TL;DR: As of August 2, 2026, EU AI Act transparency obligations and fundamental rights impact assessment requirements apply to deployers, including most businesses using third-party AI tools in production. The five evidence gaps most SME deployers have right now are: no fundamental rights impact assessment (Article 27), no human oversight procedure documentation (Article 14), no instructions-for-use log, no transparency disclosure to affected individuals (Article 50), and no incident monitoring log (Article 73). Each section below includes a copy-paste documentation template.
August 2, 2026 is the enforcement date for EU AI Act obligations covering GPAI models, prohibited AI practices, and Article 50 transparency requirements. For deployers (businesses that put AI systems into use for their operations or customers), this date brings real obligations that most SMEs have not fully addressed.
The good news is that the full Article 9 conformity assessment requirements for high-risk AI categories are still being phased in for most sectors through late 2026 and 2027. The less-good news is that several deployer-specific obligations are active now, and the documentation gaps at most small businesses are significant.
This article covers who counts as a deployer, what the August 2 timeline actually means, and the five specific evidence gaps most SME deployers have right now, with a copy-paste template for each.
Who is a "deployer" under the EU AI Act
The EU AI Act defines a deployer as any natural or legal person that puts an AI system into service or use under its own authority, except for personal non-professional use.
In practice, you are a deployer if your business:
- Uses a vendor-supplied AI tool in your operations (hiring software, customer service AI, AI-generated content tools, scoring or recommendation systems)
- Makes that AI tool available to end users or uses it to make decisions affecting people
- Operates under your own brand or authority, even if the AI was built entirely by a vendor
Most businesses using third-party AI tools in production are deployers. The definition does not require building the AI yourself. It does not require being large. And it does not grant an exemption for using a well-known vendor's product.
For the full picture of what applies to your team right now versus what is still being phased in, see what's delayed vs what applies, EU AI Act August 2026.
What the August 2, 2026 date actually means for deployers
August 2, 2026 is the enforcement date for three categories of EU AI Act provisions:
- GPAI model obligations: requirements on providers of general-purpose AI models
- Prohibited AI practices (Article 5): bans on unacceptable-risk AI systems
- Article 50 transparency obligations: disclosure requirements when users interact with AI
Deployers are directly in scope for Article 50, and may be in scope for Article 5 if they deploy a system that falls into a prohibited category.
For high-risk AI systems (Annex III categories), Article 14 (human oversight) and Article 27 (fundamental rights impact assessment for certain deployers) are also active. Full technical conformity assessment requirements for most high-risk categories are on a longer implementation timeline, but the operational and documentation requirements for deployers are not.
The five gaps below reflect what is missing from most SME deployer documentation files right now.
Gap 1: No fundamental rights impact assessment (Article 27)
What the law requires: Article 27 of the EU AI Act requires deployers of high-risk AI systems, particularly public bodies and private entities conducting activities with fundamental rights implications (employment, credit, education, essential services), to conduct a fundamental rights impact assessment before deploying the system.
Who this applies to: Deployers using high-risk AI as defined in Annex III, including AI systems used for recruitment and HR screening, credit scoring, essential services access, or law enforcement-adjacent functions. Many common HR and finance tools fall into this category.
What most SMEs are missing: No documentation that an assessment was conducted, no record of findings, and no evidence that the results were considered before deployment.
Copy-paste template: Fundamental rights impact assessment record
Document title: Fundamental Rights Impact Assessment AI system name: [System name and vendor] Date of assessment: [Date] Assessed by: [Name, role]
System description: [One paragraph describing what the AI system does, what decisions it informs or makes, and which individuals are affected.]
Fundamental rights categories reviewed:
| Right | Potential impact | Mitigation in place |
|---|---|---|
| Right to non-discrimination | [Low/Medium/High] | [Description of control or "None identified"] |
| Right to privacy | [Low/Medium/High] | [Description of control] |
| Right to explanation of automated decisions | [Low/Medium/High] | [Description of control] |
| Right to human review | [Low/Medium/High] | [Description of control] |
Assessment conclusion: [State whether the deployment is approved to proceed, conditionally approved with listed mitigations, or requires further review before deployment.]
