Bismart Blog: Latest News in Data, AI and Business Intelligence

EU AI Act: 10 Compliance Areas Your Business Needs to Review

Written by Núria Emilio | Aug 11, 2026, 7:02:45 AM

The EU Artificial Intelligence Act (AI Act) has moved firmly from legislation to compliance. As of 2 August 2026, a new set of requirements under the European Union’s AI regulation applies to organisations operating across Europe.

The AI Act is being introduced in stages, with implementation continuing through 2028. Different compliance deadlines apply to areas such as transparency, general-purpose AI models and high-risk AI systems.

Requirements covering prohibited AI practices, AI literacy, transparency and general-purpose AI models are already part of the EU AI Act compliance timeline and should now be on every organisation’s agenda.

The challenge is no longer simply understanding what the regulation says. Businesses must now be able to demonstrate that they know where and how AI is being used across the organisation, who is accountable for it and what controls are in place.

That means being able to answer questions that, until recently, may have seemed largely operational: What AI systems are currently in use? What data do they rely on? Which providers are involved? Who is responsible for overseeing them? What risks do they introduce? And, crucially, what evidence can the organisation provide to demonstrate effective governance and control?

In this article, we examine which EU AI Act requirements are already in force, what changes from August 2026, which organisations fall within the scope of the regulation, which AI use cases require closer scrutiny, and which obligations have been postponed.

EU AI Act Compliance in 2026: What Changes From 2 August 

The Artificial Intelligence Act (AI Act) entered into force in 2024, but its requirements have been introduced gradually rather than becoming applicable all at once.

Officially known as Regulation (EU) 2024/1689, the AI Act follows a phased implementation timeline, with different obligations becoming applicable at different stages.

This staggered approach has created some confusion. Some organisations have interpreted delays to certain requirements as a reason to postpone their compliance efforts. In practice, however, important parts of the AI Act compliance framework for businesses already apply:

  • Since February 2025, rules on prohibited AI practices have been in force. AI literacy requirements also began to apply at that stage, although the framework was subsequently amended as part of the 2026 AI Omnibus.
  • Since August 2025, providers of general-purpose AI models (GPAI models) have been subject to specific obligations under the AI Act.
  • 2 August 2026 marks another major milestone. The transparency obligations set out in Article 50 now apply, affecting a broad range of AI systems and business use cases. The European Commission’s AI Office and national authorities have also begun enforcing the Act.

For businesses, these developments have very practical consequences. Organisations using chatbots, generative AI assistants, content creation tools, biometric categorisation systems, emotion recognition technologies, AI embedded in internal workflows or third-party AI solutions can no longer assume that compliance is solely the provider’s responsibility.

Under the AI Act, an organisation’s obligations depend on the role it plays in relation to each AI system. Depending on the circumstances, a company may act as a provider, deployer, importer or distributor, while a separate set of requirements applies to providers of general-purpose AI models.

A company does not need to develop its own AI models to fall within the scope of the AI Act. Simply using, deploying or integrating AI into internal processes, customer-facing channels, operations, human resources, marketing, customer service, analytics or decision-making may be enough to trigger specific responsibilities under the Regulation. 

The AI Act is therefore becoming much more than a regulatory matter for legal and compliance teams. It raises a broader and highly practical business question: Does the organisation know which AI systems it uses, who is responsible for them, what data they rely on, which controls are in place and what evidence it can provide to demonstrate that those systems are being properly governed? 

To help organisations answer these questions, Bismart has created a Practical Guide to the AI Act for Businesses. The guide helps companies identify what they need to review, understand which requirements may apply to them and begin developing a structured approach to AI compliance, governance and traceability

Why the AI Act delays are not a reason to wait 

One of the biggest risks for businesses is interpreting the revised AI Act timeline as a blanket extension. The postponement of certain requirements for high-risk AI systems does not mean organisations can put compliance on hold.

The Digital Omnibus on AI has delayed some requirements under Chapter III. Rules for high-risk AI systems covered by Article 6(2) and Annex III will apply from 2 December 2027, while those covered by Article 6(1) and Annex I, including AI systems embedded in regulated products, will apply from 2 August 2028.

However, AI Act compliance is already a reality. Rules on prohibited AI practices already apply, AI literacy obligations are in place, transparency requirements now affect relevant AI use cases, and general-purpose AI models are already subject to specific rules.

Businesses that wait until 2027 to identify their AI systems, assess risks, review contracts, document data practices or assign responsibilities will already be behind. They may lack the foundations for effective AI governance, traceability and the evidence needed to demonstrate AI Act compliance.

