The AI Act: four questions to answer before 2 December
Since 2 August 2026, part of the European AI regulation has applied to your company. Not the part everyone wrote about. And you have until 2 December.
By Patrick de Carvalho, CEO Apps Velocity
Contents
- The deadline that matters to you: 2 December 2026
- What actually applies since 2 August
- The word that changes everything: deployer
- Question 1: does your conversational agent say it is a machine?
- Question 2: what do you publish, and on what subjects?
- Question 3: who reviews, and can you prove it?
- Question 4: how many AI tools are actually running in your company?
- And the 35 million euro fines?
- Where to start, concretely
What actually applies to a small or mid-sized company since 2 August 2026, and why the real risk is not the one being sold to you
By Patrick de Carvalho, CEO and co-founder of Apps Velocity.
In short: contrary to what was widely reported, the rules on high-risk AI have not applied since 2 August 2026. They have been postponed to 2 December 2027 and 2 August 2028 by Regulation (EU) 2026/1744. Article 50 on transparency, however, does apply from that date, and it targets the deployer, meaning any company that uses an AI tool under its own authority. For systems already in service before 2 August, compliance runs until 2 December 2026. Four checks are enough to know where you stand. Allow half a day and zero euros of software.
Let us clear up the misunderstanding first, because three weeks on it is still everywhere.
No, the European rules on high-risk artificial intelligence systems did not come into application on 2 August 2026. They have been pushed back to 2 December 2027 for standalone systems, and to 2 August 2028 for those embedded in products that are already regulated. The decision was made by Regulation (EU) 2026/1744 of 8 July 2026, published in the Official Journal of the European Union on 24 July and in force since 27 July. Six working days before the deadline everyone was waiting for.
Many company directors read a headline, understood "it has been postponed", and filed the subject away. That is the kind of shortcut you only make once, but that you pay dearly for.
Because another part of the regulation does apply. Quieter, and it concerns far more people.
I am answering the only question that really matters to you here: does this affect me? The answer is probably yes. But not for the reason you think.
The deadline that matters to you: 2 December 2026
Remember that date, it is yours.
Article 50 has applied since 2 August 2026. But for systems already placed on the market before that date, the regulation grants a compliance period running until 2 December 2026. That period was cut from six months to three by the Digital Omnibus.
In other words: if your conversational agent was already running this summer, if your AI-assisted content was already online, you are not out of time today. You have a window, and it closes at the start of winter.
That is comfortable. It will not be in November.
What actually applies since 2 August
Three things came into force that day.
The first is the transparency obligations of Article 50 of the regulation. That is the subject of this article, and the one that concerns you.
The second is the European Commission's supervisory and enforcement powers over providers of general-purpose AI models, the engines behind ChatGPT, Claude, Gemini and Mistral. Since 2 August 2026 the Commission can demand their documentation, technically evaluate their models, impose corrective measures, restrict a model on the European market, and issue fines. This does not concern you directly, but it will change your suppliers' behaviour in the months ahead.
The third is the entry into service of the national penalty regime. In France, the CNIL acts as the reference authority, surrounded by around fifteen sector authorities depending on the field: the DGCCRF for consumer affairs, Arcom for broadcasting and digital, the ACPR for banking and insurance, the ANSM and the HAS for health. Coordination falls to the DGE and the DGCCRF, with technical support from the ANSSI.
The word that changes everything: deployer
Before the four questions, one piece of vocabulary. Just one, but it governs everything else.
The regulation distinguishes the provider, who develops an AI system and places it on the market under their own name, from the deployer, who uses that system under their own authority in the course of their professional activity.
If you pay for a subscription to a generative AI tool and your teams use it to produce content, visuals or customer replies, you are not a provider. You are a deployer. And the regulation places obligations on you that are your own, distinct from those of your software vendor.
This is the point that nine directors out of ten miss. "My vendor is compliant, so I am covered." No. Your vendor answers for their product. You answer for what you do with it.
Question 1: does your conversational agent say it is a machine?
Article 50 requires that a person interacting directly with an AI system be informed of it, from the very start of the first interaction, in a clear and distinguishable way. There is an exemption, but it is narrow: unless this is obvious to a reasonably well-informed and observant person.
If you have a conversational agent on your site, an assistant in your online shop, an intelligent phone system, go and test it now. Open it the way a customer would. Is the notice there, visible, before the first exchange? Or is it buried in a terms-and-conditions page nobody opens?
This check takes ten minutes. And it is probably the most common point of exposure in a smaller company.
Question 2: what do you publish, and on what subjects?
