Women in AI by FemTechConf

EU AI Act Guide for Businesses: What Applies in 2026 and What Comes Next

The EU AI Act is now in its enforcement phase. This guide explains the 2026 transparency rules, GPAI obligations and the later timetable for high-risk systems.

By Elena Marković, Women in AI Editorial Fellow · 26 August 2026

The EU AI Act is no longer a future compliance project.

From 2 August 2026, the European Commission's AI Office and national authorities began enforcing key parts of the Act, and new transparency requirements started to apply to certain AI systems and AI-generated content.

Businesses still need to distinguish between rules that apply now and high-risk requirements that come later.

What already applies?

The AI Act entered into force in August 2024 and has been phased in over time.

Prohibited AI practices and AI literacy obligations began applying in February 2025. Governance rules and obligations for providers of general-purpose AI models became applicable in August 2025.

From 2 August 2026, enforcement expanded and Article 50 transparency obligations came into effect.

What changed on 2 August 2026?

The European Commission says providers of interactive AI systems must inform users when they are interacting with AI rather than a human where the rule applies.

The Act also introduces requirements around AI-generated or manipulated content. Certain providers must make generated content detectable through machine-readable marking, while deployers have disclosure obligations for deepfakes and some AI-generated text on matters of public interest.

There is a limited transition until 2 December 2026 for the marking obligation on some systems placed on the market before 2 August 2026.

What about high-risk AI systems?

The timeline is different.

Following changes under the AI Omnibus, the Commission states that rules for systems used in certain high-risk areas, including employment, education, critical infrastructure, biometrics, migration and border control, will apply from 2 December 2027.

For high-risk AI embedded in regulated physical products, the relevant date is 2 August 2028.

That later timetable should not be interpreted as permission to ignore high-risk systems until 2027. Organisations need time to inventory systems, define ownership, collect documentation and build the necessary controls.

Who is affected by the AI Act?

The Act can apply to providers, deployers, importers, distributors and other actors depending on their role in the AI value chain.

A company does not need to build its own foundation model to have obligations. Businesses deploying third-party AI systems can still fall within the rules, particularly where the use case is high risk or subject to transparency requirements.

A practical compliance starting point

Build an AI inventory

Record where AI is being developed, purchased and used. Include embedded AI features inside wider software products.

Identify your role

For each system, determine whether the organisation is acting as provider, deployer or another regulated actor. Obligations vary materially by role.

Classify the use case

Map systems against prohibited practices, transparency-risk categories and potential high-risk uses.

Review transparency obligations

Check whether users must be informed that they are interacting with AI and whether generated or manipulated content needs marking or disclosure.

Review general-purpose AI exposure

If the organisation provides a general-purpose AI model or modifies and places one on the market, separate obligations may apply.

Prepare high-risk documentation early

Organisations using AI in employment, education or other sensitive areas should start preparing before the later application dates.

AI literacy is already part of the picture

One overlooked part of the Act is AI literacy.

The requirement reflects a practical truth: governance fails if the people using AI do not understand enough about its capabilities and risks to make sensible decisions.

Training therefore should not be limited to the legal team. Employees need role-appropriate guidance on approved tools, sensitive data, model limitations and escalation routes.

The EU AI Act should sit inside wider AI governance

Treating the Act as a stand-alone legal checklist is risky.

The same controls that support compliance also support safer AI adoption: inventories, risk classification, documentation, evaluation, human oversight and clear accountability.

That is why companies increasingly connect legal compliance with broader Responsible AI and AI governance programmes.

The regulatory timeline will continue to evolve as standards, guidance and enforcement practice develop. Businesses should therefore work from current European Commission guidance and maintain an implementation process that can be updated rather than relying on a one-time compliance document.

Sources and further reading