Back to the blog
AI regulation Published on 6 min read

EU AI Act: which obligations already apply to businesses

The EU AI Act has entered a new phase of application. Businesses need to identify which systems they use, the role they play and the transparency, training and control obligations that apply to them.

AIRegulationTransparencyCompliance
Artificial intelligence system connected to risk, transparency, security and human oversight controls

2 August 2026 marked a new phase in the application of the European Union's Artificial Intelligence Act. Since that date, new transparency obligations have applied and European and national authorities have assumed supervisory and enforcement powers.

This does not mean that every business must meet the same requirements or that every AI tool is high-risk. The Act follows a risk-based approach and also distinguishes between those that develop, market, import or use a system.

The first practical step is not to read a generic list of requirements, but to establish which systems the organisation uses, what they are used for and which role the organisation plays in each case.

Not everything began on 2 August 2026

The Act has applied in stages and the timetable was updated in July 2026 by the AI Omnibus Regulation. The main milestones are:

  • 1 August 2024: the Artificial Intelligence Act entered into force.
  • 2 February 2025: the prohibited practices and AI literacy provisions began to apply.
  • 2 August 2025: governance rules and obligations for providers of general-purpose AI models began to apply.
  • 2 August 2026: the Act became generally applicable, new transparency obligations took effect and supervisory and enforcement powers began.
  • 2 December 2027: the rules for high-risk systems listed in Annex III will apply, including certain uses in employment, education, critical infrastructure or essential services.
  • 2 August 2028: the rules for high-risk systems embedded in regulated products, such as machinery, toys or lifts, will apply.

Waiting until 2027 is not a sufficient strategy: several obligations already apply, and classifying systems requires an understanding of how they are actually used.

A risk-based approach

The Act does not regulate every use of AI with the same intensity. It distinguishes between prohibited practices, systems subject to transparency requirements, high-risk systems and uses presenting minimal or no risk.

Many common business tools may fall into limited- or minimal-risk categories, but that does not remove every obligation. A chatbot may need to make it clear that the user is interacting with a machine. Synthetic content may require technical marking or a visible label. A tool used in recruitment may fall into an entirely different category.

Classification depends on the intended purpose and actual use, not merely on the technology or the product's commercial name.

The first task: identify the business's role

Obligations change according to the organisation's position in the value chain. A single business may play more than one role:

  • Provider: develops an AI system, or has one developed, and markets it or puts it into service under its own name or trade mark.
  • Deployer: uses an AI system under its authority as part of a professional activity.
  • Importer or distributor: brings into or makes available in the European Union a system supplied by another entity.
  • Product manufacturer: integrates an AI system into a regulated product and markets it under its own name or trade mark.

Buying an external tool does not automatically make the business its provider. Professional use may, however, make it a deployer, with responsibilities of its own that cannot be transferred entirely to the manufacturer.

Which obligations should many businesses already be reviewing?

The precise scope depends on each system, but four areas already deserve priority attention.

  • Prohibited practices: uses covered by Article 5 must be ruled out, including certain manipulative techniques, social scoring systems and some biometric processing. The list and its exceptions require a case-specific assessment.
  • AI literacy: providers and deployers must take measures to support the development of the people who use or operate their systems. They are not required to guarantee a specific individual level or obtain a particular certificate.
  • Transparency: certain interactive systems must disclose that a person is dealing with AI. There are also marking obligations for synthetic content and visible disclosure requirements in cases such as deepfakes, emotion recognition or certain texts on matters of public interest.
  • Governance and oversight: since August 2026, competent authorities have been able to supervise and enforce the provisions already applicable. Having owners, documentation and evidence is no longer purely voluntary preparation.

What should be prepared for a high-risk system?

The specific obligations for high-risk systems will apply later, but businesses should not postpone all preparation until those dates. Classification, contracts, data quality and traceability cannot be resolved overnight.

The elements that will need to be demonstrated include risk management, technical documentation, activity logging, data quality, human oversight, accuracy, robustness and cybersecurity. The precise responsibility will depend on whether the business is a provider, deployer or another operator.

The AI Act does not replace other rules. Data protection, information security, employment rights, intellectual property and sector-specific regulation may still apply to the same project.

A practical six-step plan

  • Inventory the systems. Include purchased tools, internal developments, AI functions embedded in software and pilots already using real data.
  • Define purpose and ownership. Record what each system is used for, who administers it and who reviews its outputs.
  • Identify the role and risk level. Distinguish between provider, deployer and other operators, and assess each use case under the Act.
  • Review transparency and communication. Check user notices, content labelling and any information that must be provided to affected people.
  • Train teams according to their role. Adapt AI literacy measures to their knowledge, the context of use and the impact the system may have on other people.
  • Establish controls and evidence. Retain decisions, sources, permissions, validation, incidents and human oversight points in proportion to the risk.

Compliance can also improve the process

Useful governance is not about accumulating documents. It is about clarifying which data a system uses, which decisions it may support, who is accountable for its operation and when a person must intervene.

This work also helps identify duplicate tools, unnecessary access, processes without an owner and automation that is not producing reliable outcomes. Compliance can therefore become an opportunity to organise the use of AI and focus it on cases that deliver real value.

At Ai4G, we help turn these principles into practical solutions by combining inventory, data, automation, traceability and human oversight from the design stage.

This article provides general information and does not replace a legal assessment of a specific case. The starting point is simple: know which AI the business uses, why it uses it and who is accountable for each decision.

Official source: European Commission, AI Act and application timeline

Want to apply it to your business?

Let's discuss your data, processes and automation opportunities to define an initial practical use case.

Contact Ai4G

Related articles

You may also be interested in

More insights