Article 50 requires the deployer to disclose the artificial origin of two categories of content.
Deepfakes, first. The term covers image, audio or video content generated or manipulated by AI, resembling existing persons, objects, places or events, and which would falsely appear authentic.
AI-generated text published for the purpose of informing the public on matters of public interest, second. This is the category that surprises people, and the one that catches the most of them.
Sort through your output. A product sheet, no. A commercial newsletter, no. A blog article on developments in your sector's regulation, on a health, environmental, economic or political subject, yes, potentially.
Disclosure, where it is due, must be made through a visible or audible marking that a person understands without needing a detection tool. In other words: a legible notice, not a technical signature hidden inside the file.
Two exemptions worth knowing. Manifestly artistic, creative, satirical or fictional works benefit from an adapted regime that does not distort the work. And above all, text that has undergone human editorial review falls outside the scope.
Question 3: who reviews, and can you prove it?
Here is the most important point in this whole article, and the one nobody comments on.
The European Commission defines human editorial review as a substantial review by a competent person holding the authority to approve, modify or reject the content.
Translation: if a human in your company genuinely reviews, can modify and can reject, your text falls outside the disclosure obligation.
Which means your best compliance tool is not a piece of software. It is a shared spreadsheet with three columns: who reviewed, when, what was changed.
Open it this week. It will be worth more than you think, and not only for the regulation. In eighteen months, when a major client sends you their procurement questionnaire on AI use, that is exactly the document they will ask for. I have seen it happen: in May 2026, an industrial company I work with received, in an energy-sector tender, a four-page annex requiring an inventory of its AI systems, a traceability commitment for generated content and the appointment of a named contact. No legal obligation applied directly to that company. It was the buyer's caution that created the requirement.
Compliance comes down through the contract, not through the inspection. That is how the GDPR spread from 2018 onwards, through contractual annexes far more than through penalties. The same mechanism is under way.
Question 4: how many AI tools are actually running in your company?
Last question, and the most uncomfortable.
In April 2026, in a services company of around sixty people, I asked the management how many generative AI tools were in use in the building. The answer: two. The inventory carried out by the teams themselves, over three weeks, found eleven. Nine had been subscribed to directly by employees, often on free plans, without going through management.
This phenomenon has a name, shadow AI: the use of artificial intelligence tools by employees outside any defined framework. It is not disobedience, it is resourcefulness. But those tools produce content published under your company's name, and you answer for it.
Until you have that inventory, you cannot answer any of the three previous questions. That is why it comes first in the method I apply in the field.
And the 35 million euro fines?
You have seen them quoted everywhere, so let us put them in their place.
The regulation provides for up to 35 million euros or 7 % of total worldwide annual turnover for prohibited practices, and up to 15 million euros or 3 % of worldwide turnover for transparency breaches.
Those ceilings are calibrated for global players. A twenty-five-person company will not receive a 35 million euro fine. Using those figures to sell you an emergency audit would be selling through fear, and I have always refused to do that.
Your real risk is commercial before it is administrative. It is called "the client who asks you for guarantees you cannot provide".
Where to start, concretely
Three actions, half a day of a director's time.
The inventory. A shared spreadsheet, open to the whole company, four columns: who uses what, to produce what, is it published externally, who reviews it before publication. Without judgement and without sanction, otherwise nobody will declare anything and you will be steering with a false map.
The touchpoints. Test your conversational agent. Look at your last ten publications. Two ten-minute checks that cover most of your real exposure.
The review log. Open it today, with whatever tools you have. It is the document that will serve you longest.
What you do not do this week: buy a compliance solution, commission a fifteen-thousand-euro audit, or panic. 2 August 2026 did not make your company a target. It made visible an organisation you should have had anyway.
And if you only do one of the three, do the inventory. Without it, everything else is an opinion.
By the way: RAPID is a method, a book, and 40 free practical sheets
Taking stock of your real usage, knowing who answers for what, keeping a record of what a human has validated: this is not a compliance posture. It is a method, built with the directors I work with and tested on more than 150 projects. I called it RAPID, five letters for five phases: Recenser, Analyser, Piloter, Itérer, Déployer (identify, analyse, steer, iterate, deploy).
There are three ways in:
- The 40 practical sheets, one per step of the method, freely available online: rapid.appsvelocity.com/fr/livre/#book-fiches
- The book, where Pascal Roche and I document the method end to end: rapid.appsvelocity.com/fr/livre
- The full method and advisory work with directors: rapid.appsvelocity.com
Start with the sheets. They are free, they are concrete, and that is exactly where you get your foot in the door.