# ChatGPT in the Workplace: AI Act Obligations and Operational Compliance

> The AI Act regulation imposes transparency, information, and compliance obligations on companies using ChatGPT or another generative AI tool, applicable from August 2026, regardless of the provider and the size of the company. Sanctions can reach 7.5 million euros or 1% of turnover.

- Tags: chatgpt ai act, ia générative obligations, copilot ai act, conformité IA entreprise, deepfake réglementation, transparence chatbot, haut risque IA, sanctions AI Act
- Main keyword: obligations ChatGPT AI Act entreprise

## Key points

- Any professional use of ChatGPT makes your company a "deployer" subject to the AI Act starting in August 2026.
- Article 50 requires explicitly informing every user interacting with an AI chatbot, with no size exceptions.
- Any AI creation imitating a real person (deepfake, voice, image) must be labeled as synthetic content.
- OpenAI and other GPAI providers have been subject to specific obligations since August 2025, but the deployer's responsibility remains full.
- If AI is involved in HR decisions, scoring, or access to essential services, the usage may be reclassified as high risk (Annex III).
- No SME is exempt from Article 50: transparency is required for all companies from the first chatbot.

## Introduction

The use of ChatGPT, Copilot, Gemini, Claude, Mistral, or any other generative AI tool has become widespread in European companies: email writing, document summarization, marketing content creation, customer support automation, etc. However, **EU Regulation 2024/1689 (AI Act)** now regulates these uses and imposes strict requirements on all organizations, regardless of their size.

Contrary to popular belief, not being a provider of the tool does not exempt you: the AI Act clearly distinguishes between the role of provider and deployer. Any company that integrates a generative AI system into its professional processes becomes a **deployer** within the meaning of the regulation, with obligations to anticipate by August 2026.

## Content

## Provider or Deployer: What is your company's position?

**Article 3** of the AI Act regulation distinguishes between:

- **Provider**: The entity developing and marketing the AI system (e.g., OpenAI, Microsoft, Google). They bear the heaviest constraints: technical documentation, CE marking, registration with the EU.
- **Deployer**: Any organization using an AI system in a professional context. This applies to every company that integrates ChatGPT into its tools, deploys a Copilot chatbot on its website, or automates tasks via an LLM.

As a deployer, you do not have to produce exhaustive technical documentation, but you are subject to concrete obligations starting in August 2026.

## Article 50: Mandatory AI Transparency for All

**Article 50** constitutes the universal foundation of the AI Act. It imposes transparency obligations on all companies, regardless of size, as soon as an AI system interacts with people or generates content.

### Explicitly inform every user in contact with an AI

As soon as a chatbot, assistant, or AI tool (ChatGPT, Copilot, etc.) is made available on a website, an application, or internally, it is mandatory to **clearly inform users that they are interacting with an AI** (Article 50§1). This applies to both customers and employees.

It is not permitted to imply human intervention when it is not the case (for example, indicating "response from our team" when the response comes from GPT-4). The only exceptions concern contexts where the AI nature is obvious to everyone, or in the context of explicitly scripted artistic/fictional works.

### Mandatory labeling of deepfakes and synthetic content

Any content generated or manipulated by AI (video, image, audio) representing a real, identifiable person must be **clearly presented as synthetic** (Article 50§4). This concerns:

- Marketing videos using AI avatars resembling real people
- Artificial voices imitating existing voices
- Generated photos of identifiable individuals
- Deepfakes used in corporate communication

### Machine-readable watermarking by November 2026

Article 50§2 provides that AI-generated content must be marked in a machine-readable way. This obligation primarily targets providers (OpenAI, Google, Mistral…), but deployers must verify that their tools comply with this principle. The effective date is set for **November 2, 2026**, for systems already on the market.

## ChatGPT Usage and High-Risk Classification: Beware of Annex III

Using ChatGPT for routine tasks (writing, summarizing, etc.) falls under limited risk: only the transparency of Article 50 applies. However, **the risk level depends on the usage, not the tool**.

