The AI Act does not only concern model developers. It also affects organisations integrating chatbots, recruitment systems, predictive analysis, content generation or intelligent automation into everyday operations.

The European regulation entered into force on 1 August 2024 and applies progressively. Prohibited-practice and AI-literacy provisions have applied since February 2025; governance and general-purpose AI rules since 2 August 2025; and a substantial part of the regulation, including transparency requirements, since 2 August 2026. Following the AI Omnibus amendments that entered into force on 27 July 2026, rules for Annex III high-risk systems will apply from 2 December 2027, while those for systems embedded in regulated products will apply from 2 August 2028. The exact timeline depends on the organisation's role, use case and risk classification.

You do not need another document. You need a map.

Starting with a policy is a common mistake. Rules written before understanding the tools in use describe a theoretical company rather than the real operation. Begin with a lightweight inventory:

  • tool, provider and version;
  • process and internal owner;
  • data entered, produced or transformed;
  • people and customers affected by the output;
  • degree of autonomy and human control;
  • potential impact if the system fails.

This map also reveals shadow AI: personal accounts, extensions and services adopted without approval. A blanket ban rarely solves the issue; authorised alternatives and understandable rules are usually more effective.

Operational principleA concise, current register connected to real processes is worth more than a perfect policy nobody reads.

Provider, deployer or user?

The AI Act assigns different obligations according to role. A business using an AI service in its own process is normally a deployer, but its responsibilities may change if it markets the system under its own name, substantially changes its purpose or makes significant modifications.

A note-taking assistant does not carry the same risk as a system used in employment decisions or access to essential services. Not every business application is high-risk, but every use deserves a proportionate assessment.

  • Does the output support a decision or effectively make it?
  • Can a competent person challenge, correct and stop it?
  • Does the provider document limitations, data, security and intended use?
  • Is there a channel for reporting errors and incidents?
  • Can staff recognise a plausible but incorrect result?

Transparency is part of the experience.

From 2 August 2026, transparency obligations apply to certain systems. People must be informed when they interact with AI unless this is obvious, while generated or manipulated content must be machine-readable in the cases defined by the regulation.

Good design provides information at the right moment: what the AI does, which data it uses, where automation ends and how a person can be reached. Compliance becomes a component of trust rather than an obstacle.

A realistic first 30-day plan.

  1. Week 1 — inventory: collect official and unofficial tools, processes, owners and data.
  2. Week 2 — priorities: assess impact, error probability, reversibility and human control.
  3. Week 3 — rules: define permitted, prohibited and approval-only uses; review suppliers and clauses.
  4. Week 4 — skills: train teams on real cases, create a reporting channel and assign responsibility.

AI literacy is broader than prompting. Marketing, HR, administration and production face different errors and need training grounded in their work.

Governance improves return on investment.

Proportionate governance reduces duplication, unnecessary subscriptions and experiments with no owner. More importantly, it links each tool to an outcome: time saved, quality, response speed, fewer errors or greater productive capacity.

We apply this product mindset to applied artificial intelligence and process automation: measurable objective, suitable data, ownership, human oversight, quality threshold and stopping criteria.

Sources and updates

Updated 12 August 2026. This article is for information only and does not replace legal assessment.

How many AI tools does your business rely on today?

We start with inventory, risks and opportunities to build a practical roadmap without stopping the team.

Request an assessment