Skip to content

EU AI Act from 02 August 2026.

What every business owner needs to know.

12 min readUpdated 18 July 2026

The EU AI Act already applies: the AI literacy obligation (Art. 4) since February 2025, the transparency obligation (Art. 50) from 02 August 2026. Many SMBs don't know which obligations specifically apply to them. Anyone deploying AI in customer interactions is affected.

EU Regulation 2024/1689 (commonly 'EU AI Act' or 'AI Regulation') is the world's first comprehensive AI regulation. It applies in stages: Art. 4 (AI literacy obligation) since 02 February 2025, Art. 50 (transparency obligation when deploying AI with end users) from 02 August 2026, additional obligations for high-risk systems through 2027. For DACH SMBs in the mid-market (1-50 employees), two main obligations apply in practice, and both can be fulfilled with manageable effort if your AI provider supports them. The bad news: many US providers still don't have full Art. 50 disclosure implemented by default. The good news: German and European providers like rinqo make default disclosure standard from day 1, you don't have to manage compliance yourself.

rinqo is the EU AI Act-compliant provider for DACH SMBs: default transparency announcement at every first AI contact (phone, chat, email), AI literacy templates to adapt for your employee documentation, Hetzner hosting in Germany, AI models with contractually guaranteed EU data processing (EU Data Boundary), data processing agreement at contract closure. The technical part, the Art. 50 disclosure, rinqo handles from day 1; for the Art. 4 documentation you get ready-made templates, without any legal setup of your own.

Start AI Act-compliant

Warum rinqo?

Art. 50 default disclosure

On first contact with a rinqo AI agent, every user clearly learns they are speaking with an AI, wording editable to your brand, disclosure itself not deactivatable.

Art. 4 AI literacy templates

Templates to adapt for documenting deployment limits, escalation logic and data protection measures of your AI setup. Fulfills the obligation since 02.02.2025 with manageable effort.

GDPR + AI Act in one platform

One platform, one compliance story, Hetzner DE, LLM processing in the EU, DPA automatic. Instead of 5 different providers with 5 different compliance stories.

Disclosure fulfilled from day 1

The Art. 50 transparency obligation is active by default at rinqo, in every customer channel. That covers the platform part of your AI Act obligations from day 1, without any legal setup of your own.

GDPR-native, data processing in the EU

Hetzner Falkenstein and Nuremberg, AI models with contractually guaranteed EU data processing (EU Data Boundary). DPA under Art. 28 GDPR, no training on your data.

Updates on regulatory changes

When the EU updates the Code of Practice or Guidelines, rinqo automatically adjusts disclosure wording and AI literacy templates. You stay compliant without reading up.

Vorher. Nachher.

Ohne rinqo

DIY compliance: lawyer for €2,000-€5,000 setup plus monthly lawyer hours for every regulatory change. Disclosure texts to formulate yourself and retrofit into every AI workflow. AI literacy documentation to create yourself. On a violation, the SMB carries the risk.

Mit rinqo

rinqo fulfills the most important EU AI Act obligations from day 1: default disclosure at every first contact, AI literacy templates to adapt, Hetzner hosting, LLM processing in the EU, DPA. Compliance shifts largely from customer to platform provider, transparent pricing from €99 net per month.

What is the EU AI Act and why does it affect SMBs?

The EU AI Act (officially: EU Regulation 2024/1689 on Artificial Intelligence) has been in force since 02 August 2024 but becomes enforceable in stages. It regulates the deployment of AI systems in the EU with a risk-based approach: high-risk systems (e.g. AI in medical diagnosis, personnel selection, credit scoring) require comprehensive conformity assessments. Lower risk (AI in customer interactions, chatbots, voicebots, marketing automation) requires 'merely' transparency obligations, but these are strict from 02 August 2026. What many SMB owners don't know: even if you don't develop the AI yourself but only deploy it (the regulation calls this 'deployer'), you are responsible for the obligations in your business. Anyone using an AI phone assistant, chatbot or marketing AI must inform their end users and document for their employees. The regulation applies EU-wide, also to providers from third countries (USA, UK, Switzerland) when they make AI systems available in the EU. So anyone using a US tool or any other third-party provider must check whether the provider supports the obligations at all.

The 4 most important obligations for DACH SMBs in 2026

First, Art. 4 (AI literacy), already in force since 02 February 2025. Anyone deploying AI in their business must produce minimum documentation of deployment limits and escalation logic. In practice: a PDF describing how your AI is deployed, what it cannot do, when it escalates to humans. Second, Art. 50 (transparency obligation), enforceable from 02 August 2026. Every person interacting with your AI system (caller, chat visitor, email recipient) must be clearly informed at first contact. For voice agents: greeting announcement must disclose AI nature. For chat widgets: persistent AI badge. For emails: header disclaimer. Third, GDPR Art. 28 (data processing), already mandatory since 2018. When deploying third-party AI, a data processing agreement (DPA) must be in place that regulates data processing. Fourth, GDPR Art. 22 (automated decisions), for legally relevant AI decisions, human escalation must be possible. In practice for customer service AI: on complaints, returns, cancellations, the AI agent must be able to escalate to a human.

