The EU AI Act: What Enterprises Need to Have in Place in 2026
The EU AI Act has been in force since August 1, 2024 (Regulation (EU) 2024/1689, Art. 113). Since February 2, 2025, the use of prohibited practices has been banned, and organizations are required to ensure AI literacy among their staff (European Commission, Digital Strategy, 2026). On August 2, 2026, the next wave of obligations took effect - and it applies to far more companies than most assume.
Just as GDPR, NIS2, and cybersecurity are now standard parts of how systems are designed and operated, the AI Act is becoming another area that must be addressed at the design stage of any AI solution, rather than bolted on once it's already in production.
How the AI Act Actually Works
The regulation classifies AI systems into four risk tiers: unacceptable risk (banned outright), high risk, systems subject to transparency obligations, and systems with minimal or no risk (Regulation (EU) 2024/1689; European Commission, 2026). Every obligation an organization has depends on which tier a given system falls into, making correct classification the first real decision point, rather than a formality.
Some deadlines have shifted since the Act was adopted. The "AI Omnibus" - a legislative package simplifying parts of the Act - reached political agreement on May 7, 2026, and formally entered into force on July 27, 2026 (European Commission, Digital Strategy, July 2026). It pushed the deadline for high-risk systems in sensitive areas like employment and education (Annex III) to December 2, 2027, and for high-risk systems embedded in regulated products (Annex I) to August 2, 2028. What didn't move: the core obligations themselves, only when enforcement begins.

What Non-Compliance Actually Costs
Non-compliance with the AI Act isn't a minor risk. Serious fines back it up. Under Article 99 of Regulation (EU) 2024/1689, depending on the severity of the breach, penalties range from €7.5 million up to €35 million, or up to 7% of a company's global annual turnover, whichever is higher. The more serious the violation, such as engaging in prohibited practices, the closer it sits to the top of that range.
This isn't a distant, theoretical risk either. The enforcement authority for the AI Act became active on August 2, 2026 (European Commission, Digital Strategy, 2026), meaning the exposure to AI systems is real from day one, not something to plan for later.
Who the AI Act Actually Applies To
This is the assumption we see companies get wrong most often: the AI Act applies not only to companies building their own AI models, but also to organizations that use AI systems or supply them to their customers. The scope of those obligations depends on two factors: the role a company holds and the risk of the specific system.
The AI Act distinguishes between roles such as provider (placing an AI system on the market or into service under your own name) and deployer (using an AI system). Each carries a different set of obligations, which is why getting the role right matters more than anything else.
A few questions worth every company being able to answer, regardless of industry:
- Do you have a full inventory of which AI systems are actually used across the company - including tools adopted without central visibility?
- Do you know your role under the Act for each system - provider, deployer, or another relevant role?
- Have you confirmed the AI Act actually applies to a given solution? Not everything labeled "AI" meets the regulation's definition - classic rule-based logic (if-then rules, regex) often falls outside its scope, and correct classification is a foundational first step.
- Do you know which risk category each AI system falls into, and therefore which obligations apply - from minimal requirements up to full documentation, risk management, and high-risk obligations?
- Is your team's AI literacy where it needs to be? Under Article 4, organizations must ensure that people using AI understand what a tool can do, its limitations, its risks, and when outputs need to be verified.
- Do you have internal rules for AI use? Uncontrolled use of public AI tools (shadow AI) is one of the most common security risks organizations face today.
- Can you actually demonstrate compliance? For certain AI systems, being compliant isn't enough. You also need documentation, process, and evidence to prove it.
These are no longer purely IT questions. Management, HR, legal, compliance, and security teams are now all part of answering them, because the AI Act governs processes and organizational accountability as much as it governs technology.
Why This Matters More in Healthcare, Space, and Defense
For most industries, this is a compliance exercise. In Healthcare, Space, and Defense, AI systems from clinical workflows to mission control frequently fall into the AI Act's high-risk category, and they run alongside frameworks like HIPAA or existing security clearances that already demand strict control, documentation, and oversight. The AI Act doesn't replace these standards; it formalizes what these organizations are already expected to hold themselves to - which is exactly why we've built our expertise here.

How We Build Compliance Into Every AI Solution We Deliver
Assessing AI Act requirements is a standard part of how we design, build, and deploy every AI solution. For each project, we continuously evaluate the AI system itself, how it's used, the roles of each party involved, and the obligations arising under the AI Act, and we deliver corresponding documentation.
That work results in an AI Act Compliance Statement - a document you can add directly to your project, technical, or compliance records as verifiable evidence that the AI solution has been assessed against the AI Act. It includes:
- Determination of roles under the AI Act (provider, deployer, and other relevant roles)
- Risk classification of the AI system, with reasoning
- Identification of all AI Act requirements that apply to the solution
- Assessment of transparency, human oversight, user AI literacy, and other relevant obligations
- Documentation covering any third-party models used (including general-purpose AI / GPAI models)
- Identification of residual technical risks the AI Act doesn't directly regulate but that can materially affect safety or reliability - such as model hallucinations or prompt injection.
- A list of delivered compliance artifacts and the conditions under which the system's classification should be reassessed in the future
We design AI solutions around the Human-in-the-Loop principle: the final decision or output check generally remains with a person. AI should support human decision-making, not replace it without oversight.
Why This Belongs in Your Planning Now, Not Later
Compliance built in from the start of a project is far cheaper (in cost, time, and risk) than compliance reconstructed under deadline pressure once an auditor or regulator asks for it. GPAI and transparency obligations are active; GDPR enforcement is already affecting AI systems today; and as of August 2, 2026, the next wave of obligations is now in effect. This is no longer a future date to plan around; it's the compliance baseline your AI systems are already expected to meet.
If you'd like to talk through where your specific systems stand, we can help you get clarity on:
- What you're actually running - a practical inventory of the AI systems in use across your organization, including tools adopted without central visibility
- Where you stand under the AI Act - your role for each system (provider, deployer, or other), and its risk classification, with the reasoning behind it
- What's missing - the gap between what you have today and the documentation, oversight, and evidence you'd need to demonstrate compliance
Know where you stand before compliance becomes urgent.
Whether you're building AI solutions or already using them across your organization, we can help you understand your obligations, identify gaps, and build a practical path to compliance.



