LinkedInInstagramXTikTok

The EU AI Act Takes Effect on 2 August 2026 – How to Get Your Company Ready

EU AI Act 2026 – Lawgent

Why 2 August 2026 is a turning point for any company that touches AI

Few regulations have created as much uncertainty in boardrooms and management teams as the EU AI Act. It is the world’s first comprehensive law on artificial intelligence, and on 2 August 2026 the bulk of its obligations begin to apply. For business leaders who have heard about the regulation but kept putting it off, this is the moment it shifts from an abstract worry about the future to a concrete compliance responsibility.

The most common mistake is to assume the Act only concerns companies that build their own AI models. In practice it hits just as hard the many businesses that buy in and use AI day to day, often embedded in tools they already rely on for recruitment, credit assessment, customer service or monitoring. This article explains what the Act actually requires, who carries the responsibility and how you prepare before the deadline passes.

What the Act requires – and of whom

The regulation rests on a simple but frequently misunderstood division of roles. Your obligations are determined by the role you hold in relation to an AI system, and the same company can hold different roles for different tools.

Provider or deployer – the role decides everything

A provider is the party that develops an AI system, or has it developed, and places it on the market under its own name. A deployer is the party that uses an AI system in the course of its business. The vast majority of companies are deployers, and that is an important insight, because deployers also carry their own obligations: to use the system in line with the instructions, ensure human oversight, monitor that input data is relevant and inform affected individuals where required. Having bought the tool from someone else does not move the whole responsibility away from you.

The risk classification that drives your requirements

The Act grades AI by risk. Certain uses are prohibited, such as social scoring and some forms of biometric categorisation, and those rules have applied since February 2025. The heavy category for most companies is high-risk systems, which the Act takes to include AI for recruitment and selection of staff, credit assessment of individuals, certain insurance applications and AI in critical infrastructure. If your system is high-risk, a long list of requirements follows. If it is not, lighter transparency rules apply instead, such as clearly informing a customer that they are speaking to a chatbot or that content is AI-generated.

Where the requirements bite: high-risk systems

For high-risk systems the Act requires a documented risk management system, governance of the data the model is trained and run on, technical documentation, automatic logging, meaningful human oversight and a level of accuracy, robustness and cybersecurity proportionate to the use. Before a high-risk system is placed on the market, the provider must also carry out a conformity assessment, draw up an EU declaration of conformity, affix CE marking and register the system in an EU database.

As a deployer of a high-risk system you do not inherit the provider’s entire burden, but you must, among other things, follow the instructions for use, exercise the human oversight the system requires and ensure the data you feed in is appropriate. That makes due diligence on your supplier a legal necessity, not merely a procurement question.

A practical example: the company that was a provider without knowing it

Imagine a mid-sized SaaS company that has built a clever feature on top of a bought-in language model and sells it on to its customers as part of its product. Management sees itself as a deployer of someone else’s AI and assumes compliance sits with the underlying model provider.

The problem is that by releasing the feature under its own name the company has in practice become a provider in the meaning of the Act, with everything that entails in terms of documentation, risk management and a possible conformity assessment if the feature is used for a high-risk purpose at the customer end. When a customer asks for evidence of compliance in a procurement document, the company is left without documentation, without having mapped its obligations and with a deadline that has already passed. An early role analysis would have shown it was a provider and given it months to build the right foundation.

Common mistakes companies make

The first mistake is to assume the Act does not apply because the company does not build AI. Anyone who buys in and uses AI is a deployer with their own obligations, and anyone who bakes AI into their own product may inadvertently become a provider.

The second mistake is to treat the 2 August 2026 deadline as the date to start looking at the question. Mapping systems, classifying risk and building documentation takes time, and several requirements assume measures that must be in place before the system is used.

The third mistake is to rely blindly on the supplier’s assurances. A supplier’s CE marking helps you, but it does not relieve you of your own deployer obligations or of the responsibility to check that the tool is fit for what you actually use it for.

Legal risks

The penalties are designed to be felt. Prohibited AI uses can carry fines of up to 35 million euro or seven percent of global annual turnover, whichever is higher. Breaches of the high-risk requirements can reach 15 million euro or three percent of turnover. For smaller companies the lower of the amount and the percentage usually applies, but the levels still show that the legislator means business.

Beyond the formal fines there is commercial exposure. A growing number of customers, investors and partners ask for evidence of compliance before entering into contracts, and a company that cannot show its AI is properly governed risks losing deals long before a regulator gets in touch.

Recommended actions

Start with an inventory of all AI that touches your business, including features embedded in systems you already use. For each system, establish your role and whether the use is high-risk. That determines which requirements apply.

Then build the documentation and governance your role requires, ask your suppliers sharp questions about their compliance and keep the answers, and make sure genuine human oversight exists where the Act requires it. Treat this as an ongoing process, because both your systems and the exact deadlines continue to evolve. During 2026 the EU has also proposed adjustments to certain deadlines for high-risk systems, which makes it all the more important to confirm the dates that apply to your particular systems.

Frequently asked questions about the EU AI Act

Does the Act apply to us if we only use bought-in AI?

Yes. Anyone who uses an AI system in their business is a deployer and has their own obligations, particularly if the system is high-risk. The fact that you did not build the model yourself does not change that.

What actually happens on 2 August 2026?

That is when most of the Act’s obligations begin to apply, including the rules for high-risk systems. Some parts apply earlier, and certain high-risk deadlines have been subject to proposed changes, so the exact dates should be confirmed for your systems.

How do we know if our AI system is high-risk?

The Act identifies specific use cases as high-risk, including recruitment, credit assessment and certain applications in insurance and critical infrastructure. A structured review of where and how you use AI provides the answer.

Is it enough that our supplier is compliant?

No. The supplier’s compliance matters but only covers the supplier’s obligations. As a deployer you are responsible for how the tool is used in your context, for oversight and for the suitability of your input data.

We are a small company – are the penalties really relevant to us?

Yes. For smaller companies the lower of the fixed amount and the percentage often applies, but in practice compliance is at least as much about not losing customers and investors who demand proof that your AI is properly governed.

Summary

The EU AI Act is not only a matter for tech giants building their own models. It reaches every company that uses AI, and on 2 August 2026 most obligations move from theory to practice. The companies that get into difficulty are rarely those acting in bad faith, but those that never mapped their role, their risk class and their obligations in time. Those who carry out that analysis now can make use of AI with confidence and meet the demands of customers and investors without losing momentum.

Lawgent helps companies map their AI, determine whether they are a provider or a deployer and build the documentation and governance the Act requires. We combine experienced business-law advice with AI-driven efficiency, so you get clear, practical guidance faster and more cost-effectively than at a traditional firm. Want to know where your company stands ahead of 2 August 2026? Contact Lawgent for a review of your AI systems and your obligations.

Leave a Reply

Your email address will not be published. Required fields are marked *


0Cart0,00 

No products in the cart.

Return to shop