The EU AI Act since August 2026: what a small software vendor actually has to do
The big high-risk deadline moved to December 2027 three weeks before it was due. What did start on 2 August 2026 is smaller and reaches far more products: telling people when they are talking to AI and marking what it generates. A plain guide for vendors outside the EU.

For two years, 2 August 2026 was the date in every EU AI Act slide deck. It was the day the rules for high-risk AI were due to start, and the day most of the law became enforceable. Then, in July, the EU moved the hardest part. An amending regulation, published on 24 July 2026 and in force three days later, pushed the high-risk rules back to December 2027 (Regulation (EU) 2026/1744).
If you run a small software company, it would be easy to read that headline and close the tab. Don't, at least not yet. One part of the law did start on schedule, and it's the part most likely to touch an ordinary product: a support chatbot, a "draft this for me" button, an image generator. This is a guide to what applies now, written for a vendor of five or fifty people who sells into Europe from somewhere else.
First: does it reach you at all?
The Act doesn't care where your company is registered. Article 2 applies it to anyone who places an AI system on the EU market "irrespective of whether those providers are established or located within the Union or in a third country", and to providers and deployers outside the EU "where the output produced by the AI system is used in the Union" (Regulation (EU) 2024/1689). Free products count the same as paid ones.
So the working test is simple. Do you have customers in the EU, or do you go after them: prices in euros, a German or French version, EU case studies on the site? Then you're in scope. One stray sign-up from Lisbon is a different matter. The Commission's guidelines say that incidental, unforeseeable or unauthorised use in the EU shouldn't on its own pull a company in (National Law Review summary). If Europe is a market you want, though, plan as if the law applies.
Second: which hat are you wearing?
Nearly every duty in the Act hangs on one of two roles, and a small company can easily hold both.
Provider. You develop an AI system, or have one developed, and offer it under your own name. This is where many small vendors are surprised: calling someone else's model through an API doesn't make that model's maker the provider of your product. They provide the model. You provide the system built on it. If your app has a chat assistant with your logo on it, you are its provider.
Deployer. You use an AI system in the course of your business. If you put a vendor's support bot on your website, the vendor is the provider and you are the deployer. If you use an image tool to make your marketing visuals, you're a deployer of that too.
What has applied since 2 August 2026
Article 50, the transparency article. It has four duties. The Commission published final guidelines on them on 20 July 2026, and there is a voluntary code of practice for the marking and labelling parts (guidelines, code of practice).
1. Tell people they're talking to a machine (providers)
If your system interacts directly with people, they have to be told it's AI, clearly, and no later than the first interaction. That covers chat widgets, voice agents and AI that writes to people on your behalf. There is an exception where it's "obvious" to a reasonably well-informed person, but the guidelines read it narrowly. A coding assistant inside a developer's editor is obvious. A help-desk bot named Sophie with a friendly photo is not.
In practice this is a line of text. "You're chatting with our AI assistant. Ask for a person at any time." Put it in the widget before the first reply, not in the terms of service. For a voice agent, say it in the greeting. And if your product is a bot that other businesses put in front of their customers, build the notice in so they can't forget it: the duty sits with you as the provider.
2. Mark what your product generates (providers)
If your system generates synthetic text, images, audio or video, the output has to be "marked in a machine-readable format and detectable as artificially generated or manipulated". This is about a signal software can read, such as signed metadata or an invisible watermark. It isn't about a visible badge.
Two things soften this for a small vendor. Tools that only help with standard editing, or that don't substantially change what the user put in, are outside it: a grammar fixer or a crop tool is not a content generator. And products that were already on the market before 2 August 2026 have until 2 December 2026 to comply; anything launched after that date has to comply from day one (AI Act Service Desk FAQ).
Be aware that the bar is still moving. Paul, Weiss notes in its reading of the guidelines that the Commission hasn't found any single marking technique that meets the Act's standard today, and expects techniques to be layered (Paul, Weiss). If you build on a large model, most of the marking will come from your supplier. Your job is to ask them, in writing, what marking their output carries, and then to check that your own pipeline doesn't remove it. An image step that resizes and re-saves every file will often strip the metadata on the way through.
3. Label deepfakes and unreviewed public-interest text (deployers)
If you publish AI-made or AI-altered images, audio or video that look like real people, places or events, you have to say so. The same goes for AI-written text published to inform the public on matters of public interest, unless a person has reviewed it and someone holds editorial responsibility for it. For most company blogs that are read and signed off by a human, the text rule won't bite. A realistic AI-generated "customer" in an advert is another story.
4. Say so if you read emotions or sort people by biometrics (deployers)
Few small products do this. If yours analyses a caller's tone to score their mood, or a camera feed to categorise people, the people exposed to it have to be told.
