Provider or deployer?
Most companies are deployers: they use AI systems made by others (ChatGPT, Copilot, an HR tool). Providers develop AI or put it on the market under their own name. Deployers have far fewer obligations — but if you substantially modify a system or sell it under your brand, you can become a provider.
Four risk levels
- Prohibited (since 2 Feb 2025): e.g. social scoring, emotion recognition at work and school, manipulative techniques; from 2 Dec 2026 also AI for non-consensual intimate images
- High risk: AI for hiring, evaluating workers, credit scoring, education, critical infrastructure — obligations apply from 2 Dec 2027 (Annex III) and 2 Aug 2028 (Annex I products)
- Transparency (from 2 Aug 2026): people must know they talk to a chatbot; deepfakes and AI-generated content must be labelled
- Minimal risk: most everyday use — no special obligations beyond AI literacy
AI literacy (Article 4)
Since the Digital Omnibus (Regulation (EU) 2026/1744) companies must take measures to support the AI literacy of staff who use AI on their behalf. No certificate or specific level is required; the Commission recommends keeping an internal record of training. Supervision applies from 3 August 2026.
In Slovenia
The Act implementing the AI Act (ZIUDHPUI) has applied since 21 November 2025; AKOS is the central authority and single point of contact. The Information Commissioner remains responsible for personal data (GDPR), and the Media Act requires AI-generated media content to be labelled.
To do this quarter
- Make a list of AI tools used in the company and for what
- Check none of them falls under prohibited practices
- Mark high-risk uses (especially HR) and plan for 2027
- Label chatbots and AI content for customers
- Train staff and keep a record — this course is one way