AI Act
The European AI Act for SMEs: the real 2026 timeline (with the June delay)
General information about the law. It’s no substitute for a lawyer’s advice or a look at your specific case.
Direct answer: if your business uses a chatbot, a voice assistant or any AI that generates text, images or audio for your customers, the European AI Act (Reglamento (UE) 2024/1689) requires you to tell people they are talking to an AI from 2 August 2026 (art. 50). The heavier obligations — the "high risk" systems in Annex III, such as those that screen CVs or assess employees — no longer arrive in August 2026: on 29 June 2026 the Council of the European Union approved a reform package (the «Digital Omnibus») that postpones them until 2 December 2027. This guide, reviewed on 16 July 2026, separates what is already obligatory from what has moved, with the official source for each date.
This article is general information about the AI Act. It does not replace advice from a lawyer or a specific analysis of your business: use it as a map, not as a legal opinion.
Contents
- What is the AI Act and why does it affect you even if you don't "do" AI?
- Which obligations are already in force today?
- What exactly changes on 2 August 2026?
- Is it true that the timeline has been delayed? The «Digital Omnibus», explained
- Who supervises this in Spain: the AEPD, AESIA or both?
- The full timeline at a glance
- What does your SME have to do before August 2026? (15 minutes)
- What happens if you don't comply?
- Frequently asked questions
What is the AI Act and why does it affect you even if you don't "do" AI?
Reglamento (UE) 2024/1689, known as the «Reglamento de IA» or «AI Act», is the European rule that governs the use of artificial intelligence. It was published in the Official Journal of the European Union on 12 July 2024 and entered into force on 1 August 2024, but its obligations do not all arrive at once: they apply in phases, and each phase has its own date (art. 113 of the Regulation).
You do not have to develop artificial intelligence for it to affect you. It affects you if you use it: a customer service chatbot, a voice assistant, ChatGPT or another AI for drafting text, an image generator for your website, a program that filters CVs or assesses your team's performance. The law distinguishes between whoever creates an AI system (the provider) and whoever uses it in their business (the deployer), and SMEs almost always fall into this second category — with lighter obligations, but real ones.
Which obligations are already in force today?
Two things have been obligatory for more than a year, and nothing that happened in 2026 has changed them:
- Since 2 February 2025: prohibited AI practices (art. 5) — for example, systems that manipulate people without their noticing, that score people socially or that recognise emotions at work or in education — and the obligation for anyone using AI in their business to give their team a minimum level of training ("AI literacy", art. 4).
- Since 2 August 2025: the Regulation's governance and penalty regime (the chapter on supervisory authorities and fines) and the obligations for those who develop general-purpose AI models, such as the models behind ChatGPT or similar.
The Agencia Española de Protección de Datos (AEPD, Spain's data protection authority) itself confirmed this in a press release of 15 July 2025: it can act against a prohibited AI system if that system processes personal data, regardless of the fact that Spain had then — and still has, as at the date of this review — yet to approve its national implementing law.
What exactly changes on 2 August 2026?
For most SMEs, 2 August 2026 has a name and an article: transparency, article 50. From that date:
- If a customer talks to a chatbot, a voice assistant or any system that interacts as though it were a person, you have to tell them clearly from the start — unless it is obvious from the context. A visible sentence along the lines of "this chat uses artificial intelligence" is enough.
- If you generate images, audio, video or text with AI and publish them in a way that could be confused with real content, you have to mark them as AI-generated or AI-manipulated.
- If you use emotion recognition or biometric categorisation, you have to inform the people exposed to it, on top of complying with the RGPD (the EU's general data protection regulation).
This is the obligation that most SMEs will notice, because it does not depend on your sector: it depends on whether your business uses an AI that talks to customers or that generates content. 2 August 2026 is also, as a general rule, the date on which the rest of the Regulation that has no date of its own applies — but, as the next section explains, that general date is no longer the one that matters for the more demanding obligations.
Is it true that the timeline has been delayed? The «Digital Omnibus», explained
Yes, and it is the most important development in this article compared with any guide written before June 2026. By the end of 2025 it was clear that neither the technical standardisation bodies nor a good number of Member States were going to be ready by 2 August 2026 with the tools needed to apply the "high risk" obligations. The European Commission then proposed a simplification package, the «Digital Omnibus on AI», which the European Parliament backed on 16 June 2026 and which the Council of the European Union definitively approved on 29 June 2026.