Sign-off: [Name, title, date]
Keep this document in your AI governance file. Review and update it before making significant changes to how the system is used.
Gap 2: No human oversight procedure documentation (Article 14)
What the law requires: Article 14 requires deployers of high-risk AI systems to implement appropriate human oversight measures. Critically, this obligation falls on the deployer, not just the provider, even when the AI system was built by a third party.
What most SMEs are missing: No written procedure describing how humans review, override, or intervene in AI outputs. Many teams rely on informal practices ("we always check before sending") without documenting them.
Copy-paste template: Human oversight procedure
Document title: Human Oversight Procedure for [AI System Name] Version: 1.0 Owner: [Name, role] Last reviewed: [Date]
Scope: This procedure applies to all use of [AI system name] by [company name] employees and contractors.
Oversight requirement: No AI-generated output from this system may be acted upon or communicated to affected individuals without human review by an authorized staff member. The human reviewer must be capable of overriding, modifying, or rejecting the AI output.
Review steps:
- The AI system produces output (recommendation, score, decision, draft).
- The designated reviewer examines the output for accuracy, fairness, and appropriateness.
- The reviewer approves, modifies, or rejects the output and records the action in [logging system or field].
- Only approved outputs proceed to the next step.
Override authority: Any reviewer may override an AI output without additional approval. Overrides must be logged with a brief reason.
Escalation: If a reviewer is uncertain whether to approve or override, escalate to [name/role] before proceeding.
Record retention: Human review records are retained for [X] years in accordance with our data retention policy.
Gap 3: No instructions-for-use log
What the law requires: Deployers must use AI systems in accordance with the provider's instructions for use. The EU AI Act requires deployers to document that they have received and followed those instructions. This is distinct from just having the vendor's documentation. You need evidence that you reviewed and applied it.
What most SMEs are missing: No record that the instructions-for-use were reviewed, no log of limitations or prohibited uses noted in the documentation, and no confirmation that staff were trained on those limitations.
Copy-paste template: Instructions-for-use acknowledgment log
Document title: Instructions-for-Use Review Log AI system: [System name and vendor]
| Date reviewed | Document reviewed | Key limitations noted | Reviewed by | Staff training completed |
|---|---|---|---|---|
| [Date] | [Document name/version] | [List any prohibited uses, limitations, or conditions from the vendor docs] | [Name] | [Yes/No; if yes, date and format] |
Deployment confirmation: I confirm that [company name] has reviewed the above documentation and that our use of [AI system name] is within the scope described by the provider's instructions for use.
Signed: [Name, title, date]
Update this log each time the vendor issues updated instructions or significant product changes.
Gap 4: No transparency disclosure to affected individuals (Article 50)
What the law requires: Article 50 requires deployers to inform individuals when they are interacting with an AI system, before or at the start of that interaction, unless it is obvious from context. This applies to AI chatbots, AI-generated content presented as human-created, and emotion recognition or biometric categorization systems.
What most SMEs are missing: No disclosure language in their product, website, or customer communications. Many teams assume the vendor handles this. The vendor handles their own disclosure as a provider. The deployer is separately obligated to disclose to affected individuals.
See the EU AI Act Article 50 watermarking and deepfake disclosure article for the full technical requirements.
Copy-paste template: AI interaction disclosure statement
For use at the start of customer interactions involving AI:
"You are interacting with an AI assistant operated by [Company Name]. This system uses artificial intelligence to respond to your messages. A human [is/is not] monitoring this conversation in real time. If you prefer to speak with a human representative, please [action, e.g., type 'human' or call our support line at X]."
For email or written communications that are AI-drafted:
"[Company Name] uses AI tools to assist in drafting communications. This message was [reviewed and approved / generated] with AI assistance."
