Skip to Content

EU AI Act 2026: What It Means for Your Odoo Business in Hungary (and What It Doesn't)

The EU AI Act is far less threatening for a business than the panic headlines suggest — we look at where typical Odoo + AI use actually falls, and what you genuinely need to do now.
30 July 2026 11 min read

If you've been reading the panic headlines, you'd think the EU AI Act brings billion-forint fines to every company. The reality is different. The typical Odoo and AI features a business operating in Hungary actually uses — automated invoice reading, demand forecasting, natural-language queries — fall into the lightest, “minimal risk” category, where the regulation sets no special obligations. Two things genuinely matter right now: if customers talk to an AI, you need to disclose it, and you need to make sure the colleagues using AI understand what they are doing. The strict rules apply to high-risk uses; most of them have been pushed back to 2027 — the European Parliament and the Council both approved this package in June 2026, and it becomes law once published in the EU Official Journal. The HUF 13 billion figure is the ceiling for prohibited practices — not the risk facing a business running a chatbot.

Note: this is business-technical guidance for owners, not legal advice. If you're operating in a border area — HR, credit scoring, biometrics, healthcare — it's worth getting a separate legal opinion.

Panic and reality

The AI Act is the world's first comprehensive AI regulation, and with it came the usual wave of scare stories: fines, paperwork, compliance nightmares. As a business owner, it's understandable to be cautious. But the regulation's logic isn't to bury every AI use in bureaucracy.

The AI Act doesn't penalise based on whether you “use AI” — it penalises based on what for. The greater the harm an AI system could cause in someone's life — in a job interview, a credit decision, a medical decision — the stricter the rule. Where the stakes are low, the obligations are minimal too. And most SMEs aren't using AI to decide people's fates — they're using it to speed up internal operations: reading invoices, finding data, building forecasts.

The EU AI Act's four risk categories — layered pyramid illustration

The four categories, simply put

The regulation sorts uses into four tiers:

  • Prohibited. A handful of practices simply aren't allowed — social scoring, for example, or manipulative systems that can harm people. An ordinary business never runs into these.
  • High risk. This is where the strict rules live: systems that decide people's fates. CV-screening AI, credit scoring, certain biometric tools. Full documentation, human oversight, and logging all apply.
  • Limited risk. Chatbots and AI-generated content fall here. One main rule: be transparent. People need to know they're talking to a machine, or that an image or text was AI-generated.
  • Minimal risk. Everything else. The regulation sets no special obligation here. Most internal, operations-support AI features may fall into this tier, as long as they don't decide on people's rights, access, or opportunities.

Where do your Odoo AI features fall?

In day-to-day operations, this mostly comes down to the cases below. The AI features typically used in an Odoo environment for a business operating in Hungary generally fall into the minimal-risk category:

  • reading incoming supplier invoices automatically and turning them into accounting entries,
  • demand or stock forecasting,
  • asking a plain-language question about your data (“show me the overdue invoices”),
  • automation you trigger with a written instruction.

In typical cases, these carry no separate AI Act paperwork burden, though data protection and internal controls still apply. There's exactly one place where you need to pay separate attention: if you run a chatbot visible to customers, that's limited risk — you need to disclose that the visitor is talking to a machine. The same applies to publicly published AI-generated content.

You're in high-risk territory when AI makes an important decision about a person in your place — screening or ranking CVs, or assessing creditworthiness. If you're planning something like that, the task gets more serious — but you have time for that too, more on that shortly.

An example from practice. A twenty-person trading company reviews what it's running. AI reads incoming invoices — minimal risk. A chatbot answers on its webshop — limited risk, so it needs to disclose that visitors are talking to a machine. It doesn't screen CVs with AI in recruitment — so it avoids the high-risk part. Five minutes, and the picture is clear: the one real task is labelling the chatbot.

The two things you actually need to do now

The good news: if you're using minimal-risk AI, your to-do list is short.

1. Build AI literacy. This is the one obligation that has applied to every organisation since February 2025. It's not a form, not an audit: it means the colleagues using AI understand what the tool can and can't do, and when a human needs to check its output. For many companies, a short, plain-language internal briefing is enough to start: what the tool is good for, what it isn't, and when a person needs to verify it.

2. Label your chatbot. If AI chat answers on your website or in customer service, make it clear the visitor is talking to a machine. The deadline for this is 2 August 2026, so you still have time — often a clearly visible line at the top of the chat window is enough.

That's roughly it for the first round. The rest matters mainly to those considering riskier AI uses.

The EU AI Act rollout timeline from 2025 to 2028 — timeline with milestones

What takes effect when?

To make the timeline clearer:

  • 2 February 2025 — prohibited practices and the AI literacy obligation apply.
  • 2 August 2025 — rules for general-purpose AI models.
  • 2 August 2026 — the regulation applies in full; this is when the transparency rule for chatbots and generated content kicks in.
  • 2 December 2027 — the main obligations for high-risk systems (August 2028 for embedded cases).