  • Art. 4 AI literacy: documentation of deployment limits + escalation logic (since 02.02.2025)
  • Art. 50 transparency obligation: disclosure at first AI contact (from 02.08.2026)
  • GDPR Art. 28: data processing agreement with every AI provider
  • GDPR Art. 22: human escalation for legally relevant decisions

EU AI Act fines, the amounts at a glance

The EU AI Act provides graduated fines. Violations of the strictest obligations (prohibited AI practices per Art. 5, social scoring, manipulation, biometric mass surveillance) can be sanctioned with up to €35M or 7 percent of global annual turnover, whichever is higher. Violations of obligations for high-risk AI systems: up to €15M or 3 percent. Violations of transparency obligations (Art. 50) and most other obligations: up to €15M or 3 percent. False or misleading information to authorities: up to €7.5M or 1 percent. For SMBs with annual turnover under €500M, the fixed monetary amounts apply, not the percentage of turnover. In practice, for most SMBs it is above all the Art. 50 transparency obligations that matter, and that is exactly what rinqo covers by default.

EU AI Act vs. GDPR, where the obligations overlap and where not

Many SMBs confuse EU AI Act and GDPR. In fact, the two regulations are complementary: GDPR regulates the processing of personal data (all data attributable to a natural person), EU AI Act regulates the deployment of AI systems regardless of whether personal data is processed. In customer service AI context, both apply simultaneously: GDPR regulates handling of caller data (Hetzner hosting, LLM processing in the EU, DPA, privacy notices per Art. 13 GDPR). EU AI Act additionally regulates transparency obligation (Art. 50, the caller must know they are speaking with an AI) and AI literacy (Art. 4, the employee deploying the AI must know the deployment limits). In practice for DACH SMBs: a GDPR-compliant AI provider is not automatically AI Act-compliant. You need both, GDPR + Art. 50 + Art. 4. rinqo fulfills all three obligations in one platform: Hetzner Germany (GDPR), default disclosure announcement (Art. 50), AI literacy templates to adapt (Art. 4). With US providers, you must check GDPR compliance separately (Cloud Act exposure, DPF volatility remains) and implement Art. 50 disclosure yourself (which is often technically not possible at all).

How rinqo fulfills the EU AI Act, concrete and verifiable

rinqo fulfills all EU AI Act obligations for DACH SMBs from day 1, without the customer having to do any compliance work. First, Art. 50 default disclosure: every rinqo AI agent (phone, chat, email) makes a clear announcement on first contact that this is an AI, wording is editable to your brand voice, disclosure itself not deactivatable. For voice: 'Hello, this is the AI assistant from [company]. You are speaking with an AI, the call is processed for quality assurance.' For chat: persistent AI badge in header + entry banner. For email: 'This response was created with AI support' disclaimer in footer. Second, Art. 4 AI literacy: templates in the rinqo dashboard you can adapt to your specific deployment configuration, which AI models are deployed, which data is processed, which escalation thresholds apply. You document once, keep the documentation current on configuration changes. Third, GDPR Art. 28: DPA contract is automatically provided at contract closure, without separate request. Fourth, GDPR Art. 13: privacy notices are automatically announced at the start of voice agent calls. Fifth, EU hosting: Hetzner Falkenstein and Nuremberg as hosting location, AI models with contractually guaranteed EU data processing (EU Data Boundary, no training on customer data; sub-processors are transparently disclosed on /security), EU data residency for your customer data.

The EU AI Act, explained simply

The AI Act (Regulation (EU) 2024/1689) is Europe's AI law. It sets out the conditions under which companies may use artificial intelligence. Whether you search for “AI Act”, “EU AI Act”, “European AI regulation” or “AI law”, you will land on the same piece of legislation. Its official title is the Regulation on artificial intelligence, but almost everyone simply calls it the AI Act. The regulation classifies AI systems by risk: prohibited practices are banned outright, high-risk systems require extensive evidence, and AI in customer contact is subject to transparency obligations. For most SMEs, two articles matter. Art. 4 has required documented AI literacy within the company since 02.02.2025: who uses AI for what, where the limits sit, and when a human takes over. Art. 50 requires AI in customer-facing contact to be disclosed from 02.08.2026. Importantly, these obligations apply even if you only use AI rather than develop it yourself. The regulation calls this role the “deployer”: the party that puts an AI system to use in its own business. An AI phone assistant, a chat widget or an email agent all fall under it. rinqo takes the technical part off your hands. The phone, chat and email agents identify themselves as AI by default in customer contact. You can adjust the wording, but you cannot switch the disclosure off. Setup takes around 10 minutes, and the agents work in 17 languages.