Your usage shifts to **high risk (Annex III)** if you use an LLM for:

- **Sorting or evaluating candidates/employees**: Any tool influencing HR decisions (hiring, promotion, dismissal) falls under Annex III, section 4.
- **Financial or credit scoring**: Any automation of solvency assessment falls under section 5 of Annex III.
- **Decisions on access to public/essential services**: AI involved in the allocation of social rights, benefits, etc.
- **Individual risk profiling**: In insurance, security, or risk management involving natural persons.

In these cases, **Article 26** imposes additional measures: human oversight, traceability (logs), and enhanced information for the persons concerned.

> Key takeaway: It is not the tool, but the usage that determines the risk level. Writing a newsletter with ChatGPT = limited risk. Using ChatGPT to evaluate HR performance = high risk.

## GPAI: Specific Provider Obligations since August 2025

Providers of language models (OpenAI, Google, Anthropic, Mistral…) have been subject to the obligations of **Articles 51 to 56** since **August 2, 2025**. For user companies, this implies:

- Right of access to a **summary of training data** (Article 53)
- Possibility to consult **technical documentation** in case of an audit
- Guarantee of copyright compliance regarding training data
- For systemic risk models (more than 10^25 FLOPs), enhanced obligations (GPT-4, Gemini Ultra…)

These provider requirements do not exempt user companies from their own obligations as deployers.

## Preparing for Compliance before August 2026: Practical Steps

1. **Map all generative AI usages**: Identify every tool (ChatGPT, Copilot, Gemini, Claude, CRM/HR integrations…) and specify its exact usage.
2. **Classify each usage by risk level**: Editorial usage = limited risk (Article 50). Usage impacting decisions about people = Annex III verification.
3. **Audit user interfaces**: Every AI chatbot must clearly indicate its nature. Correct any missing mentions.
4. **Update legal notices and T&Cs**: Transparency must appear in your contractual documents if the AI processes customer data or produces content for them.
5. **Verify the compliance of your SaaS tools**: Ask your providers if they comply with the AI Act. Their response determines your own regulatory exposure.

For a quick diagnosis, the [free compaia diagnostic](https://compaia.eu/diagnostic) helps you classify your AI usages in less than 3 minutes and determine if you fall solely under Article 50 or a high-risk regime.

## Sanctions and Controls: What you risk

Starting in August 2026, non-compliance with Article 50 exposes both providers and deployers to fines of up to **7.5 million euros** or **1%** of global annual turnover. National authorities (DGCCRF, CNIL in France) will have control and sanction powers. To anticipate deadlines, consult the [AI Act timeline](https://compaia.eu/echeancier-ai-act).

## FAQ on the AI Act, ChatGPT, and Corporate Compliance

### Our use of ChatGPT is strictly internal: are we affected by the AI Act?

Yes, the information obligation of Article 50 also applies to internal interactions. If ChatGPT is used to evaluate employees or influence HR decisions, you fall under the high-risk regime and Article 26 is added.

### Does the AI Act apply to OpenAI despite its US domicile?

Yes. Any AI whose output is used in the EU is subject to the AI Act, regardless of the provider's country. OpenAI must apply GPAI obligations for European users, particularly since August 2025.

### Does ChatGPT Enterprise change my obligations compared to the free version?

No, your AI Act responsibilities depend on the usage, not the version. ChatGPT Enterprise provides GDPR guarantees, but the AI Act framework remains identical for the deployer, regardless of the edition used.

### Must we always signal AI-generated content to clients?

Not systematically. Reporting obligations mainly concern deepfakes (Article 50§4) and direct interactions with a chatbot (Article 50§1). Marketing content generated and then validated by a human is not automatically covered, unless published without human intervention.

### What are the risks of non-compliance before August 2026?

Non-compliance with Article 50 exposes you to fines of up to 7.5 million euros or 1% of global annual turnover. French authorities, such as the DGCCRF and the CNIL, will be able to impose sanctions starting in August 2026. Consult the AI Act timeline: https://compaia.eu/echeancier-ai-act.

## Official source
- [Source](https://www.aiacto.eu/fr/blog/chatgpt-entreprise-ai-act-obligations)
