The EU AI Act after the Omnibus: what a CEO must do now

The European Union flag alongside an AI Act document symbol

The AI Omnibus deferred part of the obligations for high-risk systems. It did not defer executive accountability for the AI already running in your company. From 2 August 2026 further parts of the AI Act start to apply, including transparency for certain AI systems. The obligation to support AI literacy has applied since February 2025.

For most companies, therefore, the main question is not whether to commission a legal analysis.

The main question is this:

Do you know which AI systems you use, who owns them, what data they can reach and who is accountable for their outputs?

If you do not, the problem is not created by the AI Act. The regulation merely makes visible the fact that your company is using technology without a clear operational owner.

Decisions for the executive team

Question Practical conclusion
Do we have to stop AI projects because of the AI Omnibus?No. But you do have to map, classify and manage them.
Were all obligations deferred?No. What was deferred is mainly part of the rules for high-risk systems.
Does the AI Act cover ordinary use of ChatGPT or Copilot?Yes, at minimum in the area of AI literacy and responsible use.
Must we label everything created with AI?No. Obligations differ by system type, content and the company's role.
Do we need a register of the AI systems we use?Without one you cannot reliably determine obligations, risk or return.
Must we appoint a Head of AI?The law does not mandate a specific function. But someone has to own and coordinate the AI agenda.
What should the CEO approve first?A single owner of the AI agenda and a 30-day inventory of all AI use cases.

What changed on 27 July 2026

On 27 July 2026, Regulation (EU) 2026/1744, known as the Digital Omnibus on AI, entered into force. It amended the original AI Act and shifted some deadlines, because European standards, methodologies and national supervisory infrastructure were not ready in time.[1][2]

For an ordinary company, four changes matter.

1. Rules for high-risk systems were deferred

Obligations for systems classified as high-risk under Annex III start to apply from 2 December 2027.

This covers, for example, certain AI systems used in:

  • recruitment, selection and evaluation of employees;
  • education;
  • creditworthiness assessment;
  • access to certain essential services;
  • biometrics;
  • critical infrastructure.

Rules for AI embedded in regulated products apply from 2 August 2028.[2][3]

That does not mean you can deploy a risky system today and start caring about it in a year's time.

GDPR, employment law, consumer protection, cybersecurity requirements, contractual liability and the duty of executives to act with due managerial care all still apply. An expensive AI solution deployed without an owner, documentation and human oversight is a badly managed investment regardless of when a particular AI Act article takes effect.

2. AI literacy remains an obligation

Article 4 of the AI Act has applied since 2 February 2025.

The AI Omnibus softened its wording: a company no longer has to guarantee a specific or "sufficient" level of AI literacy for each individual. It must, however, continue to take proportionate measures supporting the development of AI literacy among staff and other persons working with AI on its behalf.[2][4]

That does not mean buying everyone a generic webinar on prompting.

The scope of measures should match:

  • the systems in use;
  • the knowledge of the specific users;
  • the purpose of use;
  • the associated risks;
  • the groups of people the AI outputs may affect.

Someone using AI to proofread marketing copy needs a different level of preparation than an HR specialist working with AI candidate scoring, or an employee approving the output of an autonomous agent operating over the CRM.

The company does not need to obtain a special certificate. It should, however, be able to evidence what measures it took, whom they covered and why they were proportionate given the systems in use.[4]

3. Transparency was not deferred

Article 50 starts to apply from 2 August 2026.

Obligations differ depending on whether the company is a provider of the AI system or merely uses it. They may include in particular:

  • informing a person that they are communicating with AI;
  • technical marking of AI-generated or AI-modified content;
  • informing people exposed to emotion recognition or biometric categorisation systems;
  • labelling deepfake content;
  • labelling certain AI-generated texts published to inform the public on matters of public interest.

