# Generative AI obligations for businesses: what changes by 2026

> In 2026, companies using generative AI will have to comply with new obligations: transparency for chatbots and synthetic content from November 2, 2026, GPAI compliance since August 2025, and mandatory AI training for teams. Sanctions can reach 35 million euros or 7% of global turnover.

- Tags: ia générative entreprise, ai act obligations 2026, gpai conformité, transparence chatbot, haut risque IA, conformité réglementaire IA, formation IA entreprise, sanctions AI Act
- Main keyword: obligations IA générative entreprise 2026

## Key points

- November 2, 2026: transparency obligation for chatbots and AI content (Art. 50).
- 35 million euros or 7% of global turnover: maximum sanction for prohibited practices.
- Since February 2025, AI proficiency is required for all relevant personnel (Art. 4).
- Three regimes of obligations: minimal risk, high risk, GPAI according to the AI Act.

## Introduction

The AI Act strictly regulates the activities of companies involved in the creation or use of generative AI systems. With the entry into force of GPAI obligations from August 2025 and mandatory transparency rules starting in November 2026, regulatory constraints are gradually tightening. Here are the essential points to know.

## Content

## 2026: The pivotal year for corporate AI compliance

The AI Act is now a concrete reality for all affected companies. Since August 2025, several major obligations have been in effect, and the November 2026 deadline is shaping up to be a decisive milestone.

[The European Artificial Intelligence Act](https://eur-lex.europa.eu/legal-content/FR/TXT/?uri=CELEX:32024R1689) (Regulation EU 2024/1689), effective since August 1, 2024, imposes a four-year compliance schedule. Companies that develop, deploy, or use generative AI systems must anticipate three major regulatory phases between 2025 and 2026. Prohibited practices have been banned since February 2, 2025. Specific requirements for General Purpose AI (GPAI) models apply from August 2, 2025. Finally, the transparency obligation toward end-users takes effect on November 2, 2026.

Neglecting this schedule exposes companies to significant financial risks and increased reputational issues. National supervisory authorities, such as the [CNIL in France](https://www.cnil.fr/fr/intelligence-artificielle), are currently being designated and will soon be able to exercise their audit and supervision powers once their mandate is officially assigned.

## Provider or deployer: understanding the fundamental difference

The AI Act distributes obligations and responsibilities according to two central roles. Determining your status is essential for approaching compliance.

### The Provider

A provider is any organization that designs an AI system and places it on the market, whether for commercial or non-profit purposes. For example, if your company uses the API of an advanced language model to develop a service or product for other users, you fall into this category. As such, it is your responsibility to prepare **technical documentation**, conduct a conformity assessment of your solution, and affix the CE marking if your system is considered to present a high level of risk.

### The Deployer

A deployer is any entity that, without having developed the AI system, uses it in a professional context. If you integrate SaaS software using generative AI into your business—for writing, meeting transcription, or customer support—your status is that of a deployer. The resulting obligations are more limited but remain unavoidable: these include informing users, ensuring human oversight of major decisions, following the provider's recommendations, and ensuring adequate training for your teams.

Using an AI device to make decisions regarding employees without notifying them in advance of the system's presence and operation constitutes a double infringement, both of the AI Act and the GDPR.

## GPAI: obligations in effect since August 2025

Articles 51 to 56 of the AI Act establish a framework dedicated to General Purpose AI (GPAI) models. This provision concerns any provider making a foundational model available, whether it is a large language model, an image generator, or a multimodal model.

As of 2025, GPAI providers must meet four main requirements. They are required to prepare and update **technical documentation** detailing the model's architecture, the datasets used for training, and its functionalities. They must also ensure compliance with **copyright law** during the training phase by publishing an appropriate compliance policy. A **summary of the training data** must be made public. Finally, they are responsible for transmitting all necessary information to downstream users to ensure their compliance.

### Systemic risk GPAI

When a GPAI model has been trained with a computing power greater than 10^25 FLOPs, it is classified as presenting a systemic risk. Additional requirements apply to these models: conducting adversarial evaluations according to recognized protocols, [mandatory reporting of major incidents to the European AI Office](https://digital-strategy.ec.europa.eu/en/policies/european-approach-artificial-intelligence), and deploying cybersecurity measures adapted to the identified risk level.

## Article 50: mandatory transparency starting November 2, 2026

Article 50 introduces a transparency requirement that will apply massively to companies from the end of 2026. This measure requires providing explicit information to users when they interact with artificial intelligence systems or consume content produced by an AI.

### Chatbots and conversational agents

Any organization implementing an AI system designed to interact directly with natural persons must, in accordance with Article 50, notify the user in real-time that they are interacting with an AI. This obligation does not apply if the artificial nature of the interaction is obvious in the context of use. This concerns, for example, chatbots used for customer service, virtual assistants integrated into software or applications, as well as AI agents made available to the public.

### AI-generated content and deepfakes

Providers of systems capable of producing synthetic content (images, sounds, videos, text) are required to affix a machine-readable label to these creations. Furthermore, any entity distributing such content must clearly indicate that it has been generated by an artificial intelligence. There are, however, regulated exceptions, notably for _satire_, _parody_, or certain uses related to national security.

All these transparency obligations stemming from Article 50 will enter into force on November 2, 2026.

## High-risk AI systems: how to anticipate the 2027 deadline?

Annex III of the AI Act lists the sectors where an artificial intelligence system is automatically considered to be high-risk. December 2, 2027, marks the major deadline for the compliance of these systems, but it is recommended that providers anticipate today to comply in time.

