediate obligations moved.

Who it applies to: you do not have to build AI to have obligations

The most common mistake is assuming the AI Act only addresses those who build models.

The Regulation distinguishes between a provider, who develops the system or places it on the market, and a deployer, who uses it in the course of their professional activity. A company becomes a deployer the moment somebody uses ChatGPT, Copilot, a CRM with automated scoring, or any tool with AI built in, whether or not it wrote any code.

The obligations, one by one

AI literacy, Article 4, in force since 2 February 2025. Providers and deployers must ensure a sufficient level of knowledge, training and understanding of the AI their staff use: what it can do, what risks it carries, what its limits are. It does not require anyone to code. It requires you to be able to show your workforce is not using AI blind.

Transparency, Article 50, in force since 2 August 2026. Anyone deploying a chatbot must make clear the person is talking to an AI and not a human, unless that is obvious from context. Anyone deploying systems that generate synthetic content must ensure that content is detectable as AI-generated or manipulated, in a machine-readable format.

High-risk deployer obligations, Article 26, applying to Annex III systems from 2 December 2027. Among others: use the system according to the provider's instructions, assign human oversight with real competence and authority, monitor operation and report any risk immediately, keep automatically generated logs for at least six months, and inform workers before putting a high-risk system into use in the workplace.

Although the bulk of Article 26 moves to December 2027 for Annex III systems, literacy and transparency are already running in parallel, and do not wait for that date.

What the fines actually are

Article 99 sets three tiers:

InfringementFixed amountPercentage
Prohibited practices under Article 5up to EUR 35 million7% of total worldwide annual turnover
Other infringements, including Article 50 transparencyup to EUR 15 million3%
Supplying misleading information to authoritiesup to EUR 7.5 million1%

For a large company, the higher of the fixed amount and the percentage applies. But Article 99(6) sets a different rule for SMEs and start-ups: for them, whichever of the two is lower applies.

That distinction is not cosmetic. A company turning over EUR 2 million does not face EUR 35 million. At worst it faces 7% of that turnover, roughly EUR 140,000. Still enough to put real pressure on a small company's cash position, but nothing like the headline number.

And a point that gets missed: AI Act fines do not replace GDPR fines, they stack. If a data leak through generative AI involves personal data, the same incident can trigger an AI Act enforcement file and a GDPR one, and the GDPR has been in force since 2018 with no possible delay.

What is already happening in Spain

Spain is worth watching here even if you are not based there, because it moved first and its enforcement structure is the one taking shape earliest in the EU.

AESIA, the Spanish Agency for the Supervision of Artificial Intelligence, is headquartered in A Coruña and was created in 2023, making Spain the first EU country with a dedicated state agency for this.

On 26 May 2026 the Council of Ministers approved sending Parliament the draft Organic Law on the good use and governance of artificial intelligence, which gives AESIA its definitive national enforcement framework and splits competences with the data protection authority, the judiciary's governing body, the Bank of Spain and the securities regulator depending on the domain. The text was published on 12 June 2026 and is still going through Parliament. Public administrations are exempt from financial penalties in the approved text; private companies have no equivalent carve-out.

The national law still being in progress suspends nothing. The European regulation already applies directly, and the obligations in force (prohibitions and literacy since February 2025, transparency since August 2026) are enforceable with or without national legislation. The Spanish data protection authority has already opened investigations into improper use of AI with personal data under the GDPR, which waits for nothing.

What to do now

Take a real inventory of what AI is in use, including whatever nobody formally approved. A list of purchased applications is worthless if half the team uses ChatGPT from a personal account.

Cover what is already enforceable first: staff literacy, and transparency if you run chatbots or generate content with AI. Do not leave risk classification until December 2027 if any system touches recruitment, educational assessment or scoring.

Offer an approved alternative before banning anything, and add a technical layer that does not depend on forty people remembering the policy every time they open an AI chat.

We also wrote about the opportunities and challenges the regulation creates for European companies if you want the strategic side rather than the compliance one.

Sources

All accessed 9 August 2026. If something does not add up, check it.

Official text and articles

The Digital Omnibus

Spain

Our earlier articles


If you are left wondering where to start, that is the easy part to solve. An AI inventory and Article 4 training are bounded work: weeks, not quarters, and they are exactly what you need to be able to show if anyone asks.

It is what we do. Montevive works with companies and institutions to inventory what AI is actually in use, train teams to the level Article 4 expects, and classify the systems that may fall under Annex III before the date arrives. If you want us to look at it with your case in front of us, get in touch.


This article reflects the state of the regulatory framework as at 9 August 2026, including adoption of the Digital Omnibus on AI. It is informational and does not constitute legal advice: always check the current official documentation before making compliance decisions.