For systems generating synthetic content placed on the market before 2 August 2026, there is a limited transitional period until 2 December 2026. It applies only to the provider obligation to ensure machine-readable marking under Article 50(2). It is not a general deferral of transparency.[2][5]

4. Supervision becomes a practical question

The AI Act is a European regulation and therefore applies directly. National law mainly designates the supervisory and support infrastructure, the competences of authorities and practical enforcement.

In the Czech Republic, the Ministry of Industry and Trade leads implementation. The proposed national infrastructure splits competences across several institutions depending on the type of system and the regulated area.[9]

For a CEO, the conclusion is simple:

A legal memorandum stored on SharePoint is not enough. You must be able to show how AI is actually governed in the company.

First, determine your role

The AI Act distinguishes several roles. For most companies, two matter most.

Deployer: you use the system

A deployer is an organisation using an AI system under its authority in the course of a professional activity.[6]

Typical examples:

  • staff use Microsoft Copilot;
  • the sales team uses AI features in the CRM;
  • marketing uses ChatGPT or Claude;
  • the contact centre uses a voice agent supplied by an external vendor;
  • HR uses a third-party tool for candidate pre-screening.

For most of their tools, most ordinary companies will be deployers.

Provider: you place the system on the market under your own name

A provider is an entity that develops an AI system, or has one developed, and places it on the market or puts it into service under its own name or trademark.[6]

You can find yourself in this role when, for example, you:

  • sell your own AI service to customers;
  • supply a white-label chatbot under your brand;
  • have an AI product built and offer it as your own;
  • substantially change the purpose or functioning of someone else's system;
  • integrate a third-party model into a product whose resulting function you are answerable for.

The fact that a system uses a model from OpenAI, Anthropic or Google does not automatically mean that company carries all the obligations.

The model, the resulting AI system, the user interface and the specific corporate deployment are different layers of accountability.

Seven common use cases

1. Staff use ChatGPT, Claude or Copilot

Likely role: deployerImmediate problem: AI literacy, data and accountability for the output

The company should know:

  • who uses the tools;
  • what types of data may be entered into them;
  • whether personal or client data is involved;
  • who checks the results;
  • in which processes AI is merely an assistant and where it already influences decisions.

Buying an enterprise licence is not governance.

A licence may address part of the data processing terms. It does not address whether an employee can spot a hallucination, whether they are authorised to process a given document, and whether an AI output may be used as the basis for a decision.

2. A chatbot or voice agent runs on your website

Likely role: deployer; provider for an in-house or white-label solutionImmediate problem: transparency and accountability for what the system does

In relevant situations, the customer must know they are communicating with AI.[5]

But that is not the only question.

The executive team must decide:

  • what the agent may promise a customer;
  • which systems and data it can reach;
  • whether it can change orders or delivery dates;
  • when it must hand the conversation to a human;
  • who is accountable for incorrect information;
  • how incidents are recorded;
  • how the commercial benefit is measured.

Adding "I am an AI assistant" is the easiest part of the whole deployment.

3. Marketing generates text, images and video

Likely role: deployerImmediate problem: content provenance, human review and reputational risk

The AI Act does not mean every text touched up with AI needs a visible label.

Particular attention is needed for:

  • deepfake image, audio or video;
  • content that could be mistaken for authentic;
  • AI-generated publications on matters of public interest;
  • automated publishing without human review;
  • content for which nobody took editorial responsibility.

Providers of generative systems are expected to handle machine-readable marking of synthetic content. A company using such a tool should verify that its technology and publishing chain preserves the necessary metadata.[5]

4. AI screens candidates or evaluates employees

Possible classification: high-risk system depending on the specific purposeImmediate problem: discrimination, human oversight and documentation of decisions

AI systems intended for candidate selection, decisions on employment relationships, task allocation or performance evaluation may fall under Annex III of the AI Act.[7]

The main obligations for this category were deferred to 2 December 2027. That is not a reason to introduce the system without control.

