You publish an article you wrote with help from ChatGPT. You plugged a chatbot into your sales page. Do you have to warn your readers? Stick an "AI-generated" label everywhere? Since August 2, 2026, the EU AI Act, Europe's regulation on artificial intelligence, answers those questions. Its answer often surprises people.
The AI Act sorts AI uses into four risk levels, and your obligations depend on three things: your role (do you build the system or just use it?), what the tool is for, and who gets affected by the result. Using a chat assistant to draft your copy triggers almost nothing. Screening job applications with AI triggers a lot.
Here is what it means for an employer, for an employee, for someone publishing AI-assisted content, and for a freelancer working alone. No legal background needed.
What is the AI Act?
The AI Act is Regulation (EU) 2024/1689, the first law anywhere to regulate artificial intelligence from end to end. It covers how AI systems are developed, placed on the market and used inside the European Union.
Its logic fits in one idea. The more an AI use can damage someone's health, safety or rights, the heavier the obligations climb. A spam filter and software that decides who gets fired do not sit in the same bracket, even when they run on the same technology.
Two words show up everywhere in the text. A provider builds an AI system or puts it on the market under its own name. A deployer uses an AI system under its authority, as part of its professional activity. Almost all our readers are deployers.
The four risk levels
Classification does not follow the name of the tool. It follows what you do with it. The same model can jump from one bracket to another depending on its purpose.
| Level | Principle | Example | What falls on you |
|---|---|---|---|
| Unacceptable risk | Banned practice | Social scoring, emotion recognition at work | Straight prohibition |
| High risk | Strong impact on rights or safety | CV screening, employee evaluation, credit scoring | Reinforced obligations |
| Transparency risk | Risk of deceiving a person | Chatbot, deepfake, some published texts | Inform, label |
| Minimal or no risk | No identified risk | Spam filter, AI in a video game | Nothing specific |
The European Commission states that the vast majority of AI systems used across the Union land in that last bracket. The regulation adds no new rule for them.
Does using ChatGPT, Claude or Copilot make you a regulated company?
Yes, the AI Act concerns you. No, it does not drop every obligation on your head at once. A company that gives its team access to a chat assistant acts as a deployer, not as the provider of the model.
That deployer status lifts a lot of weight. You owe no technical documentation on the model, no CE marking, no entry in the European database. Those burdens sit with whoever builds and sells the system.
One situation flips your status: if you rebrand an AI system under your own name, or if you change what it is used for, you can become a provider under the regulation. An agent resold as "your" product is no longer plain internal use.
Employers and HR: the most closely watched ground
Annex III of the regulation puts a long list of work-related uses into the high-risk bracket. Recruiting, filtering applications, deciding on a promotion or a termination, assigning tasks based on worker behaviour, monitoring performance.
None of that is banned. It does trigger heavy duties for the employer who deploys it:
- follow the instructions for use supplied by the system's vendor;
- set up human oversight handled by trained people;
- monitor how the system behaves over time;
- check that input data is relevant whenever you control it;
- inform the affected workers and their representatives before switching the system on.
These rules apply from December 2, 2027 for employment-related systems. The AI Omnibus, the simplification package that entered into force on July 27, 2026, pushed that deadline back so technical standards have time to land.
One use crosses the red line: inferring a person's emotions in the workplace. Article 5 bans it, except for medical or safety reasons. A tool claiming to measure team engagement from facial expressions or voice has no business inside a European company.
Employees: which rights exist, and which do not
The AI Act creates no general right to know that your employer uses AI. It creates one precise duty to inform, in one precise case. Before putting a high-risk system into service in the workplace, the employer must tell the affected workers and their representatives.
The regulation gives no right to refuse AI at work either. It sets guardrails instead: human oversight on high-risk systems, information for the people concerned. Other rights may come from labour law, collective agreements or the GDPR.
On training, the text is softer than the headlines suggest. Since the AI Omnibus amended it, Article 4 asks providers and deployers to take measures to build up their staff's AI literacy. No numeric skill level, no mandatory certification.
An employee who wants training can lean on that article with their HR team, tying the request to the tools the company actually uses. A course on working day to day with an AI assistant, such as our Claude Cowork course, fits that logic. An employer can also pick internal awareness sessions or coaching, since Article 4 does not choose for them.
Content creators: what to label, and what not to label
Article 50 carries the transparency obligations, applicable since August 2, 2026. It does not say every piece of content touched by AI needs a badge. It targets identified cases.
Two situations hit anyone who publishes. Images, audio and video that qualify as deepfakes (content that convincingly imitates a real person) must be flagged as artificially generated or manipulated. AI-generated text published to inform the public on matters of public interest must be flagged too.
That second duty comes with a wide exception. It does not apply when the content went through human editorial review and a natural or legal person takes editorial responsibility for it. An article you read, fix and sign falls outside the scope.
Content produced before August 2, 2026 does not have to be labelled retroactively. Generative AI systems placed on the market before that date had until December 2, 2026, and only for the marking and detection functions set out in Article 50(2).
Watch out for a common mix-up. YouTube, Meta and TikTok run their own synthetic content disclosures, quite separately from EU law. Falling outside Article 50 does not excuse you from ticking the box the platform asks for.
Chatbots and agents: say that the other side is a machine
AI systems built to talk directly with people must make that clear. The information arrives at the first interaction at the latest, in plain terms. One exception only: when the artificial nature of the counterpart is obvious from the context.
