This week you will be offered several things the regulation does not ask for. That is not an accusation against the sellers, it is the usual soundtrack of a deadline. Which makes the opposite direction more useful than another list of duties: what you can cross off.
Every point below has an article behind it. If someone tells you otherwise, ask for the source.
An AI Act certification you can buy
There is none. For deployers, meaning anyone using AI inside their own business, the regulation provides for no certification at all.
What does exist is the Article 43 conformity assessment for high-risk systems. That is a procedure the provider goes through, in some cases with a notified body, and it concerns the product, not the company using it. A badge you acquire for your own business and hang on the wall does not appear in the regulation.
Anyone selling you one is selling a piece of paper with no legal basis. That is not illegal, it is simply worthless.
A fine for not training your staff
Art. 99(4) lists exhaustively which breaches carry up to 15 million euros or 3 per cent of worldwide annual turnover: the provider obligations of Art. 16, those of authorised representatives, importers and distributors, the deployer obligations of Art. 26, the requirements for notified bodies, and the transparency duties of Art. 50.
Article 4, AI literacy, is not on that list. It was not before the Omnibus either.
That does not make Article 4 harmless, and it is not an argument for doing nothing. It means the 15 million figure in a training pitch is a misquotation. Where the risk actually sits, which is Art. 26(2) and the competence, training and authority it requires of whoever exercises oversight, we have written up separately.
High-risk obligations that probably do not reach you
Annex III lists eight areas, and the list is exhaustive: biometrics, critical infrastructure, education, employment and worker management, access to essential services including creditworthiness, law enforcement, migration and border control, and administration of justice and democratic processes.
Internal document search is not there. Meeting summaries are not there. Draft text, translation and code completion are not there.
If you run nothing from those eight areas, December 2027 is simply not your date. And if you run something close to the line, read the filter in Art. 6(3), with one hard limit: an Annex III system that profiles natural persons is always high-risk, with no exception available.
The GPAI obligations, because you use ChatGPT
The Chapter V obligations fall on providers of general-purpose models, meaning the houses that develop the models and place them on the market.
Anyone using such a model inside their own business is a deployer. You carry the deployer obligations, and for the ordinary case they are manageable. The documentation and transparency duties for the model itself are not yours.
One practical effect: running an open model on your own hardware does not shift those obligations onto you, they stay with the original developer of the model.
A shutdown date
There is no obligation in the regulation requiring you to switch a system off on 2 August. What arrives are the notice and labelling duties of Art. 50: a chatbot must make clear that the person is talking to a machine, and generated images or video with external effect must be disclosed as artificial.
That is work on the surface, not on the operation.
What is left, and it is little
Three things, for most companies:
An inventory of the AI systems in use in the building, your own and bought in. A spreadsheet and one meeting will do.
Documented basic training for the people working with them. Article 4 asks for measures, not guaranteed outcomes; what counts is being able to show what you did.
From 2 August, the Article 50 notices wherever you talk to customers or publish generated content.
Which of these applies to you is settled by our checklist in six questions, with article, deadline and what you would have to show. If you would rather start by knowing which category a specific system falls into, the decision tree gets there in five steps.
The sentence that is wrong in most places this week
To finish, the point where even the articles presenting themselves as the calm version get it wrong: supervision and penalties do not begin on 2 August 2026. Chapter VII with the national authorities and Chapter XII with the fines have applied since 2 August 2025, and the Omnibus did not touch Art. 113(3)(b). The one exception is Art. 101, the Commission fines for GPAI providers, and those do begin now.
Moving the date by twelve months turns a state of affairs into an event. That is exactly where this week's urgency comes from.
Frequently asked questions
Do I need an AI Act certification?
No. For deployers the regulation provides for no certification at all. What exists is the Article 43 conformity assessment for high-risk systems, which is a provider procedure and not a badge you buy.
Can I be fined 15 million for not training staff?
No. Art. 99(4) lists exhaustively, from (a) to (g), which breaches carry up to 15 million or 3 per cent. Article 4 is not on that list, neither before nor after the Omnibus.
Do I have to switch anything off on 2 August?
No. No obligation in the regulation requires switching a system off. What arrives are the notice and labelling duties of Article 50.
Am I responsible for GPAI obligations because I use ChatGPT?
No. The Chapter V obligations fall on the model provider. A company using someone else's model is a deployer and carries the deployer obligations.