Preparing for the AI Act therefore means acting now: knowing which AI systems are in use, what data they rely on, what controls are in place and who is accountable for them.

 

AI Act for Businesses: 10 Key Compliance Areas to Address 

1. Build an AI System Inventory Before Assessing Risk 

The first step in preparing your business for the AI Act is not drafting an internal policy. It is understanding exactly which AI systems are being used across the organisation.

Most companies use more AI than they realise. Chatbots, AI copilots, analytics tools, predictive models, recommendation engines, marketing automation platforms, recruitment software, cloud services and third-party applications may all contain AI capabilities that are not immediately visible to users.

Without an AI system inventory, there is no reliable basis for compliance.

At a minimum, the inventory should record each AI system, its provider, business function, use case, data processed, level of autonomy, people affected, available documentation, related contracts and whether it supports or makes automated decisions.

The aim is not to create more bureaucracy, but to regain visibility over technologies that have often been adopted in a fragmented and decentralised way.

An AI system inventory is the foundation of AI Act compliance because it turns hidden AI exposure into something the organisation can actually manage. Without it, businesses cannot properly classify risk, assign accountability, assess providers or demonstrate that appropriate controls are in place.

This also highlights a broader issue: readiness for AI Act compliance is closely linked to data maturity. Organisations with fragmented systems, poorly governed data, limited metadata and weak traceability will find compliance more difficult — and will also struggle to scale AI safely and effectively.

2. Define Your Organisation’s Role Under the AI Act 

The EU AI Act does not impose the same obligations on every business. What an organisation is required to do depends on the role it plays in relation to each AI system and how that system is used.

A company will typically be considered a deployer when it uses an AI solution provided by a third party. However, it may also qualify as a provider if it develops an AI system, markets or puts it into service under its own name, or, in certain cases, substantially modifies an existing high-risk AI system. Organisations may also act as distributors, importers or downstream providers.

This distinction matters:

There is no one-size-fits-all approach to AI Act compliance. Each AI system must be assessed individually, based on how it is used and the role the organisation plays.

The key question is simple but critical: What role does our organisation play in relation to this AI system?

Without a clear answer, it is difficult to determine which requirements apply, what evidence must be retained and who should be accountable for the system’s use.

3. Assess AI Risk Before Scaling Its Use 

The AI Act is based on a simple principle: not every AI system carries the same level of risk. Not all uses of AI are prohibited, and not every AI system is considered high-risk.

Even so, any AI system that plays a significant role in the business should undergo an initial risk assessment before its use is scaled across the organisation.

An AI risk assessment should help determine where a system sits within the AI Act framework: whether it involves a prohibited AI practice, is subject to transparency obligations, could qualify as a high-risk AI system, involves a general-purpose AI model, or presents minimal risk. 

For this reason, AI risk classification should not be carried out in isolation. Legal teams can interpret regulatory requirements, while business teams understand how the system is used in practice. IT, data, security and compliance teams also play a key role in assessing architecture, data quality, access, exposure and the evidence needed to demonstrate that appropriate controls are in place.

In practice, AI Act compliance requires collaboration across business, technology, data, security and compliance teams, as well as the people responsible for the processes where AI is being used.

To support this process, Bismart has created an AI Act Guide for Businesses. It brings together the key dates, core AI Act requirements, review criteria, an AI risk assessment framework and a responsibility matrix to help organisations prepare for compliance.

4. Prohibited AI Practices: Rules That Already Apply 

The AI Act’s rules on prohibited AI practices have applied since February 2025. These are not requirements businesses can postpone until a later stage of the AI Act timeline.

Article 5 covers practices such as certain subliminal, manipulative or deceptive techniques that materially distort behaviour and cause harm, the exploitation of vulnerabilities, social scoring, and certain AI systems used to assess or predict the risk of a person committing a criminal offence based solely on profiling.

For businesses, the priority is to identify and review sensitive AI use cases before they become embedded in day-to-day operations.

That review should extend beyond systems developed in-house to include third-party tools, pilots, proofs of concept, departmental automations and vendor solutions with AI capabilities.

The main risk is not that a business will knowingly deploy a prohibited AI practice. It is that a feature is enabled without sufficient review, an AI system is used beyond its original purpose, or a vendor introduces AI capabilities that the organisation has never properly assessed.

At Bismart, our view is simple: data governance should come before AI is scaled across the business.

