EU AI Act Coming August 2 What Businesses Need to Know
- Creative Shin
- 2 days ago
- 9 min read
August 2 is not a soft reminder on the compliance calendar. For many organizations using, buying, building, or selling AI systems in or into the European Union, it marks the point where the EU AI Act becomes much harder to ignore.
The law is already in force, but it applies in phases. Some rules began earlier, including bans on certain AI practices and AI literacy duties. The bigger shift arrives on August 2, 2026, when many of the core obligations for high-risk AI systems start to apply.
That matters even for companies based outside the EU. If an AI system affects people in the EU, serves EU customers, or produces outputs used in the EU, the law may still reach it.
This article is informational only and is not legal advice. Use it as a practical starting point for internal planning, then confirm your obligations with qualified counsel.

The EU AI Act is a risk-based law
The EU AI Act is built around a simple idea: the higher the risk, the stricter the rules.
The law does not treat every chatbot, recommendation tool, or prediction model the same way. A tool that suggests music does not carry the same risk as a system that helps screen job applicants, assess creditworthiness, or support medical decisions.
The Act groups AI uses into several broad categories:
Category | What it means | Business impact |
Prohibited AI practices | Uses the EU considers unacceptable | These systems cannot be placed on the EU market or used in the EU |
High-risk AI systems | Systems used in sensitive areas such as employment, education, critical infrastructure, safety, and access to key services | These carry the heaviest compliance duties |
Limited-risk AI systems | Systems that need transparency, such as chatbots or some generated content tools | Users must often be told they are interacting with AI |
Minimal-risk AI systems | Common low-risk uses | Few or no specific AI Act duties, though other laws may still apply |
The practical takeaway is clear. Businesses need to map what AI they use, not just whether they use AI.
A company may not describe itself as an AI company and still fall within the law. HR screening software, fraud scoring tools, customer support bots, product safety tools, and AI-assisted decision systems can all raise questions under the Act.
Why August 2 matters
The EU AI Act follows a staged application schedule. That schedule gives businesses time to prepare, but it also creates different deadlines for different duties.
Here is the simplified version.
Date | What changes |
August 1, 2024 | The EU AI Act entered into force |
February 2, 2025 | Bans on certain prohibited AI practices began to apply, along with AI literacy duties |
August 2, 2025 | Rules for general-purpose AI models began to apply, along with parts of governance and enforcement |
August 2, 2026 | Most core rules begin to apply, including many obligations for high-risk AI systems |
August 2, 2027 | Some rules for certain high-risk systems, including those tied to regulated products, apply later |
For many businesses, August 2, 2026 is the major operational deadline. By that point, organizations should know which AI systems they use, which category each one falls into, and what evidence they can show if regulators ask.
This is why waiting until the deadline is risky. AI compliance is not a single policy document. It requires inventory work, vendor review, technical testing, documentation, staff training, and ongoing monitoring.

Which businesses need to pay attention
The EU AI Act applies to a wider group than many companies expect.
A business should review the law if it:
Develops AI systems for customers in the EU
Uses AI systems in the EU
Sells software or connected products into the EU that include AI
Uses AI outputs in decisions affecting people in the EU
Provides general-purpose AI models or integrates them into products
Buys AI tools from vendors and uses them in hiring, education, finance, insurance, safety, or public-facing services
The Act uses roles such as provider, deployer, importer, distributor, and product manufacturer. A single company can hold more than one role.
For example, a US software company that builds an AI tool and sells it to EU customers may be a provider. A retailer that buys a third-party AI hiring tool and uses it to rank candidates may be a deployer. A manufacturer that embeds AI into a regulated device sold in the EU may have duties under both product safety rules and the AI Act.
The key question is not, “Are we an AI business?” The better question is, “Where does AI affect people, safety, rights, or access to important services?”
High-risk AI systems need the most preparation
High-risk systems are the main reason August 2 deserves attention. These systems are not banned, but they must meet strict requirements before and during use.
High-risk areas can include:
Employment and worker management
Education and vocational training
Access to essential private or public services
Law enforcement uses
Migration, asylum, and border control
Critical infrastructure
Safety components in certain regulated products
For businesses, the employment category is one of the most common pressure points. AI tools that screen resumes, rank candidates, assess performance, or support promotion decisions may need careful review.
High-risk obligations can include:
A risk management system
Data governance and data quality controls
Technical documentation
Recordkeeping and logging
Transparency for users
Human oversight
Accuracy, cybersecurity, and reliability controls
Post-market monitoring
Incident reporting in some cases
These are not just IT tasks. Legal, compliance, security, procurement, HR, product, and operations teams may all need to contribute.
For example, a company using AI to shortlist job applicants should be ready to explain how the tool works, what data it uses, how bias risks are reduced, who reviews the output, and what happens when the system produces a questionable result.
That does not mean every AI-assisted process becomes unlawful. It means the business needs governance that matches the risk.
Prohibited AI uses are already a red line
Some AI practices are not allowed under the Act. These prohibitions started applying before the August 2, 2026 milestone, so businesses should already have addressed them.
The prohibited category includes certain uses that involve manipulation, exploitation of vulnerabilities, certain forms of social scoring, and some biometric practices. The details matter, but the message is simple: some AI use cases are off-limits because the EU sees them as incompatible with fundamental rights and public safety.
Businesses should check for prohibited practices even if they do not build AI themselves. Risk can enter through vendors, internal experiments, pilot programs, or tools adopted by individual teams.
A practical review should look at:
AI tools used to influence behavior
Biometric identification or categorization tools
Emotion recognition in sensitive settings
Scoring systems that affect access to services
Tools used with children, workers, or vulnerable groups
This review should not be limited to approved software. Shadow AI use can create real exposure.
General-purpose AI is treated differently
The Act also creates specific duties for general-purpose AI models. These are models that can perform a wide range of tasks and can be integrated into many downstream systems.
For businesses, this matters in two ways.
First, companies that develop or provide general-purpose AI models may face direct duties. These can include technical documentation, information for downstream providers, and copyright-related policies. Some stronger obligations apply to models with systemic risk.
Second, companies that build products on top of general-purpose AI models still need to understand the risks of their own use case. A model may be general, but the application can still become high-risk depending on how it is used.
A chatbot that summarizes public product information is one thing. A chatbot used to advise patients, screen applicants, evaluate students, or support credit decisions is a different matter.
The model is only part of the picture. The business process around it matters just as much.