Precision matters here: the delay to the high-risk rules was set by a political agreement in spring 2026, then approved by the European Parliament (16 June 2026) and the Council (29 June 2026); the changes take legal effect once published in the EU Official Journal, which is expected before 2 August 2026. The core point is stable, though: most of the strict obligations don't apply to typical internal Odoo automation, and several elements still leave you preparation time.

The fines — realistically

The HUF 13 billion figure genuinely appears in Hungarian law, but it's worth knowing what it applies to. It's the ceiling for prohibited AI practices — the cap set for the most severe cases, not the risk facing an average company. Breaching high-risk obligations falls into a lower band, and giving false information to the authority falls lower still.

And there are two things that specifically protect smaller companies. The regulation requires that fines be proportionate — an SME can't receive the same penalty as a large corporation. Second, every EU member state must provide a free regulatory testing environment, where you can safely try out an AI solution — with priority given to SMEs. In Hungary, this framework was created by Act LXXV of 2025; oversight sits with the NMHH and the new AI Market Surveillance Authority.

For a typical business operating in Hungary that uses minimal-risk Odoo + AI features, and takes care of AI literacy and chatbot labelling, the billion-forint fine bracket is not, in practice, where you sit.

Data sovereignty — company data around AI running in a controlled EU environment

A question every company runs into: where does the data go?

The AI Act is about risk, but alongside compliance there's a related question that occupies a lot of business owners: if you use AI, where does your company data end up? On top of that, the AI Act doesn't replace GDPR — the two apply in parallel, and personal data is still governed by GDPR.

Where the model runs matters a great deal here. If you upload your documents to an external cloud provider, you have less visibility into what happens to them. If the AI instead runs in your own, or a controlled EU environment, it's far easier to keep track of where the documents go, and what the provider can use them for.

That's why we favour solutions where the AI works around Odoo and your company's own knowledge base, in a controlled environment. We build private AI assistants for exactly this purpose: the system works from your own data, shows its sources, and you don't need to upload every document to an uncontrolled external tool. If data control matters to you too, we wrote more about this on a separate page.

FAQ

Can I really be fined HUF 13 billion?
The HUF 13 billion figure is the ceiling for prohibited AI practices, not the risk facing an average company. If you use minimal-risk features and take care of AI literacy and chatbot labelling, in practice you're not looking at that fine.

What does AI literacy mean in practice?
It means the colleagues using AI understand what the tool can and can't do, and when a human needs to check it. A short internal briefing is enough to start — there's no official form for it.

Can an AI feature used in Odoo be high-risk?
Generally not, for typical Odoo use. The usual invoice reading, stock forecasting, and internal queries are typically minimal risk, as long as they don't decide on people's rights or opportunities. You move into high risk when AI decides someone's fate — CV screening or credit assessment, for example.

What do I need to do if I use a chatbot?
Disclose that the visitor is talking to AI. The deadline is 2 August 2026. In many cases a clearly visible sentence is enough, but the exact wording and placement should be adapted to your actual interface.

Does the AI Act replace GDPR?
No. The two apply side by side; personal data is still governed by GDPR. With AI features, you need to watch both.

Do I need to act right now?
If you're using minimal-risk AI, the urgent items are just AI literacy and — for a chatbot — labelling. Everything else can wait until you're considering a riskier use.

What's worth doing now

The AI Act isn't a reason to panic, but it's a good occasion to think through where and how you use AI. The first step isn't a big legal project — it's a simple AI inventory: where does your company use AI, what data does it access, is it customer-facing, and does it decide anything about a person? Odoo is a good base for this, because you're not guessing from scattered spreadsheets — you see the processes, the data, and the AI touchpoints in one system.

For this, we created our AI Act checklist for SMEs: go through it, and you'll see what AI features you have, which risk category each falls into, where there's real work to do — and where it's just unnecessary panic.

Book a free consultation with a Glazer-Innovation Kft. expert. In one conversation, we'll go through:
1. AI inventory — where are AI features running in your Odoo and on your website?
2. Risk classification — which feature falls into which AI Act category?
3. Actual to-dos — where's the real work (labelling, AI literacy), and where's it just unnecessary panic?
4. Data control — where does your company data end up, and how do you keep it under control?

➜ Request a quote

The consultation is free and no-obligation. We don't provide legal opinions, but we help you see more clearly what's worth checking with a lawyer too.

We are an official Odoo Learning Partner and an accredited supplier — we build AI Act awareness into your Odoo + AI system from the start, rather than bolting it on afterward.

This article is for information only and does not constitute legal advice; the exact classification is a matter of interpretation, so seek a professional opinion in doubtful cases.

References

An SAP Alternative for Hungarian SMEs: When Is Odoo a Better Choice?
SAP or Odoo? An objective, SME-focused comparison — when an enterprise system is genuinely the right call, and where a modular alternative localised into Hungarian works better.