Back to home

Training

the ai act without panic

On what the AI Act actually asks of a small business: one afternoon of work, two calendar reminders, and no panic beyond that

There’s an AI portal chat at an installation firm whose systems I run. Customers drop their questions there. And that thing falls under the AI Act. So I went and dug up what that actually asked of me, and the whole obligation came down to one line of text at the top of the conversation. Plus some homework you clear in an afternoon. No conformity dossier, no EU registration, no pricey scan.

Right, the core of it, for a normal small business with a customer service chatbot. From 2 August 2026 the AI Act comes down to three things: show customers they’re talking to AI, make sure there’s demonstrable attention to AI knowledge in your team, and know which AI tools you’ve got in the building. That’s it. Those conformity assessments, EU registrations, thick risk dossiers? Those only hit high-risk applications. AI that screens job applicants, or handles credit applications, that kind of work. And those obligations in particular are all but certain to slide to December 2027.

Only that’s not how it sounds in your inbox. And the numbers don’t help either. Look: research by the Dutch Chamber of Commerce (KVK) found half of Dutch business owners don’t know the AI Act at all. Only 7 percent are well informed. And 2 to 3 percent are actually taking preparatory steps (KVK, 2025). That survey’s from June 2025, well over a year before the deadline. It’s the most recent hard number we’ve got, and today the picture’s hopefully a bit friendlier. But still, the gap stays striking. On one side, an audience that barely knows the law. On the other, a compliance industry selling AI scans, register subscriptions and training courses at hundreds of euros a head. As if every bakery needed a conformity dossier.

With fikst I build chatbots and AI workflows for Dutch small businesses. So I read this law as someone who’s got to comply with it himself. What’s below is practical explanation with the sources attached. Not legal advice, mind. Got a real edge case? Then take it to a lawyer once and be done.

what needs to be in place for my chatbot on 2 august 2026?

From 2 August 2026, every customer who talks to your AI system has to be able to know it’s AI. That’s the transparency duty of article 50(1). No transition period. And it applies just as much to chatbots that have been live for years (Latham & Watkins, 2026). There’s one exception: when it’s already dead obvious to a normal user that they’re talking to a machine. But you don’t want to gamble on that as a business, of course. One visible sentence at the start of the conversation, and you’re done. At that portal chat, that was literally the whole job. A little line where the assistant announces itself for a second.

And for a regular service or FAQ chatbot, that’s where it stops. Does it answer questions about opening hours, return policy or order status? Then it sits in the limited-risk category. Disclosure required, and nothing extra on top of that (research by chatbot company Gurusup, 2026). Only once a system like that starts making decisions about people on its own does it move up to the high-risk category, with the full package of obligations. Think rejecting job applicants, or assessing claims. Only then.

One nuance that dies in most summaries. That “no transition period” is specifically about paragraph 1 of article 50, the chatbot disclosure. Because there’s also a paragraph 2: the marking duty for synthetic content, the machine-readable marking of AI-generated image and audio. And that one did get a deferral through the Digital Omnibus. Generative AI systems that were already on the market before 2 August 2026 only have to comply from 2 December 2026 (Latham & Watkins, 2026).

On paper the sanctions are hefty. Break the transparency obligations and it can run up to 15 million euros or 3 percent of global annual revenue. For SMBs and startups the lower of the two applies (AI governance platform AIGN, 2026). Sounds heavy, right? But that number’s mostly handy to hold up next to how small the fix is. One line of text at the top of your chat. That small.

so is the ai act postponed or not?

Partly. And the wording’s fiddly here: the deferral’s all but certain, it’s just not formally in force yet. Let me walk the route. The European Parliament voted for the Digital Omnibus on 16 June 2026. The Council gave the final green light on 29 June 2026 (Shumaker, 2026). That package shifts the heavy obligations for high-risk AI under Annex III, think recruitment and credit scoring, from 2 August 2026 to 2 December 2027. AI in regulated products under Annex I goes to August 2028. Only, and here’s the catch: at the time of writing, 10 July 2026, that text still isn’t in the Official Journal of the EU. And until that publication plus three days, the old timeline formally stays the legal baseline (DLA Piper, 2026). Publication’s expected mid to late July. Right before the deadline, then. But an expectation isn’t law yet. And one thing stays standing here either way: the transparency duty for chatbots sits plain on 2 August 2026.

And how confusing is it? You see it at the regulator itself. On 10 July 2026 the Dutch Data Protection Authority’s page on the AI Act still said supervision of high-risk AI starts in August 2026, and that the regulation’s fully in force by August 2027. Both those dates got overtaken by the Digital Omnibus (Autoriteit Persoonsgegevens, 2026). And the European Commission? On its own page about AI literacy it puts two different enforcement start dates. On one and the same page, watch this: 2 and 3 August 2026 (European Commission, 2025). Look, if the official sources can’t keep their own story straight, you really don’t have to feel bad you lost the thread. This is the legislator wrestling with what I call the production gap elsewhere. The difference between announcing something and actually having it running in production.

the quiet obligation: ai literacy has applied since february 2025

The least known obligation is at the same time the oldest one. Article 4, the AI literacy duty, has applied since 2 February 2025. For every business that puts AI to professional use (European Commission, 2025). So also for the shop where the team’s got ChatGPT or Copilot open all day. And what’s new from August 2026? That the national regulators start actually enforcing it now. In the Netherlands that’s the AP.

