On 2 August 2026 the transparency provisions of the EU AI Act (Article 50) enter into application. If July went by on other priorities, the checklist below will let you close the topic in August without chaos. Ten points. Each with a short explanation of why it exists and how to check it's done. Tick them off one by one.
1. A register of AI systems in the company
Why: you can't ensure the compliance of systems you don't know exist. The register is the foundation, and also the first thing an auditor or corporate client will ask about.
How to check: there is a single document (a spreadsheet is fine) listing all AI tools and systems: name, provider, department, use, whether the output reaches customers, whether personal data is processed. A designated person updates it with every new rollout.
2. Risk classification of every system
Why: the EU AI Act imposes different obligations depending on category: prohibited practices, high risk (Annex III, obligations from 2 December 2027 after the Digital Omnibus), limited risk (Article 50, from 2 August 2026), minimal risk (no additional obligations).
How to check: every entry in the register has a category assigned along with a short justification. The "don't know" entries have been consulted, internally or with an advisor.
3. Verifying the absence of prohibited practices
Why: the bans (including subliminal manipulation, social scoring, emotion recognition in the workplace) have been in force since February 2025 and carry the highest fines: up to EUR 35 million or 7% of turnover.
How to check: a review of the register against the list of prohibited practices, closed with a written note: "none identified" or a plan for immediate withdrawal.
4. Labelling chatbots and voicebots
Why: the user must know they are talking to AI. This is the core of Article 50.
How to check: visit your own website as a customer would. Before a conversation with the bot starts, is there a clear notice along the lines of "You are talking to an AI assistant"? Is it visible on a phone? Does it work in all language versions of the site?
5. Labelling AI-generated content
Why: content generated or substantially modified by AI, especially published content, requires a legible annotation; deepfakes always require clear disclosure.
How to check: a company rule exists (from what threshold you label, with what wording, where you place it) and is applied consistently on the blog, in social media and in graphic materials. A random sample of the last five publications passes the test.
6. A plan for technical marking (watermarking)
Why: Article 50(2) provides for marking AI content in a machine-readable format. New generative systems are subject to it from 2 August 2026; systems already on the market have a transition period until 2 December 2026, which is only four months longer.
How to check: you know which of your tools support technical marking (metadata, headers, watermarks), and for the rest you have a planned path or a question to the provider with a deadline for the answer.
7. Updating contracts with AI tool providers
Why: responsibility is shared between the system's provider and the deployer using it. Without contractual provisions it's hard to hold the provider to, say, supporting marking or informing you of model changes.
How to check: for the most important tools in the register you have reviewed the contracts and terms of service against the EU AI Act and noted the gaps. New contracts contain clauses on compliance with the regulation.
8. An internal AI usage policy
Why: employees use AI whether or not the company has regulated it. Better that they do it under clear rules: what is allowed, what data must not be pasted into tools, when to label content, who approves new tools.
How to check: the policy exists, it's short (2–4 pages do more than 40), it has been communicated to everyone and has an owner responsible for updates.
9. Team training (AI literacy)
Why: the regulation requires organisations to ensure an adequate level of AI competence among people working with these systems. And beyond the obligation itself, it's the cheapest way to reduce the risk of errors.
How to check: at least one training session has taken place (an hour, in-house, is fine) covering the AI policy rules, labelling obligations and typical risks. An attendance list or confirmations were kept afterwards: this is part of your due diligence documentation.
10. Documentation and periodic review
Why: compliance is a process, not a one-off project. If a regulator, client or partner asks questions, the documentation shows you acted systematically.
How to check: all the points above have a written trace (register, notes, policy, training confirmations), and a review date is in the calendar: quarterly is sensible, and always when a new AI tool is rolled out. The review also covers the upcoming deadlines: 2 December 2026 (watermarking) and 2 December 2027 (Annex III high-risk systems).
How much of this can you do yourselves?
Honestly: most SMEs can close points 1, 4, 8 and 9 on their own within a week or two. Risk classification (points 2–3), the contract review (point 7) and technical marking (point 6) more often call for support from someone who has done this many times and knows where the typical traps are.
ESKOM AI provides advisory and implementation services in AI compliance: from inventory and classification, through the design of labels and policies, to team training. We also develop our own tools, including for data anonymisation and monitoring changes in the law. We implemented these requirements at home first, on eskom.ai, so we speak from practice, not from slides.
FAQ
Can this really be closed out in August?
For a typical SME with a limited number of AI tools: yes. The realistic effort is a dozen or so hours of work spread over 3–4 weeks, assuming one person coordinates the topic. Companies with systems close to the high-risk category should add time for analysis.
Which point should we start with if we only have time for one?
Point 4, labelling the chatbot. It's the most publicly visible obligation under Article 50 and its absence is the easiest to demonstrate. Right after that, point 1, because without the register the rest of the list hangs in a vacuum.
We're only a user of off-the-shelf tools — does the checklist apply to us?
Yes. Most of the points (register, classification, labels, policy, training) apply precisely to deployers of AI, not just its creators. The scope is simply smaller than for a system provider.
Close the list with us
If you'd rather walk through this checklist with someone who has done it many times, book a free compliance consultation via the form at eskom.ai/pl/kontakt. In an hour we'll establish which points you've already closed and which need action.
This article is for information purposes and does not constitute legal advice. Consult a lawyer before making decisions on EU AI Act compliance.