← Blog

AI Meeting Assistants and the EU AI Act: What Applies Now

    If you let an AI notetaker sit in on your sales calls, standups, and customer meetings, part of the EU AI Act already applies to you today. Not in December 2027. Not in 2028. Now. The transparency duties in Article 50 of the AI Act have been in force since August 2, 2026, and they land on the organisation using the tool, not just the vendor who built it. The problem is that most of the guidance you will find online was written before the summer of 2026 and tells you the opposite: that everything has been pushed back. That advice is out of date, and acting on it is a compliance risk rather than a shortcut.

    This is a practical guide for deployers: companies and teams that use AI meeting assistants, as opposed to the vendors who make them. It explains what is genuinely live, what was actually deferred by the Digital Omnibus, who enforces it in Germany and the Netherlands, and gives you a checklist you can run this week plus an avoid-list of the mistakes we keep seeing. It is general information to help you scope the work, not legal advice.

    The short version

    Live now: Article 50 transparency (since August 2, 2026), Article 5 prohibitions and Article 4 AI literacy (since February 2025). Deferred by the Digital Omnibus: high-risk Annex III duties (to December 2, 2027) and AI in regulated products (to August 2, 2028). Most standard meeting assistants are not high-risk, so the deferral does not switch off their obligations.

    What is actually in force right now

    The AI Act (Regulation (EU) 2024/1689) is a phased law. Different tiers of obligation switch on at different dates, and the meeting-assistant-relevant ones are among the earliest, not the latest. Here is the part of the timeline that matters for a deployer.

    Date What is enforceable
    Feb 2, 2025 Prohibitions and AI literacy. Article 5 (banned uses, including certain emotion-inference and manipulation practices) and Article 4 (a duty to ensure staff who use AI systems have adequate AI literacy) have been binding since this date. Both apply to deployers.
    Aug 2, 2026 Article 50 transparency. The transparency obligations for AI systems that interact with people and generate synthetic content are in force. This is the core provision for AI notetakers: disclose the AI, and make AI-generated output identifiable as such.
    Dec 2, 2026 End of the legacy grace window. For systems already on the market before August 2, 2026, there is a grace period for the Article 50(2) synthetic-content marking duty that runs until this date. After it, the marking duty applies to those systems too.
    Dec 2, 2027 Annex III high-risk duties (deferred). The Digital Omnibus pushed the high-risk obligations for Annex III systems to this date. Standard meeting transcription and summarisation is generally not an Annex III use, so for most deployers this is not the operative date.
    Aug 2, 2028 AI in regulated products (deferred). AI embedded as a safety component in products already covered by EU harmonisation law was deferred to this date. It does not describe a normal meeting assistant.

    The takeaway is simple. The obligations that were pushed back are the heavy, high-risk ones that most meeting assistants do not trigger. The obligation that applies to nearly every deployer of an AI notetaker, Article 50 transparency, was not pushed back at all.

    Why most of the guides you will find are wrong

    In July 2026 the EU adopted a package widely referred to as the Digital Omnibus, which adjusted several digital-law timelines and deferred a set of AI Act high-risk deadlines. A large amount of the "EU AI Act explained" content that ranks today was published before that package, or misreads it. Two failure modes are common.

    The first is content that predates the deferral entirely and still quotes the original high-risk dates as if nothing changed. The second, and more dangerous for you, is content published after the Omnibus that overreaches in the other direction: it reports that "the AI Act has been delayed" as a blanket statement and leaves readers with the impression that nothing applies before 2027. Both are wrong for a meeting-assistant deployer, because the transparency, prohibition, and literacy duties that actually govern your use of an AI notetaker were never part of the deferral.

    If a source cannot tell you, specifically, that Article 50 remained in force on August 2, 2026 while Annex III moved to December 2027, treat it as stale. This post exists to be the accurate reference on exactly that point.

    Who enforces it: Germany and the Netherlands

    The AI Act is an EU regulation, but enforcement runs through national market surveillance authorities, and member states are standing those up on their own timelines. Two of the most relevant for our customers:

    Country Status
    Germany In force. Germany's AI Act market surveillance implementation law took effect on July 29, 2026, designating the Bundesnetzagentur as the central market surveillance authority. Enforcement structure is live.
    Netherlands Draft. The Dutch implementation act is still in draft. The Autoriteit Persoonsgegevens (AP) and the Rijksinspectie Digitale Infrastructuur (RDI) are expected to share supervision, with parliamentary treatment anticipated in the fourth quarter of 2026.

    The practical point for a deployer operating across the DACH region and the Benelux: the substantive Article 50 duty is the same everywhere because it comes from the regulation, but the authority that can question you, and how far along its powers are, differs by country. Germany already has a named, active enforcer.

    The deployer checklist: what to do this week

    None of the following requires a law firm to get started. It requires an afternoon and a willingness to be honest about what is already recording your meetings.

    1. Disclose the bot in the meeting and in the invite. Announce that an AI assistant is present and recording at the start of the call, and add a line to the calendar invite so people know before they join. Transparency to the people in the room is the single most direct way to meet the spirit of Article 50 for an AI notetaker.
    2. Run documented AI literacy training. Article 4 requires that staff using AI systems have adequate AI literacy. A short, dated, recorded internal session covering what the meeting assistant does, what it does not do, and how to handle its output is enough to show you took the duty seriously. Keep the record.
    3. Inventory your tools and hunt for shadow notetakers. List every AI assistant that joins your meetings, including the free ones individual reps connected without telling anyone. Unknown bots are the most common gap: you cannot disclose or govern a tool you do not know is in the room.
    4. Get the GDPR basics in place. Confirm your lawful basis for recording, that participants are made aware, that you have a signed data processing agreement with the vendor, and that any processing outside the EU or an adequate country has a valid transfer mechanism. The AI Act sits on top of GDPR here, not instead of it.
    5. Ask your vendor the right questions. Where is the audio processed and stored? Which model provider is behind the transcription and summaries, and where does that run? Who are the subprocessors? Does the product support disclosing the AI and identifying AI-generated output so you can meet Article 50? Get the answers in writing.

