NoCodeLab.ai

ResourcesEU AI Act

Most of the EU AI Act just moved to 2027.

The part that applies to you didn't.

In May 2026 the Digital Omnibus pushed the high-risk deadlines back by more than a year, and a lot of businesses read that as a reprieve. It wasn't. The obligations that catch ordinary companies, the ban list and the Article 4 duty to make your staff AI literate, have been law since February 2025. On 2 August 2026 the Act becomes fully applicable, and the day after that national authorities begin enforcing the literacy duty. This playbook is the practical route through: whether you are in scope, which tier your systems sit in, and the audit you can run this week.

BySara SimeoneFounder, NoCodeLab

The short version, if you would rather watch than read. The written playbook below goes further on the literacy duty and the audit.

What applies when · position as at 27 July 2026

The dates that actually bind you

1 Aug 2024
In force
The Act entered into force

The clock started. Nothing was immediately enforceable, but every date below is measured from here.

2 Feb 2025
In force
Prohibitions and AI literacy began to apply

The eight banned practices became unlawful, and Article 4 made AI literacy a legal duty for every provider and deployer. This deadline has already passed. Most organisations missed it quietly.

2 Aug 2025
In force
General-purpose AI rules and national enforcement machinery

Obligations for GPAI model providers took effect. Member states had to designate their competent authorities and put penalty regimes in place.

2 Aug 2026
Next
The Act becomes fully applicable

Transparency obligations under Article 50 apply, covering chatbot disclosure and synthetic content labelling. On the literacy duty the AI Office is precise: enforcement by national market surveillance authorities starts the following day, 3 August 2026. That is the point at which Article 4, in force since February 2025, finally gains an enforcer.

Dec 2026
Deferred
The ninth prohibition

The prohibition covering nudification tools takes effect, later than the original eight.

2 Dec 2027
Deferred
Stand-alone high-risk systems (Annex III)

Deferred from 2 August 2026 by the Digital Omnibus agreement of 7 May 2026. This covers CV screening, credit scoring and similar systems, and it is the delay everyone heard about.

2 Aug 2028
Deferred
High-risk systems embedded in regulated products (Annex I)

Also deferred by the Omnibus, to line up with the product safety regimes these systems already sit inside.

The reason the delay matters less than it sounds: the deferral bought time for the heavy engineering obligations on high-risk systems. It bought no time at all on the two things every business has, which are staff using AI and customers who must be told when they are talking to a machine.

Are you even in scope?

Two questions decide it. Is the software actually an AI system in the legal sense, and does your activity touch the EU?

What counts as an AI system

Article 3 defines it as a machine-based system that operates with some autonomy, may adapt after deployment, and infers from its input how to generate outputs such as predictions, content, recommendations or decisions that influence real or virtual environments. The load-bearing word is infers. If the software works it out, you are probably in scope.

What does not count

Recital 12 carves out systems that simply execute rules written by people. Your if-then automation, your Zapier chains, your spreadsheet macros and your rules-based workflow engine are advanced automation, not AI, however clever they are. Plenty of businesses assume they are regulated when they are not, and the distinction is worth establishing before you spend anything.

The territorial reach

This is the one that surprises people outside the EU. The Act follows the output, not the office. It applies to providers placing systems on the EU market wherever they are established, and to providers and deployers based outside the EU where the output of the system is used within it. A London firm screening candidates in Dublin is inside the perimeter.

There is no small-business exemption

Size changes the proportionality of what is expected and the ceiling on fines, but it does not switch the obligations off. What the Act does offer SMEs is priority access to the regulatory sandboxes each member state must run, which give you a supervised environment and a degree of legal certainty before you go to market.

Provider or deployer

Your obligations follow your role in the value chain, and the role is decided per system rather than per company. Most SMEs are deployers of everything and providers of nothing, until the day they ship something.

Provider · the creator

You develop an AI system, or have one developed, and place it on the market or put it into service under your own name or trademark.

  • Run a continuous risk management process across the system's life
  • Govern your training, validation and test data for quality and representativeness
  • Keep technical documentation and automatic event logs
  • Design in human oversight so a person can intervene or stop the system
  • Build for robustness and against data poisoning and adversarial attack
Deployer · the user

You use an AI system under your own authority in a professional capacity. A firm using an AI contract review tool is a deployer. This is most businesses, most of the time.

  • Use the system strictly in line with the provider's instructions for use
  • Ensure AI literacy among staff and anyone operating it for you (Article 4)
  • Monitor operation for emerging risk and retain the logs you are given
  • Inform workers and their representatives before deploying high-risk AI in the workplace
  • Meet the transparency duties where the system talks to people or makes content

The line moves under you. Put your own brand on someone else's model, or substantially modify a high-risk system, and you become the provider of it with the full obligations attached. Non-EU providers have one more duty: appoint an authorised representative established in the Union before offering the system, because that person is who the authorities will contact. The other roles the Act names, importer, distributor and product manufacturer, sit in the same chain with lighter duties.