For AI-assisted decisions affecting individuals (credit, employment, services):
"[Company Name] uses an automated system to assist in evaluating [applications/requests]. You have the right to request human review of this decision. Contact [name/email/phone] to request a review."
Add the appropriate disclosure to every customer-facing touchpoint where AI is active.
Gap 5: No incident monitoring log (Article 73)
What the law requires: Article 73 requires deployers of high-risk AI systems to report serious incidents to the national market surveillance authority. To do this, you need to be monitoring for incidents in the first place. Deployers must also maintain logs sufficient to reconstruct incidents and identify root causes.
What most SMEs are missing: No log structure for AI-related incidents. No defined threshold for what counts as a serious incident. No designated person responsible for deciding whether an incident meets the reporting threshold.
Copy-paste template: AI incident monitoring log
Document title: AI Incident Monitoring Log System covered: [AI system name] Log owner: [Name, role]
| Incident date | System involved | Description | Affected individuals | Severity | Action taken | Reported to authority | Closed date |
|---|---|---|---|---|---|---|---|
| [Date] | [System] | [Brief description] | [Number/type] | [Minor/Serious] | [Description] | [Yes/No; if yes, date and case number] | [Date] |
Severity definitions:
- Minor: AI system error or unexpected output with no adverse impact on individuals.
- Serious: Any incident involving death, serious harm to health, serious damage to property, or serious adverse impact on individuals' fundamental rights.
Reporting threshold: Any incident classified as Serious must be reported to [national authority] within 15 days of the deployer becoming aware of the incident. Designate [name/role] as the responsible person for this determination.
Log retention: Retain all incident log entries for a minimum of 10 years after the incident date.
Timeline summary: what applies to deployers now vs later
| Obligation | Applies as of August 2, 2026 | Phase-in date |
|---|---|---|
| Article 50 transparency disclosures | Yes | Now |
| Article 5 prohibited AI practices | Yes | Now |
| Article 14 human oversight (high-risk AI) | Yes | Now |
| Article 27 fundamental rights impact assessment | Yes (certain deployers) | Now |
| Article 73 serious incident reporting | Yes (high-risk AI deployers) | Now |
| Article 9 conformity assessment (most high-risk) | Partial | Late 2026 / 2027 by category |
| Full Annex III product liability compliance | No | 2027 |
For a more detailed breakdown, the EU AI Act GPAI compliance checklist, August 2 deadline covers the GPAI-specific timeline in full.
How to prioritize if you are starting from zero
If your team has none of the five documents above, start in this order:
- Article 50 disclosure: lowest effort, applies to any AI-assisted customer interaction, and is visible to regulators through your own website and product.
- Instructions-for-use log: review your vendor's documentation this week and record that you did it. One hour of work.
- Human oversight procedure: document the review step your team already does informally.
- Incident monitoring log: create the spreadsheet now, even with zero entries. You need the structure before an incident occurs.
- Fundamental rights impact assessment: the most substantive effort. If you deploy AI in hiring, credit, or essential services, this is also the highest-priority item from a regulatory risk standpoint.
The AI governance checklist 2026 covers the full set of governance documents a deployer should maintain, and the AI tool register template for small teams gives you the starting point for inventorying which systems you are using.
For broader governance structure, ISO 42001 vs NIST AI RMF for small teams compares the two main frameworks you can use as a foundation for all of this documentation.
Related reading
- EU AI Act Annex IV technical documentation guide: all 9 sections
- EU AI Act compliance guide for small teams
- EU AI Act GPAI compliance checklist, August 2 deadline
- What's delayed vs what applies, EU AI Act August 2026
- AI governance checklist 2026
- AI vendor due diligence checklist 2026
- AI tool register template for small teams
- AI data privacy for small teams, GDPR/CCPA
- GDPR-compliant AI assistants comparison 2026
- EU AI Act Digital Omnibus August 2026: will the deadline hold?
- EU AI Act enforcement starts August 2, 2026: what it means and what to d
- EU AI Act high-risk AI documentation templates for August 2026 (Articles
