EU AI Act compliance when your company uses ChatGPT

If your team uses ChatGPT for drafting, summarising, research, or code, your company is a deployer of an AI system under Regulation (EU) 2024/1689. Deployer status does not depend on how much you use the tool or whether you pay for it.

The good news is that ordinary internal use of ChatGPT sits at the light end of the Act. The obligation people miss is Article 4, which has been enforceable since 2 February 2025 and applies the moment staff start using the tool.

Typical classification
Minimal risk
Your role
Deployer
Documents needed
3

Are you a provider or a deployer?

OpenAI is the provider of the model. Your company is the deployer. Provider duties such as conformity assessment and EU database registration sit with OpenAI, not with you.

How this is classified under the Act

General-purpose drafting, summarising, and internal research does not fall into any Annex III high-risk domain. The system is not making or materially influencing decisions about people in a regulated area, so the classification lands at minimal risk and the memo records that reasoning.

What changes the answer: The classification changes if you point ChatGPT at a regulated decision. Screening job applications, ranking candidates, assessing creditworthiness, or evaluating students moves the same tool into Annex III high-risk territory and adds an Article 26 usage policy.

Want this checked against your own setup?

Run the free 6-question check →

Documents you need

Obligations that apply

Common mistakes

Where the deadlines stand

The AI literacy obligation under Article 4 and the Article 5 prohibitions have been enforceable since 2 February 2025. General-purpose AI model rules applied from 2 August 2025. The Omnibus, published in the Official Journal on 24 July 2026, moved the high-risk dates: standalone high-risk systems under Annex III to 2 December 2027, and high-risk AI embedded in regulated products under Annex I to 2 August 2028. Article 50 transparency obligations still apply from 2 August 2026. Only the narrower Article 50(2) duty on general-purpose models generating synthetic content moved, to 2 December 2026, which is also when the new prohibition on AI-generated intimate imagery and child sexual abuse material takes effect.

The delay applies to the high-risk obligations. It does not move Article 4, which is why a written AI literacy policy is the document most companies are missing today.

Generate your 3 documents in about 30 minutes

Answer a short questionnaire and get every document above, pre-filled with your company details and article citations, in 11 EU languages. Preview free, download for €99 one-time. No subscription.

This page describes obligations under Regulation (EU) 2024/1689 as amended by the Omnibus published in the Official Journal on 24 July 2026, and was verified on 29 July 2026. It is general information rather than legal advice, and classification depends on your specific configuration and use. Review by qualified legal counsel is recommended before formal adoption of any compliance document.