5. AI Literacy: Training Needs to Go Beyond a Policy Document 

AI literacy is one of the AI Act requirements businesses can easily underestimate. 

Article 4 of the EU AI ACT requires providers and deployers to take measures to support AI literacy among staff and others who operate or use AI systems on their behalf. 

This goes beyond sending employees a guide on AI or running a generic training session on generative AI tools.

In practice, AI training should help people understand the limitations, risks and responsibilities associated with the systems they use in their day-to-day work.

Employees should know when an AI output may be unreliable, how AI hallucinations can affect results, what information should not be entered into certain tools, and when human review is required.

Training should also reflect the context in which AI is used. A marketing team using generative AI to create first drafts does not need the same level of knowledge as a risk team working with predictive models.

That is why AI literacy in the workplace should be tailored to different roles, use cases and levels of risk exposure, with organisations keeping a clear record of the measures they have implemented.

6. Transparency: Users Need to Know When They Are Interacting With AI 

The AI Act’s transparency obligations are among the most visible changes in this phase of implementation. From 2 August 2026, Article 50 applies to many common business uses of AI.

Under Article 50 of the EU AI Act, AI systems designed to interact directly with individuals must make it clear that the person is interacting with AI, unless this is already obvious from the context.

This is particularly relevant for chatbots, conversational assistants, virtual agents, automated customer service systems, internal support tools and other interfaces designed to interact with customers, employees, users or members of the public.

Meeting the AI Act’s transparency requirements means reviewing user journeys, automated messages, disclosures, conversational interfaces and the circumstances in which an exception may apply. Simply stating that AI is being used may not always be enough.

The goal is to ensure that users are not misled about who or what they are interacting with, what they can expect from the system and when human oversight is available.

Transparency is therefore more than a formal compliance requirement. For businesses using AI to interact with people, it is also an important foundation for trust.

7. AI-Generated Content: Marking and Labelling 

AI-generated content is one of the areas where the AI Act’s transparency requirements will be most visible to businesses.

Since 2 August 2026, the AI Act has imposed specific transparency requirements on certain types of content generated or manipulated using artificial intelligence.

The question is not simply whether AI was used to create the content. Businesses need to know when that content must be marked or labelled — and who is responsible for doing so.

These rules are particularly relevant to deepfakes, synthetic images, video and audio, as well as certain AI-generated or manipulated text. The specific obligation depends on the type of content and whether the organisation acts as a provider or deployer.

The main risk is not using AI to create content, but failing to understand when disclosure is required, who reviews and approves the content, which tools and vendors are involved, and what evidence is retained.

Organisations therefore need more than a generative AI policy. They also need practical review and approval workflows that translate that policy into day-to-day processes.

Effective AI-generated content transparency requires sound editorial judgement, operational controls and traceability.

8. AI Governance: Accountability, Evidence and Human Oversight 

The AI Act is pushing businesses towards a more structured approach to AI governance. Innovation alone is not enough; organisations also need clear controls and accountability.

That means defining who approves new AI use cases, assesses risk, reviews vendors, oversees data and is responsible for the systems themselves.

It also means establishing clear responsibility for incident reporting, decisions about moving AI systems from pilot to production, and maintaining the evidence needed to support compliance.

AI governance means being able to show who makes decisions, who provides oversight, what data is being used, which risks have been assessed and what evidence supports those controls. Innovation without traceability is difficult to govern and even harder to defend.

A robust governance framework should also define how human oversight works in practice. It is not simply about having someone approve an AI-generated result at the end of a process. People need the authority, information and tools to understand, challenge, intervene in or stop an AI system when necessary.

This highlights a broader issue: many organisations have accelerated AI adoption without strengthening their data governance at the same pace.

And without strong data governance, AI governance will always have a blind spot.

9. Data and Cybersecurity: AI Act Does Not Replace GDPR or NIS2 Requirements 

The AI Act does not operate in isolation. Businesses must also consider the GDPR, the NIS2 Directive, DORA, sector-specific regulations, intellectual property rules, contractual obligations, cybersecurity requirements and their own internal risk frameworks.

Complying with the AI Act does not remove the need to address issues such as personal data, lawful bases for processing, data minimisation, access controls, third-party providers, data transfers, logging, retention, identity and access management, traceability and operational resilience.

AI tends to amplify existing weaknesses in an organisation’s data. If data is duplicated, poorly integrated, difficult to trace, unreliable or lacks clear ownership, AI will not solve those problems — it will scale them.

