30.06.2026

EU AI Act 2026: What businesses need to do now

Artificial intelligence has long since become part of everyday business life. Whether it be chatbots, co-pilots, automated document processing or intelligent analytics, many companies are already using AI, often without realising that this gives rise to new legal obligations.

With the EU AI Act, Europe is establishing a binding legal framework for the use of AI for the first time. The regulation will come into force in stages. By 2026 at the latest, however, companies should carefully assess which AI systems they are using and what requirements they will face.

The AI Act affects almost every company

Many small and medium-sized enterprises assume that the AI Act only affects large technology providers. This is a misconception. Simply using AI systems within one’s own company may mean that legal requirements must be met. These include, for example:

  • AI-assisted recruitment
  • Chatbots in customer service
  • AI systems for risk or creditworthiness assessment
  • Automated document analysis
  • AI-assisted decision-making
  • In-house AI applications or customised language models
  • Providing accounts for their own staff to access existing AI models such as ChatGPT

Companies should therefore start by ensuring transparency and drawing up an inventory of all AI applications in use.

The key question is: Am I a user or a provider?

The AI Act distinguishes between different roles. Anyone who uses off-the-shelf solutions such as ChatGPT, Microsoft Copilot or other AI services within their organisation is generally regarded as a user (‘deployer’). Companies that develop their own AI solutions, significantly modify existing models or offer AI products on the market, on the other hand, may be classified as providers (“Provider”). Significantly more extensive obligations apply to these. Small and medium-sized enterprises in particular often underestimate the fact that customisations or in-house AI products can already constitute a provider role.

AI Competence is Mandatory

One of the first requirements (from February 2025) of the AI Act concerns so-called AI competence. Companies must ensure that staff working with AI systems have sufficient knowledge to use the systems safely, responsibly and in compliance with the law. This includes, in particular, knowledge of:

  • The opportunities and risks of AI
  • Data protection and information security
  • The limitations and risks of errors in AI systems
  • Handling sensitive company data
  • Recognising bias and incorrect decisions

Regular training and clear guidelines thus become a key component of corporate compliance.

Documentation and governance become a competitive advantage

For many companies, the greatest challenge lies not in the technology, but in governance. Anyone using AI should document the following in a transparent manner:

  • Which AI systems are being used
  • For which processes they are being used
  • What risks exist
  • What security measures have been implemented
  • Who is responsible

Particularly in regulated sectors and for public sector clients, robust AI governance is increasingly becoming a prerequisite for successful projects and tenders.

Why is the AI Act relevant right now?

From August 2026, further key provisions of the EU AI Act will come into force. So-called high-risk AI systems – that is, AI applications that may have a significant impact on people, safety or fundamental rights – are particularly affected. These include, amongst others, AI solutions in the fields of human resources, critical infrastructure, education, credit checks and certain applications in the healthcare sector. Companies that develop, distribute or deploy such systems will in future have to meet extensive requirements. These include, for example:

  • structured risk management,
  • comprehensive documentation and record-keeping requirements,
  • measures to ensure cyber security,
  • continuous monitoring of systems, and
  • clear lines of responsibility within the organisation.

Even though discussions are still ongoing at European level regarding the simplification of individual regulations, organisations should not wait for potential policy changes. It is already advisable to analyse one’s own AI landscape and assess which systems might fall under the stricter requirements in future.

For small and medium-sized enterprises in particular, this can be a decisive competitive advantage: those who ensure transparency at an early stage and establish appropriate governance and security measures not only minimise compliance risks but also strengthen the trust of customers, partners and clients.

What companies should do now

The AI Act is no reason to abandon AI. Rather, it creates a framework for its safe and trustworthy use. Companies should now take the following steps:

  1. Identify and assess existing AI applications.
  2. Define responsibilities for AI.
  3. Train and raise awareness amongst staff.
  4. Establish guidelines for the safe use of AI.
  5. Set up documentation and governance processes.
  6. Check whether their own solutions fall under the stricter requirements of the AI Act.

Conclusion

The EU AI Act makes the responsible use of AI mandatory. Whilst this entails additional work for businesses, early implementation also presents an opportunity to build trust with customers, partners and regulatory authorities.

Those who are already prioritising transparent processes, cybersecurity and AI governance will secure a decisive competitive advantage in the long term. 

If you have any questions about cybersecurity or the AI Act, please feel free to contact the aixzellent team at any time!

 

Tag-Filter

16.07.2026 - Data for Resilient Mobility [more...]

30.06.2026 - EU AI Act 2026: What businesses need to do now [more...]

30.04.2026 - The importance of a sovereign cloud [more...]

10.04.2026 - aixzellent with a new look [more...]

13.03.2026 - Digital sovereignty in Europe: Why now, and why with aixzellent? [more...]

11.08.2025 - Private clouds in companies [more...]

22.01.2025 - We are moving! [more...]

19.12.2024 - [more...]

20.04.2023 - Increase of Cyberattacks [more...]

25.05.2022 - Mastodon - Alternative to Twitter [more...]

Back