Skip to content
Back to blog
· Ulysse Trin

EU AI Act: Mandatory in August 2026

The essentials in 5 points

  • The EU AI Act applies in full on 2 August 2026, the endpoint of a staggered rollout that began in 2024.
  • Deployers are covered, not only model providers: using an AI system in a business creates obligations.
  • The heart of the framework: classify systems by risk level, then document, govern, and ensure transparency.
  • AI literacy (Article 4) has been a legal obligation since February 2025: training your teams is not optional.
  • Penalties reach up to 35 M€ or 7 % of worldwide turnover for prohibited practices, with lower tiers for other breaches.

The short answer

2 August 2026 is not the AI Act’s entry into force, it is the date on which most of its obligations become fully applicable and enforceable. The regulation entered into force in 2024 with a phased calendar: prohibition of unacceptable uses in February 2025, obligations for general-purpose AI models in August 2025, then general application in August 2026.

The right question is not “am I an AI provider?” but “where and how does my organization use AI?”. Because the regulation also weighs on deployers, meaning professional users. Compliance comes in four stages: map the systems in use, classify them by risk level, document and govern the ones that require it, and train the teams. The rest of this article walks through each stage.

Deployers, not only providers

The most common mistake is to assume the AI Act only concerns companies that build models. The regulation distinguishes several roles, two of which touch almost every organization: the provider, who develops or places an AI system on the market, and the deployer, who uses it in a professional setting.

A firm automating contract analysis, an HR team screening applications with a scoring tool, a company embedding a conversational agent in its support: all are deployers. As such, they carry obligations of their own, particularly when they use a system classified as high-risk. The level of requirement does not depend on the size of the organization but on the use and the classification of the system.

The heart of the framework: classify by risk

The AI Act does not treat all AI the same way. It organizes obligations across four risk levels.

Unacceptable uses have been prohibited since February 2025: general-purpose social scoring, subliminal manipulation, certain forms of biometric recognition. A system that falls into this category is not brought into compliance, it is withdrawn.

High-risk systems concentrate most of the obligations that apply in August 2026: AI used in recruitment, access to credit, education, certain public services, or embedded in products that are already regulated. They require technical documentation, risk management, human oversight, logging, and control over data quality.

Limited-risk systems are mostly about transparency: informing people that they are interacting with an AI, flagging generated or manipulated content. Minimal-risk systems, finally, carry no specific obligation.

Without a prior map, it is impossible to know which category each system falls into. That is why the inventory is the very first step.

Documentation, governance, transparency

For the systems that require it, three families of obligations shape compliance.

Documentation means describing what the system does, which data it relies on, what its limits are, and how its performance is measured. It must be kept up to date and available to supervisory authorities.

Governance distributes responsibilities internally: who signs off on putting a system into production, who supervises its operation, who traces the decisions. Human oversight of high-risk systems is not an abstract principle, it requires identified people who are able to understand and interrupt the system.

Transparency applies toward the people concerned: they must know when they are interacting with an AI and when content has been artificially generated.

AI literacy, an obligation that fits well

Article 4 of the regulation requires providers and deployers to ensure a sufficient level of AI literacy among the people who design or use these systems. This provision has been in force since February 2025 and becomes fully enforceable in August 2026.

In other words, training your teams is no longer one good practice among others, it is an explicit requirement of the text. The expected competence is proportionate: it covers understanding the risks, limits, and correct use of the systems, not universal technical expertise.

Good news on the budget side: in France, a structured training program falls within the scope of the skills development plan and can be funded by an OPCO. The legal obligation and the funding line up, which often makes it the first concrete project to launch.

Penalties, with care

The regulation sets out tiered penalties, with caps that vary by the nature of the breach. Prohibited practices carry the highest amounts, up to 35 million euros or 7 percent of total worldwide annual turnover, whichever is higher. Other breaches of obligations fall under lower tiers, and transmitting incorrect information to authorities under a lower tier still. Actual amounts take into account the severity, the duration, and the size of the company. The stake is therefore not the theoretical maximum penalty but being able to demonstrate, in the event of a check, a documented compliance effort.

A four-step compliance plan

  1. Map. List every AI system in use or planned, including SaaS tools with AI built in. Without an inventory, no obligation can be correctly identified.
  2. Classify. Assign each system its risk level within the meaning of the regulation. This classification determines the intensity of the obligations.
  3. Document and govern. For high-risk systems, produce the documentation, define human oversight, organize logging and the roles that sign off.
  4. Train. Put in place the AI literacy required by Article 4, tailored to the profiles, drawing on OPCO funding.

For the broader compliance journey tailored to smaller organizations, see the EU AI Act SME guide.

Where to start

The first step is to take stock: which AI systems are used, by whom, for what, and which risk category they fall into. It is a few days’ exercise that produces a map and a prioritized action plan, without blocking ongoing use.

Colombani.ai supports this work through AI Act compliance consulting (system mapping, risk classification, documentation, and governance) and trains teams in the AI literacy the regulation requires with the AI Compliance course, Qualiopi-certified and eligible for OPCO funding. The expertise is certified by Anthropic (Claude Certified Architect).