APIS Consulting

← Blog

The EU AI Act is now enforceable: what business leaders should do next

European Union stars surrounding a governed artificial intelligence network

The EU AI Act has moved from a future compliance project to a current management obligation. On 2 August 2026, most of the Act became applicable, enforcement began for the rules already in force, and new transparency duties started to apply.

For leadership teams, the important point is not to memorise the Regulation. It is to know where the organisation uses AI, which uses could affect people or the public, who is accountable for them and whether the company can produce evidence that the risks are controlled.

This matters beyond technology companies. A business may be affected because it uses AI in recruitment, customer service, credit decisions, employee management, marketing, security or a regulated product. A company outside the EU can also enter the scope when it puts an AI system on the EU market or its AI output is used in the EU.

The Act in one management-level view

The AI Act follows a risk-based model. The higher the potential impact on safety or fundamental rights, the stronger the obligations.

Unacceptable-risk practices are prohibited. The list includes specified forms of harmful manipulation, exploitation of vulnerabilities, social scoring, certain biometric practices and emotion recognition in workplaces and education. Most of the initial prohibitions have applied since February 2025.

High-risk systems face the most demanding controls. Examples include certain uses in employment, education, critical infrastructure, essential services, biometrics, law enforcement, migration and justice. Requirements include risk management, data governance, documentation, logging, human oversight, accuracy, robustness and cybersecurity.

Some systems carry transparency obligations. People may need to be told when they are interacting with an AI system. Certain synthetic or manipulated content must be detectable and, in defined cases, clearly labelled.

Most low-risk uses remain permitted without a new mandatory control regime. Spam filters and AI-enabled games are examples given by the Commission. Voluntary good practice still makes sense, particularly where confidential data or important decisions are involved.

The classification applies to a specific system and use—not to an entire company. A low-risk writing assistant and a recruitment-ranking tool can therefore create very different obligations inside the same organisation.

What changed on 2 August 2026

The most visible change for many businesses is transparency.

According to the European Commission’s August 2026 explanation of the new rules, users must be clearly informed when they are interacting with an AI system rather than a person—for example through a chatbot, AI agent or avatar.

The rules also address AI-generated or manipulated content. Depending on the system and use, obligations can include machine-readable marking and a clear visible label. The Commission highlights:

  • images, audio and video resembling real people, objects, places or events, including deepfakes;
  • emotion-recognition and biometric-categorisation systems;
  • text published to inform the public on matters of public interest where there has been no human review or editorial control.

The practical question for management is wider than “Do we use a chatbot?” Marketing, communications, customer support, HR, training and product teams may all generate or publish AI-assisted material. Each team needs a simple rule for when a disclosure is required and who checks that it is present.

Enforcement is no longer theoretical. The Commission states that breaches of these transparency rules may lead to fines of up to EUR 15 million or 3% of global annual turnover for companies, with proportionality considered for smaller businesses.

The implementation timeline

The official AI Act implementation timeline reflects the amendments introduced through the AI simplification package. The main dates are:

  • 1 August 2024: the AI Act entered into force.
  • 2 February 2025: definitions, AI-literacy duties and the first prohibited practices began to apply.
  • 2 August 2025: governance arrangements and obligations for general-purpose AI models began to apply.
  • 2 August 2026: most remaining rules, including Article 50 transparency obligations, became applicable; enforcement began for applicable duties.
  • 2 December 2026: the new prohibition concerning systems generating non-consensual intimate content or child sexual abuse material applies; a transition deadline also applies to certain pre-existing synthetic-content systems.
  • 2 August 2027: each Member State should have at least one operational AI regulatory sandbox.
  • 2 December 2027: rules for high-risk systems in the sensitive use cases listed in Annex III apply.
  • 2 August 2028: rules for high-risk AI embedded in regulated products covered by Annex I apply.

The later high-risk dates are not permission to wait. Building an inventory, obtaining supplier documentation and redesigning an approval process can take months. A company that starts classification only when the final deadline arrives will have very little room to replace a non-compliant tool or renegotiate a vendor contract.

First determine your role

The Act distinguishes between actors such as providers and deployers.

