Skip to content
Confir.
Countries

EU AI Act in the Czech Republic: How It Applies and What Companies Must Do

Country Guide4 August 2026· 12 min read

The EU AI Act applies directly in the Czech Republic, no national law needed. Covers the Annex I product route for automotive and machinery AI, plus fines.

Directly. The EU AI Act — Regulation (EU) 2024/1689 — applies in the Czech Republic the moment it bites, with no Czech statute standing between your organisation and its obligations. If you are a Tier-1 automotive supplier in Brno, a machinery builder in Plzeň, or a software firm in Prague embedding models into regulated products, the duties already run against you. This guide explains how the Act applies in the Czech Republic, who enforces it, and why the Annex I product route is the decisive question for the Czech industrial base.


A Regulation, Not a Directive: No Czech Transposition Needed

The EU AI Act is a Regulation, not a Directive. Under Article 288 TFEU, a Regulation is binding in its entirety and directly applicable in every Member State, including the Czech Republic, without any national transposing law. There is no Czech act that you wait for before compliance starts.

What 'directly applicable' means in practice

This is the core point readers searching country terms most often get wrong. A Directive needs national legislation to give it effect; a Regulation does not. The EU AI Act entered into force on 1 August 2024, and its obligations flow straight from the Regulation's own articles. Czech companies cannot defer compliance pending a domestic statute — the deadlines are EU-wide and identical across all Member States, and there are no Czech-specific dates.

Obligations already live versus infrastructure still pending

Several duties are already enforceable. Article 5 prohibited practices and Article 4 AI literacy obligations have applied since 2 February 2025. GPAI obligations under Chapter V (Articles 51–55) have applied since 2 August 2025. What the Czech Republic must still provide is national enforcement infrastructure: a designated competent authority, domestic penalty procedures, and a single point of contact for the EU AI Office. The absence of that infrastructure does not suspend the substantive obligations — it only affects who can investigate and fine, and how.


Who Designates and Enforces the EU AI Act in the Czech Republic

The Article 70 designation mechanism

Article 70 requires every Member State to designate at least one national competent authority that also serves as the market surveillance authority (MSA), plus a notifying authority and a single point of contact (SPoC) for the EU AI Office. The Czech Republic designates its authority through national measures. The specific named body and any implementing act should be confirmed against current official Czech sources rather than assumed — at the time of writing, the designation should be verified before you rely on a particular authority name.

Central authority plus sectoral regulators (general pattern, hedged)

The common shape across Member States — offered here as the general mechanism, not a confirmed Czech choice — is a central market surveillance authority sitting alongside sectoral regulators that retain competence in their own domains, such as financial supervision or medical-device oversight. The Czech Republic is likely to follow a comparable cross-sectoral pattern, but the precise allocation is a matter for national designation and remains an item for human review before publication. Note that several Member States missed the 2 August 2025 designation deadline; the absence of a formally empowered national authority does not suspend the obligations the Regulation imposes.

GPAI and the EU AI Office

GPAI model providers based in the Czech Republic are supervised directly by the EU AI Office in Brussels under Chapter V, not by the national authority. The national SPoC coordinates with the AI Office; it does not displace it. If your Czech firm develops and places a general-purpose AI model on the market, treat that as a Brussels-supervised matter. For the underlying concept, see our explainer on what a market surveillance authority does.


The Annex I Product Route: Why It Matters for Czech Industry

This is the spine of compliance for the Czech Republic. The Czech economy is heavily weighted towards manufacturing and automotive, so a large share of affected AI is embedded in regulated products rather than standing alone. Getting the routing right is the first decision, not a detail.

Article 6(1) versus Article 6(2): two routes to high-risk

There are two routes to high-risk status. Article 6(1) routes high-risk status through products already covered by the Union harmonisation legislation listed in Annex I. Article 6(2) is the distinct stand-alone route: a system is high-risk if it falls within the Annex III list (recruitment, creditworthiness, biometrics, and so on). A stand-alone Annex III system takes the full obligation stack directly. A product-embedded Annex I system does not necessarily — and that is where Czech industry must pay attention.

Section A versus Section B under Article 2(2)

Annex I splits into two sections, and the difference is decisive.

