In short (TL;DR)

Using AI for bookkeeping, invoice processing or reporting doesn't make your company the operator of a “high-risk AI system” — accounting automation isn't on the AI Act's high-risk list. And the scary deadline moved anyway: Regulation (EU) 2026/1744, published in the Official Journal on 24 July 2026, postponed the high-risk obligations from 2 August 2026 to 2 December 2027. What does arrive on 2 August 2026 is a set of transparency duties, and an AI literacy requirement has already applied since February 2025. Here's the full picture.

What changed in July 2026?

The EU adopted the so-called Digital Omnibus on AI, Regulation (EU) 2026/1744, which appeared in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. Two big deadlines moved:

  • Use-based high-risk AI systems (Annex III): from 2 August 2026 to 2 December 2027.
  • High-risk AI embedded in regulated products (Annex I): from 2 August 2027 to 2 August 2028.

One deadline didn't move at all: the transparency obligations still take effect on 2 August 2026. If you ask an AI chatbot about this and get the old timeline back, you now know why — the amendment is newer than most models' training data. The Future of Privacy Forum's updated timeline lays out every date.

Is accounting AI a high-risk system?

Generally no. Annex III of the AI Act lists the high-risk use cases exhaustively: systems making hiring decisions, assessing a person's creditworthiness, biometric identification, law enforcement uses and similar. Invoice digitization, posting suggestions, payment matching and report drafting are not on that list.

One line was drawn back in February 2025 and hasn't moved: emotion recognition in the workplace is a prohibited practice. If a tool promises to "read your team's mood" from camera or voice, it's banned in the EU regardless of any postponed deadlines.

What already applies to your business?

  • AI literacy (since 2 February 2025): if your team uses AI tools, you must make sure the people using them understand what the tools can and can't do. For a small business, a short internal training and a clear usage guideline covers it.
  • Transparency (from 2 August 2026): if your company runs a customer-facing chatbot, people must be able to tell they're talking to an AI. AI-generated content shouldn't be presented in a way that hides its origin.
  • GDPR (always): invoices and payroll data contain personal data, and processing them in an AI tool needs the same care as in any other software. That's data protection law, not the AI Act, and it was never postponed.

What should you do if your accounting software uses AI?

Under the Act you're a deployer, not a provider: the heavy obligations sit with your software vendor. On your side, three steps are enough:

  1. Write down which AI tools your company uses and for what.
  2. Keep a human in charge of decisions that matter: AI can post and match, but approval stays with a person.
  3. Ask your software vendor how they handle their AI Act obligations. A serious vendor will have an answer ready.

We've written more about what AI can and can't do in bookkeeping our guide to AI accounting, and about giving AI assistants controlled access to your books in MCP for accounting.

Summary

Using AI in your accounting doesn't put your small business under the AI Act's high-risk regime: those rules target very different use cases and were postponed to 2 December 2027 anyway. What matters for you: AI literacy in your team, transparency towards customers from 2 August 2026, and GDPR as always. This is a general overview, not legal advice — for your specific situation, talk to a lawyer.

Try Bilnex for free e-invoicing and invoice processing.

FAQ

Does the EU AI Act ban using AI in accounting?

Well. Invoice processing, posting suggestions and reporting aren't on the Act's high-risk list or among its prohibited practices. What is banned, since 2 February 2025, is emotion recognition in the workplace.

What takes effect on 2 August 2026 under the AI Act?

The transparency obligations: people must be able to tell when they're interacting with an AI, and AI-generated content mustn't hide its origin. The high-risk obligations don't start that day — Regulation (EU) 2026/1744 postponed them to 2 December 2027.

When do the AI Act's high-risk obligations now apply?

From 2 December 2027 for use-based high-risk systems (Annex III) and from 2 August 2028 for AI embedded in regulated products (Annex I). The postponement entered into force on 27 July 2026 through Regulation (EU) 2026/1744.

What does a small business using AI tools actually have to do?

Three things: ensure your team understands the AI tools it uses (the literacy duty, in force since February 2025), be transparent with customers about chatbots and AI-generated content from 2 August 2026, and follow GDPR when personal data flows through AI tools. The heavier obligations fall on your software vendor, not on you as a deployer.