The EU AI Act and your AI agent: what applies in 2026
Since 2 August 2026, the EU AI Act's transparency obligations apply: if your company runs an AI agent that interacts with people, they must be told they are dealing with AI — and violations carry fines of up to €15 million or 3% of worldwide turnover. Meanwhile, the high-risk obligations many companies feared were postponed to December 2027 and beyond. Here is what actually applies to a company deploying an AI agent in Europe today, in plain language. (This is general information, not legal advice.)
The timeline, as it stands in September 2026
The AI Act is arriving in stages. Prohibited practices (social scoring, manipulative AI) and AI-literacy duties have applied since February 2025. Obligations for general-purpose AI models, plus the governance and penalty framework, followed in August 2025. On 2 August 2026 the remainder of the Act began to apply — including the Article 50 transparency rules that cover most business AI agents. One big change came with the EU's AI Omnibus simplification package, in force since July 2026: obligations for high-risk systems in sensitive areas (Annex III) were pushed to 2 December 2027, and for AI built into regulated products to August 2028. Transparency was not delayed.
Are you a provider or a deployer?
The Act assigns duties by role. A provider develops an AI system — or has one developed — and puts it on the market or into service under its own name. A deployer uses an AI system under its authority in a professional context. The nuance that matters for custom builds: a company that commissions an agent and runs it under its own brand is a deployer, and can also take on provider duties precisely because the system operates under its name. Sorting out which duties sit where belongs in the project's scoping phase, not after launch.
What Article 50 requires for customer-facing agents
Three practical duties. First, disclosure: people interacting directly with an AI system must be informed they are dealing with AI, clearly and at the latest at the first interaction — unless it is already obvious to a reasonably well-informed person. Second, marking: synthetic audio, image, video, and text output must be marked machine-readably as AI-generated, with the implementation deadline for the technical marking standard set at 2 December 2026. Third, deployer duties: disclose AI-generated or manipulated content, and inform people exposed to emotion recognition or biometric categorisation. In UX terms: a visible “AI assistant” label, a disclosure line in the first message, and a marking pipeline for generated content.
Most business agents are not high-risk — but check
High-risk classification under Annex III covers defined sensitive areas: employment and worker management, credit and essential services, education, law enforcement, and similar. An internal agent that triages invoices, drafts documents, or answers product questions is normally not high-risk; the transparency rules above are its main obligations. But an agent that screens job applicants or influences credit decisions will land in the high-risk regime, whose duties — risk management, data governance, human oversight, logging — apply from December 2027. If your roadmap points that way, it is far cheaper to build those properties in now than to retrofit them next year.
Penalties and enforcement are real now
The penalty framework has three tiers: up to €35 million or 7% of worldwide annual turnover for prohibited practices; up to €15 million or 3% for most other violations, including Article 50 transparency; and up to €7.5 million or 1% for supplying incorrect information to authorities. For SMEs and start-ups, the lower of the fixed amount and the percentage applies — a real protection, not an exemption. Enforcement is staffing up: the EU AI Office has been hiring dozens of new posts dedicated to it, alongside national supervisory authorities active since August 2026.
How to build an agent that is compliant by design
Compliance is cheap when it is an architecture decision and expensive when it is a retrofit. The pattern that works: AI disclosure designed into the interface from the first prototype; an audit trail of what the agent saw, decided, and did; human approval gates on consequential actions; an evaluation suite that documents intended behaviour and proves it holds — which doubles as compliance evidence; and GDPR discipline alongside (data minimisation, EU hosting or on-premises deployment, no training on your data). These are the same properties that make an agent safe to operate — the regulation and good engineering point the same way.
Does an internal-only agent need the AI disclosure?
Article 50's disclosure duty targets AI systems interacting with natural persons, and employees are natural persons — but the duty does not apply where AI interaction is obvious to a reasonably well-informed user, which internal tools usually make explicit anyway. Label it clearly and the question disappears; confirm specifics for your setup with counsel.
We are an SME — do the same fines apply to us?
The same tiers apply, but for SMEs and start-ups the fine is capped at the lower of the fixed amount and the turnover percentage. The practical takeaway is unchanged: the disclosure and marking duties are simple enough that no SME should ever be fined over them.
So was the AI Act delayed or not?
Partially. The AI Omnibus package moved high-risk obligations to 2 December 2027 (Annex III areas) and August 2028 (AI in regulated products). The transparency rules for chatbots, agents, and generated content were not delayed — they apply since 2 August 2026, with the synthetic-content marking standard due by 2 December 2026.