What has applied since 2025, and is easy to miss
The banned practices. Since 2 February 2025 a short list of uses is prohibited outright: manipulative techniques that cause harm, social scoring, emotion recognition at work and in schools, scraping faces to build recognition databases, and a few more. From 2 December 2026 the list also covers systems that generate non-consensual intimate images or child sexual abuse material, the so-called nudify apps (European Commission). If you offer open image generation, your safeguards need to be in place before that date.
AI literacy. Also since February 2025, every provider and deployer has a duty towards the staff who work with AI. The July amendment softened the wording: you now have to take measures to support the AI literacy of your staff, where the original text asked you to ensure a sufficient level of it. For a small team, a short written note on which tools you use, what they must not be given (customer data, secrets) and who checks the output, plus an hour walking new people through it, is a reasonable measure. Write down that you did it.
Rules for model makers. The duties for general-purpose AI models have applied since 2 August 2025. They fall on the companies that make the models. If you call a model through an API, they're your supplier's problem.
What moved, and who should still care
The heavy part of the Act is the high-risk regime: risk management, technical documentation, logging, human oversight, a conformity assessment, registration in an EU database. It applies to AI used in the areas listed in Annex III, which include hiring and managing workers, access to education, credit scoring, life and health insurance pricing, biometrics, critical infrastructure and law enforcement. Those rules now start on 2 December 2027. For AI built into regulated products such as medical devices, lifts or toys, the date is 2 August 2028.
If your product screens CVs, ranks job applicants, scores exam answers or decides who gets a loan, you are very likely high-risk, and fourteen months is not long for what's being asked. A non-EU provider of a high-risk system also has to appoint an authorised representative inside the EU before selling there. For a product that only falls under the transparency rules, that requirement doesn't apply.
Everyone else can stop worrying about that chapter. Most business software with an AI feature, from a support bot to a meeting summariser to a writing assistant, was never going to be high-risk.
Fines, and who hands them out
Breaking the transparency rules can cost up to 15 million euros or 3% of worldwide annual turnover, whichever is higher. For small and medium-sized companies, including startups, the Act flips that to whichever is lower, and the July amendment extended the same treatment to slightly larger "small mid-cap" companies. Enforcement sits with a market surveillance authority in each of the 27 member states, not with Brussels.
Realistically, a regulator's letter is not how a ten-person vendor will first meet this law. A customer's procurement form is. Expect European buyers to ask how the product discloses AI, what marking its output carries and where the AI Act puts it. Having a one-page answer ready closes deals faster than arguing that you're too small to matter.
An afternoon's work for a small vendor
List every place AI touches a person. Chat, voice, generated emails, generated images, summaries. For each one, write down whether you are the provider or the deployer.
Add the notice. One plain sentence at the first interaction, in the widget or the greeting. If you resell a bot, make the notice part of the product and on by default.
Ask your model supplier about marking. Get the answer in writing. Then send a generated file through your own pipeline and check the mark is still there at the other end.
Put 2 December 2026 in the calendar. It's the end of the grace period for marking in products launched before August, and the start of the new prohibition.
Check yourself against Annex III. If anything you sell touches hiring, education, credit or the other listed areas, talk to a lawyer now. December 2027 will come quickly.
Write the AI note for your team and keep a record that people have read it.
Write the one-page answer for customers: what your product does with AI, which model it uses, how people are told, and which parts of the Act you've concluded apply.
This is our reading of public material, and it is not legal advice. The Act is long, the guidance is new and national authorities haven't shown yet how they'll apply it. For anything near the high-risk list, pay for an hour with someone who does this for a living.
Two related pieces: if your product was built quickly with AI tools, check these six things before customers log in. And if the AI in question is a support bot, the disclosure line is the easy part. The harder question is whether the bot pays for itself once escalations and repeat contacts are counted, which is what happened to the companies in Klarna, Duolingo and the AI-first memo. We built a small calculator for that.
Running a support bot, or about to? See what a resolved ticket really costs.
Open the calculatorSources
Regulation (EU) 2024/1689, the AI Act (Articles 2, 3, 4, 5, 6, 22, 50, 99 and Annex III); Regulation (EU) 2026/1744, the amending "Digital Omnibus on AI" (Official Journal, 24 July 2026); European Commission, AI Act: application timeline; European Commission, Guidelines on transparency obligations for providers and deployers of certain AI systems; European Commission, Code of Practice on Transparency of AI-generated Content; AI Act Service Desk, frequently asked questions; Paul, Weiss, EU finalises transparency rules for AI-generated content (2026); National Law Review, EU AI Act: final guidelines on transparency obligations under Article 50 (2026).