The EU AI Act is now being enforced. Here’s what it means for your business.
Article 50’s transparency rules and the Act’s enforcement powers took effect on 2 August 2026. The high-risk regime moved to December 2027. Most businesses need to worry about less than they fear, and more than they’ve checked.

- EU AI Act
- AI Governance
- AI Strategy
- Compliance
· Dr Lara Okunuga · 14 MIN
For two years, the EU AI Act was something businesses could file under “we’ll deal with that later.”
Later ended on 2 August 2026.
The European Commission’s AI Office and national authorities now hold enforcement powers, and new transparency rules apply to certain AI systems, including AI that interacts with people and AI-generated content.
That doesn’t mean every company using ChatGPT is suddenly running a high-risk AI system.
It does mean a much more practical question is becoming difficult to avoid:
What AI is running inside your business, who’s interacting with it, what’s it allowed to do, and who’s responsible when something goes wrong?
That’s an AI governance question.
And increasingly, it’s also an AI strategy question.
This article is practical operational guidance, not legal advice.
What changed on 2 August 2026?
The EU AI Act didn’t suddenly appear this month. It applies in phases, and two of those phases were already live: prohibited AI practices and AI literacy requirements started applying in February 2025, and rules for providers of general-purpose AI models followed in August 2025. The European Commission maintains the full implementation timeline.
But 2 August 2026 was the big operational milestone.
Two things happened at once. Enforcement powers took effect, meaning authorities can now impose fines. And the transparency requirements under Article 50 started applying.
Those transparency rules cover:
- AI systems that interact directly with people
- AI-generated or manipulated content
- Deepfakes
- Emotion recognition and biometric categorisation
- Certain AI-generated text on matters of public interest
The Commission’s Article 50 FAQ covers the detail.
One thing that did not happen on 2 August: the high-risk regime.
The Digital Omnibus amendments adopted in mid-2026 pushed the obligations for standalone high-risk AI systems (employment, education, biometrics, access to essential services and similar) back to 2 December 2027. High-risk AI embedded in regulated products moved to 2 August 2028. Article 50 was deliberately left off that delay.
Plenty of businesses heard “the AI Act got delayed” in June and stopped paying attention.
The part that got delayed probably wasn’t the part that applies to you.
Does the EU AI Act affect normal businesses or just AI companies?
You don’t need to be training your own large language model to care about the EU AI Act.
The Act distinguishes between different actors, and the two that matter here are providers and deployers of AI systems.
That second category is the important one.
A deployer is, broadly, an organisation using an AI system under its authority for professional purposes. The definition is in the AI Act itself.
So a company using AI to help employees, deal with customers, process documents or run parts of the business may be a deployer even though it didn’t build the underlying model.
Using someone else’s AI doesn’t outsource your responsibility for how it’s used.
There’s another detail worth paying attention to.
The Act can reach organisations outside Europe. The scope provisions include providers and deployers located outside the EU where the output produced by the AI system is used in the Union. The Commission’s own guidance confirms this applies regardless of where the provider is established.
Your company being based in Dubai, London or New York isn’t by itself an exemption if the relevant use falls within the Act’s scope.
Provider vs deployer: know which hat you’re wearing
This sounds like legal terminology until you attach it to a real system.
| Who it is | Everyday example | What it means for you | |
|---|---|---|---|
| Provider | Develops an AI system (or has one developed) and puts it on the market or into service under its own name or trademark | You build a booking agent and sell it, or launch one under your brand | Design obligations: build the disclosure and marking in before it ships |
| Deployer | Uses an AI system under its authority for professional purposes | You pay for an existing AI tool and point it at your customers or staff | Use obligations: correct disclosure, labelling where required, knowing what the system touches |
The line moves. Rebrand, modify or resell somebody else’s system and you can pick up provider obligations.
The distinction matters because the obligations are different.
And the line isn’t always as clean as built it = provider, bought it = deployer. How a system is branded, modified, sold and operated can matter. Put an AI system into service under your own name or trademark and you may be acting as the provider even though somebody else’s model sits underneath.
Which is why “we use OpenAI underneath” isn’t a governance model.
Before putting an AI system into production, you should know what role your business is actually playing.
AI chatbots and voice agents now need more thought
This is probably the most relevant change for small and medium businesses.
Article 50 requires AI systems designed to interact directly with people to be built so those people are informed they’re talking to AI, unless it’s already obvious. The Commission’s guidance is specific: the disclosure has to come at the start of the first interaction, clearly, and the “unless it’s obvious” exception is meant to be read narrowly.
The principle is simple.
If somebody thinks they’re speaking to Sarah from reception but they’re actually speaking to a voice model, that matters.
A customer-facing AI voice assistant might answer missed calls, qualify leads, check availability and book appointments. It’s the first system on our list of high ROI AI systems worth building.
Useful system.
But the design question is no longer just:
Can it answer the phone convincingly?
