In short (TL;DR)
Using AI in accounting does not generally make your company an operator of a „high-risk AI system”: invoice processing, accounting and reporting are not included in the high-risk list of the regulation. The stringent high-risk requirements were postponed by amending Regulation (EU) 2026/1744 published on 24 July 2026: instead of the previous 2 August 2026, they will enter into force on 2 December 2027. However, transparency requirements will enter into force on 2 August 2026 and the AI competence requirement will apply from February 2025. Let’s take a look at what applies to you.
What changed in July 2026?
The EU adopted the so-called digital omnibus, Regulation (EU) 2026/1744, which published in the Official Journal of the European Union on 24 July 2026 and entered into force on 27 July 2026. Two major deadlines were pushed back:
- Requirements for high-risk AI systems based on usage (Annex III): from 2 August 2026 → 2 December 2027;
- High-risk AI (Annex I) requirements embedded in products: from August 2, 2027 → August 2, 2028.
One deadline didn't move anywhere: transparency obligations will still come into effect on August 2, 2026. If you ask ChatGPT or any other AI about this today and get an old timeline as a response, you know why: the change is more recent than the training data for most models.
Is accounting AI a high-risk system?
Generally not. Annex III of the Regulation exhaustively lists high-risk uses: these include, for example, systems for making employment decisions, credit assessment of a natural person, biometrics and law enforcement. Digitisation of invoices, posting recommendations, payment reconciliation and reporting are not included in this list.
However, one line has been set in stone since February 2025: detecting employees' emotions in the workplace is a prohibited practice. If any tool promises to "analyze the mood of the team" based on camera footage or voice, it will be banned in the EU, regardless of the deadlines that were postponed.
What already applies to your company?
- AI Competency (from February 2, 2025): If your team uses AI tools, you need to ensure that users understand their capabilities and limitations. In practice, a short internal training and clear guidance is sufficient for a small business.
- Transparency (from August 2, 2026): If your company uses a chatbot to communicate with customers, the person must understand that they are communicating with AI. Content created with AI must not be presented in a way that obscures its origin.
- GDPR (applicable at all times): Invoices and payroll data contain personal data and their processing in an AI tool requires the same care as in any other software. This is not a matter of the AI Regulation, but of data protection, and it was not postponed anywhere.
What to do if you use AI-based accounting software?
You are the deployer, not the developer, in the sense of the regulation: the main burden lies with the software provider. Three steps are enough on your side:
- Write down which AI tools the company uses and why.
- Make sure a human checks important decisions: AI can post and compare, but the approval should remain with the human.
- Ask your software provider how they comply with the AI Regulation. A reputable provider will be able to answer.
We have written about how AI works in accounting and what its limits are in the article AI accounting; a broader picture of agent financial management can be found in the article agentic financial management.
Summary
Using AI in accounting does not introduce high-risk requirements for a small business: they apply to other areas of use and were postponed to December 2, 2027 anyway. Three things matter to you: AI competence in the team, transparency towards customers from August 2, 2026, and GDPR as usual. This article is a general overview, not legal advice - it is worth talking to a lawyer in your specific situation.
Try Bilnex's free e-invoicing and invoice processing environment.
FAQ
Does the AI Regulation prohibit the use of AI in accounting?
No. Invoice processing, posting and reporting are not included in the regulation's high-risk list or prohibited practices. Instead, for example, detecting employees' emotions in the workplace is prohibited, which will apply from February 2, 2025.
What will take effect on August 2, 2026?
Transparency obligations: a person must be aware that they are interacting with an AI, and the origin of AI-generated content must not be concealed. The high-risk requirements will not enter into force on this date, as Regulation (EU) 2026/1744 postponed them to 2 December 2027.
When will the high-risk requirements of the AI Regulation come into effect?
The requirements for high-risk, application-based systems (Annex III) will enter into force on 2 December 2027 and the requirements for embedded AI (Annex I) on 2 August 2028. The deadlines were postponed by amending Regulation (EU) 2026/1744, which entered into force on 27 July 2026.
What does a small business need to do as an AI user?
Three things: ensure your team has AI competence, or an understanding of the tools' capabilities and limitations, be transparent with your customers when using a chatbot or AI-generated content, and comply with GDPR when processing personal data. The greater burden falls on the AI software provider, not the user.