AI for business · Summary for management
AI in the company — one-page summary for management
Print it or save it as PDF for your next board meeting.
What applies now
| Obligation | Rule | Who |
|---|---|---|
| AI literacy measures for staff who use AI (training, rules, record) | AI Act Art. 4 | Everyone using AI |
| No prohibited AI (emotion recognition at work, social scoring, manipulation) | AI Act Art. 5 | Everyone |
| Tell people when they talk to a chatbot; label deepfakes | AI Act Art. 50 | Customer-facing AI, content |
| Legal basis, processing agreement and DPIA for AI with personal data | GDPR, ZVOP-2 | Everyone with personal data |
| Report exploited vulnerabilities within 24 h | Cyber Resilience Act | Makers of software and devices |
| Label all AI content in media | ZMed-1 | Slovenian media |
Deadlines in the next 24 months
| 2 Dec 2026 | AI Act — New bans (non-consensual intimate images, child sexual abuse material) apply; end of the grace period for machine-readable marking of AI content (Art. 50(2)) for systems already on the market. |
| 2 Dec 2026 | Platform Work Directive — Transposition deadline for Member States. |
| 9 Dec 2026 | Product Liability Directive — Transposition deadline; applies to products placed on the market after this date. Slovenia has prepared a draft law. |
| 19 Dec 2026 | ZInfV-1 (NIS2) — Deadline to implement risk management measures (18 months). |
| 12 Jan 2027 | Data Act — Cloud switching charges are abolished. |
| 20 Jan 2027 | Machinery Regulation — The regulation applies (replaces Directive 2006/42/EC). |
| 26 Mar 2027 | EHDS — General date of application; key parts follow in phases until 2031. |
| 2 Aug 2027 | AI Act — General-purpose AI models placed on the market before 2 Aug 2025 must comply; national regulatory sandboxes must be operational. |
| 12 Sep 2027 | Data Act — Unfair-terms rules also apply to data contracts concluded before 12 Sep 2025. |
| 2 Dec 2027 | AI Act — Obligations for stand-alone high-risk AI (Annex III: employment, credit, education, essential services …). |
| 11 Dec 2027 | Cyber Resilience Act — All CRA requirements apply. |
| 2 Aug 2028 | AI Act — Obligations for high-risk AI inside regulated products (Annex I: medical devices, toys, lifts …). |
Five decisions for management
- Appoint a person responsible for AI (owner of the register, policy and training).
- Approve a one-page AI usage policy: allowed tools, forbidden data, human review.
- Budget AI literacy training and keep an internal record.
- Allow personal or confidential data only in business AI plans with a processing agreement.
- Review high-risk uses (HR, credit, customers) now — the rules apply from December 2027.
Fines (maximum)
| AI Act — prohibited practices | €35M or 7% of turnover |
| AI Act — other obligations | €15M or 3% |
| GDPR | €20M or 4% |
| Cyber Resilience Act | €15M or 2.5% |
SMEs and small mid-caps: the lower of the two amounts under the AI Act.
Source: hypervision.si/business — status of regulations as of 29 Sep 2026.
General information, not legal advice — consult a lawyer for borderline cases. Regulations reviewed on 29 Sep 2026.