The four risk tiers

The Act does not ban AI. It sorts it into four tiers and scales the rules to the harm. Sort every system you touch into one of these, because the tier sets everything that follows.

Unacceptable risk

Banned outright

Examples: Social scoring, untargeted scraping of facial images, emotion inference in workplaces and schools, and systems using subliminal or manipulative techniques to distort behaviour and cause harm.

What you owe: Stop. These have been unlawful since February 2025 and carry the heaviest penalty tier in the Act.

High risk

Heavily regulated

Examples: CV screening and recruitment, credit scoring for essential services, emergency healthcare triage, critical infrastructure, and AI as a safety component in a regulated product.

What you owe: The full provider stack of risk management, data governance, documentation, logging, human oversight and robustness. Deployers owe rigorous oversight by competent, authorised people. Deferred to December 2027, but the systems are in use today.

Limited risk

Transparency duties

Examples: Customer-facing chatbots, AI-generated images, audio and video, and synthetic content that could be mistaken for real.

What you owe: Disclosure. Tell people they are dealing with AI, and label synthetic content so it is detectable. This lands on 2 August 2026, and it is the obligation most consumer-facing SMEs will feel first.

Minimal risk

Largely unregulated

Examples: Spam filters, recommendation engines in games, inventory forecasting, and the long tail of everyday business AI.

What you owe: No specific obligations beyond Article 4 literacy, which follows your staff into every tier including this one.

Worth reading twice: literacy is the only duty that spans all four tiers. Every other obligation switches on at a threshold. That is why an organisation whose entire AI footprint is minimal risk still has something to do.

Article 4, the AI literacy duty

One sentence of legislation, and the only obligation that reaches every organisation using AI regardless of tier or size.

Providers and deployers of AI systems shall take measures to ensure, to their best extent, a sufficient level of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf.

Three phrases carry the weight. Best extent makes this an effort standard, which means what you did and can show matters more than any outcome. Sufficient level is deliberately undefined, and it is judged against your context rather than a syllabus. On their behalf stretches the duty past your payroll to contractors, agencies and anyone operating AI for you.

Recital 20 frames literacy as more than a compliance chore: it exists to improve working conditions and to build the competence that makes trustworthy AI sustainable. That framing is useful when you are trying to get a budget approved, because the same work that satisfies the regulator is the work that makes AI adoption stick. At NoCodeLab we have spent three years training leaders on exactly this, and the pattern is consistent: the organisations that treat literacy as capability rather than paperwork are the ones whose AI projects survive first contact with real work.

One thing to watch. The Digital Omnibus proposals include softening Article 4 so that providers and deployers would support the development of AI literacy rather than ensure a sufficient level of it. If that lands, the duty gets gentler in wording. It does not disappear, and the evidence you build now still serves.

What sufficient actually means

The AI Office declines to publish a curriculum and instead sets out the variables sufficiency is measured against. These four are the ones to document.

General understanding

Do your people know what AI is, roughly how it works, and where it goes wrong? This is the baseline everyone needs, including the staff who only ever touch a chatbot.

Your organisational role

Building the system and using someone else's demand different depths. A provider's team needs to understand development logic. A deployer's team needs to understand how the thing was built well enough to spot bias and apply it safely.

The risk of the system in hand

Literacy scales with what the system can do to someone. A person operating a recruitment screen needs to know its failure modes and mitigations in a way a person using a spam filter does not.

The background of the person

Existing technical knowledge, experience and education all count. The same training delivered to a data scientist and a receptionist is over-specified for one and useless to the other, and neither result is sufficiency.

Why the annual compliance module fails this test

Does not meet it
  • One curriculum issued to everyone regardless of role
  • Static content bought once and left alone
  • Pointing staff at the vendor's instructions for use, which the AI Office has explicitly called insufficient
  • Completion rates with nothing recorded about which systems were covered
Meets it
  • Segmented by role, and tied to the systems that role actually touches
  • Refreshed as the tools change, because the technology moves faster than any annual cycle
  • Names the concrete risks: hallucination, data leakage through prompts, automation bias, discriminatory output
  • Recorded and mapped to your risk register, so the effort is evidenced

A practical way to segment: the C-suite needs strategic risk and the human-centric principles behind the Act, frontline operators need technical use, bias detection and output interpretation, and staff affected by AI decisions need to understand their rights and how those decisions are reached. If you want to see what other organisations are actually doing, the AI Office maintains a living repository of AI literacy practices with over forty worked examples, though copying one grants you no presumption of compliance.

