In exactly six days, on August 2, 2026, the European regulation on artificial intelligence — the AI Act — will become applicable in almost its entirety. Adopted in 2024 after years of negotiations, this landmark legislation now governs the development and use of AI systems in Europe. For French businesses, large and small, the time for theoretical questions is over: they now need to understand what applies in practice and what consequences it entails.

A phased timetable reaching maturity

The AI Act did not arrive all at once. Its provisions have been applied in stages since it entered into force in August 2024:

  • February 2025: AI systems deemed unacceptable were prohibited, including social scoring of citizens and psychological manipulation without their knowledge.
  • August 2025: specific obligations began applying to general-purpose AI models (GPAI) — large language models such as GPT or Claude, which must notably comply with transparency and copyright rules.
  • August 2, 2026: transparency obligations under Article 50 take effect, along with the start of application for a large share of high-risk AI systems.

From that date onward, failures to comply with the transparency rules can be fully penalized under the regulatory framework.

What takes effect on August 2: two key obligations

1. Tell users that they are speaking to an AI

This is the most direct obligation, and it affects a very large number of businesses. If you deploy a chatbot, virtual assistant or any conversational system on your website or applications, you must clearly inform users that they are interacting with a machine, not a human. This requirement applies whenever there is a reasonable risk of confusion.

In practice, a simple banner or introductory notice — “You are chatting with our AI assistant” — will often be enough. What is not acceptable is deliberately designing a chatbot to impersonate a real person.

2. Identify AI-generated content

Deepfakes and synthetic content (images, videos and text) produced by AI in contexts that could mislead the public must be labelled as such. This requirement particularly affects political, informational and commercial content. Platforms hosting this type of content also bear part of the responsibility under the scheme.

High-risk systems: gradual compliance

The AI Act classifies AI systems according to their potential level of risk. High-risk systems are those that make or influence decisions with significant consequences for individuals: recruitment and candidate assessment, credit scoring, academic grading, access control, medical decisions and more.

Good news for businesses: most of the heaviest obligations for these systems — documented risk management, mandatory human oversight and decision traceability — have been pushed back to December 2027 following negotiations on the “Digital Omnibus” adopted at the beginning of the year. This gives developers and deployers of such solutions a little more time. But beware: adaptation must begin now, not at the last minute.

Who is actually affected in France?

The AI Act applies to any organization that deploys or markets AI systems within the European Union, regardless of its size or country of establishment. The most common cases in France include:

  • E-commerce and customer service: support chatbots, recommendation agents and personalization tools.
  • HR and recruitment: CV-screening software, candidate assessment tools and performance-management systems.
  • Finance and credit: automated scoring, fraud detection and personalized advice.
  • Marketing and communication: AI-generated images, text or videos published for the general public.
  • Healthcare: diagnostic-support tools, triage systems and medical devices incorporating AI.

Very small businesses and SMEs are not exempt, but the regulation takes their size into account: when a penalty is imposed, the lower amount between the fixed ceiling and the percentage of worldwide turnover applies, which in practice limits their immediate financial exposure.

What are the penalties for non-compliance?

The AI Act provides for a deterrent range of penalties. The maximum amounts are:

  • €35 million or 7% of worldwide turnover for the most serious infringements involving prohibited systems.
  • €15 million or 3% of worldwide turnover for failure to comply with obligations concerning high-risk systems, GPAI or transparency rules.
  • €7.5 million or 1.5% of worldwide turnover for supplying incorrect information to the authorities.

In France, the CNIL has been designated as the competent supervisory authority for some obligations, particularly those involving personal data. Other sector-specific authorities may also be involved depending on the field.

What should you do before August 2?

If you have not yet begun a compliance process, these are the priority actions:

  • Inventory your AI systems: list every tool and application using AI in your organization, whether developed internally or purchased from a supplier.
  • Assess the risk level: for each system, determine whether it falls into the “high-risk” category under the AI Act criteria, particularly where decisions affect individuals in sensitive areas.
  • Update your conversational interfaces: add a clear AI identification notice to your chatbots and virtual assistants.
  • Train your teams: Article 4 of the AI Act requires businesses to ensure a sufficient level of “AI literacy” among people working with these systems.
  • Document your practices: begin compiling a record of AI governance within your organization — it will be essential for future obligations.

A law forming part of a lasting transformation

Beyond the immediate obligations, the AI Act signals a paradigm shift. Artificial intelligence is no longer an unregulated space: it is now treated like any other technology with a major social impact, with corresponding responsibilities and safeguards. For businesses that anticipate the change, it is also an opportunity to earn the trust of customers and partners by demonstrating a responsible approach to AI.

August 2, 2026 is not an end point, but a starting point. Businesses that prepare seriously will be one step ahead as the regulatory framework continues to evolve alongside the technology itself.