Perspective July 20, 2026 8 min read

The AI rule you're already under — and why the rewrite everyone called relief isn't quite one

By PeakSpitz Team

On 18 June, in Brussels, the European Union finished rewriting a piece of its own AI law. The document runs to 102 pages and carries the reference PE-CONS 30/26. It was signed on 8 July. Almost nobody outside a compliance department read it, and the coverage it did get said roughly one thing: good news for small firms.

That reading is correct about the intention. The Union wrote the reason into the text itself. The old wording, it says, was "not suitable for all types of providers and deployers" and created "an additional compliance burden, particularly for smaller enterprises."

Here is the part that got lost.

The clause they softened is Article 4 of the AI Act. It has applied to you since 2 February 2025 — not to AI companies, to you, the business that merely uses the stuff. It has been law for a year and a half, and it is still barely known outside compliance teams. A rule you didn't know you were under does not become less binding because someone has now made it gentler.

The direction of travel matters more than either date

Take two dates and hold them next to each other.

2 February 2025. Article 4 — the AI literacy duty — took effect for "providers and deployers." A provider builds an AI system. A deployer uses one under its own authority. If a member of your staff uses an AI feature inside software you already bought, your business is a deployer. That is the whole test. There is no employee threshold and no turnover floor.

2 August 2026. A different chapter of the same act starts to apply, and its title is not subtle: "Transparency obligations for providers and deployers of certain AI systems." Again, both. Article 50 sets out duties that land on the business using the system, not only the one that sold it.

One clause about competence, already live. One chapter about disclosure, arriving this month. Two years ago, essentially all of this regulation pointed at the people building AI. The line has been moving steadily towards the people using it, and it has not stopped moving. That is the trend, and it is the reason this outlives the news cycle.

First, what this is not

A note of caution belongs here, because a small industry is forming around making owners frightened of this.

There is no AI licence. There is no register you must join. There is no certificate, and no inspector is coming to audit your staff's competence. The rewritten Article 4 says so in terms: the obligation "does not require providers or deployers to guarantee any specific level of AI literacy of any individual." The European Commission has committed to publishing practical examples of how to comply, free.

Nobody should stop using AI features over this, and nobody should buy a compliance package this week. The large software vendors have real compliance teams and will handle their own side of it properly — that part genuinely is not your problem. Your problem is smaller and more specific, and it is the question underneath all of it:

If someone in your business acted on something an AI feature suggested, and it turned out to be wrong — would you know it happened, would you know who approved it, and would you know what they were looking at when they did?

Many businesses cannot answer that. Not because they are careless. Because nothing in the way the software is put together ever asked them to.

Why a law aimed at AI companies has your name on it

Start with the part that isn't your fault.

The regulation splits the world into providers and deployers, and it puts the heavy obligations — conformity assessments, risk management, technical documentation — on providers. That is the right way round. But a handful of duties attach to use, because the Union took the view that some risks only appear at the point where a real person acts on a machine's output, in a real business, on a real Tuesday.

You didn't opt into this by adopting some ambitious AI strategy. You opted in when your accounting tool added a suggestion box, or your inbox started drafting replies, or your design software got a generate button. The AI arrived inside tools you already owned, as an upgrade, usually without a decision being taken.

What actually changes on 2 August

Article 50 is about disclosure — telling people when a machine was involved.

Most of it points at providers: systems that interact with people should say they are systems; synthetic audio, image, video and text should be machine-readably marked as artificially generated. Your vendors own that.

Two paragraphs point at deployers, and these are yours. If you use a system that generates or manipulates image, audio or video amounting to a deep fake, you must disclose it. And if you publish AI-generated text to inform the public on a matter of public interest, you must disclose that too.

Read that second one slowly if you run marketing through an AI tool.

What "taking measures" looks like with eleven staff and no compliance officer

The honest answer is: less than you fear, and something different from what you'd guess.

The instinct is to book a training course, keep the certificate, and file it. That is not wrong, and it is not enough, because the duty is not about certificates — it's about people understanding the tool in the context they use it in. A two-hour generic AI webinar does not teach an estimator what a quoting tool does when it has thin data.

