Compliance & AI

AI Act: what actually applies to your AI tools since 2 August 2026

2 August 2026 was the AI Act's big deadline. It has just passed, and two opposite stories have been circulating since, both of them wrong. The first says the AI Act has been postponed and there is nothing to do. The second announces an avalanche of obligations for any business that touches AI. The reality comes down to one distinction: what was postponed concerns high-risk systems; what applies concerns everyone.

This article sets out what the European AI Regulation actually requires of a professional using AI tools day to day, using voice dictation as a worked example. And, above all, what it does not settle at all, contrary to widespread belief.

One single regulation, applicable across all 27 Member States

First misconception to clear up: the AI Act is not a national law. It is Regulation (EU) 2024/1689, which entered into force on 1 August 2024. Two practical consequences follow:

Also worth noting: paragraph 10 of that same article carves out the obligations of deployers who are natural persons using an AI system in the course of a purely personal, non-professional activity. Dictating your shopping list engages nothing. Dictating your client notes does.

The real timeline, after the digital omnibus

On 8 July 2026 the Union adopted Regulation (EU) 2026/1744, known as the digital omnibus on AI, published in the Official Journal of the European Union on 24 July 2026 and in force since 27 July. This is what redrew the timeline, and it is the source of the rumour of a blanket postponement. Here is what it changes, and what it does not.

Key takeaway

What was postponed is the heavy compliance machinery for high-risk systems: technical documentation, risk management, conformity assessment. The prohibitions, the transparency rules and the penalties are very much in force. The shorthand "the AI Act has been postponed" is false.

The figures, to put the stakes in perspective: up to 35 million euros or 7 % of total worldwide annual turnover for a prohibited practice, and up to 15 million or 3 % for breaching the obligations of providers or deployers, or the transparency rules in Article 50, whichever is higher. One nuance that matters for an SME or a start-up: Article 99(6) provides that in their case it is the lower of the two figures that applies, not the higher.

The four risk tiers, and where a dictation tool lands

The AI Act does not regulate AI as a block: it sorts systems by risk tier, and makes the obligations depend on that classification. Four levels, from the most constrained to the lightest: unacceptable risk (prohibited), high risk (heavily regulated), specific transparency risk (disclosure duty), minimal risk (no particular obligation).

The point almost everyone misses: it is the intended purpose of the system that determines its tier, not the technology inside it. The same speech recognition building block can be minimal risk or high risk depending on what it is intended for.

In other words, the question to put to a vendor is not "does your tool use AI?", but "what is your system intended for, and which risk tier do you place it in?". The answer should be reasoned, not decorative.

The real trap for voice tools: inferring emotions

For a tool that listens to humans speak, the provision that deserves the most attention is not the high-risk chapter, it is Article 5. Its paragraph 1, point (f), prohibits AI systems used to infer the emotions of a natural person in the areas of workplace and education institutions, except where the use is intended for medical or safety reasons.

This is not a future obligation: it is a prohibition in force since 2 February 2025, in the most heavily penalised category of the Regulation. And it does not target the vendor alone: a company that deploys such a tool among its staff is squarely concerned.

The line to hold is clear: transcribing is not inferring. A dictation tool turns what you say into text, it does not analyse your emotional state. Caution is warranted, however, around the features some meeting tools advertise: sentiment analysis of participants, engagement scoring, stress or tone detection. In a workplace setting, those marketing promises can tip into the prohibited zone.

The question to ask before rolling out a voice tool internally

Does the tool simply transcribe what is said, or does it claim to deduce something from the way it is said? The first is minimal risk. The second, in a workplace, deserves legal advice before any deployment.

Do you have to watermark text produced with AI?

This is the most widespread confusion since 2 August 2026. Article 50(2) requires providers of AI systems that generate synthetic audio, image, video or text content to mark those outputs in a machine-readable format. Many conclude that any text written with the help of AI must now carry a mark.

That is inaccurate, and the Regulation says so itself. The same paragraph specifies: "This obligation shall not apply to the extent the AI systems perform an assistive function for standard editing or do not substantially alter the input data provided by the deployer or the semantics thereof."

A voice dictation tool sits squarely inside that exemption. It transcribes your words, then fixes punctuation, grammar and hesitations. It does not manufacture content on your behalf and does not change the meaning of what you said: it formats input data you provided. The text remains yours. The difference from a tool that drafts an article from a three-line prompt is one of nature, not of degree.

Two caveats, on the other hand, worth knowing:

What the AI Act requires of the professional user

The Regulation distinguishes two main roles. The provider develops the system and places it on the market. The deployer uses it under its own authority, in a professional capacity. If you equip your teams with an AI tool, or use one yourself in the course of your work, you are a deployer. Three things concern you in practice.

1. AI literacy (Article 4), softened by the omnibus. The original text required providers and deployers to ensure "a sufficient level" of AI literacy among staff. Regulation (EU) 2026/1744 replaced it with a markedly lighter formula: providers and deployers "shall take measures to support the development of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf", and the amended article adds that this obligation does not require them to guarantee any specific level of AI literacy for any individual. It moves from an obligation of result to an obligation of effort. Worth noting: Article 4 does not appear in the list of infringements subject to fines under Article 99. The obligation exists, but it carries no direct penalty at Union level.

2. Prohibited practices (Article 5). You must not use a tool that falls within the Article 5 blacklist, including the inference of emotions at work discussed above. It is the only genuinely heavy constraint on an ordinary user, and it is already in force.

