EU AI Act compliance when your company uses ChatGPT
If your team uses ChatGPT for drafting, summarising, research, or code, your company is a deployer of an AI system under Regulation (EU) 2024/1689. Deployer status does not depend on how much you use the tool or whether you pay for it.
The good news is that ordinary internal use of ChatGPT sits at the light end of the Act. The obligation people miss is Article 4, which has been enforceable since 2 February 2025 and applies the moment staff start using the tool.
Are you a provider or a deployer?
OpenAI is the provider of the model. Your company is the deployer. Provider duties such as conformity assessment and EU database registration sit with OpenAI, not with you.
How this is classified under the Act
General-purpose drafting, summarising, and internal research does not fall into any Annex III high-risk domain. The system is not making or materially influencing decisions about people in a regulated area, so the classification lands at minimal risk and the memo records that reasoning.
What changes the answer: The classification changes if you point ChatGPT at a regulated decision. Screening job applications, ranking candidates, assessing creditworthiness, or evaluating students moves the same tool into Annex III high-risk territory and adds an Article 26 usage policy.
Want this checked against your own setup?
Run the free 6-question check →Documents you need
- AI Literacy Policy Article 4
A written policy covering which AI tools you use, which roles interact with them, what those people need to understand, who owns the document, and how it gets updated. Enforceable since 2 February 2025.
- Risk Classification Memo Articles 6, 9 and Annex III
A documented assessment placing each AI system in the Act’s risk tiers, including the Article 5 prohibited-practice check and the Article 6(3) exception assessment, with article citations.
- Transparency Disclosure Article 50
Informs people when they are interacting with an AI system and labels AI-generated or manipulated content. Article 50 applies from 2 August 2026. The narrower Article 50(2) duty on general-purpose models generating synthetic content applies from 2 December 2026.
Obligations that apply
- Article 4 AI literacy for staff using the tool
Everyone using ChatGPT on the company’s behalf needs a sufficient understanding of how it works and where it fails, including hallucination and bias. This has to exist as a written policy, not only as a training session someone once ran.
- Article 50 Disclosure where output reaches other people
If ChatGPT output goes to customers or the public as generated text, or drives a customer-facing chatbot, people have to be told they are dealing with AI-generated content. Purely internal drafting that a human rewrites does not trigger this.
- Article 5 Prohibited practice check
Confirm and document that the tool is not used for social scoring, emotion inference about employees, or manipulation of vulnerable people. These practices have been banned outright since February 2025.
Common mistakes
- Assuming a paid enterprise plan handles compliance for you. The contract covers OpenAI’s obligations as provider, never your Article 4 duty as deployer.
- Treating an all-hands AI briefing as compliance. Training can be the substance of the policy, but without a written document there is nothing to show a regulator.
- Forgetting contractors. Article 4 covers anyone operating AI on your behalf, including freelancers and agencies.
- Confusing GDPR compliance with AI Act compliance. They are separate regulations and a data protection impact assessment does not satisfy the AI Act.
Where the deadlines stand
The AI literacy obligation under Article 4 and the Article 5 prohibitions have been enforceable since 2 February 2025. General-purpose AI model rules applied from 2 August 2025. The Omnibus, published in the Official Journal on 24 July 2026, moved the high-risk dates: standalone high-risk systems under Annex III to 2 December 2027, and high-risk AI embedded in regulated products under Annex I to 2 August 2028. Article 50 transparency obligations still apply from 2 August 2026. Only the narrower Article 50(2) duty on general-purpose models generating synthetic content moved, to 2 December 2026, which is also when the new prohibition on AI-generated intimate imagery and child sexual abuse material takes effect.
The delay applies to the high-risk obligations. It does not move Article 4, which is why a written AI literacy policy is the document most companies are missing today.
Generate your 3 documents in about 30 minutes
Answer a short questionnaire and get every document above, pre-filled with your company details and article citations, in 11 EU languages. Preview free, download for €99 one-time. No subscription.
This page describes obligations under Regulation (EU) 2024/1689 as amended by the Omnibus published in the Official Journal on 24 July 2026, and was verified on 29 July 2026. It is general information rather than legal advice, and classification depends on your specific configuration and use. Review by qualified legal counsel is recommended before formal adoption of any compliance document.