First you need to know:

  • what the system actually evaluates;
  • what data it draws on;
  • whether the output merely prepares material or effectively decides;
  • who can override its recommendation;
  • whether the decision can be explained;
  • whether results are continuously checked for systematic bias.

HR must not be the test lab for a tool whose logic nobody in the company can defend.

5. An internal AI assistant works over company documents

Likely classification: ordinary or limited-risk systemImmediate problem: permissions, knowledge quality and data leakage

An internal knowledge assistant will not usually be a high-risk system merely because it uses generative AI.

It can still cause real damage if it:

  • exposes a document to someone without authorisation;
  • uses an outdated policy;
  • combines information from different client files;
  • presents an unverified note as binding procedure;
  • produces an output with no source reference.

Regulatory classification is only one part of the decision. The second is operational risk and the third is economic return.

6. AI assesses creditworthiness or access to a service

Possible classification: high-risk systemImmediate problem: impact on people's rights and explainability of decisions

Some systems used for assessing creditworthiness, risk or access to essential services may fall among high-risk use cases.[7]

Here it is not enough to ask whether the system "only recommends".

If an employee almost always confirms the AI recommendation mechanically, the human presence may not amount to genuine human oversight.

7. AI recognises employees' emotions

Classification: some uses are prohibitedImmediate decision: do not deploy without specialist assessment

Using AI to infer the emotions of people in the workplace is in principle prohibited, save for limited cases relating for example to medical or safety reasons.[8]

If a vendor offers you analysis of employee mood from voice, face or biometric signals, this is not an innocent HR dashboard.

It is a reason to stop the project and have its lawfulness and actual purpose independently reviewed.

Without a register you do not know what you are managing

The first practical output of AI governance should not be a fifty-page policy.

It should be a register of the AI systems and use cases in use.

At minimum it should contain:

Field What to record
SystemName of the tool or solution
Use caseWhat the company actually uses it for
OwnerThe person accountable for the operational result
SupplierVendor, model and implementation partner
Company's roleProvider, deployer or another role
UsersWho operates the system
Affected personsWho the outputs may affect
DataWhat data the system receives and where it sends it
OutputWhat the system recommends, generates or executes
Human oversightWho must intervene and when
RiskPreliminary regulatory and operational classification
TransparencyHow the customer, employee or public is informed
KPIHow benefit, quality and error rate are measured
StatusExperiment, pilot, production, suspended, terminated

Without a register you cannot:

  • determine which obligations apply to you;
  • design proportionate AI literacy;
  • manage access to data;
  • assess suppliers;
  • track incidents;
  • evidence human oversight;
  • calculate the real return;
  • decide which experiment to stop.

The register is not compliance paperwork produced for an inspector.

It is a management tool for steering investment and risk.

Why a lawyer, IT or the vendor is not enough

The AI Act is a cross-disciplinary problem. That is precisely why it often ends up with no real owner.

Role What they do well What they typically do not own
LawyerInterpreting the regulation and legal riskSystem operation, architecture, adoption and ROI
DPOPersonal data and GDPRThe whole AI portfolio and commercial priorities
IT and securityIdentity, access, integration and infrastructure protectionUse case selection and accountability for business impact
SupplierTheir own product and its implementationThe company's interest across vendors and the return on the whole portfolio
Department headA specific process and its needsConsistent rules and risks across the company
Head of AIPriorities, governance, architecture, deployment and measured impactThe final specialist legal opinion

The AI Act does not require you to create a Head of AI position or a particular governance structure.[4]

It imposes, or progressively introduces, obligations that someone has to translate into reality.

That is a meaningful difference.

A lawyer can establish the legal interpretation. They cannot decide alone whether a voice agent pays off, what permissions it needs, where it must hand over to a human and which vendor offers the best architecture without lock-in.

IT can connect the system to the CRM. It cannot decide alone whether the agent has the right to change a price, promise a date or turn a customer away.

The vendor will explain why their product is safe. They will not independently tell you their product makes no economic sense in your process.

