The EU AI Act: what does it mean for my business?
03 August 2026 · Strategic Funding Partners
<span style="color:#787774">Published 3 August 2026 · Strategic Funding Partners · Policy & Strategy</span>
Two things happened to the EU AI Act in quick succession, and they pull in opposite directions.
On 27 July 2026 the Digital Omnibus on AI entered into force, deferring the Act's high-risk obligations to 2027 and 2028. On 2 August 2026 the Act became generally applicable and the transparency rules in Article 50 took effect.
Significant parts of the Act were already in force before then. The ban on prohibited practices and the duty to support AI literacy applied from 2 February 2025, and the governance rules, general-purpose AI obligations and the general penalties framework applied from 2 August 2025.
So the picture is split. Some duties are live now. The heaviest ones have moved. For most organisations this does not mean stopping the use of AI or launching a large legal compliance project. It means knowing where your organisation uses AI, supporting the people who use it, and being clear with customers and the public when AI is involved.
Start here: five questions
For every use of AI in your organisation, ask:
-
What is the AI doing?
-
Who could be affected?
-
Is a person checking the output?
-
Do we need to tell anyone that AI is being used?
-
Have the people using it received suitable guidance?
If you can answer these for each tool you use, you have made a meaningful start. The rest of this article explains what sits behind them.
Does the AI Act affect my business?
It may affect you if your organisation:
-
uses AI tools in its operations
-
develops or sells an AI-powered product
-
uses chatbots or virtual assistants
-
creates images, videos, audio or public-facing content with AI
-
uses AI in recruitment, education, lending, healthcare or public services
-
supplies AI systems or services to customers in the EU
The rules can also apply to UK and other non-EU organisations where an AI system is offered or used in the EU, or where its output affects people in the EU.
Most organisations will be deployers of AI. This means they use systems supplied by companies such as Microsoft, Google, OpenAI or specialist software providers.
An organisation that develops an AI system, or has one developed and sells it under its own name, may be considered a provider, with additional responsibilities.
What applies now, and what comes later
| Date | What applies |
|---|---|
| 2 February 2025 | Prohibited AI practices and the Article 4 duty to take measures to support the development of AI literacy |
| 2 August 2025 | Governance, general-purpose AI obligations and the general penalties framework, except Article 101 on fines for general-purpose AI providers |
| 2 August 2026 | Article 50 transparency obligations |
| 2 December 2026 | Article 50(2) machine-readable marking for qualifying systems placed on the market before 2 August 2026 |
| 2 December 2027 | High-risk obligations for standalone systems listed in Annex III |
| 2 August 2028 | High-risk obligations for AI embedded in regulated products under Annex I |
For breaches covered by the general penalties tier, fines can reach €15 million or 3% of worldwide annual turnover, whichever is higher for undertakings. Higher maximum penalties apply to prohibited practices.
The deferral of the high-risk regime is real, but it applies only to the high-risk rules. A plan built on the assumption that every AI Act deadline has moved would be wrong.
Some uses are banned outright
The Act prohibits eight practices outright, rather than merely regulating them, and has done since 2 February 2025. The Digital Omnibus added two more, covering AI-generated non-consensual intimate imagery and the generation of child sexual abuse material, which apply from 2 December 2026. The four most likely to catch an ordinary organisation are:
-
Emotion recognition in the workplace or in education institutions, except for medical or safety reasons. This covers video-interview analysis in recruitment, call-centre software that infers agent mood from tone, and learning platforms that track facial expressions to measure engagement.
-
Biometric categorisation used to infer sensitive characteristics such as race, political opinions, trade union membership, religion or sexual orientation.
-
Social scoring of individuals based on unrelated personal characteristics or behaviour.
-
Untargeted scraping of facial images from the internet or CCTV to build facial recognition databases.
If you are doing any of these, disclosure is not the remedy. They need to stop.
What must I do now?
1. Record where AI is being used
Create a simple list of the AI tools used across the organisation.
Include:
-
who uses each tool
-
what it is used for
-
what information is entered into it
-
whether its output affects customers, staff or members of the public
-
whether a person reviews the output before it is used
This does not need to be complicated. A basic spreadsheet is enough for many organisations.
2. Support AI literacy among staff
Since 2 February 2025, providers and deployers have had to take measures to support the development of AI literacy among staff and others operating AI systems on their behalf. This is an obligation of effort rather than a requirement to guarantee or certify a particular level of individual competence.
Training should cover:
-
what the tool can and cannot do
-
the risk of inaccurate or invented information
-
confidentiality and personal data
-
copyright and intellectual property
-
when human review is required
-
which information must never be entered into a public AI tool
Keep a record of the guidance or training provided.
3. Tell people when they are dealing with AI
From 2 August 2026, transparency rules apply in a number of situations.
For example:
-
A customer-facing chatbot should make it clear that it is an AI system.
-
People must be told when they are exposed to emotion-recognition or biometric-categorisation systems, in the cases where those systems are permitted at all.
-
Deepfake images, video or audio must be disclosed as artificially generated or manipulated.
-
AI-generated text published to inform the public about matters of public interest may need to be disclosed where it has not received human review or editorial control.
Providers of systems covered by Article 50(2) must ensure that qualifying synthetic content is marked in a machine-readable format, using techniques such as watermarks, metadata or provenance indicators. For qualifying systems placed on the market before 2 August 2026, this marking requirement applies from 2 December 2026.
You do not automatically need to label every internal email, draft or document that was assisted by AI. The key questions are whether the content is public-facing, whether it could mislead someone, and whether meaningful human review took place.
4. Introduce human checks
AI should not make important decisions without appropriate oversight.
Be particularly careful when using it for:
-
recruitment and employee management
-
credit or insurance decisions
-
education and assessment
-
healthcare
-
access to essential services
-
biometric identification
-
decisions affecting a person's legal rights
The detailed high-risk requirements now apply from 2 December 2027 for standalone systems and 2 August 2028 for AI embedded in regulated products. That is a genuine extension, but these systems take time to document, test and govern, so organisations working in these areas should be using the additional time rather than treating it as a reprieve.
5. Review suppliers and contracts
Ask AI suppliers:
-
whether their system is intended to comply with the EU AI Act
-
what information they provide about how it works
-
how customer data is used and stored
-
whether data is used to train the supplier's models
-
what security and incident-reporting measures are in place
-
whether AI-generated outputs include the required technical markings
Do not assume that using a well-known AI provider removes your own organisation's responsibilities.
6. Update your internal policies
Your AI policy should explain:
-
which tools staff may use
-
what data may be entered
-
which uses require approval
-
when a human must check the result
-
how AI-generated content should be disclosed
-
how errors or incidents should be reported
Where to start
For most organisations, the immediate priority is not complex certification. It is establishing visibility, responsibility, staff awareness and appropriate transparency.
The EU AI Act is intended to make AI safer and more trustworthy. An organisation that can explain where it uses AI, how it supervises it, and how it protects customers and staff will already have made a meaningful start.
Official sources
How SFP can help
If you would like to talk through what this means in practice for your organisation, get in touch.
Strategic Funding Partners helps organisations find the right EU funding opportunities, build consortia and prepare competitive proposals. Explore our services.
If this is useful to people in your network, please pass it on.
This article provides a practical overview and is not legal advice.