Two things changed for TYPO3 teams in the summer of 2026, and they point in opposite directions. The obligations everyone was bracing for moved further away. The ones almost nobody was watching arrived instead, and they land on exactly the features already running in TYPO3 installations today: a chatbot, an AI search, AI-generated text and images.
Most of the EU AI Act has applied since 2 August 2026, which makes the EU AI Act for TYPO3 teams a question about this quarter rather than a future one. The obligations for high-risk systems moved out to December 2027. The transparency obligations did not move at all.
This post sorts out what applies, from when, and who carries which duty. We work through it together, starting from the role, because the role decides everything after it. How the labelling side works in practice is in our post on AI content labelling in TYPO3.
What has applied since 2 August 2026
The short answer: the prohibitions and the AI literacy duty have applied since 2 February 2025. The Article 50 transparency obligations have applied since 2 August 2026. Enforcement by the European Commission and the national authorities started the same day, as the Commission set out when it announced the start of enforcement. The Annex III high-risk obligations do not arrive until 2 December 2027.
For an ordinary company website, Article 50 is therefore the part that counts today. The full picture sits in the Commission's own AI Act implementation timeline.
| Date | What applies | Who it binds |
| 2 February 2025 | Prohibited practices (Article 5) and AI literacy (Article 4) | Providers and deployers |
| 2 August 2025 | Obligations for general-purpose AI models, governance, penalty framework | Model providers, member states |
| 2 August 2026 | Article 50 transparency obligations, enforcement begins | Providers and deployers |
| 2 December 2026 | End of the transitional period for machine-readable marking, only for systems already on the market before 2 August 2026 | Providers of generative systems |
| 2 December 2027 | Obligations for Annex III high-risk systems | Providers and deployers |
| 2 August 2028 | High-risk AI embedded in regulated products under Annex I | Providers |
Article 50 comes down to two sentences. People must be told when they are dealing with an AI rather than a person. And certain AI-generated or AI-modified content has to be recognisable as such. Which content is covered and which is expressly not is the subject of a separate post. It is our piece on AI content labelling in TYPO3. We are happy to work through that judgement with you.

Figure: when each part of the Act starts to apply.
What the Digital Omnibus moved, and what it left alone
This is where the picture gets muddled, so it is worth being exact. Regulation (EU) 2026/1744 of 8 July 2026, known as the Digital Omnibus on AI, was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. It moves two dates, softens one wording, and leaves the part that matters most for websites untouched.
- Moved: Annex III high-risk systems, from August 2026 to 2 December 2027.
- Moved: high-risk AI in regulated products under Annex I, from August 2027 to 2 August 2028.
- Not moved: Article 50. There is a narrow transitional period until 2 December 2026. It covers only the machine-readable marking duty, and only systems that were on the market before 2 August 2026. The Commission states it plainly in its own Q&A on Article 50: the grace period is limited, and it applies to that one obligation.
In practice: if you are planning a careers portal with AI-assisted screening, you have real room. If you are running a chatbot today, you do not. We would rather check that distinction with you a quarter early than a quarter late.
Provider or deployer: your role decides your duties
The Act allocates duties by role, not by company size. Two roles apply to almost every TYPO3 project.
A deployer uses an AI system under its own authority in a professional context. That is the normal case: you install an extension, configure it, and run it on your site. A provider develops an AI system, or has one developed, and places it on the market under its own name or trademark.
For agencies the second role is the unwelcome surprise, because you slide into it rather than choosing it. Article 25 names three triggers that turn a deployer into a provider:
- You put your own name or trademark on a high-risk system that is already on the market.
- You substantially modify a system, in a way that affects its compliance or its intended purpose.
- You give a general-purpose AI system a new, high-risk purpose it was never classified for.
Install and configure a standard extension and you stay a deployer. Turn it into your own rebranded product for clients and the role needs settling deliberately. Ideally in writing, in the project contract. That allocation belongs in the statement of work, not in a conversation after the fact. We are glad to draft it together with you.

Figure: any one of the three Article 25 triggers is enough on its own.