    The avoid-list: mistakes to skip

    • Assuming everything was delayed. The Digital Omnibus deferred high-risk Annex III duties and regulated-product AI, not Article 50 transparency, not the Article 5 prohibitions, and not the Article 4 literacy duty. Treating the deferral as a blanket pause is the headline mistake this post is written to prevent.
    • Letting bots join unannounced. An AI assistant that silently records people who were never told is the exact scenario the transparency duty targets, and it is a GDPR problem at the same time. Silent capture is not a grey area you want to be defending.
    • Panic-buying compliance tooling for rules that may not apply to you. A wave of vendors will sell you Annex III high-risk conformity tooling for the December 2027 deadline. Most standard meeting assistants are not high-risk. Spend first on the transparency and literacy work that is live now, and classify your actual use before buying for obligations you may never carry.

    Where EU hosting and model control make this easier

    Two of the checklist items above, the GDPR transfer question and the vendor subprocessor question, get materially simpler when the tool keeps everything inside EU jurisdiction. If call audio, transcription, storage, and the coaching model all run in the EU, there is no cross-border transfer to paper over with standard contractual clauses, and the list of subprocessors you have to disclose and defend gets shorter. Controlling the model that generates summaries also makes the Article 50 transparency story cleaner, because you can say precisely how AI output is produced rather than pointing at an opaque third party.

    To be clear about what this does and does not do: no tool makes you AI Act compliant on its own. The disclosure, the training, the inventory, and the consent handling are your responsibilities as the deployer, and no vendor can discharge them for you. What EU hosting and model control do is remove friction from the parts of the work that touch data location and vendor transparency. Numi is built to keep call audio, transcription, storage, and coaching under EU control for that reason, but the governance steps in the checklist remain yours to run.

    Disclaimer

    This article is general information about the EU AI Act and related rules as they stood in August 2026. It is not legal advice, it does not create a lawyer-client relationship, and it does not account for your specific circumstances. Regulations and national implementation continue to change. Confirm your own obligations with qualified counsel before you rely on any of the above.

    For adjacent reading, see the date-pegged companion piece on what actually applied on 2 August 2026, our GDPR-compliant AI meeting assistant comparison, the broader EU AI Act timeline for B2B SaaS, and the guide to recording sales calls legally in Europe.

    Frequently asked questions

    Was the EU AI Act delayed for AI meeting assistants?

    Only partly, and not the part that governs meeting assistants. The Digital Omnibus that entered into force in July 2026 deferred high-risk obligations: Annex III systems now apply from December 2, 2027, and AI embedded in regulated products from August 2, 2028. It did not delay the transparency duties in Article 50, which have applied since August 2, 2026, nor the Article 5 prohibitions and Article 4 AI literacy duty, both binding since February 2025. Most standard AI notetakers are not high-risk, so the deferral does not remove their live obligations.

    What does Article 50 require when you use an AI notetaker in a meeting?

    Article 50 of Regulation (EU) 2024/1689 sets transparency duties that have been in force since August 2, 2026. In practice, people interacting with an AI system should be made aware of it, and AI-generated output such as machine summaries should be identifiable as artificially generated. For a meeting assistant that means disclosing the bot to everyone on the call and in the calendar invite, and being transparent that notes and summaries are produced by AI. For systems that were already on the market before August 2, 2026, there is a grace period for the Article 50(2) synthetic-content marking duty until December 2, 2026. This is general information, not legal advice.

    Do I need consent to record a meeting with an AI assistant in the EU?

    Recording and transcribing a call captures personal data, so GDPR applies alongside the AI Act. You generally need a lawful basis, participant awareness, a data processing agreement with your vendor, and a valid transfer mechanism if any processing leaves the EU or an adequate country. The AI Act transparency duty and the GDPR obligations are separate frameworks with separate enforcers, so satisfying one does not satisfy the other. This is general information, not legal advice.

    Which authority enforces the EU AI Act in Germany?

    Germany brought its AI Act market surveillance implementation law into force on July 29, 2026, and designated the Bundesnetzagentur as the central market surveillance authority for the AI Act. In the Netherlands, an implementation act is still in draft, with the Autoriteit Persoonsgegevens (AP) and the Rijksinspectie Digitale Infrastructuur (RDI) expected to share supervision and parliamentary treatment anticipated in the fourth quarter of 2026.

    Does using an EU-hosted meeting assistant make me AI Act compliant?

    No. No tool makes you AI Act compliant on its own, because most obligations sit with you as the deployer: disclosing the bot, training staff, keeping a tool inventory, and handling consent and data processing. What EU hosting and control over the model do is simplify the surrounding work. Keeping call audio, transcription, storage, and coaching inside EU jurisdiction removes cross-border transfer complexity and shortens the subprocessor list you have to disclose and defend. Numi is built that way, but the transparency and governance steps remain your responsibility.

    Numi keeps call audio, transcription, storage, and coaching under EU jurisdiction, so the data-location and vendor-transparency parts of your AI Act and GDPR work start from a simpler place.

    Get Early Access