It’s also:
Does the caller understand they’re speaking to AI?
If you deploy a third-party AI assistant, you should know whether that disclosure has been implemented properly rather than assuming the vendor has dealt with everything.
And while you’re there, ask the harder questions.
What can the agent say?
What can it change?
What customer data can it access?
When does a human take over?
What happens if it confidently gives somebody the wrong answer?
Those are governance questions whether a regulation forces you to ask them or not.
What about AI-generated content?
This part is more nuanced than “everything made with AI needs an AI label.”
That’s not what the Act says.
Providers of generative AI systems must make generated or manipulated content detectable using machine-readable marking. (Systems already on the market before 2 August 2026 have until 2 December 2026 to comply with that marking requirement.)
And this isn’t theoretical. The marking has already started shipping.
In August 2026, Anthropic began embedding invisible watermarks into text generated by its Claude models, applied worldwide rather than only in Europe, alongside signed provenance metadata on generated files. Google’s SynthID already marks image, audio and text outputs, and OpenAI has joined the C2PA provenance standard and embeds SynthID in its image outputs, though it hasn’t broadly deployed text watermarking yet. Nearly 200 companies, including Microsoft, Google, Meta and OpenAI, have signed the EU’s Code of Practice on transparency of AI-generated content.
Two things follow if your business generates content with these tools.
First, assume AI-generated text can increasingly be identified as AI-generated, wherever you are in the world. The compliance was built into the model, not into a European setting.
Second, a watermark is a signal, not proof of authorship. Anthropic itself is clear on this: a detected mark shows text passed through Claude at some point, not that Claude wrote it. Run a human-written proposal through AI for proofreading and it may carry a mark. Heavily edit AI output and the mark may not survive. (We’ve written separately about why the watermark isn’t the real problem, our discomfort with admitting we use AI is.)
Which makes the next distinction matter more, not less.
Deployers have disclosure obligations in particular situations. Deepfakes need to be disclosed. And AI-generated or manipulated text published to inform the public on matters of public interest needs labelling, unless it has undergone human review or editorial control.
The Commission has published both Guidelines on Transparency of AI-Generated Content and a voluntary Code of Practice providers and deployers can sign up to.
And the word review is doing real work there.
The Commission’s guidance distinguishes meaningful review (deliberate examination of the substance by somebody with relevant knowledge, or an editor with the authority to approve, alter or reject the content) from superficial checks. Running a spell-check doesn’t count.
The second one isn’t just a better editorial process.
It’s actual human oversight. And under Article 50, it’s also the difference between text that needs an AI label and text that doesn’t.
What about internal AI workflows?
Not every AI system talks to a customer.
A lot of the most useful AI sits quietly behind the business.
Read an invoice → extract the data → update the finance system
Read an enquiry → classify it → update the CRM → notify sales
Analyse meeting notes → identify tasks → update the project system
Article 50’s disclosure requirement doesn’t apply the same way to AI operating purely in the background or machine-to-machine. The Commission’s guidance explicitly puts systems with no direct human interaction outside that particular obligation.
But internal doesn’t mean outside the AI Act.
AI literacy obligations already apply, and the Commission’s AI Literacy Q&A specifically addresses businesses whose staff use tools like ChatGPT for everyday tasks.
Which makes AI governance wider than the systems the IT department officially approved.
You also need to know what staff have quietly adopted themselves.
The AI meeting recorder.
The browser extension.
The proposal generator.
The chatbot somebody connected to the CRM six months ago.
Shadow AI is still AI.
Which AI uses create more risk?
The EU AI Act is risk-based. Not every AI system gets treated the same way.
A spam filter and an AI system deciding whether somebody gets shortlisted for a job are obviously doing different jobs. The Act reflects that.
| Tier | What’s in it | Example | Status |
|---|---|---|---|
| Prohibited | Harmful manipulation, social scoring, certain biometric and emotion-recognition practices | Social scoring of citizens | Banned since Feb 2025 |
| High-risk | AI in employment, education, essential services, biometrics, critical infrastructure | CV-sorting recruitment tools | Applies from Dec 2027 (embedded in products: Aug 2028) |
| Transparency | AI interacting with people, generated content, deepfakes | Chatbots, voice agents, AI-generated media | Applies since Aug 2026 |
| Minimal | Everything else | Spam filters, internal drafting assistants | No specific obligations (AI literacy still applies) |
Some practices are prohibited entirely, including particular uses involving harmful manipulation, social scoring and certain biometric and emotion-recognition practices. AI in areas like employment, education, essential services and critical infrastructure can fall into the high-risk category when those rules apply from December 2027; recruitment tools that sort CVs are one of the Commission’s own examples.
The practical lesson isn’t to become an expert in every article of the regulation.
It’s to stop treating every AI system as interchangeable.
An assistant rewriting an internal email doesn’t need the same governance as a system helping decide who gets hired.
