AI Act: the compliance guide for businesses
Since 2 August 2026, the AI Act has become enforceable and punishable. Roles, risk levels, deployer obligations, timeline: what a business that uses AI needs to put in place.
The essentials in brief
The European regulation on artificial intelligence (the AI Act) entered a decisive phase on 2 August 2026: the obligations applying to high-risk AI systems come into full effect, the registration of those systems becomes mandatory without exception, and the supervision and penalty regime run by national authorities becomes operational.
Contrary to a widespread belief, the AI Act does not concern only the makers of AI models. It also applies to any business that deploys AI in its processes — even AI bought off the shelf. The starting point of compliance is therefore not legal but operational: knowing where AI is used in your organisation, at what level of risk, and who is responsible for it.
This article sorts out what is genuinely mandatory, what falls under good practice, and where to start concretely.
Provider or deployer: which side are you on?
The AI Act distinguishes several roles. The two that concern most businesses are:
- The provider: the party that develops an AI system (or has it developed) and places it on the market under its own name.
- The deployer: the party that uses an AI system in the course of its professional activity.
Most businesses are deployers: they integrate existing AI tools into their processes. But beware — the line is not always clear. If you have a business application developed that embeds AI, or if you substantially modify an existing system, you may shift into the provider role, with heavier obligations. This is precisely why compliance is thought through at the design stage of a project, not after the fact.
The four risk levels
The AI Act classifies AI systems according to the risk they pose to people's rights and safety:
- Unacceptable risk: prohibited practices (social scoring, manipulation, certain forms of biometric surveillance). Banned since February 2025.
- High risk: systems used in sensitive areas (recruitment, access to credit, education, critical infrastructure, etc.). These are the ones whose obligations come into full effect on 2 August 2026.
- Limited risk: systems subject to transparency obligations (for example, telling a user they are talking to an AI).
- Minimal risk: the vast majority of everyday uses, with no specific obligation.
The first question to ask is therefore not "am I concerned?" but "which category does each of my AI uses fall into?". The same tool can be minimal in one context and high-risk in another, depending on the decision it helps make.
Your obligations as a deployer
For all AI systems
Since February 2025, Article 4 imposes an AI literacy obligation: ensuring that the people who use or supervise AI have a sufficient level of competence to understand its limits and risks. This obligation already applies — but it is on 2 August 2026 that the supervision and penalty regime becomes fully operational, making it far more concrete. We cover this point in our dedicated article on the AI training plan (Article 4 of the AI Act).
For limited-risk systems
A transparency obligation: clearly informing people when they interact with an AI, or when content has been generated or manipulated by an AI.
For high-risk systems
This is where the obligations are most demanding, and where they come into full effect on 2 August 2026:
- use the system in line with its instructions and under human oversight;
- ensure the quality and relevance of the data you feed into it;
- keep the logs generated by the system;
- monitor its operation and report incidents;
- carry out the required registration — now mandatory without exception, including for systems that benefit from a lighter high-risk regime.
The timeline to know
- 2 February 2025: ban on unacceptable-risk practices + entry into force of the AI literacy obligation (Article 4).
- 2 August 2025: obligations for general-purpose AI models (GPAI) and setting up governance.
- 2 August 2026: full application of obligations for high-risk systems in Annex III; mandatory registration; operational penalty regime.
- 2 August 2027: extension to high-risk systems embedded in products already regulated (medical devices, machinery, toys, etc.).
In other words, the 2026 deadline is not a distant horizon: it is the point at which compliance becomes checkable and punishable.
Reconciling the AI Act with a bespoke project
Compliance is often experienced as a constraint. It is in fact a design framework. When AI is embedded in a business application built for you, every AI Act requirement — human oversight, traceability, data quality, transparency — can be built by design rather than bolted onto a tool you do not control.
This is a structural advantage of bespoke over a closed off-the-shelf package: you know what the system does, where your data lives, and you can document how it works. Whereas a black-box tool leaves you carrying a risk you can neither see nor prove.
Where to start, concretely? With an inventory of your AI uses, a classification by risk level, and the identification of responsibilities — the foundation of our consulting and audit engagements. When AI is embedded in a business application built for you, that inventory becomes a design brief rather than a paperwork exercise.
Frequently asked questions
Does the AI Act apply to my business if I only use off-the-shelf AI tools?
Is an SME concerned in the same way as a large group?
What is the risk of non-compliance?
Where should I start, concretely?
Sources
- AI Act : obligations, calendrier et sanctions 2026 — Leto
- AI Act : les nouvelles obligations depuis août 2026 — Pôle d'excellence cyber
- AI Act et littératie IA : les sanctions applicables dès le 2 août 2026 — Sowaycom
A project or a business challenge?
A first 30-minute conversation to understand your context and assess how we can help. No commitment.
Let's talk about your project →