AI for business · Summary for management

AI in the company — one-page summary for management

Print it or save it as PDF for your next board meeting.

What applies now

ObligationRuleWho
AI literacy measures for staff who use AI (training, rules, record)AI Act Art. 4Everyone using AI
No prohibited AI (emotion recognition at work, social scoring, manipulation)AI Act Art. 5Everyone
Tell people when they talk to a chatbot; label deepfakesAI Act Art. 50Customer-facing AI, content
Legal basis, processing agreement and DPIA for AI with personal dataGDPR, ZVOP-2Everyone with personal data
Report exploited vulnerabilities within 24 hCyber Resilience ActMakers of software and devices
Label all AI content in mediaZMed-1Slovenian media

Deadlines in the next 24 months

2 Dec 2026AI Act — New bans (non-consensual intimate images, child sexual abuse material) apply; end of the grace period for machine-readable marking of AI content (Art. 50(2)) for systems already on the market.
2 Dec 2026Platform Work Directive — Transposition deadline for Member States.
9 Dec 2026Product Liability Directive — Transposition deadline; applies to products placed on the market after this date. Slovenia has prepared a draft law.
19 Dec 2026ZInfV-1 (NIS2) — Deadline to implement risk management measures (18 months).
12 Jan 2027Data Act — Cloud switching charges are abolished.
20 Jan 2027Machinery Regulation — The regulation applies (replaces Directive 2006/42/EC).
26 Mar 2027EHDS — General date of application; key parts follow in phases until 2031.
2 Aug 2027AI Act — General-purpose AI models placed on the market before 2 Aug 2025 must comply; national regulatory sandboxes must be operational.
12 Sep 2027Data Act — Unfair-terms rules also apply to data contracts concluded before 12 Sep 2025.
2 Dec 2027AI Act — Obligations for stand-alone high-risk AI (Annex III: employment, credit, education, essential services …).
11 Dec 2027Cyber Resilience Act — All CRA requirements apply.
2 Aug 2028AI Act — Obligations for high-risk AI inside regulated products (Annex I: medical devices, toys, lifts …).

Five decisions for management

  1. Appoint a person responsible for AI (owner of the register, policy and training).
  2. Approve a one-page AI usage policy: allowed tools, forbidden data, human review.
  3. Budget AI literacy training and keep an internal record.
  4. Allow personal or confidential data only in business AI plans with a processing agreement.
  5. Review high-risk uses (HR, credit, customers) now — the rules apply from December 2027.

Fines (maximum)

AI Act — prohibited practices€35M or 7% of turnover
AI Act — other obligations€15M or 3%
GDPR€20M or 4%
Cyber Resilience Act€15M or 2.5%

SMEs and small mid-caps: the lower of the two amounts under the AI Act.

Source: hypervision.si/business — status of regulations as of 29 Sep 2026.

General information, not legal advice — consult a lawyer for borderline cases. Regulations reviewed on 29 Sep 2026.