Targeted areas include **human resources management** (such as candidate screening, performance analysis, or promotion decisions), **education**, access to **essential services** (such as credit, insurance, or social benefits), as well as the administration of **justice** and democratic processes. If your generative AI solution is involved in one of these sectors, it may be considered high-risk, regardless of its technical operation.

The classification used by the AI Act is based on the actual use of the system, rather than its technology. For example, the same language model used to write a newsletter remains low-risk, but if it is used to evaluate candidates, it becomes high-risk. It is therefore the **actual application** that determines the level of risk, not the technology employed.

## Six key steps to comply before November 2026

Regardless of your role in the artificial intelligence value chain, here are the essential steps to take to ensure your compliance in view of the upcoming regulatory deadlines.

1. **Inventory your AI systems**: establish an exhaustive inventory of all AI solutions in use or deployed, specifying their risk category (minimal risk, high risk, GPAI).
2. **Determine your legal status**: identify, for each system, whether your organization acts as a provider or deployer. If you offer a service based on an external API, your responsibility as a provider entails increased obligations.
3. **Check for the absence of prohibited practices**: ensure that no system in operation uses subliminal manipulation, exploitation of vulnerabilities, or generalized social scoring, effective from February 2025.
4. **Anticipate transparency requirements**: prepare the information to be communicated to users for chatbots or generative systems, in accordance with the transparency expectations to be implemented before November 2, 2026.
5. **Train your teams (Art. 4)**: training on AI system proficiency must have been effective since February 2, 2025. Documentary traceability of the training, adapted to the tools actually used, is the minimum required.
6. **Ensure documentary traceability**: record conformity assessments, human control measures, and incidents in a dedicated register. This document will be required in the event of an audit by a competent authority.

[Our free diagnostic tool](https://compaia.eu/diagnostic) helps you determine, in less than 3 minutes, the specific obligations for your structure according to your sector and your AI usage.

## Overview of key texts to master

**AI Act – Art. 4**
Since February 2, 2025, operators are required to ensure effective management of the artificial intelligence systems under their responsibility.

**AI Act – Art. 5**
As of February 2, 2025, certain AI practices are formally prohibited in the European Union, according to a strictly defined list.

**AI Act – Art. 50**
Transparency requirements regarding chatbots and tools generating synthetic content must be met by November 2, 2026.

**AI Act – Art. 51 to 56**
GPAI models are subject to a specific regime including documentation obligations, consideration of copyright, synthesis of data used, and specific measures for models presenting a systemic risk.

**AI Act – Annex III**
This annex lists the sectors and uses considered high-risk, with a major deadline set for December 2027.

**GDPR – Art. 22**
The right not to be subject to a strictly automated decision, as well as the right to an explanation, apply in parallel to the AI Act framework.

### Is your organization aligned with the AI obligations for 2026?

In just 3 minutes, evaluate the requirements applicable to your structure: provider or deployer qualification, identification of affected systems, and prioritization of deadlines. Diagnostic offered, no registration required.

## Frequently asked questions about AI obligations in 2026

Find here detailed answers to common questions regarding the requirements of the AI Act regulation for companies in 2026.

When a company uses an AI solution developed by a third party in a professional context, it is considered a deployer under the AI Act. As such, it must apply the provider's instructions, communicate the use of AI to end-users, ensure human intervention on any major decision, and provide adapted training to its teams (Art. 4, applicable since February 2025). If the company designs a product based on a third-party API, it then assumes the role of provider, which significantly extends its responsibilities.

The provider designates the organization that designs and markets an AI system, while the deployer uses it without having developed it. The provider must ensure the creation of technical documentation, CE marking, and conformity assessment. For its part, the deployer is required to follow the provider's instructions, inform users, and ensure human control over any automated decision having an impact on a natural person.

The obligation to clearly indicate the use of a chatbot applies if it interacts with natural persons and this interaction is not immediately obvious. This requirement will enter into force on November 2, 2026. An internal chatbot, whose AI nature is obvious to all users, may benefit from a contextual exception. Conversely, a conversational assistant accessible to customers cannot claim this exception and will have to display explicit information.

Failure to comply with the transparency rules set by Article 50 exposes the company to a sanction of up to 15 million euros or 3% of total worldwide annual turnover, whichever is higher. Infringements of the prohibitions provided for in Art. 5 are more severely punished: up to 35 million euros or 7% of total worldwide annual turnover.

Providers of open-source GPAI models benefit from relief on certain documentation obligations, provided they make the model parameters public. However, as soon as the model presents a systemic risk (training capacity greater than 10^25 FLOPs), these exemptions no longer apply: the reinforced obligations also extend to open-source models.

The risk qualification is based on the use of the system and not on the type of model. A generative AI tool is classified as high-risk if it is involved in one of the areas of Annex III, such as human resources, education, credit, insurance, or justice. For example, if it is used to pre-select candidates, evaluate credit applications, or make decisions affecting access to rights, it will be considered high-risk, regardless of the underlying AI model.

Yes, Article 4 entered into force on February 2, 2025. It requires providers and deployers to ensure the competence of their employees working on AI systems. Authorities expect at least documented training, adapted to the technologies used.

Jeremy Pierre

Founder compaia.eu . AI Act compliance expert

Supports AI providers and deployers in operational compliance. Author of practical guides on the AI Act regulation and the GDPR applied to generative AI.

## Official source
- [Source](https://www.aiacto.eu/fr/blog/ia-generative-entreprise-obligations-2026)