A provider develops an AI system or has one developed and places it on the market or puts it into service under its own name. A deployer uses an AI system under its authority, except for purely personal activity. Importers, distributors and product manufacturers can have separate responsibilities.

Most ordinary businesses will be deployers for many of their tools, but this should not be assumed. Rebranding a system, changing its intended purpose or making a substantial modification can alter the position. Contracts should state who performs each compliance task rather than relying on the vendor’s general claim that a product is “AI Act ready.”

A practical 90-day readiness plan

The most effective starting point is a controlled inventory, not a long AI policy.

First 30 days: establish visibility and ownership

  1. Appoint an executive sponsor and a working owner with access to legal, security, privacy, HR, procurement and operational teams.
  2. Inventory AI systems already purchased, embedded in software, built internally or used informally by employees.
  3. Record the purpose, users, affected people, data, supplier, geography and decisions supported by each system.
  4. Screen immediately for prohibited practices and pause anything that cannot be confidently cleared.
  5. Document a proportionate AI-literacy programme for employees who procure, configure, supervise or use AI.

Days 31–60: classify and prioritise

  1. Determine whether the company is provider, deployer or another regulated actor for each use.
  2. Identify potential Annex III uses, especially employment, education, biometrics, essential services and critical infrastructure.
  3. Map current transparency duties: human-versus-AI interaction, synthetic content, deepfakes and public-interest communications.
  4. Ask vendors for intended-purpose documentation, risk classification, data and model information, logging capabilities, human-oversight controls and incident processes.
  5. Give every material system an accountable business owner and an approval status.

Days 61–90: make the controls operational

  1. Add required notices and content labels to customer and public-facing workflows.
  2. Define where human review is mandatory and who has authority to stop or override the system.
  3. Retain the decisions, testing, approvals, versions and incidents needed to demonstrate control.
  4. Integrate AI risk into procurement, privacy review, cybersecurity, change management and incident response.
  5. Create an executive dashboard showing systems by risk, unresolved decisions, vendor gaps and upcoming deadlines.

This approach should be proportionate. A low-risk productivity assistant does not need the governance structure of a high-risk employment system. It still needs basic rules covering confidential information, access, output verification and approved use.

Cybersecurity is part of AI compliance

AI governance and cybersecurity cannot be managed separately. The Commission’s overview of the AI Act includes robustness and cybersecurity among the obligations for high-risk systems.

Management should expect the control framework to cover:

  • access to models, agents, plug-ins and connected business systems;
  • confidential data entered into prompts or used for retrieval and training;
  • manipulation of models, prompts, data sources and AI-generated decisions;
  • monitoring for abnormal use, data leakage and unauthorised automation;
  • supplier and model dependencies, including changes outside the company’s control;
  • deepfake, impersonation and fraud scenarios targeting employees and customers;
  • tested fallback procedures when the system is unavailable or cannot be trusted.

An AI register maintained only by the legal team will miss technical changes. A model inventory maintained only by IT will miss employment, consumer and fundamental-rights risks. The control owner must connect both views.

Questions the board should ask

Leadership does not need to review every model. It should insist on clear answers to a short set of questions:

  1. Do we know where AI is being used, including AI embedded in existing software?
  2. Which systems influence decisions about employees, customers or access to services?
  3. Are any teams publishing synthetic content without a defined review and disclosure process?
  4. Can suppliers provide evidence for their classification and compliance claims?
  5. Who is accountable for each material system, and who can stop it?
  6. Have relevant employees received role-appropriate AI training?
  7. Could we show a regulator our inventory, decisions, controls, logs and incident response?

If the answer to the first question is uncertain, the remaining answers are likely assumptions.

The management takeaway

The EU AI Act should not become a programme to produce paperwork around every use of AI. Its purpose is to identify the systems capable of causing meaningful harm and make their ownership, safeguards and transparency defensible.

For most companies, the immediate priorities are straightforward: find the AI, remove prohibited uses, train the people operating it, meet today’s transparency requirements and begin evidence-based preparation for high-risk deadlines.

This article is a management overview, not legal advice. Applicability and classification should be confirmed against the final legislation and current official guidance for the organisation’s specific role and use case.

Official sources

If your organisation needs to turn its AI inventory into a practical governance and readiness plan, contact APIS Consulting.

← All articles