The duty to disclose AI: what Art. 50 actually requires

The disclosure obligation means every person must be clearly informed when they are interacting with an AI. It is set out in Art. 50 of the AI Act 2024/1689 and becomes binding on 02.08.2026. Who is affected? Every company that uses AI in customer contact, regardless of size or sector. There is no SME exemption and no headcount threshold. What does the obligation require in practice? On the phone, an announcement at the start of the call that discloses the AI. In chat, a visible notice that an AI agent is responding. For email, a note that the reply was produced with AI support. The information must come at first contact, not somewhere in the small print. What happens if you fail to comply? Fines of up to 15 million euros or 3 per cent of global annual turnover, whichever is higher. How does rinqo handle this? In every customer channel (phone, chat, email), the disclosure is switched on by default. You can adapt the wording to your brand, such as the greeting and the tone. You cannot switch the disclosure off; that is a deliberate design decision. As a result, the Art. 50 disclosure obligation is technically covered from the very first call, with no legal setup of your own. In addition, the data processing agreement (DPA) under Art. 28 GDPR is provided when you sign the contract.

High-risk AI: does this affect my business?

Customer service agents are, as a rule, not high-risk AI. Annex III of the AI Act lists the high-risk areas, and ordinary customer contact is not one of them. High-risk would be, for example: AI that selects job applicants or evaluates employees. AI that decides on creditworthiness. AI that controls critical infrastructure such as power or water networks. Systems like these require conformity assessments, risk management and documented human oversight. An AI agent that answers calls, responds to questions, books appointments and hands complex cases to humans does not fall into these categories. It is subject to the transparency obligations of Art. 50, not the high-risk requirements. That is exactly how the rinqo agents are built: they answer, sort and escalate. They make no decisions about employment, credit or any other Annex III area. Two honest caveats. First, the classification depends on the specific use, not on the product name. If you use the same agent for recruitment or credit decisions, you move into high-risk territory. Second, this page is a guide, not legal advice. In borderline cases, have the intended use reviewed by a lawyer. For the typical scenario, customer enquiries by phone, chat and email, the picture stays straightforward: disclosure under Art. 50 is enough, and with rinqo it is active by default.

EU AI Act summary: timeline and obligations for 2026

For SMEs, two dates matter: Art. 4 has applied since 02.02.2025, and Art. 50 applies from 02.08.2026. That is the shortest honest summary of the AI Act 2024/1689. Since 02.02.2025 you have been required to document how AI is used in your company: limits of use, data processed, escalation rules (Art. 4, AI literacy). From 02.08.2026, every AI in customer contact must be disclosed (Art. 50, transparency). Breaches cost up to 15 million euros or 3 per cent of global annual turnover. What you should do now, in practical terms: first, list every AI tool running in customer contact in your business. Second, produce the Art. 4 documentation; rinqo provides templates for this. Third, check for each tool whether the Art. 50 disclosure is active. Fourth, check whether a data processing agreement under Art. 28 GDPR is in place. With rinqo, points three and four are done from day one: disclosure active by default across every customer channel (phone, chat, email), and the DPA provided at contract signing. Hosting sits in Germany with Hetzner (Falkenstein and Nuremberg, ISO 27001:2022). The language models run with contractually guaranteed processing within the EU Data Boundary, with no training on your customer data. Pricing starts at 99 euros net per month, and every agent is live and testable on our website beforehand.

  • 02.02.2025: Art. 4 AI literacy applies, with a documentation duty for every company using AI
  • 02.08.2026: Art. 50 disclosure obligation for AI in customer contact
  • Fines: up to 15 million euros or 3 per cent of global annual turnover, whichever is higher
  • Do now: list your AI tools, produce the Art. 4 documentation, check disclosure and the DPA

Frequently asked questions

Sources

Last updated: 2026-07-18

Sven Pflüger

Sven Pflüger

Founder & CEO, rinqo

Sven builds rinqo from a simple observation: most AI tools are built for large enterprises and overwhelm the business around the corner. The workshop in the Black Forest, the veterinary practice in Salzburg, the family hotel in Tyrol get software that doesn't speak their language. rinqo flips that: on European servers, set up in ten minutes, in 17 languages, with templates built by the industries themselves.

LinkedIn

Last updated:

Try it live

View agent

Related solutions