What changes, with the official date it moves from and the date it moves to:
- The obligations for standalone "high risk" AI systems (Annex III — for example, recruitment, credit scoring, education or certain uses of biometrics) move from 2 August 2026 to 2 December 2027.
- The obligations for high-risk AI embedded in regulated products (Annex I — medical devices, toys, machinery) move from 2 August 2026 to 2 August 2028.
- The deadline for each country to set up its regulatory "sandboxes" (controlled spaces for testing AI systems under supervision) is put back to 2 August 2027, with priority access for SMEs.
- A new prohibited practice is added, which was not included before: using AI to generate non-consensual sexual content of real people (for example, fake nudes) or child sexual abuse material. This new prohibition joins the timeline in December 2026.
What does not change with this package, according to the documentation available up to the date of this review: the prohibitions in art. 5 (since February 2025), the AI literacy obligation (art. 4, since February 2025), the governance regime (since August 2025) and, above all, the transparency obligation in art. 50 still has 2 August 2026 as its reference date for what affects an SME most: warning people that they are talking to an AI.
⚠️ An honest note: as at the date of this review (16 July 2026), the Council has already given its final approval, but the reformed text of the Regulation has not yet been published in the Official Journal of the European Union; publication is expected before 2 August 2026, and the text enters into force three days after it is published. Until that happens, these dates are the ones set out in the Council's official press releases, not yet in the consolidated legal text. If you take an important decision on the basis of this timeline, confirm it with your gestoría (the Spanish firm that handles your administrative and tax filings) or with a legal professional before August 2026.
Who supervises this in Spain: the AEPD, AESIA or both?
Spain was the first country in the European Union to create a national agency designed for this: the Agencia Española de Supervisión de Inteligencia Artificial (AESIA), Spain's AI supervision agency, based in A Coruña, whose statute was approved by Real Decreto 729/2023, de 22 de agosto (BOE-A-2023-18911) — even before the AI Act existed as a final rule.
Even so, having the agency created is not the same as having it formally designated as the AI Act authority: that requires a national law allocating the powers. That law, the Proyecto de Ley Orgánica para el buen uso y la gobernanza de la inteligencia artificial (the bill on the good use and governance of artificial intelligence), was approved by the Government and sent to the Congreso (Spain's lower house) on 12 June 2026, and as at the date of this review it is still going through parliament — it is not yet a law in force. The bill provides that AESIA will be the market surveillance authority for most high-risk systems and for the transparency obligations in art. 50, and that the AEPD (together with the regional data protection authorities) will handle systems for biometrics, migration and border control.
Until that law is approved, the AEPD has already made clear in writing, in the press release cited, that it can act as the data protection authority against any AI system that processes personal data improperly, whether or not a company uses the word "AI" to describe it.
The full timeline at a glance
| Date | What applies | Source |
|---|---|---|
| 2 February 2025 | Prohibited AI practices (art. 5) and AI literacy for staff (art. 4) | Reglamento (UE) 2024/1689, art. 113 |
| 2 August 2025 | Governance, national authorities and penalty regime; obligations for general-purpose AI models | Reglamento (UE) 2024/1689, art. 113; AEPD, press release 15/07/2025 |
| 2 August 2026 | Transparency towards whoever uses your AI and for AI-generated content (art. 50); general application of the rest of the Regulation with no date of its own | Reglamento (UE) 2024/1689, art. 50 and 113 |
| 2 December 2026 | New prohibition: non-consensual sexual content / child sexual abuse material generated with AI | Council of the EU, press release 29/06/2026 |
| 2 August 2027 | Deadline for countries to set up their regulatory AI sandboxes, with priority for SMEs | Council of the EU, press release 29/06/2026 |
| 2 December 2027 | Obligations for standalone high-risk systems (Annex III) | Council of the EU, press release 29/06/2026 (date postponed from 2/08/2026) |
| 2 August 2028 | Obligations for high-risk systems embedded in regulated products (Annex I) | Council of the EU, press release 29/06/2026 (date postponed from 2/08/2026) |
What does your SME have to do before August 2026? (15 minutes)
You do not need a big project. For most businesses, this covers the essentials:
- Make a list of your AI systems. Website chatbot, AI in your email, image generator, spellchecker or machine translator, any program with AI that you use for your team or your customers.
- Mark which of them talks or writes to your customers. That is the one that needs the transparency notice in art. 50 before 2 August 2026.
- Add a visible sentence in that channel: "This chat uses artificial intelligence" (or equivalent) is enough in most cases.