Annex I sectionExamples and governing actsWhich AI Act provisions apply directly
Section BMotor vehicles (Regulation (EU) 2018/858), agricultural and forestry vehicles (Regulation (EU) 167/2013), aviation, rail, marine equipmentUnder Article 2(2), only Article 6(1) and Articles 102–109 and 112 apply directly. The Articles 8–15 / 16 / 43 stack does NOT apply directly.
Section AMachinery (Regulation (EU) 2023/1230), medical devices (MDR 2017/745, IVDR 2017/746), toys, lifts, radio equipmentConformity is routed through the sectoral acts via Article 43(3) rather than applying Article 43 directly.
Stand-alone (Annex III)Recruitment, creditworthiness, biometric categorisation, educationThe full high-risk stack (Articles 9–15, 16, 26, 43) applies directly under Article 6(2).

What this means for automotive and machinery suppliers

The practical takeaway for Czech automotive suppliers and machinery builders is to identify whether their AI is a Section A or Section B safety component first, before any other compliance work. That single classification determines which obligations apply and which conformity pathway you follow. A lane-keeping component in a type-approved vehicle and a vision system in CE-marked machinery are governed by different parts of the Act, even though both are "product-embedded AI".


The EU AI Act Timeline as It Applies in the Czech Republic

The deadlines are EU-wide and identical in every Member State. There are no Czech-specific deadlines — a common misconception on country pages.

DateWhat applies
2 February 2025Article 5 prohibited practices and Article 4 AI literacy — in force, enforceable now
2 August 2025GPAI obligations (Articles 51–55), governance, and Article 99 penalties
2 August 2026General application including Article 50 transparency (chatbots, deepfakes, synthetic-content marking)
2 December 2026New content-marking duties under Article 50 (Digital Omnibus, adopted June 2026)

Fixed dates already in force

The dates above the line are fixed and live. "Stop the clock" — the idea of pausing the whole framework — was rejected. Not everything is delayed: Article 5 and the GPAI dates are settled and apply now. Any Czech company persisting with a prohibited practice has been exposed since 2 February 2025.

Deferred high-risk dates and the Omnibus caveat

The high-risk dates are where the picture is moving. The statute sets 2 August 2026 for stand-alone high-risk Annex III systems (Article 6(2)), with an adopted deferral to 2 December 2027. Annex I product-embedded high-risk AI (Article 6(1)) carries a statutory 2 August 2027 date with an adopted move to 2 August 2028.

The Digital Omnibus was approved by the European Parliament on 16 June 2026 and formally adopted by the Council on 29 June 2026; it enters into force on publication in the Official Journal, expected before 2 August 2026. Companies should plan against 2 December 2027. For Czech industry, the Annex I product-embedded route carries the latest dates but the most demanding sectoral conformity work, so an early start is still warranted.


Penalties Czech Companies Face Under Article 99

The three Article 99 tiers

Article 99 sets three tiers, applied by national authorities once the Czech designation is complete:

  • €35 million or 7% of total worldwide annual turnover, whichever is higher — for breaches of the Article 5 prohibitions (Article 99(3)).
  • €15 million or 3% — for non-compliance with most other obligations, including high-risk requirements (Articles 9–15), provider duties (Article 16), deployer duties (Article 26), and Article 50 transparency (Article 99(4)).
  • €7.5 million or 1% — for supplying incorrect, incomplete, or misleading information to notified bodies or competent authorities (Article 99(5)). The third tier is 1%, not 1.5%.

Article 99(6) cap for smaller companies

Article 99(6) provides a proportionality protection for SMEs and start-ups: the fine is capped at the lower of the fixed amount or the percentage. Penalty procedures are operationalised through national measures, so until the Czech designation is complete the procedural detail is pending — but the substantive ceilings are set by the Regulation itself and do not wait for a Czech act.

GPAI-specific fines are a separate instrument under Article 101: up to €15 million or 3%, imposed by the Commission directly on GPAI model providers, not by the national authority.


Worked Example: A Czech Tier-1 Automotive Supplier

Consider Brno Drive Systems, a fictional Czech Tier-1 automotive supplier with roughly 1,400 employees and €320 million annual turnover, supplying AI-enabled driver-assistance and in-cab monitoring components.

