Your website has an AI chatbot, your marketing team makes product images and social posts with AI, and HR has started trying AI to screen résumés. Then a German customer sends a supplier questionnaire, and one question reads: "Do the AI systems your company uses comply with the EU AI Act?" That's when many companies realize AI is no longer just a technology question. It's a compliance question too.

2026 is the year AI rules got real. The EU AI Act's transparency duties started to apply on August 2. Taiwan's AI Basic Act took effect in January, and in July Taiwan's Ministry of Digital Affairs published an AI risk classification framework. Meanwhile, the EU's "Digital Omnibus" postponed some obligations, leaving plenty of people unsure what's actually in force.

This article lays out where things stand as of September 2026 and what companies can start on right away. (This is general information, not legal advice. Talk to a lawyer about your specific situation.)

The timeline: what's in force and what's been delayed

Timeline of the EU AI Act and Taiwan's AI rules: in force in 2024, prohibitions and general-purpose AI duties in 2025, transparency duties in 2026, high-risk duties delayed to 2027 and 2028
Key dates for the EU AI Act and Taiwan's AI rules (as of September 2026): transparency duties arrived on schedule; high-risk duties were delayed.
DateWhat happenedWhat it means for a typical business
Aug 1, 2024EU AI Act enters into forcePhased application begins
Feb 2, 2025Prohibited practices and AI literacy duty applyE.g. no AI emotion recognition of employees at work
Aug 2, 2025General-purpose AI model duties applyMostly the model developers' responsibility
Jan 14, 2026Taiwan's AI Basic Act promulgated and in effectGovernment has two years to adapt its rules
Aug 2, 2026Most of the EU AI Act applies, including Article 50 transparencyChatbots must disclose; deepfakes must be labeled
Dec 2, 2026Grace period for marking AI output ends; new prohibition appliesSee "What was delayed" below
Dec 2, 2027Annex III high-risk duties apply (originally Aug 2, 2026)Hiring, credit scoring and similar uses
Aug 2, 2028Duties for high-risk AI in products apply (originally Aug 2, 2027)Machinery, medical devices and other regulated products

The official schedule is on the European Commission's AI Act Service Desk timeline.

The EU AI Act: why Taiwan companies should pay attention

The EU AI Act (Regulation (EU) 2024/1689) doesn't care where your company is based. Under Article 2, it can apply if:

  • you sell an AI system or a product with AI in it on the EU market;
  • you have a presence in the EU and use AI in your business; or
  • your company is outside the EU but the output of your AI system is used in the EU, for example an AI chatbot on your English-language website answering European customers.

The law also distinguishes two roles: the provider (who develops an AI system and offers it under their own name) and the deployer (who uses an AI system in their business). If you build a chatbot on a large-model API and put it on your website, you may be both. If you use an off-the-shelf SaaS tool, you're most likely a deployer.

Four risk levels

The EU AI Act's four risk levels as a pyramid: prohibited, high-risk, transparency, minimal risk, with typical business uses and what to do listed on the right
The EU AI Act's four risk levels and where common business uses roughly fall (illustrative; the actual classification depends on the specific use).
  • Prohibited: for example social scoring, manipulating people by exploiting their vulnerabilities, and emotion recognition at work or in schools.
  • High-risk: the uses listed in Annex III, including recruitment and HR (screening résumés, evaluating employee performance), creditworthiness assessment of individuals, education and more, plus AI safety components in products covered by EU product-safety laws.
  • Transparency: chatbots that talk to people, AI that generates content, and deepfakes.
  • Minimal risk: inventory forecasting, spam filters, internal document summaries and the like. No extra duties, though data protection and other laws still apply.

Maximum fines depend on the tier: up to €35 million or 7% of worldwide annual turnover for prohibited practices, and up to €15 million or 3% for breaching high-risk or transparency duties. For small and medium-sized businesses, whichever amount is lower applies.

What was delayed, and what wasn't

In November 2025 the Commission proposed the "Digital Omnibus." Its AI part was adopted as Regulation (EU) 2026/1744 and took effect on July 27, 2026 (Commission announcement):

  • Delayed: Annex III high-risk duties move to December 2, 2027; high-risk AI in products moves to August 2, 2028.
  • Eased: the AI literacy duty changes from "ensure staff have sufficient AI literacy" to "take measures to support it," and simplifications for small businesses now extend to "small mid-caps."
  • Not delayed: Article 50 transparency duties still applied from August 2, 2026. The only relief is for machine-readable marking of AI output: systems already on the market before August 2 have until December 2.
  • Added: a ban on using AI to generate non-consensual intimate images and child sexual abuse material, applying from December 2, 2026.

Delayed doesn't mean cancelled. If you use AI for hiring or credit decisions, use the extra time to get your documentation, review process and records in order.

From August 2: what the transparency duties require

Article 50 is the provision that touches the most companies. In July the Commission published guidelines on the transparency obligations, and in June a voluntary Code of Practice on marking and labeling AI-generated content.