Figure: when a deployer becomes a provider, under Article 25.
The diagram says the same thing in words. Install and configure an AI extension and you remain a deployer. Ship it under your own name or trademark, modify it substantially, or give it a new high-risk purpose, and you become the provider and take on the provider's duties.
AI literacy under Article 4: the duty that has applied since 2025
Article 4 has applied since 2 February 2025 and still rarely comes up in project conversations. It binds providers and deployers, and it asks for measures so that the people who work with AI systems build a sufficient level of AI literacy.
The Digital Omnibus softened the wording from "ensure" to "support the development of". The Act sets no minimum level and no certification. What counts is the context, the team's existing knowledge, and the people affected.
A documented, proportionate measure is enough. That means a short internal policy on who may use which AI features, a briefing, and a note of when it happened. What matters is that it genuinely exists. How to express those roles and rights in the system itself is something we set up with you in AI Foundation for TYPO3, the open-source foundation T3Planet maintains, and it is walked through in our post on turning TYPO3 into an AI-ready platform.
Beyond transparency: prohibited practices and high-risk
Two further areas touch websites less often, but not never.
Prohibited practices (Article 5) have applied since February 2025 with no transitional period. Three of them matter for marketing and websites. First, manipulative or deceptive techniques that materially distort behaviour and cause harm. Second, the exploitation of vulnerability by age, disability or social situation. Third, biometric categorisation that infers sensitive characteristics. Personalisation without AI-driven behavioural manipulation is not caught by this, and we are glad to check that boundary with you before it becomes a question.
Annex III high-risk usually comes down to a single case on a company website: the careers portal. As soon as AI pre-sorts, scores or filters applications, that is high-risk use in the employment field. Education access and creditworthiness or eligibility assessments join it where your site supports those decisions. These duties apply from 2 December 2027. Deployers then carry human oversight by trained staff, log retention of at least six months, and information duties towards the workers affected.
A careers portal with AI-assisted screening is the most likely high-risk case on an ordinary company website. Look at it early, even though the obligations only arrive on 2 December 2027.
Penalties, and who supervises in Germany
The Act has three tiers. Breaching the Article 5 prohibitions costs up to 35 million euro or 7 percent of worldwide annual turnover, whichever is higher. The other obligations, including the Article 50 transparency duties, sit at up to 15 million euro or 3 percent. Supplying incorrect or misleading information to authorities costs up to 7.5 million euro or 1 percent. For SMEs and start-ups the lower of the two figures applies in each tier.
In Germany the supervisory question was settled on 29 July 2026, when the KI-MIG, the German act on market surveillance and support for AI innovation, entered into force. The Bundesnetzagentur describes its own new role as becoming "the market surveillance authority, single point of contact and point for complaints for the AI Act". It also runs an AI regulatory sandbox for small and medium-sized enterprises. Sector regulators keep their lanes, with BaFin for finance and the state media authorities for media. Which of them applies to your organisation is something we map out with you.
Five steps to get ready
This order has worked in our projects because each step makes the next one possible. We are happy to walk it through with your team.
Step 1: build an AI inventory
- List every AI feature on the site and in the backend, including the ones you bought in.
- Record, per feature, which vendor is behind it and who operates it.
- Flag the careers portal, the chatbot and the search separately.
- The inventory is what everything else is built on.
Step 2: assign a role per feature
- Decide deployer or provider for each feature, with a reason.
- Walk the three Article 25 triggers.
- On agency projects, record the role in the contract.
- An unsettled role is the most expensive open item on this list.
Step 3: make transparency visible
- Check that visitors are told at first contact when they are talking to an AI.
- Check which published content is AI-generated or AI-modified.
- Decide who holds editorial responsibility.
- The detail is in our post on AI content labelling in TYPO3.
Step 4: document AI literacy
- Write a short internal policy and talk it through with the team.
- Set roles and rights in the system so they match the policy.
- Note the date and who took part.
- Proportionate means short, not absent.
Step 5: collect the evidence
- Bring logs, approvals and responsibilities together in one place.
- Put a yearly review in the calendar.
- Reflect changes to AI features back into the inventory.
- Whoever has to demonstrate something later will do it with what this step produced.
Frequently asked questions about the EU AI Act for TYPO3
Yes. The Act distinguishes by role and risk, not by company size. Small and medium-sized enterprises do benefit from the lower of the two penalty figures and from simplified documentation requirements.
Usually a deployer, as long as you install and configure finished extensions. You become a provider if you ship a system under your own name, modify it substantially, or give it a new high-risk purpose.
No. The labelling duty for published text covers text on matters of public interest published without human review or editorial control. Text that has been reviewed, with a named person holding editorial responsibility, is not caught.
The transitional period for machine-readable marking ends, but only for generative systems that were on the market before 2 August 2026. Anything placed on the market since then has had to mark from the start.
The Bundesnetzagentur, since the KI-MIG entered into force on 29 July 2026, alongside the existing sector regulators.
If your question is not here, we are glad to work through it together with you.
Jürgen Pietschmann
TYPO3 Consultant at T3PlanetJürgen Pietschmann is a T3Planet Product Consultant at T3Planet Shop and Head of Technology at keeen GmbH. He specialises in integrating AI into editorial workflows – from intelligent content creation and automated SEO to…
More From Author