Single Blog

  • Home
  • The EU AI Act: what changes for businesses
Colorful contract and pen — AI governance

The EU AI Act: what changes for businesses

IN DEPTH · GOVERNANCE & STRATEGY

Colorful illustration of a contract and pen — AI governance

The EU AI Act: what changes for businesses

The implications extend beyond choosing an AI model. They affect software procurement, service design, decisions and accountability. Here is how to turn the European regulation into practical business decisions.

Analysis as of October 3, 2026 · Includes the July 2026 AI Omnibus changes · Approximately 11 minutes

1. Rules that follow AI uses, including outside Europe

The AI Act, Regulation (EU) 2024/1689, establishes requirements according to risk and role. It is neither a blanket ban on AI nor a universal software certification. Read the applicable version with its amendments, including the AI Omnibus that entered into force on July 27, 2026. European Commission: regulatory framework and amendments.

Its scope can include suppliers established outside the EU that place systems on its market, as well as third-country providers and deployers whose systems produce outputs used in the EU. A Tunisian or Moroccan business therefore cannot assume it is outside scope simply because of its registered office. Article 2: scope.

For businesses across EMENA: mapping customers, locations of use and output flows matters alongside server locations. A cross-border project should establish who operates the system, which decisions it supports and who is affected. Resolve these questions before contracting, rather than discovering them during acceptance testing.

Provider and deployer: contracts must reflect actual roles

A provider develops or commissions a system and markets it or puts it into service under its name. A deployer uses a system under its authority in a professional activity. One organization may occupy both roles across different systems. A general-purpose model provider is not necessarily the provider of the final application. Article 3: definitions.

Rebranding a high-risk system, substantially modifying it or changing an intended purpose so that a system becomes high-risk can shift provider responsibilities. An integration is not always just a purchase. Article 25: responsibilities across the value chain.

2. What already applies, and what to prepare for

Deferring certain provisions does not suspend the entire regulation. These are the main milestones; specific transitional arrangements require examining the system and when it was placed on the market.

Date Main milestone Business response
February 2, 2025 Initial prohibited practices and AI literacy Review uses and support the people operating AI.
August 2, 2025 General-purpose AI model rules and governance Identify model-provider responsibilities and available information.
August 2, 2026 General application, including transparency Review affected interfaces, interactions and content.
December 2, 2026 Additional targeted Omnibus prohibitions Check relevant content-generation capabilities and uses.
December 2, 2027 Main Chapter III requirements for Annex III high-risk systems Prepare classification, responsibilities, controls and evidence.
August 2, 2028 Corresponding main requirements for high-risk systems under Article 6(1) and Annex I Coordinate with regulated-product conformity work.

Sources: amended Article 113 and transparency guidelines. Transitional provisions for existing systems and models appear in Article 111.

Use the preparation period to avoid a rushed implementation. Building test datasets, negotiating access to logs and training teams take time. Start with sensitive processes while allowing appropriately controlled digital projects to progress.

3. Classify a defined purpose, not an entire department

Begin with a use described in one sentence: answering document questions, ranking applicants or calculating a premium. Labeling an entire CRM or insurance company “high-risk” would produce an inventory with little operational value.

01 · EXCLUDE

Prohibited practices

Check the prohibitions, conditions and exceptions first. Certain manipulation, social-scoring and biometric uses belong here.

02 · ASSESS

High risk

Examine the product criteria or listed Annex III uses. Record the reasoning, rather than only a color in a spreadsheet.

03 · INFORM

Transparency

Assess AI interaction and content generation separately. Transparency requirements can apply alongside high-risk requirements.

For example, workplace emotion inference is prohibited subject to the medical or safety exceptions in the text. The new prohibition addressing certain non-consensual sexual or intimate generated content and child sexual abuse material is part of the 2026 amendments. Article 5: prohibited practices and conditions.

Some narrow or preparatory Annex III tasks may qualify for an exception where the Article 6 conditions are met, including the absence of significant risk or material influence on decisions. This is not automatic. Profiling natural persons in Annex III uses removes this route to exemption. Article 6: classification rules.

4. What changes in procurement, teams and operations

Teach people how to use their actual systems

Amended Article 4 requires measures supporting AI literacy, tailored to staff knowledge and the context of use. It does not require guaranteeing a specific individual literacy level. Supporting staff nevertheless remains an obligation. Updated Article 4.

Our practical recommendation is to build learning by role: detecting fabricated answers for users, tests and versioning for technical teams, incident decisions for business owners. Working through a fictional case that the system gets wrong may teach more than a broad presentation of twenty tools.

Make AI visible where people encounter it

Article 50 distinguishes disclosure of AI interaction, technical marking of synthetic outputs and deployer disclosure of particular content. For public-interest text, the human-review or editorial-control exception also requires identified editorial responsibility. AI-assisted content does not all carry the same disclosure duty. Article 50.

Walk through the service as a first-time customer. Can they understand who is answering, what actions are possible and how to reach a person? Information buried in a legal page does little to explain the experience. Product and communications teams should participate in that review.

Prepare the high-risk provider’s evidence

Provider obligations include meeting applicable requirements, a quality management system, documentation, conformity assessment, an EU declaration, CE marking and registration where required. This is not a commercial badge purchased once for every future version. Article 16.