Routing the in-vehicle AI (Annex I Section B)

Step 1 is inventory and routing. Its lane-keeping AI is a safety component of a motor vehicle type-approved under Regulation (EU) 2018/858, placing it in Annex I Section B. Under Article 2(2), only Article 6(1) and Articles 102–109 and 112 apply directly, so compliance flows through the existing automotive type-approval framework rather than the Articles 8–15 / 43 stack. The trap is assuming the full high-risk stack applies to in-vehicle AI; for Section B, it does not apply directly.

The HR tool as stand-alone Annex III

Step 2: the same company runs an Annex III employment AI tool — CV screening, Annex III point 4(a) — for its HR team. That stand-alone system takes the full high-risk stack directly, and the deployer must complete an Article 27 Fundamental Rights Impact Assessment where applicable. Two systems, two completely different obligation routes, inside one company.

Article 25 role-shift risk

Step 3 is the role check. If Brno Drive Systems fine-tunes a vendor model on its own data, places a system under its own name, or substantially modifies it, Article 25 can convert it from deployer to provider, triggering the full Article 16 provider obligations — including the Annex IV technical documentation and the Article 47 / Annex V Declaration of Conformity.

Step 4 is sequencing: classify each system, separate Section B product-route items from stand-alone Annex III items, and start the demanding sectoral conformity work early despite the 2 August 2028 product date. On penalties, scale matters. With roughly 1,400 employees and €320 million turnover, Brno Drive Systems is not an SME or start-up, so the Article 99(6) lower-of cap does not apply to it; each tier resolves to the higher of the fixed figure or the percentage. For a misleading-information breach (Article 99(5)), the exposure is the higher of €7.5 million or 1% of €320 million — 1% is €3.2 million, so the €7.5 million figure governs. For a high-risk breach (Article 99(4)), the exposure is the higher of €15 million or 3% of €320 million — 3% is €9.6 million, so the €15 million figure governs. The percentage only overtakes the fixed amount for a much larger group.


How Confir helps

Czech compliance teams face a documentation-heavy obligation set across two distinct routes: product-embedded AI under Article 6(1) and stand-alone systems under Article 6(2). Confir is an EU-hosted compliance tool built for exactly this work. Its classification engine is deterministic and rule-based — no model inference, no hallucination — so the same intake always produces the same finding, with a human-readable explanation of which rule fired. It builds the AI inventory, runs Article 6 plus Annex III classification, generates the Annex IV technical documentation pack and the Article 47 / Annex V Declaration of Conformity, and supports the Article 27 FRIA. There is no AI or LLM in the product, and the GPAI workflow remains on the roadmap.


What Czech Companies Should Do Now

Immediate Article 5 audit

Audit for any Article 5 prohibited practice: subliminal or manipulative techniques (5(1)(a)), biometric categorisation inferring sensitive attributes (5(1)(g)), emotion recognition in the workplace or education (5(1)(f)), social scoring, and real-time remote biometric identification in public spaces. These have been enforceable since 2 February 2025. If a system fits and no exemption applies, stop or restructure it.

Classify and split product-route from stand-alone

Before 2 August 2026, ensure customer-facing systems meet Article 50 transparency — chatbots disclose they are AI; deepfakes and synthetic image, audio, or video are disclosed as artificially generated. Generative-AI output content-marking duties land 2 December 2026 under the Omnibus, adopted in June 2026. From 2026 onward, build the AI inventory, classify every system through Article 6, and explicitly split Annex I product-route systems (Section A versus Section B) from stand-alone Annex III systems, because the obligations and conformity pathways differ. For Section A machinery and medical-device AI, engage notified bodies early — Article 43(3) routes conformity through the sectoral acts and accredited-body capacity is constrained.

Track designation and the Omnibus

Monitor the Czech national designation: track when the competent and market surveillance authority is formally named and the SPoC confirmed. The Digital Omnibus has cleared European Parliament plenary and Council adoption; only Official Journal publication remains, expected before 2 August 2026 — plan against the adopted 2 December 2027 date.


Manage your EU AI Act compliance in one place

Confir automates risk classification, technical documentation, and audit trails for any company. No consultants. No 6-month projects. 14-day free trial.

Start free trial →

Keep reading