The closer AI gets to people, rights, money or important decisions, the more seriously you should treat the system around it.
What happens if you don’t comply?
There are real penalties, and since 2 August 2026 the authorities that impose them are operational. Enforcement sits mainly with national market surveillance authorities, with the Commission’s AI Office covering certain cases.
€35M / 7%
of worldwide turnover, prohibited AI practices
€15M / 3%
of worldwide turnover, other breaches including Article 50
EU AI Act penalty framework, maximums
For SMBs, the regulation applies the lower of the relevant fixed amount or percentage. The Commission sets out the framework in its enforcement guidance.
Those are maximums, not an automatic parking ticket for a missing AI label.
But the existence of the fines changes the calculation.
AI governance is no longer something to add once the system becomes important.
By then, you may already have a problem.
Is this just an EU thing?
No. The EU moved first and furthest, but it isn’t alone.
| Region | Where it stands | In practice |
|---|---|---|
| EU | AI Act in force, phased through to 2028 | The benchmark everyone else reacts to |
| US | No federal act; a patchwork of state laws (Texas, California, Colorado and others) | Compliance varies state by state |
| UK | No dedicated act; five cross-sector principles applied by existing regulators, with legislation under debate | Regulator-led for now |
| China | Binding sectoral rules, including mandatory labelling of AI-generated content since 2025 | Operationally strict on content marking |
| Australia | Voluntary AI safety standard, with mandatory guardrails for high-risk AI proposed | Drifting toward binding rules |
| GCC (UAE, Saudi) | National AI strategies, charters and ethics guidelines rather than a horizontal act; sector rules apply | Soft law today; adoption-first, regulation following |
A snapshot, not legal advice. Statuses as of August 2026.
The direction of travel in most jurisdictions points the same way: toward binding, EU-flavoured rules.
And even where no binding law exists yet, the EU’s rules are arriving anyway, through the tools. Anthropic applied its watermarking globally, not just in Europe. When frontier providers build EU compliance into the model itself, businesses everywhere inherit it, whether their local regulator asked for it or not.
So the governance questions below aren’t a European compliance exercise.
They’re where every jurisdiction is heading, at different speeds.
The FreshStack AI Governance Checklist
Governance is one of the four gaps we test in every AI Assessment, and there’s a reason it’s there: in our own assessments, 87% of audited clients couldn’t produce a list of what their AI tools have access to.
Before putting any AI system into production, we’d want clear answers to ten questions.
Before it goes into production
- 01
What AI is running?
Not just the official tools. What’s actually being used?
- 02
Who owns it?
A named person accountable after launch.
- 03
What role are we playing?
Provider, deployer, or something messier?
- 04
What data does it touch?
Customer, employee, financial, internal documents?
- 05
Who does it affect?
Employees, prospects, customers, applicants, the public?
- 06
What can it decide or do?
Drafting an email is one thing. Rejecting a candidate or issuing a refund is another.
- 07
What does the person interacting with it need to know?
Disclosure, labelling, or another explanation?
- 08
Where does a human take over?
Not a vague “human in the loop.” A defined point, with context and authority.
- 09
What happens when it fails?
Wrong answer, bad classification, hallucination, prompt injection, outage. Know the failure before production finds it.
- 10
What evidence can we show?
Logs, testing, approvals, documentation, training, monitoring.
Not sure which gap is yours? The Bottleneck Finder takes two minutes and tells you whether governance is your first problem or your third.
If the only evidence that your AI works is “we tried it and it looked good,” you have the same problem we wrote about in One good loaf is not a bakery.
AI strategy now includes governance
AI strategy is no longer just about where AI can save time or make money. It’s also knowing what you’re running, what it touches, who it affects and who owns it when it’s wrong.
The businesses that get this right won’t be the ones with the longest AI policy or the biggest collection of tools.
They’ll be the ones that know exactly where AI is being used, why it’s there, what the boundaries are and who owns the outcome.
Before asking what you can automate next, know what you’re already running.
If AI is already running in your business and you can’t answer these ten, that isn’t a compliance failure. It’s just the governance work nobody has done yet.
Free · 30 minutes · No pitch
Sources
- European Commission, AI Act enforcement
- European Commission, AI Act regulatory framework and timeline
- European Commission, Article 50 transparency FAQ
- European Commission, Guidelines on Transparency of AI-Generated Content
- European Commission, Code of Practice on Transparency of AI-Generated Content
- European Commission, AI Literacy Questions & Answers
- EU AI Act Service Desk, Articles 2 and 3
- Goodwin, EU AI Act transparency obligations now in force (Digital Omnibus analysis)
- Euronews, Anthropic to watermark Claude’s output worldwide (August 2026)
- The Next Web, Anthropic starts marking Claude’s output as EU transparency rules take effect
- AI Risk Aware, AI regulation by country 2026
- FreshStack, One good loaf is not a bakery
