The AI Act is the most cited and at the same time worst understood European regulation of recent years. Half the Czech articles about it wave a EUR 35 million fine around, the other half claim "everything applies from August 2026" — and both are wrong. Meanwhile Brussels actually moved part of the deadlines, so even articles that were correct last year are outdated today.
This is a practical overview for an ordinary Czech company — not a bank, not a medical device manufacturer. I'm not a lawyer and this isn't legal advice; every claim links to a source so you can verify it.
For an ordinary Czech company that uses ChatGPT, Claude or AI tools in marketing and operations, two things apply today: the AI literacy obligation for employees (since 2 February 2025) and, from 2 August 2026, mandatory transparency — a chatbot must admit it's an AI, and AI-generated content must be labelled. The strict rules for "high-risk" systems mostly don't concern you, and they were postponed to 2 December 2027 and 2 August 2028 respectively. Supervision in Czechia will be led by the Czech Telecommunication Office (ČTÚ).
What the AI Act is and why the deadlines cause such confusion
The AI Act (Regulation (EU) 2024/1689) is a directly applicable European regulation — it applies in Czechia regardless of whether parliament manages to pass the accompanying national act. Obligations phase in over several waves, and that's exactly where the confusion comes from: each wave has a different date, and one of them moved in 2026.
The timeline after the changes:
| Date | What applies | Who it concerns |
|---|---|---|
| 2 Feb 2025 | Prohibited practices + AI literacy obligation (Art. 4) | every company using AI |
| 2 Aug 2025 | Rules for general-purpose AI models (GPAI) | developers of large models (OpenAI, Google…) |
| 2 Aug 2026 | Transparency (Art. 50): chatbots, AI content, deepfakes | every company with a chatbot or AI content |
| High-risk systems (Annex III: hiring, credit, education…) | companies deploying AI in sensitive areas | |
| High-risk AI embedded in products (medical, machinery) | manufacturers of regulated products |
The postponement is news from spring 2026: the European Commission proposed the Digital Omnibus package in November 2025 and the European Parliament endorsed it on 16 June 2026. The high-risk deadlines moved by 16 and 24 months respectively. Articles written before summer 2026 therefore quote deadlines that no longer hold.
Obligation no. 1: AI literacy — in force for a year and a half already
This is the one most Czech companies aren't addressing at all, even though it has applied since 2 February 2025. Article 4 of the AI Act says: whoever provides or uses AI systems must ensure a "sufficient level of AI literacy" among employees and anyone working with AI on their behalf.
What that means concretely:
- It covers ordinary ChatGPT use at work. You don't have to develop your own AI — it's enough that employees use it for company tasks.
- No mandatory certificate, no prescribed number of hours. The scope follows from how and for what the company uses AI and who works with it.
- Sending people a video link is not enough. In May 2025 the European Commission explicitly described distributing a manual or video as "ineffective and insufficient" fulfilment of the obligation.
- There is no standalone fine for breaching Art. 4 in the regulation itself. Enforcement runs through national authorities, and insufficient literacy can count as an aggravating factor in other breaches — and real enforcement starts in August 2026.
What a reasonable training should cover to hold up:
- What to put into AI and what not — personal data, trade secrets, client data.
- How to verify outputs — models make things up; whoever uses an output without checking is responsible for it.
- Where the risks are — copyright, GDPR, confidentiality, discrimination.
- Internal rules — which tools the company allows, for what, with what data.
- Evidence — a record of who was trained, when and in what. Without a record, fulfilment is hard to prove.
When someone eventually asks (a supervisory authority, a client in a tender, an insurer), what's on paper decides: the list of AI tools in use, what they may be used for, who completed training and when. A company that has this is essentially done as far as Art. 4 goes. A company that "did some training but has no record" is not.
Obligation no. 2: transparency — takes effect 2 August 2026
This is the part that is not postponed and touches a surprising number of ordinary companies. From 2 August 2026, Article 50 requires four things:
- A chatbot must admit it's an AI. Running an AI support chatbot on your site? The user must be informed they're not talking to a human — unless it's obvious.
- Synthetic content must be machine-labelled. Image, audio and video generators must mark outputs (watermark, metadata) — this is mainly an obligation for tool providers.