And what that duty asks has changed in the meantime. In your favor, luckily. That same Digital Omnibus rewrites article 4 from an obligation of result, “ensure a sufficient level of AI literacy”, into a duty of effort: take appropriate measures to support the development of AI literacy (Stibbe, 2026). In plain words: no prescribed knowledge level, no exam, no certificate. What you do have to be able to show is effort. An overview of which AI tools your team uses. A team session on what those tools can and can’t do. And a note with the date and who was there. That’s your file. Done.

For completeness, this too. Dutch supervision of the AI Act gets split across ten market surveillance authorities. The AP’s the catch-all there for domains without their own sectoral regulator, the transparency obligations of article 50 included (Binnenlands Bestuur, 2026). But for you as a small business owner it just comes down to this: in practice the AP’s your point of contact.

what do I not have to do?

More than the average compliance mailing wants you to believe. Have a look with me. You don’t have to get a conformity assessment done, and you don’t have to register your system in an EU database. That belongs to high-risk AI, and a service chatbot doesn’t fall under it, as long as it makes no decisions about people on its own (research by chatbot company Gurusup, 2026). You don’t have to buy certified AI training. The law knows no certificates at all, and after the softening of article 4 the bar’s come down rather than up. You don’t have to subscribe to AI register software either. For a business with a handful of tools, a little list in a shared document is enough. And a written-out AI policy? That’s nowhere in the law. Though one page of A4 is the easiest way to make your effort demonstrable.

But the other side belongs here too, fair’s fair. Do you use AI in recruitment and selection, credit decisions or another Annex III application? Then that deferral to December 2027 is extra prep time, precisely. For a track that’s genuinely real work: risk management, documentation, human oversight. Start on that this year, and get help in. And do you offer a generative AI product yourself that makes image or audio? Then put that marking duty of December 2026 in your calendar.

the checklist: done in one afternoon

For the average small business with a chatbot and a few AI tools around the office, this is the whole homework. In the order I keep to myself. And the one I kept to at that portal chat too.

I always start with taking stock. 30 minutes. Just run through what AI’s running in your business: the chatbot on your site, ChatGPT or Copilot at the desks, and those AI features that quietly crept into your email or accounting software. All of it in one document. Then the high-risk check, 15 minutes. And for me that’s the step that decides everything: does one of those systems decide about people on its own? Applications, credit, claims, that sort of thing. Is the answer no? Then you’re done with the rest of this list in a flash. Is it yes, then you plan a separate track toward December 2027 and bring in expertise. Because then you really are in a different story.

The AI notice itself is the real work of this afternoon. And it still costs only 30 minutes. Have your chatbot introduce itself as an AI assistant at the start of every conversation. Got a telephone voice bot? Don’t forget that one. How you deliver that notice without customers dropping off, I wrote that out in what klarna really teaches. And do you also publish AI-generated image or audio that could pass for real? Then make it recognizable. Another 15 minutes.

That leaves the paperwork. And that’s less work than it sounds. One page of A4 AI policy, 45 minutes: which tools do you use, what for and what not, what never goes in a prompt (customer data, passwords), and who’s the point of contact. Then go sit with your team over it for 60 minutes. Talk through that A4, show where the tools go wrong, and note down date, participants and topics. That last bit’s no formality, mind. That is your article 4 effort, in black and white. And finally, 5 minutes of work, put two reminders in your calendar: December 2026 for the marking duty on existing generative systems, and late 2027 for the high-risk obligations. At those moments, just check where things actually stand. Preferably in the Official Journal itself, so not only on some regulator’s page, because those lag behind. You saw that above already.

Add it all up and you’re at around three hours of work. No scan. No certificate.

My position? For the vast majority of Dutch small businesses the AI Act is an afternoon of work and two calendar reminders. And whoever sells you a bigger package is earning off uncertainty. Uncertainty the legislator fed with its own fumbling of the timelines. So just block that afternoon this month. Then you’re ready on 2 August, and you can file the rest of those compliance mailings away with a clear head.

frequently asked

Do I have to tell customers they are talking to a chatbot?
Yes. From 2 August 2026, article 50(1) of the AI Act requires that users know they are communicating with AI, unless that is already obvious. One visible notice at the start of the conversation is enough for a regular service chatbot. The duty applies without a transition period, so it also covers chatbots that have been live for years.
Is an AI register or AI certificate mandatory for small businesses?
No. Nothing in the AI Act obliges an SMB with only low-risk tools to buy register software, certificates or certified training. Your own overview of your AI tools and a documented team session are enough to make the article 4 duty of effort demonstrable.
What fine can I get if my chatbot has no AI notice?
On paper up to 15 million euros or 3% of global annual revenue, with the lower of the two applying to SMBs. How actively the Dutch Data Protection Authority (AP) will enforce in practice from August 2026 has not been announced yet. Since the fix costs one line of text, this is a risk to remove rather than to estimate.
Does the AI Act apply if I only use ChatGPT or Copilot?
Yes, through the AI literacy duty of article 4, which has applied since 2 February 2025 to every business that uses AI professionally. Since the Digital Omnibus it is a duty of effort: you must be able to show appropriate measures, such as a short internal policy and a documented team session. The law asks for no exams or certificates.
nlen