Using AI without breaking the rules
The AI Act has largely applied since 2 August 2026. The AI literacy duty under Article 4 has been in force since 2 February 2025 and affects practically every company using AI tools. We bring your processes, your documentation and your team up to that standard.
What actually applies right now
As at 17 August 2026. The Digital Omnibus (Regulation (EU) 2026/1744, in force since 27 July 2026) postponed the deadlines for high-risk systems.
since 2 February 2025
AI literacy, Article 4
Staff using AI tools must be sufficiently trained. This is currently the only duty that applies directly to nearly all companies, including where they merely use ChatGPT or Copilot.
since 2 August 2026
Transparency duties, Article 50
Chatbots must identify themselves as AI; AI-generated content and deepfakes must be labelled.
from 2 December 2027
High-risk under Annex III
Duties for high-risk systems under Article 6(2). Postponed by the Digital Omnibus.
from 2 August 2028
High-risk under Annex I
Duties for high-risk systems under Article 6(1).
What we actually do
AI inventory
Which AI tools are in use, who uses them for what, and which data goes in. The result is a documented AI inventory as the basis for any further assessment.
AI inventory and usage overview
Article 4 AI literacy training
Practical training for the people using AI day to day: what is allowed, what is not, which data may go in, how to spot bad output. With attendance records.
Training, materials, attendance record
Implementing transparency
Labelling chatbots and AI-generated content technically and editorially, so Article 50 is actually met in daily operation.
Implemented labelling, editorial guide
Embedding data protection in processes
Documenting processing activities, recording technical and organisational measures, building deletion concepts into workflows rather than parking them in a folder.
Process documentation, TOM overview
Privacy-friendly automation
Building automations with data minimisation, access separation and traceability from the start instead of retrofitting them.
Implemented automation with data concept
Internal AI policy
A short, readable rule set on which tools are allowed for which purposes and which data must never go in. Short enough that people read it.
AI policy and team rollout
Building your AI Act documentation
We produce the records the regulation provides for: classification, system description, data provenance, controls, human oversight, logging. Structured along Annex IV, and for SMEs in the simplified form under Article 11.
Documentation set per AI system
Setting up logging and evidence
Building automations so that they traceably record what happened with which data, with retention that carries the six-month requirement. Retrofitting this is expensive.
Logging in operation, retention concept
The documentation the AI Act provides for
The AI Act calls for fewer forms than feared. The ones it does call for, though, have to exist when someone asks. This overview shows which records the regulation provides for and where each one comes from.
Which of these your specific case needs depends on the individual system and on your role. This overview restates the content of the regulation; it is not an assessment of your situation.
Evidence of AI literacy
Article 4, in force since 2 February 2025
The regulation prescribes no particular form but does require sufficiently trained staff. In practice: a training concept, the content covered, and attendance records showing who learned what and when.
Applies to: Providers and deployers
Labelling and user-facing notices
Article 50, in force since 2 August 2026
Chatbots must be identifiable as AI, and AI-generated content and deepfakes must be labelled. What has to be shown is the implementation itself, backed by a labelling and editorial guideline.
Applies to: Providers and deployers of affected systems
Your assessment when you conclude a system is not high-risk
Article 6(4)
Anyone who considers an Annex III system not to be high-risk must document that assessment before the system is placed on the market or put into service, register under Article 49(2), and provide the documentation to authorities on request.
Applies to: Providers of systems in the Annex III areas
Technical documentation
Article 11 with Annex IV
Nine sections, from the system description through risk management to the post-market monitoring plan. SMEs and start-ups may supply the elements in simplified form; the Commission provides a simplified form that notified bodies must accept.
Applies to: Providers of high-risk systems, Annex III from 2 December 2027
Logs
Article 12 for providers, Article 26(6) for deployers
Systems must record events automatically. Deployers keep those logs for at least six months. That is a requirement on the technical build, not merely on filing.
Applies to: High-risk systems
Deployer duties in day-to-day operation
Article 26
Use in line with the instructions, control of input data, assigned human oversight, monitoring of operation, incident reporting, and informing affected workers and their representatives under paragraph 7.
Applies to: Deployers of high-risk systems
Fundamental rights impact assessment
Article 27
A private-sector SME outside public service provision is generally not covered. Worth clarifying early, because the scope is usually assumed to be wider than it is.
Applies to: Public bodies, private providers of public services, specific cases under Annex III points 5(b) and 5(c)
What the GDPR already requires
Articles 30, 32 and 35 GDPR
Records of processing activities, technical and organisational measures and, where risk is high, a data protection impact assessment. These duties exist independently of the AI Act and overlap with it in substance.
Applies to: effectively every company
The point SMEs most often miss
Anyone who deploys an AI system under their own name or substantially modifies it can become a provider in their own right under Article 25, even if they only bought it in. The same applies where a system’s intended purpose is changed so that it becomes high-risk. A lean deployer role then turns into the full set of provider duties, technical documentation included. This is exactly what we keep in view while building automations: we record what was built, with which data and with which controls, while the answers are still known.
Common questions on the AI Act and documentation
- What documentation does the AI Act require from an SME?
- It depends on the role. A company that only uses AI mainly needs evidence of sufficient AI literacy under Article 4 and, where chatbots or AI-generated content are involved, the labelling required by Article 50. Technical documentation under Article 11 with Annex IV applies to providers of high-risk systems, for Annex III from 2 December 2027. GDPR duties under Articles 30, 32 and 35 apply regardless. Which duty applies to your specific case is a legal question.
- Does the AI Act apply if we only use ChatGPT or Copilot?
- For the Article 4 AI literacy duty, yes. It has applied since 2 February 2025 to providers and deployers and does not require you to build anything yourself. The regulation prescribes no particular form of evidence; a training concept, the content covered and attendance records are the usual approach.
- Can we become a provider even though we only bought the system in?
- Yes. Under Article 25, anyone who deploys a high-risk system under their own name, substantially modifies it, or changes a system’s intended purpose so that it becomes high-risk becomes a provider. The full provider duties then apply, technical documentation included.
- May SMEs keep the technical documentation in simplified form?
- Article 11(1) allows SMEs and start-ups to provide the Annex IV elements in a simplified manner. The Commission provides a simplified form which notified bodies must accept for the conformity assessment. What is simplified is the form, not the substance.
- Does Optima Solutions produce the documentation or review it legally?
- We produce it. Optima Solutions is a management consultancy, not a law firm: we take stock, document, set up logging and train your team. The legal assessment of whether the records are sufficient in your case belongs to your legal counsel.
What we explicitly do not do
Optima Solutions is a management consultancy, not a law firm. We assess the current state, document, design processes and train your team. We do not produce legal opinions, do not legally assess whether a processing operation is lawful, do not carry out conformity assessment under the AI Act and do not certify conformity. We are not a notified body and not a certification body.
- For legal assessment we work with your legal counsel or a data protection lawyer, and prepare the documentation so that review is quick.
- Conformity assessment under the AI Act, where required, is carried out by the bodies designated for it, not by us.
- Our output is organisational and technical implementation plus documentation, not a promise of a legal outcome.
- We produce documentation following the content of the regulation. We do not confirm that it is legally sufficient in your specific case; that assessment belongs to the legal review.
Where do you stand on the AI Act?
In a first conversation we clarify which duties currently affect you and what needs doing organisationally.
The information on this page reflects the legal position as at 17 August 2026 and is provided for general information. It does not constitute legal advice and creates no client relationship.