- Deepfakes must be visibly disclosed. Whoever publishes AI-generated content depicting real people, places or events as genuine must state that the content is artificial.
- AI text published to inform the public (news, public-information texts) must carry a notice that it was generated, unless it went through human editorial review with responsibility.
Fines for transparency breaches: up to EUR 15 million or 3% of worldwide turnover. For comparison — prohibited practices (manipulative AI, social scoring) carry the 35-million / 7% ceiling, but an ordinary company doesn't run those.
What it means in practice for a Czech website or e-shop:
- AI chatbot on the site → add a clear "I'm an AI assistant" notice at the start of the conversation.
- AI photos of products or people that look real → label as AI-generated.
- Blog articles written with AI help that went through your editing and you stand behind them → the mandatory label does not apply (exemption for content under human editorial responsibility).
What got postponed: high-risk systems
"High-risk" in the AI Act is a legal category, not a feeling. It covers AI for recruiting and evaluating job candidates, credit scoring, access to education, biometrics, critical infrastructure or law enforcement (Annex III), plus AI embedded in regulated products — medical devices, machinery, toys (Annex I).
Hard obligations apply to these systems: risk management, data governance, technical documentation, human oversight, registration. And precisely these obligations moved with the Digital Omnibus:
- standalone high-risk systems (Annex III): 2 December 2027
- AI in products (Annex I): 2 August 2028
Beware of two common misunderstandings. First: using ChatGPT to write emails is not a high-risk use. Second: if you use AI for, say, pre-screening job applicants, you can fall into the category even as a small company — and the postponement to 2027 is time to prepare, not a reason to ignore it.
Who will police it in Czechia
The main supervisory authority will be the Czech Telecommunication Office (ČTÚ) as the single point of contact, alongside the Czech National Bank for the financial sector and the Office for Personal Data Protection (ÚOOÚ) for personal data. The Czech adaptation act that distributes competences and sets national sanction procedures is still being finalised at the time of writing — but the regulation's obligations apply directly, regardless of it.
Checklist for an ordinary company
What to have done now (August 2026):
- An inventory of AI tools the company uses, and for what.
- Internal rules — allowed tools, forbidden data, output checks.
- A trained team with a record — who, when, in what (Art. 4, applies since 2/2025).
- A labelled chatbot, if one runs on your site (Art. 50, from 2 Aug 2026).
- Labelled AI visuals that pass as real (Art. 50).
- If AI touches hiring, credit or evaluating people → map whether it's a high-risk use and start preparing for 12/2027.
And what you don't have to do: pay for an "AI Act employee certification" (no mandatory one exists), panic about the 35-million fine (that's for prohibited practices, not for an untrained team), or solve medical-device-manufacturer duties if you don't manufacture any.
Summary
For an ordinary Czech company the AI Act carries two real obligations in 2026: employee AI literacy (in force since 2 Feb 2025 — you're a year and a half behind if you haven't started) and transparency for chatbots and AI content (from 2 Aug 2026). High-risk systems moved to 2 Dec 2027 and 2 Aug 2028 and mostly don't concern ordinary companies anyway. ČTÚ will supervise. The cheapest path to compliance is one proper training with documentation and an hour of work on a site with a chatbot.
I run AI training for companies and schools — from a two-hour intro to a transformation programme, always on the tools your team actually uses, with a training record that satisfies Art. 4. If you're not sure what exactly applies to your company, get in touch — we'll go through it on concrete tools, not paragraphs.
Sources and links
- Regulation (EU) 2024/1689 — the AI Act, consolidated text — EUR-Lex
- Article 4 — AI literacy and Article 50 — transparency — artificialintelligenceact.eu
- Digital Omnibus on AI — state of the legislative process — European Parliament
- EU agrees Digital Omnibus deal — White & Case on the new 2027/2028 deadlines
- ČTÚ press release on 2 August 2026 — the Czech supervisory authority
- Deepfakes, Chatbots, AI-Generated Text — Art. 50 obligations in detail — Greenberg Traurig
A practical overview, not legal advice. For borderline cases — hiring, credit, biometrics, regulated products — consult a technology lawyer.