Transparency duties will affect everyday AI use
Not every covered system is high-risk. Some systems mainly trigger transparency duties.
For example, people may need to be told when they are interacting with an AI system rather than a human. AI-generated or manipulated content may need clear labeling in certain cases. This is especially relevant for chatbots, synthetic media, and systems that produce text, images, audio, or video.
Businesses should review customer-facing and employee-facing AI tools for basic disclosure needs.
Good transparency is plain and visible. It should not hide in long terms of service or vague language. A short notice such as “This chat is handled by an AI assistant” may be more useful than a dense legal paragraph.
The rule of thumb is straightforward. If people could reasonably believe they are interacting with a person, or if generated content could mislead them, disclosure deserves attention.
What companies should do before August 2
The best first step is an AI inventory. Without one, compliance planning becomes guesswork.
A useful inventory should capture:
The name of each AI system
The vendor or internal owner
The business purpose
The data used
The people affected
The decision or output supported
The level of human review
The countries where it is used
The likely AI Act risk category
Existing documentation and controls
Once the inventory exists, businesses can triage. Not every tool needs the same level of review. A spelling assistant and an AI hiring system should not compete for the same compliance resources.
Next, review vendor contracts. Many organizations rely on third-party AI tools, and the Act can require technical and compliance information that vendors may not provide by default.
Ask vendors for:
System documentation
Intended use and prohibited use guidance
Data governance details
Accuracy and performance information
Human oversight guidance
Security controls
Logging and audit features
Subprocessor and model provider information
Contracts should make clear who handles updates, documentation, incident notices, support for audits, and changes in the system’s risk profile.
Then focus on governance. A simple approval process can stop risky tools from spreading without review. It should cover new AI purchases, internal builds, pilot projects, and major changes to existing systems.
AI literacy is not optional
One earlier duty deserves special attention: AI literacy.
The Act expects providers and deployers to take measures so staff and other relevant people have enough AI knowledge for their role and the context in which AI is used.
This does not mean every employee needs to become a machine learning engineer. It does mean people should understand the limits of the systems they use.
Training should be role-based.
Role | What they should understand |
Executives | Risk categories, accountability, and resource needs |
Legal and compliance teams | Duties, documentation, vendor controls, and enforcement risk |
HR and operations teams | Human oversight, bias risks, and affected-person rights |
Product teams | Intended use, design limits, monitoring, and documentation |
Customer-facing teams | Transparency duties and safe escalation paths |
Security teams | AI-related cyber risks, logging, and incident response |
AI literacy also protects the business from overreliance. Staff should know when AI output needs review, when to challenge it, and when to stop using a tool.
The cost of waiting could be high
The EU AI Act includes serious penalties. The highest fines can reach significant percentages of global annual turnover, depending on the type of violation. Exact exposure depends on the conduct, the organization, and the enforcement path.
Fines are not the only risk. A business may also face product delays, suspended deployments, customer contract issues, reputational harm, or forced changes to systems already in use.
For vendors, compliance may become a sales requirement. EU customers are likely to ask for AI Act documentation before buying or renewing AI-enabled products. Companies that can answer those questions clearly will have an advantage over those still trying to find their own inventory.
That is one reason to treat compliance as a product and operations issue, not only a legal issue.
A practical readiness checklist
Before August 2, businesses should aim to complete a focused readiness plan.
Build an AI inventory across departments
Identify systems used in the EU or affecting people in the EU
Classify systems by likely risk category
Stop or escalate any potentially prohibited uses
Review high-risk systems first
Check transparency notices for chatbots and generated content
Request documentation from AI vendors
Update procurement and contract templates
Assign owners for AI governance
Train staff based on role and risk
Create a process for monitoring AI systems after deployment
Prepare records that show decisions, controls, and oversight
The goal is not perfection on day one. The goal is to show disciplined governance, clear ownership, and a good-faith effort to meet the law’s requirements.

Businesses should treat August 2 as an operating deadline
The EU AI Act is not just another privacy-style notice requirement. It asks businesses to understand where AI is used, how it affects people, what risks it creates, and who is responsible for controlling those risks.
August 2 brings many of those expectations into practical focus. Businesses that start with an inventory, rank their risks, review vendors, and train staff will be in a much better position than those rushing to respond after a customer, regulator, or board member asks for proof.
The next step is simple: list every AI system in use, then identify the ones that touch employment, safety, education, essential services, finance, or EU users. Those systems deserve attention first.


Comments