3. Deployer obligations for high-risk systems (Article 26). These are substantial: human oversight, log retention, informing the workers concerned. But they only bite if you actually deploy a system classified as high risk, and not before 2 December 2027 for Annex III.

Let us be straight about this

For an SME, a professional firm or a freelancer using voice dictation, an AI-assisted mail client or a proofreader, the AI Act imposes no compliance file, no impact assessment and no audit. Telling you otherwise would be dishonest. The compliance question that genuinely concerns you lies elsewhere, and that is the subject of the next section.

The crucial point: the AI Act says nothing about sovereignty

This is the costliest confusion, because it creates a false sense of security. The AI Act governs the placing on the market and the use of AI systems: what they are allowed to do, how they must be documented, what they must disclose. It contains no data localisation requirement.

Nowhere does the Regulation require your audio, your text or your documents to be processed in Europe. Nowhere does it neutralise the US Cloud Act. A tool can be beyond reproach under the AI Act and still route every one of your dictations to servers operated by a company subject to US law, and therefore compellable by a US order.

What governs those questions is the GDPR, and the GDPR alone: lawfulness of processing, retention periods, processors, and the framework for transfers outside the European Union under its Chapter V. The AI Act says as much itself, in Article 2(7): Union law on the protection of personal data continues to apply to personal data processed in the context of the Regulation. The two texts stack, one does not replace the other.

Key takeaway

"AI Act compliant" does not mean "your data stays in Europe". These are two entirely separate questions, and for a profession bound by confidentiality it is the second one that decides.

We go into that second question, by far the more decisive in practice, in our dedicated guide: voice dictation and GDPR, where does your voice go. It explains why server location is not enough, what the Data Privacy Framework is really worth, and why the jurisdiction a vendor answers to outweighs the address of its datacenters. For professions bound by confidentiality, the applicable framework is set out on our page on attorney-client privilege.

6 questions to ask any AI vendor

A simple way to decide, combining both regulations. The first questions come from the AI Act, the last ones from the GDPR, and those are often the ones that make the difference.

  1. What is the declared intended purpose of your system, and which risk tier do you place it in? Expect an answer reasoned against Annex III, not a bare "we are compliant".
  2. Does your tool infer emotions, or categorise people from their voice? In a workplace, the right answer is no, without ambiguity.
  3. Do your outputs fall under the marking obligation in Article 50(2), or under the assistive editing exemption? A serious vendor knows where it stands and why.
  4. Which AI models do you use, where are they run, and from which suppliers? It is the only way to know who really handles your data at the end of the chain. A vendor calling a third party's API exposes you to that third party, whatever else it may say.
  5. Is my data used to train your models, and how long is it kept? The right answers: no, and zero retention.
  6. Where is my data processed, by which company, and under which jurisdiction? Look for processing in the Union by a European company, not merely a "datacenter in Europe".

Where Fast Dictate stands

Fast Dictate is a European voice dictation tool. Here are our answers to the six questions above, in order:

Beyond that, Fast Dictate works everywhere: Word, Gmail, Notion, your browser, any text field, with a single shortcut on Windows and Mac. The free plan gives you 2,000 words per week, no credit card.

Useful compliance is not what you advertise, it is what can be checked.

The AI Act asks what a tool is allowed to do. The GDPR asks where your data goes and who can reach it. Fast Dictate answers both in writing. See the detail on our Security page and our pricing.

This article is informational and does not constitute legal advice. The classification of an AI system depends on its intended purpose and its actual use: if you are in doubt about your own situation, seek professional advice. The official sources are available on EUR-Lex and on the European Commission page on the AI Act. Article current as of 15 August 2026.

Frequently asked questions

Has the AI Act been postponed?

Not as a whole. Regulation (EU) 2026/1744, the digital omnibus on AI, published in the Official Journal on 24 July 2026, postponed the obligations for high-risk systems: to 2 December 2027 for Annex III, and to 2 August 2028 for Annex I. Everything else applies: prohibited practices since 2 February 2025, penalties since 2 August 2025, and Article 50 transparency since 2 August 2026.

Does the AI Act apply in the same way in every Member State?

Yes. Regulation (EU) 2024/1689 applies directly in all 27 Member States with no transposing law, and its content is identical everywhere. Member States only designate their supervisory authorities and set their penalty regime. Its reach is also extraterritorial: a provider or deployer established in a third country is covered where the output produced by the system is used in the Union.

Is a voice dictation tool a high-risk AI system?

No. Classification depends on the intended purpose of the system, not on the technology it uses. A tool intended to turn speech into text appears in none of the eight areas of Annex III: it is minimal risk. The same speech engine would become high risk if it were intended to assess job candidates or to recognise emotions.

Do you have to disclose that a text was dictated using AI?

As a rule, no. Article 50(2) requires synthetic content to be marked, but states that the obligation does not apply to the extent the AI system performs an assistive function for standard editing, or does not substantially alter the input data or its semantics. A tool that transcribes your own words falls within that exemption. Caveat: Article 50(4) requires a disclosure for text published to inform the public on matters of public interest, unless it underwent human editorial review with editorial responsibility assumed.

Does the AI Act require data to be hosted in Europe?

No. The AI Act governs the placing on the market and the use of AI systems. It contains no data localisation requirement and does not neutralise the US Cloud Act. A tool can be fully AI Act compliant and still send your data to servers subject to US law. Localisation and transfers outside the European Union are governed by the GDPR, and by the GDPR alone.

Try Fast Dictate for free →

Related articles

Privacy & GDPR

Voice dictation and GDPR: where does your voice go?

By Pierrick Michel · August 2026