SituationWhat to doWho's mainly responsible
AI customer service, chatbotsTell people they're talking to AI (unless it's obvious)Provider
AI-generated images, audio, video, textMark it in a machine-readable way, e.g. watermarks or metadataProvider of the generative AI
Deepfakes (realistic people, places, events)Clearly disclose that AI generated or altered itDeployer
AI text published on matters of public interestDisclose it's AI-generated, unless a person reviewed it and took editorial responsibilityDeployer
Emotion recognition, biometric categorizationInform the people being analyzedDeployer

Day to day, that comes down to three things:

  1. Say it up front in your chatbot, e.g. "I'm an AI assistant; I'll hand complex questions to a person." The Commission's draft guidelines say a line buried in the terms of use, or vaguely calling it an "assistant," isn't enough: the disclosure has to appear in the conversation itself.
  2. Don't strip the markers your tools add. Generative AI tools usually embed watermarks or metadata in their output; keep them through editing.
  3. Treat marketing assets case by case. An ordinary product lifestyle image isn't necessarily a deepfake. Making a real person "say" something they never said, or synthesizing footage that looks like a real event, needs a label.

A chatbot that answers only from your company's own content and hands off to a person when it can't find an answer (see our guide to RAG knowledge bases) reduces risk far more than adding labels after the fact.

Taiwan: the AI Basic Act is in force, the details are still coming

Taiwan's AI Basic Act (人工智慧基本法) passed the Legislative Yuan, Taiwan's parliament, on December 23, 2025 and was promulgated and took effect on January 14, 2026. It has 20 articles, and the lead authority is the National Science and Technology Council (NSTC). As a "basic act," it mainly sets out what government must do:

  • Government AI policy must follow seven principles: sustainability and well-being, human autonomy, privacy and data governance, cybersecurity and safety, transparency and explainability, fairness and non-discrimination, and accountability.
  • The Ministry of Digital Affairs (MODA) is responsible for a risk classification framework aligned with international standards. Version 1.0 was published in July 2026. It sorts AI risks into 3 categories and 20 subcategories and recommends four steps: inventory, identify, assess, respond.
  • Sector regulators are to write risk-based rules using that framework, and government must finish adapting its laws within two years of the Act taking effect. For uses designated high-risk, the Act calls for warnings or cautionary labels, clear allocation of liability, and remedy, compensation or insurance mechanisms.

In other words, the Basic Act itself doesn't fine companies, but the direction is clear, and sector-specific rules will arrive over the next two years.

Laws that already apply

  • Personal Data Protection Act (PDPA): tell people why you collect their data, use it only within that stated purpose, and keep it secure. Before pasting customer data into an outside AI service or training a model on customer conversations, ask: "Is this within the purpose we told people about?" The PDPA was amended in November 2025, adding rules such as breach notification; the Executive Yuan (Taiwan's cabinet) will set the effective date, so keep an eye on it.
  • Sector rules: for example, the Financial Supervisory Commission's AI guidelines for the financial industry set expectations on fairness, explainability and governance.
  • Your existing responsibilities don't disappear because AI is involved: Taiwan's Employment Service Act prohibits hiring discrimination, so if an AI résumé screener systematically filters out candidates by age or gender, the company is still responsible.

Seven things to start on now

  1. Build an AI inventory: list every AI use, the tool or vendor, the data it handles, who it serves (including anyone in the EU) and who owns it. Include AI tools employees signed up for on their own.
  2. Classify the risk: map each use against the EU's four levels and MODA's framework, and flag what's high-risk and what carries transparency duties.
  3. Add transparency labels: disclose at the start of chatbot conversations, label deepfakes and AI text on public-interest topics, and build this into your content workflow.
  4. Ask your vendors:
    • Is our input used for training? Where is it stored, and for how long?
    • Is generated content marked in a machine-readable way?
    • Will you notify us before model changes?
    • If the product is used in the EU, can you provide the documentation and instructions for use the law requires?
  5. Handle personal data carefully: give AI only the data it needs, de-identify where you can, and update your privacy notice.
  6. Keep a human in the loop for consequential decisions: for hiring, lending and dismissals, AI recommends and a person decides, and the reviewer must understand the reasoning and have the authority to override it. If you process EU residents' personal data, the GDPR already restricts fully automated decisions with significant effects.
  7. Keep records: which model version was used, inputs and outputs, and who approved what. Deployers of high-risk systems in the EU must keep logs for at least six months (Article 26, applying from December 2027).

The last three depend directly on how your AI systems handle permissions and logging; see AI agent security.

Bottom line: get a clear view of your own AI first

The rules will keep changing, but an inventory, risk classification, labels, human review and records will be useful however they end up. This article is general information as of September 2026, not legal advice. If you sell into the EU or use AI for high-risk decisions, confirm the details with a lawyer.

If you'd like to build your AI inventory, human review steps and audit logs into the systems you already run, take a look at our AI integration services and custom business systems, or get in touch.