Someone has to hold the whole chain:

Business case → classification → data → architecture → human oversight → operations → KPI → board reporting.

If that person does not exist, the AI agenda is effectively run by a mixture of employees, suppliers, IT and randomly purchased licences.

A thirty-day plan for the CEO

Week 1: find out what is actually running

Do not rely only on centrally purchased licences.

Also map:

  • individually adopted generative tools;
  • AI features built into CRM, ERP and office applications;
  • automations built by individual departments;
  • external agencies using AI on your behalf;
  • pilots that already affect customers or employees.

The output is the first version of the AI register.

Week 2: determine role, risk and owner

For each use case, determine:

  • why it exists;
  • who owns it;
  • whether you are a provider or a deployer;
  • what data it uses;
  • whom it affects;
  • whether it may fall among prohibited or high-risk uses;
  • whether transparency obligations apply;
  • who is legally and operationally accountable for the output.

A system without a named owner must not go to production.

Week 3: set the minimum control layer

For each approved system, define:

  • access and least-privilege permissions;
  • permitted and prohibited data;
  • human approval points;
  • logging;
  • how to report an incident;
  • transparency rules;
  • the required preparation of users;
  • a fallback on failure;
  • the ability to reverse an action or switch the system off.

The goal is not zero risk. The goal is known, proportionate and managed risk.

Week 4: turn the register into board decisions

Put each use case into one of four categories:

  • Continue — proceed under current conditions;
  • Remediate — proceed once a specific gap is closed;
  • Pilot only — restrict to a controlled pilot;
  • Suspend — pause, because the risk or the economics are not acceptable.

The board should not receive a list of AI tools.

It should receive an overview of:

  • what AI earns or saves the company;
  • where risk arises;
  • who is accountable for each system;
  • what must be fixed;
  • what the next phase will cost;
  • which projects should be stopped.

The biggest risk is not the fine

Fines are the visible part of regulation. For most mid-sized companies, though, the first regulatory sanction will not be the biggest cost.

Larger operational costs often arise earlier:

  • several departments pay for the same or overlapping tools;
  • company data ends up in services nobody approved;
  • an AI agent takes an action nobody accepted accountability for;
  • the company has to expensively rebuild a finished integration;
  • employees stop trusting the system's outputs;
  • a customer receives an incorrect promise;
  • vendor lock-in makes changing the model expensive;
  • the system has no KPI, so you cannot decide whether to scale it or end it.

Good AI governance is therefore not a cost invented in Brussels.

It is operational discipline the company would need even if the AI Act did not exist.

What the CEO should approve this week

  1. Appoint a single owner of the AI agenda. Not a working group without authority. One person where accountability stops.
  2. Start an inventory of all AI use cases. Including unofficial tools and AI features embedded in existing software.
  3. Prohibit any new system going to production without registration. Every production use case must have a purpose, an owner, data, human oversight and a KPI.
  4. Review customer-facing systems before 2 August 2026. Especially chatbots, voice agents, deepfake content and automatically published content.
  5. Introduce targeted AI literacy. By role and system, not as one generic course for everyone.
  6. Increase scrutiny of HR, scoring, biometrics and decisions about people. Deferral of high-risk obligations is not consent to uncontrolled deployment.
  7. Separate the legal opinion from operational ownership. A lawyer confirms contested classifications. Someone else must run the whole system.

My recommendation

Do not start with a sprawling "AI Act compliance project".

Start by taking control of the AI you already use.

For a company with one simple AI tool, the agenda can temporarily be handled by the CEO, the CTO or another capable internal owner.

But once AI:

  • runs across multiple departments;
  • uses company or personal data;
  • communicates with customers;
  • affects employees;
  • performs actions in enterprise systems;
  • consumes a significant budget;
  • or is expected to deliver measurable impact,

it is no longer a side IT task.

The company needs someone with the mandate to join business case, technology, governance, vendors, deployment and board reporting into one managed system.