The regulation publishes no list of covered tools. Support chatbot, conversational assistant, agent answering incoming messages: function decides, not the marketing label. If you assemble your own agents with a tool like n8n, the question lands the moment the agent talks to an outside human.
AI Act and GDPR: two laws, two purposes
Both regulations often apply to the same use at the same time. They do not protect the same thing. The AI Act governs the risks created by the system. The GDPR protects people and their personal data.
| Topic | AI Act | GDPR |
|---|---|---|
| Main object | Risks tied to the AI system | Protection of personal data |
| AI in recruitment | High risk, reinforced obligations | Applies too (legal basis, information) |
| Automated decision | Depends on the system and the use | Specific rules |
| Transparency | Article 50, listed cases | Information of the people concerned |
Automated CV screening falls under both laws at once. France's data protection authority, the CNIL, publishes its own recommendations on AI and personal data, which neither replace nor duplicate the AI Act.
Fines, and how to read the numbers
The ceilings look terrifying. They target serious breaches, not a missing disclosure on one blog post.
| Breach | Maximum administrative fine |
|---|---|
| Practice banned by Article 5 | €35 million or 7% of annual worldwide turnover |
| Other obligations, including deployer duties and some transparency rules | €15 million or 3% of annual worldwide turnover |
| Incorrect or misleading information given to authorities | €7.5 million or 1% of annual worldwide turnover |
These pairs of figures do not add up. For an ordinary company, the authority keeps the higher of the two. For SMEs and start-ups, the rule flips and the lower one applies. A company with €2 million in turnover therefore does not face 7% of €2 million against a €35 million flat ceiling: it faces the smaller of the two, so €140,000.
These amounts are maximums. Severity, duration and consequences move the sum actually imposed, and each member state sets its own national penalty regime.
Dates worth remembering
- August 1, 2024: the regulation enters into force.
- February 2, 2025: banned practices become applicable, along with the first AI literacy rules.
- August 2, 2025: governance rules and obligations for providers of general-purpose models, the versatile models that sit underneath many products.
- July 27, 2026: the AI Omnibus enters into force, simplifying implementation and shifting the high-risk deadlines.
- August 2, 2026: general application of the regulation, including the Article 50 transparency obligations.
- December 2, 2027: high-risk rules in sensitive areas, including employment, education and biometrics.
- August 2, 2028: rules on high-risk AI built into regulated products, from lifts to toys.
What this changes for you in practice, even working solo
You are going to keep a list of your AI tools, even as a one-person shop. Not a twenty-page legal register: a table with the tool, what you make it do, and who is affected by the output. That list answers most of your questions, because purpose is what sets the risk level.
You stop slapping "AI-generated" on everything out of reflex, and take editorial responsibility instead. Reading it back, fixing it, checking the facts, signing your name: that move takes you outside the duty on public-interest texts. It also protects your credibility, which a badge never does.
You change your habits around the data you hand to an assistant. The AI Act says almost nothing about your prompts, but the GDPR kicks in the second you paste in a CV, a client file or a named meeting report. For sensitive work, running a model locally with Ollama keeps that data off someone else's servers.
Five moves to get compliant
- Inventory your uses. Chat assistants, image generators, automations, business software that quietly ships AI inside.
- Write down each purpose. What decision does the tool prepare, what output does it produce, in what context?
- Name the people affected. Employees, candidates, customers, readers. This is the point that tips a use into high risk.
- Check the other laws in play. GDPR, labour law, intellectual property, sector rules. The AI Act replaces none of them.
- Put your internal rules in writing. Approved tools, data banned from prompts, who reviews what before publication. One page is enough to start.
The French government's business service publishes a practical AI Act factsheet for companies, handy if you operate in France and need the administration's own wording.
Frequently asked questions
Do I have to write "AI-generated" on all my blog posts?
No. Article 50 of the AI Act targets AI-generated text published to inform the public on matters of public interest. The obligation falls away when the content went through human editorial review and a person takes editorial responsibility for it. An article you read back and sign is outside the scope. Publishing platforms may still impose their own disclosures.
Can AI screen job applications in Europe?
Yes, but Annex III of the regulation classes that use as high risk. The employer using it must set up competent human oversight, follow the system's instructions for use, monitor how it behaves and inform the workers concerned. These obligations become applicable on December 2, 2027 for employment-related systems.
Does my company have to train every employee on AI?
Article 4 of the AI Act, as amended by the AI Omnibus, asks companies to take measures to build up their staff's AI literacy. No skill level is imposed and no certification is mandatory. Training is one option among several. For high-risk systems, however, suitable training for the people in charge of human oversight is required.
What fine does a small business face for breaking the AI Act?
Ceilings run from €7.5 million or 1% of annual worldwide turnover, for misleading information given to authorities, up to €35 million or 7%, for a practice banned by Article 5. For SMEs and start-ups, the regulation says the authority keeps the lower of the flat amount and the percentage, not the higher one.
Do I have to tell a visitor they are talking to a chatbot?
Yes, when the AI system is designed to interact directly with people. The information must arrive at the first interaction at the latest, in a clear and accessible way. Article 50 sets one exception: when the artificial nature of the counterpart is obvious from the circumstances and the context.