Organize deployer accountability

High-risk deployers must, among other things, follow instructions, assign competent and empowered human oversight, monitor operations and address risks or incidents. Logs under their control must generally be retained for at least six months, unless applicable law provides otherwise. Article 26.

Our operational recommendation is to identify who can suspend the system and rehearse that suspension. Human approval routinely rushed through because of workload offers less control than a reviewer with information, resources and a real ability to disagree.

Keep GDPR in the picture

AI Act compliance does not replace GDPR compliance. Purpose, lawful basis, necessary data, individual rights, security and transfers still need assessment when personal data are processed. CNIL explanation of the relationship.

Article 27’s fundamental-rights impact assessment concerns particular deployers, including public bodies, certain public-service entities and the specified creditworthiness and life/health insurance uses. It is not mandatory for every SME using a chatbot. Relevant data-protection impact assessment material can be incorporated. Article 27.

5. Four business scenarios

These examples are illustrative. Final classification depends on the purpose, functionality and context of the deployed system.

HR: drafting an advertisement versus filtering applicants

Drafting a vacancy notice serves a different purpose from ranking candidates. Recruitment and selection appear in Annex III. Ask the supplier whether the system helps write content or influences access to employment.

Banking: document support, credit and fraud

Assessing natural persons’ creditworthiness appears in Annex III, with an explicit exception for systems intended to detect financial fraud. That exception does not waive other applicable rules, nor cover a lending engine merely renamed “fraud detection.”

Insurance: distinguish pricing from administration

Risk assessment and pricing for natural persons in life and health insurance are specified. That does not automatically classify every insurer’s tool as high-risk. Source for these sector distinctions: Annex III.

Accounting: watch the expanding scope

Imagine an assistant reconciling documents and preparing questions for a client. Separate its functions: reading, proposing entries, sending messages and final approval. If the firm later adds decisions affecting employees or customers, reassess the scope. The initial project file may no longer describe the actual service.

6. Contracts, budgets and penalties

Article 99 ceilings reach €35 million or 7% of global turnover for prohibited practices, €15 million or 3% for specified other breaches, and €7.5 million or 1% for certain incorrect information supplied to authorities. The higher figure is the general rule; SMEs benefit from the lower ceiling. These are maximums, not automatic fines. Article 99: framework and criteria.

Business exposure also includes customer rejection, urgent rework, service interruption and decisions that must be revisited. Separate model costs, integration costs and controlled-operation costs. A low price per request says little about the total cost of a correctly processed case.

Procurement should ask for verifiable answers on permitted purpose, data, known limitations, version changes, logs, exit arrangements and incident assistance. Include business acceptance criteria and grounds for rejection. Avoid an abstract clause under which each party assumes the other owns “all compliance.”

For general-purpose models, Article 53 addresses documentation, information for downstream integrators, a copyright policy and a training-content summary. Specific open-source exemptions are limited; open source does not mean a general absence of obligations. Article 53.

7. A 90-day action plan

The following is Neopolis’s suggested working method, not a statutory deadline or a promise of compliance within three months. Its objective is to produce usable decisions and evidence.

DAYS 1–30

Make uses visible

Inventory purchased tools, internal systems and informal uses. Record owner, purpose, users, data, supplier and possible actions. Prioritize sensitive cases with legal, business, security and data-protection teams.

Output: initial inventory and decisions requiring escalation.

DAYS 31–60

Test the assumptions

Document roles and classification. Test representative cases and edge cases. Review contracts and interfaces. Prepare incident handling and train relevant teams with their own scenarios.

Output: evidence file and remediation plan.

DAYS 61–90

Decide and monitor

Authorize ready uses, constrain those requiring additional controls and suspend those with uncontrolled risks. Review important changes to models, data or intended purpose.

Output: recorded decisions and monitoring dashboard.

Useful indicators include the proportion of uses with an accountable owner, current classification records, material errors by case type, human rework time, open incidents and resolution time. Avoid a single “compliance score” that conceals critical gaps.

8. Common questions

Should an SME stop using AI assistants?

Size alone determines neither permission nor the applicable regime. Identify uses, data and decisions first. Targeted measures may allow useful uses to continue while priority gaps are addressed.

Does a European or open-source model make the project compliant?

Those choices may support architectural or technical-control goals. On their own, they do not resolve intended purpose, responsibility, individual rights or control of the final service.

Can we wait until 2027?

The regulation has several milestones. Distinguish existing obligations from future application dates, then check the transitional provisions that apply to your own situation.

How do we avoid creating a parallel bureaucracy?

Connect the AI inventory to existing procurement, security, privacy and release processes. Appoint a coordinating owner and ask for concrete evidence supporting each significant decision.

Make governance part of delivery

Our strategic assessment is that a company able to explain its uses, controls and limitations is better equipped to work with customers and evolve its services. That capability lives in products, contracts and everyday working practices. It requires business expertise as well as technology.

Neopolis can contribute to technical scoping, integration, testing and training in coordination with your legal and compliance teams. Explore our AI Enterprise approach or discuss your project.

This article was written with the help of artificial intelligence and reviewed by experts to strengthen its clarity, rigor and relevance for businesses.