That is the Head of AI role.

Map the AI systems and accountability in your company. In an initial AI Leadership Call we establish where AI is already running, which systems need immediate attention, whether an internal owner is enough, whether you need a narrow remediation — or whether a 90-day AI Leadership Sprint makes sense. No sales deck. If a wider mandate does not make economic sense, I will say so.

Book an AI Leadership Call

Frequently asked questions

Does the AI Act apply to a company whose staff merely use ChatGPT?

Yes. The company is generally a deployer of an AI system and is subject at minimum to the obligation to take proportionate measures supporting AI literacy. Depending on how it is used, obligations relating to transparency, personal data protection, employment law or a specific regulated process may be added.

Do we have to label every text produced with AI?

No. The AI Act does not impose a general obligation to label every text AI was involved in. Specific obligations apply for example to deepfake content and to certain texts published for the purpose of informing the public on matters of public interest. Human review and taking editorial responsibility also matter.

Is sending staff a set of AI usage rules enough?

Simply circulating a document may not be proportionate. Measures should reflect the systems in use, the experience of the users, the purpose of use and the associated risks. The company should be able to evidence what it did and why it considered that proportionate.

Are we legally required to appoint an AI officer or Head of AI?

No. The AI Act does not mandate a specific organisational structure. The company must, however, ensure obligations are met and AI is used responsibly. With multiple systems across departments, keeping consistent rules, accountability and impact measurement without a single owner is very difficult.

If the high-risk rules were deferred, can we wait before preparing?

Technically you have more time to meet the specific high-risk requirements. Operationally, waiting makes no sense. Classification, contracts, data flows, human oversight and documentation are hard to retrofit into a finished system. And the other legal and operational requirements continue to apply.

Does a Head of AI replace a lawyer?

No. A Head of AI prepares the system register, use case classification, operating rules, technical groundwork and the accountability model. A specialist lawyer should confirm contested legal questions. The point of a Head of AI is to make sure the legal conclusion does not stay on paper but is reflected in architecture, processes and day-to-day operations.

Trusted sources

  1. Regulation (EU) 2024/1689 of the European Parliament and of the Council — Artificial Intelligence Act. The foundational text of European AI regulation, in force since 1 August 2024. eur-lex.europa.eu
  2. Regulation (EU) 2026/1744 of the European Parliament and of the Council — Digital Omnibus on AI. The final legal text of the amendments, published in the Official Journal of the EU and in force since 27 July 2026. eur-lex.europa.eu
  3. European Commission: AI Act — application timeline. Current overview of deadlines including 2 December 2027 for Annex III and 2 August 2028 for regulated products. ai-act-service-desk.ec.europa.eu
  4. European Commission: AI Literacy — Questions & Answers. Official interpretation of the amended Article 4, proportionate measures, documentation and oversight. digital-strategy.ec.europa.eu
  5. European Commission: Transparency obligations under Article 50. Guidelines and FAQ on chatbots, marking of synthetic content, deepfakes and texts on matters of public interest. digital-strategy.ec.europa.eu
  6. EU AI Act Service Desk: Article 3 — Definitions. The official European information portal with definitions of provider, deployer and other roles. ai-act-service-desk.ec.europa.eu
  7. EU AI Act Service Desk: Annex III and deployer obligations for high-risk systems. Categories of sensitive uses including employment, education, biometrics and essential services. ai-act-service-desk.ec.europa.eu
  8. European Commission: Guidelines on prohibited AI practices. Interpretation of prohibited practices including emotion recognition in the workplace and in education. digital-strategy.ec.europa.eu
  9. Ministry of Industry and Trade of the Czech Republic: AI Act implementation in Czechia. Information on the Czech implementation, supervisory infrastructure and transparency of AI content. mpo.gov.cz

Sources and legislative deadlines verified as at 28 July 2026. This text is a practical AI governance analysis for company leadership, not individual legal advice.