A practical guide to EU AI Act compliance for organisations using AI, including scope, roles, risk, governance and the 2026 implementation position.
What the EU AI Act means for an organisation using AI
The EU AI Act is a risk-based regulation. It does not create one identical compliance checklist for every organisation that uses an AI tool. The obligations depend on factors such as the organisation's role, the intended purpose of the AI system and the level of risk attached to that use.
For most businesses, the useful starting point is not to ask whether the company 'uses AI'. It is to identify which systems are actually in use, what they do, who provides them, what data they process and whether their outputs influence decisions about people.
The implementation position in August 2026
The AI Act entered into force in 2024 and is now generally applicable. Some requirements arrived earlier, including the rules on prohibited AI practices and AI literacy from February 2025, while some high-risk system requirements have later transition dates. The AI Omnibus, which entered into force on 27 July 2026, changed parts of that timetable.
This matters when reading older compliance material. A timeline published before the 2026 amendments may no longer describe the current transition dates. Organisations should check the consolidated legislation and current Commission implementation material before relying on a historic deadline.
What businesses should check first
- Create an inventory of AI systems, AI-enabled features and important use cases.
- Record the intended purpose, provider, business owner, data involved and people affected.
- Identify whether the organisation is acting as a deployer, provider, importer, distributor or in another relevant role for each system.
- Screen use cases against prohibited practices, transparency requirements and the high-risk classification rules.
- Put proportionate AI literacy, policy, human oversight, supplier review and incident controls in place.
- Keep evidence of assessments and decisions so governance can be reviewed as systems or law change.
Compliance is not just a classification exercise
A system that is not classified as high-risk can still create material privacy, confidentiality, security, intellectual property, discrimination or accuracy risks. GDPR and sector-specific rules may also apply alongside the AI Act.
That is why a practical compliance programme should combine legal applicability work with operational governance. The aim is to know where AI sits in the organisation, set usable rules and make responsibility visible before an incident forces the question.
Blanche perspective
Treat the AI Act as a governance problem before treating it as a documentation problem. A reliable inventory, clear ownership and a repeatable risk review process make later legal analysis substantially easier and prevent policies from becoming disconnected from real AI use.
Sources
Primary and authoritative sources used for this Insight.