The compliance loop

Four moves, repeated. This is the operating loop we run with clients, and it converts an open-ended legal duty into something with a start and a finish.

  1. 1

    Map

    Inventory every AI system in the business, including the ones nobody registered. Marketing has generative AI in the content workflow, HR may have screening in the applicant tracking system, operations has forecasting and assistants. Shadow AI is the norm, not the exception, and you cannot assess what you have not found.

  2. 2

    Assess

    For each system, record two things: your role for it, provider or deployer, and its risk tier. Most entries will read deployer and minimal risk, which is fine. The point is that the handful that read high risk are now visible rather than assumed away.

  3. 3

    Tailor

    Set the literacy depth from the assessment rather than from a catalogue. Limited-risk systems need transparency awareness. High-risk systems need operators who can critically evaluate an output and have the authority to override it, which is a training question and an org-design question at once.

  4. 4

    Record

    Keep a structured internal record of what you trained, for whom, on which systems, and when. Strictly speaking this is optional: the AI Office says organisations can keep such a record, and mandates no certificate, no AI Officer and no particular format. But under a best-efforts standard the record is what turns effort into evidence, and an authority asking what measures you took needs an answer that is not a memory.

Free template

The AI Literacy Register

An Excel template for exactly this step: AI system inventory, who uses what, a training log and a review calendar that works out its own due dates. Free, no sign-up, and nothing you type into it reaches us.

Get the template →

The one-afternoon audit

If you do nothing else before 2 August, do this. It is an afternoon, and it moves you from unknown exposure to a documented position.

  1. 1

    List every AI tool in the business

    Ask each team what they use, then check the expense reports and the browser extensions for what they did not mention. Aim for the real list rather than the approved one.

  2. 2

    Strike out what is not AI

    Apply the Recital 12 test. Anything executing rules a person wrote, with no inference, comes off the list. This is often a third of it, and removing it sharpens everything downstream.

  3. 3

    Mark your role and tier for what remains

    Two columns, provider or deployer, and one of the four tiers. Where you cannot tell whether something is high risk, flag it for advice rather than guessing downward.

  4. 4

    Check the ban list first

    Emotion inference in the workplace and social scoring are the two that appear in ordinary businesses without anyone recognising them. These are already unlawful and carry the top penalty tier, so they are the only genuine emergency on the list.

  5. 5

    Fix your disclosures before 2 August

    Every customer-facing chatbot says it is an AI. Every piece of synthetic image, audio or video that could pass for real is labelled. Published AI-generated text on matters of public interest is disclosed unless a person has editorially reviewed it and taken responsibility, which is the exception most content teams will rely on.

  6. 6

    Run one literacy session and write it down

    Even a single well-targeted session, recorded with date, attendees, systems covered and risks discussed, moves you from nothing to demonstrable effort. That distinction is the whole of Article 4. Then put a refresh in the calendar, because a one-off in July 2026 will not look like best effort in July 2027.

A note on what this is. This playbook is a practitioner's guide written to help you get organised, and it is not legal advice. The Act is being actively amended, as the Omnibus shows, and the position here reflects 27 July 2026. Check the Commission's own timeline before you rely on any date here, and see the sources below for the primary texts. For a system you believe is high risk, or a question of liability, take advice that is specific to your circumstances and your member state.

Official sources

Go to the source. This playbook is a route through the Act, not a substitute for it, and the Commission's own pages are the only thing that stays current as the Omnibus keeps moving.

  • Regulation (EU) 2024/1689 itself. Article 4 is the literacy duty, Article 50 the transparency rules, Annex III the high-risk list, Article 99 the penalties.

  • The authoritative source for what applies when. This is where the Omnibus changes to the high-risk dates are reflected, and it is the page to re-check before you rely on any timeline, including the one above.

  • The official answer on what sufficient means, and the source for there being no mandated certificate and no required AI Officer.

  • Over forty real training and awareness practices from businesses and the public sector. Useful for shaping your own, though the Commission is explicit that copying one grants no presumption of compliance.

  • The Commission's own help desk and resource library for businesses working out their obligations.

  • The AI Pact

    Official EU

    The voluntary pledge covering an AI governance strategy, mapping your high-risk systems, and promoting staff literacy.

  • An interactive walkthrough of your role and risk tier. Genuinely useful, but published by the Future of Life Institute rather than the EU, so treat it as a guide and not as a determination.

Questions we hear

Does the EU AI Act apply to my small business?

Almost certainly, if you use AI at all and you touch the EU market. The Act has no small-business exemption. It applies to providers and deployers of AI systems, and a deployer is simply an organisation using an AI system in a professional capacity. A five-person firm running CV screening software is a deployer with real obligations. What changes with size is the intensity of what you have to do, not whether the rules reach you.

