The EU AI Act is now in force and most businesses deploying AI are not ready for what that means

On August 2, 2026, the European Union's Artificial Intelligence Act reaches full applicability for most provisions — making it the first comprehensive legal framework governing AI anywhere in the world. For businesses operating in or selling to European markets, the deadline is not a distant regulatory event to prepare for someday. It is happening now, and the enforcement exposure for non-compliance is substantial: fines reaching 7% of global annual revenue for prohibited AI violations and 3% for high-risk system failures. To put that in context, those figures exceed the maximum penalties under GDPR, which itself transformed how the world approaches data protection.
Yet despite years of advance notice since the Act entered into force in August 2024, the compliance picture across enterprise organizations is deeply uneven. Legal and compliance teams are grappling with a regulation that overlaps with, but is architecturally distinct from, GDPR — creating a dual-layer obligation that most companies' existing privacy tools were not built to address. Shadow AI — staff deploying unapproved AI tools across enterprise functions — has expanded the organizational AI surface area by five to ten times in eighteen months, far outpacing governance frameworks built for a simpler environment. For the companies operating across the target markets of this blog — spanning the UK, EU member states, the US, Canada, Australia, and New Zealand — understanding the new regulatory reality is not a compliance department responsibility alone. It is a strategic and operational imperative.
What the EU AI Act actually requires
The Act is built on a graduated, risk-based structure rather than a single uniform standard. AI systems are classified into four categories based on the potential harm they pose. At the top, a small set of practices are outright prohibited — social scoring by public authorities, real-time biometric surveillance in public spaces without authorization, and AI systems that exploit psychological vulnerabilities to manipulate behavior. These prohibitions entered application in February 2025 and are already enforceable.
High-risk AI systems — the category attracting the most attention from enterprise compliance teams — include systems used in employment decisions (hiring, promotion, performance monitoring), credit and insurance assessments, educational access, critical infrastructure management, border control, and administration of justice. For these systems, the Act imposes a comprehensive set of obligations: risk management systems documented before deployment, high-quality training data with governance trails, technical documentation sufficient for regulatory assessment, human oversight mechanisms built into the system architecture, and registration in a public EU database before market availability.
The August 2, 2026 date is critical because it is when Annex III high-risk obligations become enforceable for most covered systems. However, a political agreement reached in May 2026 on the Digital Omnibus — a package aimed at streamlining EU digital regulation — has introduced some nuance. Certain high-risk obligations, particularly for systems embedded into regulated products, have been extended to December 2027 or August 2028 for specific categories. Organizations should not interpret this as a general reprieve. The core high-risk obligations for AI in employment, credit, and education contexts apply from August 2026, and prudent compliance planning treats that as the binding deadline.
Generative AI models — large language models and similar general-purpose AI systems — face their own obligations under the Act, which became applicable in August 2025. Providers must publish summaries of training data, implement policies to comply with EU copyright law, and ensure AI-generated content is identifiable where required. Transparency rules, including disclosure that users are interacting with AI in consumer-facing contexts, also apply from August 2026.
The GDPR collision
For organizations already managing GDPR compliance, the EU AI Act creates a second, overlapping layer of obligation rather than replacing or simplifying what already exists. The two laws are built on different regulatory logics: GDPR is fundamentally a rights framework centered on individual control over personal data, while the AI Act is a product safety regulation focused on risk management and organizational accountability. Both apply simultaneously to any AI system that processes personal data about EU residents — which describes the majority of AI in commercial use.
The practical friction this creates is significant. GDPR requires a lawful basis for processing personal data, including when training or running AI models. Article 22 restricts solely automated decisions that produce legal or similarly significant effects on individuals — a provision that directly constrains AI systems used in hiring, credit, and similar contexts without human oversight. Data Protection Impact Assessments, already mandatory under GDPR for high-risk processing, must now be coordinated with the AI Act's conformity assessments for high-risk AI systems. The documentation standard the AI Act demands — technical documentation, risk assessments, testing records, training data governance — exceeds what most organizations have historically maintained even for traditional software systems.
US state-level legislation adds a third layer for organizations with American operations. In 2025 alone, US states introduced 1,208 AI-related bills and enacted 145 of them. Colorado's Artificial Intelligence Act, effective June 30, 2026, imposes reasonable care obligations on deployers of high-risk AI systems affecting Colorado residents regardless of where the deploying business is headquartered. New York City's Local Law 144 requires annual public bias audits for automated employment decision tools. California has introduced automated profiling restrictions and consumer access rights. An AI system used for hiring decisions by a European company that also operates in the US may simultaneously be subject to the EU AI Act, GDPR Article 22, Colorado's AI Act, and New York City's bias audit requirement.
What organizations need to do right now
The most underestimated compliance burden identified by legal and technology experts across the industry is documentation. The technical documentation, risk assessments, testing records, and data governance materials the AI Act requires are not simply records to be written after the fact — they must be produced as part of the development and deployment process. Retrofitting documentation for AI systems already in production is exponentially more difficult than embedding it into development workflows from the start.
The practical starting point is inventory. Organizations need to know what AI systems they are running, which functions those systems perform, and how those functions map to the Act's risk classification. Many organizations discovering this process are surprised by the breadth of their AI footprint — the shadow AI problem means that operational AI use is consistently wider than IT records reflect.
Vendor due diligence becomes a critical procurement function under the new regime. The Act creates obligations not just for AI developers but for deployers — the organizations that use AI systems in their operations. Before deploying any third-party AI system that processes personal data or performs high-risk functions, organizations need evidence of training data provenance, lawful basis documentation, conformity assessment status, and the vendor's compliance approach. This is now a standard gating requirement for enterprise AI procurement.
For businesses operating across multiple jurisdictions, the compliance architecture needs to be designed for the most stringent applicable standard rather than jurisdiction-shopped to the most permissive one. Given the EU AI Act's extra-territorial reach — which applies to any organization whose AI systems produce outputs affecting EU residents, regardless of where the system operates — most businesses with significant European customer bases have EU Act obligations whether or not they have EU legal entities. The GDPR effect, where European data protection standards spread globally as organizations standardized on a single compliance architecture, is likely to repeat itself with AI governance.