- Check whether any of your systems screens CVs, assesses your team or decides automatically about a person. If so, a sentence will not solve it: tell your gestoría, because it falls into the high-risk category (Annex III) and, even though its deadline has moved to December 2027, it is worth having it identified now.
- Keep a written record of which AI you use, since when and what for: it is the minimum any authority will ask you for if it comes knocking, and it is also the basis of the AI literacy obligation in art. 4, already in force.
What happens if you don't comply?
The AI Act's penalty regime (art. 99) has three tiers, depending on the seriousness of the breach: up to 35 million euros or 7% of annual worldwide turnover for the prohibited practices in art. 5 (the highest tier); up to 15 million euros or 3% of turnover for the other obligations of whoever uses or deploys AI, including the transparency obligation in art. 50; and up to 7.5 million euros or 1% of turnover for giving false or misleading information to an authority. In each case the higher of the two figures applies — with one important exception for SMEs and startups: for them, the law reverses the rule and applies the lower figure, not the higher one, precisely so as not to jeopardise the viability of small businesses.
In practice, those amounts are the legal ceiling, not the norm: the authority grades the penalty according to the seriousness, the size of the business and whether you have cooperated. A small business that has its AI systems identified, has put up the transparency notice and has given its team a minimum level of training is not in the scenario of the maximum figures. That is why it is worth sorting out now: not to avoid one particular scare, but to stop thinking about it.
Frequently asked questions
Do I have to do anything if I only use ChatGPT to draft internal texts?
If it is internal use, with no customer talking directly to the AI or receiving AI-generated content presented as though it were human, art. 50 does not require you to warn anyone outside your business. The obligation to give minimum training to whoever uses it (art. 4) does still apply to you, in force since February 2025.
Does the Digital Omnibus delay mean I no longer have to do anything in 2026?
No. The delay affects the high-risk systems in Annex III (recruitment, credit scoring and the like), which move to December 2027. The obligation to warn people when a customer talks to your AI (art. 50) still has 2 August 2026 as its reference date.
Does an SME need an AI officer, like the data protection officer under the RGPD?
The AI Act does not require a figure equivalent to the data protection officer for SMEs. What it does require is that whoever uses AI in the business has a minimum level of training (art. 4) and that there is transparency towards whoever interacts with it (art. 50).
Can the AEPD and AESIA penalise me twice for the same thing?
That should not happen: each authority acts within its own remit. The AEPD steps in when personal data is involved, as the data protection authority; the full allocation of the specific powers under the AI Act depends on the national law that, as at the date of this review, is still going through parliament.
Where can I consult the exact legal text of the AI Act?
On EUR-Lex, the European Union's official legislation journal, searching for Reglamento (UE) 2024/1689 (link under "Sources", below). It is the only source that prevails if there is any difference from this article.
Do you use a chatbot, an image generator or any AI in your business? Tranquilia automatically generates your register of AI systems and your art. 50 transparency clause, from a guided questionnaire using your own business's answers — no jargon, in a few minutes. The free tier lets you try it with up to 2 companies, with no card and no time limit: visit it at tranquilia.es. If your business is an asesoría or gestoría (the Spanish firms that handle other companies' accounting, tax and employment filings), see also the guide for asesorías and gestorías or check the prices.
Article produced by Tranquilia by GRAC SA. Published on 16 July 2026. Last reviewed: 16 July 2026. The content is based on the official sources cited below and does not constitute individual legal advice — several dates depend on a legal text (the «Digital Omnibus») which as at this date has been approved by the Council of the EU but is pending official publication: check them against the Official Journal of the European Union before taking an important decision.
Sources
- Reglamento (UE) 2024/1689 (Reglamento de IA) — EUR-Lex
- Council of the EU — «Artificial Intelligence: Council gives final green light to simplify and streamline rules» (29 June 2026)
- Council of the EU — «Council and Parliament agree to simplify and streamline rules» (7 May 2026)
- AEPD — «La AEPD recuerda que ya puede actuar ante sistemas de IA prohibidos que traten datos personales» (15 July 2025)
- BOE-A-2023-18911 — Real Decreto 729/2023, Estatuto de la Agencia Española de Supervisión de Inteligencia Artificial (AESIA)
- Gobierno de España (digital.gob.es) — Approval of the Proyecto de Ley Orgánica para el buen uso y la gobernanza de la inteligencia artificial (May 2026)
Review: Tranquilia by GRAC SA — AI-assisted drafting with verification against primary sources. Translation of the Spanish original, which prevails in case of divergence.
Get your clients GDPR-compliant in 15 minutes.
No card, no sales calls. Two companies free, for as long as you like.