Does the EU AI Act apply to UK businesses?

It can, and this catches people out. The Act reaches beyond EU borders: it applies to providers placing AI systems on the EU market regardless of where they are established, and to providers and deployers outside the EU where the output produced by the system is used inside the EU. A UK agency running an AI screening tool over applicants in Ireland is in scope. UK-only operations with no EU customers, staff or outputs are not, though the direction of travel in UK regulation is similar.

Has the EU AI Act been delayed?

Partly, and the part that was delayed is not the part most businesses need to worry about. Under the Digital Omnibus agreement of 7 May 2026, obligations for stand-alone high-risk systems listed in Annex III moved to 2 December 2027, and high-risk systems embedded in regulated products moved to 2 August 2028. Nothing else moved. The prohibitions and the Article 4 AI literacy duty have applied since 2 February 2025, and 2 August 2026 remains the date the Act becomes fully applicable.

What is Article 4 of the EU AI Act?

Article 4 is the AI literacy obligation. It requires providers and deployers to take measures to ensure, to their best extent, a sufficient level of AI literacy among their staff and anyone else operating AI systems on their behalf. It is the shortest obligation in the Act and the widest: it applies whatever your risk tier, whatever your size, and it has been in force since 2 February 2025. Most organisations already met the deadline without knowing the duty existed.

What counts as a sufficient level of AI literacy?

The Act does not define a syllabus, which is the difficulty. The EU AI Office frames sufficiency as contextual: it depends on the technical knowledge and background of the people involved, the risk level of the systems they touch, and whether you are building the AI or only using it. In practice, sufficient means each person can explain what the system does, recognise where it fails, interpret its output, and knows when to escalate. A generic hour of AI awareness delivered to everyone does not meet that test.

Do I need an AI literacy certificate or an appointed AI Officer?

No. The EU AI Office is explicit that there is no mandated certification, no required AI Officer and no prescribed governance structure for Article 4. A training register is not legally required either: the AI Office says organisations can keep an internal record of trainings, not that they must, and Article 4 imposes no documentation duty at all. That is worth knowing, because the Act is prescriptive about record-keeping elsewhere and deliberately silent here. What makes a record worth keeping anyway is that Article 4 is a best-efforts standard, and best efforts is something you did rather than a state you are in. When an authority asks what measures you took, a record of what was delivered, to whom, on which systems and when is the only practical way to answer. The register is not the obligation, it is the evidence of it. Buying a certificate proves nothing on its own.

Am I a provider or a deployer under the EU AI Act?

You are a provider if you develop an AI system, or have one developed, and place it on the market or into service under your own name or trademark. You are a deployer if you use an AI system under your authority in a professional capacity. Most small businesses are deployers, but the line moves: if you white-label someone else's model and sell it as your product, or substantially modify a high-risk system, you can become a provider and inherit the heavier obligations. The test is per system, not per company, so you can be both at once.

Does using ChatGPT at work put me in scope of the EU AI Act?

Yes, as a deployer, though the burden is light. A general-purpose assistant used for copywriting or translation is not high-risk, so you are not facing the Article 9 to 17 machinery. What does apply is Article 4 literacy, and it applies specifically: staff must be informed about the risks of the system they are actually using, which for generative AI means hallucination, data leakage into prompts, and confident output that is wrong. Telling people to read the vendor's usage instructions is explicitly flagged as insufficient.

What are the penalties for breaching the EU AI Act?

The headline tiers are up to 35 million euro or 7 percent of global annual turnover for prohibited practices, and up to 15 million euro or 3 percent for most other breaches, whichever is higher. For SMEs the lower of the two figures applies. Article 4 sits differently: penalties for the literacy duty are set by each member state under Article 99(1) rather than fixed at EU level, so the exposure depends on where you operate. The practical risk for most businesses is not a headline fine but being unable to evidence anything when an authority, an enterprise client, or an insurer asks.

Three doors. Pick the one that fits where you are.

Ready to put this to work? Pick where you start.

Lab Live

A free masterclass every first Thursday at 12:30pm UK. Sixty minutes. Sara demos one thing she has built that month, walks through how it works, and answers questions. No slides. No selling.

Register, free

The Soloist

8 sessions, built entirely around your role and your tools. By session three you will be saving a day a week. By session eight you have built one working system and know how to build the next.

Explore The Soloist

The Studio

6 months, your whole team. We turn what your business knows into AI powered IP your competitors cannot replicate.

Explore The Studio
Book a free strategy call

30 minutes. No pitch. We will tell you honestly which door is right, or if the answer is none of them yet.