That is why AI Act compliance cannot be treated as a legal layer added at the end of an AI project. It needs to be built into the organisation’s data architecture, technology platforms, security controls and business processes from the outset.

10. Third-Party AI and Vendor Contracts: A Common Compliance Blind Spot 

Much of the AI used by businesses is not developed in-house. It is embedded in third-party products and services such as SaaS platforms, cloud services, CRM and ERP systems, analytics tools, productivity software, marketing platforms, AI copilots, APIs and enterprise applications.

This makes AI vendor contracts an important part of AI Act compliance.

Organizations should review contractual terms covering data use, model training, intellectual property, technical documentation, transparency, subprocessors, audit rights, security, data location, incident management, substantial modifications and the allocation of responsibilities between the parties.

They should also understand which AI capabilities a vendor provides, what those systems can and cannot do, and which responsibilities remain with the business when it acts as the deployer.

The risk does not always come from an unfamiliar vendor. It can also arise from widely used business software whose AI features and configurations evolve faster than the organisation’s internal review processes.

Using third-party AI does not remove a company’s responsibilities under the AI Act. Businesses need visibility into the AI capabilities included in the products they use, the data those capabilities rely on, the documentation vendors can provide and the obligations that remain with the organisation deploying the system. 

What Businesses Should Already Have in Place for AI Act Compliance 

Any organisation using AI should already have the foundations of an operational AI Act compliance framework. Businesses do not need to have every possible high-risk AI system scenario fully addressed today, but they do need the processes and governance required to manage those systems when they arise.

At a minimum, those foundations should include:

  • A living inventory of AI systems that is regularly updated.
  • An initial AI risk classification for each system.
  • A clear understanding of the organisation’s role in relation to each AI system.
  • A review of potential prohibited AI practices.
  • Documented AI literacy measures.
  • A review of transparency requirements for chatbots, AI assistants and relevant AI-generated content.
  • Internal policies governing the use of generative AI.
  • Clear ownership and accountability for AI governance.
  • Reviews covering data, access controls, security and third-party providers.
  • Properly maintained compliance evidence.

The goal is not to create a compliance folder that sits untouched. It is to build an organisation that can explain how it uses AI, demonstrate that the right controls are in place and stand behind the decisions it makes.

For a more detailed review of these areas, download Bismart’s AI Act Guide for Businesses, which includes a readiness checklist, a responsibility matrix and guidance on the evidence organisations should retain.

The Real Opportunity: Moving From Reactive Compliance to AI Readiness 

The AI Act can be seen as a regulatory burden. But it can also be a measure of how ready an organisation is to manage AI responsibly.

Organisations that treat compliance as a standalone exercise may end up producing little more than documentation. Those that connect it to their data strategy, AI governance and AI readiness can build something far more valuable: a clear understanding of which AI systems they use, what data those systems rely on, what risks they create, what controls are in place and which decisions can be safely automated or supported by AI.

That is where the AI Act, data governance and AI readiness come together.

An AI-ready organisation is not the one with the most AI tools. It is the one that can scale AI without losing control of its data, processes, vendors or responsibilities.

This is where Bismart helps businesses build the foundations for AI they can trust: data integration, data governance, data quality, modern data platforms, advanced analytics and AI initiatives aligned with real business needs.

Because AI Act compliance is not simply about meeting regulatory requirements. It is about creating the conditions for AI to be used confidently, responsibly and at scale.

Does Your Organisation Comply With the EU AI Act?

Bismart helps businesses assess their technology infrastructure, data readiness and governance capabilities so they can move towards AI that is safer, more traceable and better aligned with business priorities.

 

Conclusion: AI Can No Longer Be Treated as an Experiment 

2 August 2026 should not be seen as a one-off compliance deadline or simply another date on the regulatory calendar.

For many organisations, it marks a broader shift: AI can no longer be treated as a collection of disconnected tools. It needs to be managed as a business capability with clear governance and regulatory responsibilities.

AI Act compliance requires visibility into how AI is used, a structured approach to risk, AI literacy, transparency, vendor oversight, data governance and reliable evidence that the right controls are in place.

The key question is no longer whether a business uses AI. It is whether the organisation can show which AI systems it uses, what they are used for, what data they rely on, who is responsible for them, what risks they create and what controls are in place.

Businesses that can answer those questions with evidence will be better prepared for the AI Act and better positioned to compete in an economy where simply adopting AI is no longer enough. The real advantage will come from how effectively that AI is governed.