The version that actually works is duller. Write down which tools in your business have AI in them — most owners get this list wrong on the first pass, because the feature arrived quietly. For each one, write down what it is allowed to do on its own and what needs a human to say yes. Tell the people who use it what it is good at and where it goes wrong. Keep a record when someone approves something that matters.

That's it. It is a morning's work, not a project.

The assumptions that won't survive an incident

These are the common ones, and every one of them is a reasonable thing to have believed:

  • "We don't use AI." You almost certainly do. It came bundled into something you already pay for.
  • "The vendor is responsible." For their obligations, yes. Not for what your people do with the output.
  • "We're too small." There is no size threshold in Article 4. There is no size threshold in the deployer paragraphs of Article 50 either.
  • "Someone checked it." If nobody can say who, on what date, seeing what — then for any purpose that matters later, nobody checked it.

Where this departs from the consensus

Here is where this reading parts company with the general reaction, and it is a reading worth arguing with.

The rewrite is being reported as a win for small business. It is, at best, a mixed one, for two reasons.

First, the new wording is unmeasurable. The duty moved from taking measures to ensure a sufficient level of AI literacy, to taking measures to support the development of it. Softer, yes. But "ensure a sufficient level," for all its heaviness, told you what finished looked like. "Support the development of" has no finish line. You cannot prove you did it. If a dispute ever turns on whether a business took the duty seriously, vaguer wording is not obviously its friend — the only thing that will speak for it is whatever was actually written down at the time.

Second, and more practically: at the time of writing, the rewrite is not in force. The final act was signed on 8 July and is awaiting publication in the Official Journal. It takes effect three days after that. Until then, the version of Article 4 binding on European businesses is still the original, stricter one — the "ensure a sufficient level" text.

So the relief is real, and it is also, today, in the future tense. Firms currently relaxing because they read a headline are relaxing about a duty that at this moment still says "ensure."

All of which may matter less in practice than it reads. Enforcement against an eleven-person business over AI literacy is not a likely event, and anyone claiming otherwise is selling something. But "you probably won't get caught" is a poor foundation for anything, and it is a particularly poor answer to give a customer who asks.

A disclosure, which is also the point

This essay is published by PeakSpitz, which builds business-management software that includes an AI assistant. It acts the moment a person approves it, never before — a design decision taken long before this regulation, for reasons about trust rather than compliance. There is a commercial interest here, and the piece should be read knowing it.

It was written and edited by people, and PeakSpitz holds editorial responsibility for it. That is worth stating plainly, because it is not only good manners. Article 50's disclosure duty for AI-generated text carries an exemption, written into the law, for content that "has undergone a process of human review or editorial control and where a natural or legal person holds editorial responsibility for the publication."

The law's own way out is a named person — natural or legal — standing behind the output. That is more or less the whole lesson, and it applies far past this regulation.

Where the line is

Not a checklist. Four thresholds — if any is true on Monday, it's worth an hour:

  • You cannot name, from memory, every tool in your business with an AI feature in it.
  • Something goes out to a customer or the public with AI in its drafting, and no named person signs off before it leaves.
  • Someone would have to reconstruct from memory who approved a decision that mattered.
  • You publish AI-drafted text about matters of public interest, and you have not decided what you disclose.

If none of them is true, you were compliant before you read this, and you can get on with your day.

References

Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (the AI Act) — Article 4 (AI literacy), Article 50 (transparency obligations for providers and deployers of certain AI systems), and Article 113 (entry into force and application, which sets 2 February 2025 for Chapters I and II, and 2 August 2026 as the general date). Full text via EUR-Lex, CELEX 32024R1689.

Digital Omnibus on AI — Council document PE-CONS 30/26, Brussels, 18 June 2026; final act signed 8 July 2026. Replaces Article 4 and inserts Article 111(4). Available from the Council document register at data.consilium.europa.eu.

European Parliament Legislative Observatory, procedure 2025/0359(COD) — status as at 20 July 2026: "Procedure completed, awaiting publication in Official Journal."

Every quotation above is taken verbatim from those texts.

Ready to Stop Running Your Business on Forms?