- The new legislation outlines what organisations can and can’t do when it comes to AI systems.
- An AI system is a machine-based system that is designed to operate with varying levels of autonomy.
- It applies to public and private companies inside and outside of the EU. Confirm whether you should be following the rules by filling out the EU AI Act Compliance Checker.
- If you haven’t already, establish how much the rules apply to you and get your governance in line.
As of August 2, 2026, the EU AI Act has come into law. The new legislation outlines what organisations can and can’t do when it comes to AI systems.
What is an AI system?
An AI system is a machine-based system that is designed to operate with varying levels of autonomy. From the input it receives it can generate outputs such as predictions, content recommendations or decisions that have the potential to influence physical or virtual environments.
You’ll see mentions of ‘downstream providers’ in the Act. These are the providers of an AI system – including a general-purpose AI (GPAI) system – which integrates an AI model, whether it was provided by themselves or a third-party.
Who does it apply to?
It applies to public and private companies inside and outside of the EU. Confirm whether you should be following the rules by filling out the EU AI Act Compliance Checker.
What rules do I need to know?
The following types of AI system are prohibited:
- Deploying subliminal, manipulative or deceptive techniques to distort behaviour and impair decision-making, ‘causing significant harm’
- Exploiting vulnerabilities based on age, disability or socioeconomic circumstances to distort behaviour, again, causing significant harm
- Biometric categorisation systems inferring sensitive attributes (race, political opinions, trade union membership, religious or philosophical beliefs, sex life, or sexual orientation), except filtering or labelling of lawfully acquired biometric datasets or when law enforcement categorises biometric data
- Social scoring, in other words, evaluating or classifying individuals based on social behaviour or personality traits, causing detrimental or unfavourable treatment of these people
- Assessing the risk of someone committing criminal offences solely based on profile or personality traits, except when used to augment human assessments based on objective, verifiable facts directly linked to criminal activity
- Compiling facial recognition databases by untargeted scraping of facial images from the internet or CCTV
- Inferring emotions in workplaces or educational institutions except for medical and safety reasons
- Real-time biometric identification in publicly accessible spaces for law enforcement
High risk providers need to:
- Establish a risk management system throughout the high-risk AI system’s lifecycle
- Conduct data governance
- Draw up technical documentation to approve compliance and provide authorities with the means to approve that compliance
- Design their high-risk system for automatic record-keeping
- Provide instructions for use for ‘downstream deployers’
- Design high-risk systems to allow human oversight, while achieving robustness, accuracy and cybersecurity
- Establish quality management systems to ensure compliance
General Purpose AI is more likely to apply to a broader range of organisations. It covers AI models, including those trained on large datasets and are autonomous at scale. Note that it doesn’t cover AI models that are used before release on the market for research, development and prototyping activities.
A GPAI system refers to an AI system which is based on a general purpose AI model that can serve a variety of purposes for direct use and for integrations with other AI systems.
All providers of GPAI models must:
- Create technical documentation, including training and testing process and evaluation results
- Compile information and documents to give to downstream providers that want to integrate the GPAI model into their own AI system so that they understand what can and can’t do as well as being able to comply
- Establish a policy to respect the Copyright Directive
- Publish a detailed summary about the content used for training the GPAI model
What about Article 50?
The key target here is imagery and text that looks authentic but isn’t:
- Artificially generated images, audio and text designed to look authentic must be labelled
- Customers must know that they are interacting with chatbots or viewing images or text manipulated by AI.
- Media must have a machine-readable watermark to show origins of content (due to an omnibus, existing AI systems have until December 2, 2026 to meet this requirement)
- Texts on matters of public interest must be labelled as AI if there hasn’t been any human editorial oversight
- Should be labelling existing content as AI, but this is not compulsory
Fines of up to €15 million (£12.8 million) or 3% of the company’s global turnover will be imposed for breaches, whichever is greater.
How will the AI Act be implemented?
To enforce the Act, the European AI Office will be monitoring the implementation and compliance of GPAI model providers.
Downstream providers can file a complaint about infringement by upstream providers to the European AI Office.
The Office may do inspections of a GPAI model to:
- Judge whether compliance is being met where the information gathered under its powers to request information isn’t enough
- Investigate systemic risks, particularly following a qualified report from the scientific panel of independent experts
What can I do about this?
Industry experts weigh in on what your organisation should be doing as a matter of urgency.
Tech firms
Peter Van Dyck, partner at A&O Shearman, has commented on the impact these rules will have on Big Tech and how they will be enforced in practice:
“Big Tech firms will need to adapt how they operate if they want to continue to do business in Europe. Due to the EU AI Act’s substantial extraterritorial reach, any lab with European customers now needs to be aware that if its model’s outputs reach EU users, it’s considered in scope. The most immediate obligation requirement is that all AI-generated content – synthetic text, images, audio, and video – is labelled as such.”
Get your governance in line now
Ivana Bartoletti, global chief privacy & AI governance officer at Wipro, said:
“As the EU AI Act’s core transparency obligations take effect this week, organisations should stop treating this as paperwork and start treating it as design. Map the AI systems and content workflows you provide or use, build clear disclosures for deepfakes, machine-readable marking where required, and review processes with real accountability behind them.
“Governance by design is what makes innovation scalable, defensible and sustainable.”
Establish how much the rules apply to you
Mark Molyneux, field CTO of Northern Europe at Commvault, said:
“Following Sunday’s ruling, companies with their own AI projects or those using external AI services should now assess to what extent the AI rules apply to them from a governance perspective and how they should rethink their existing concepts. For IT leaders and CISOs, the task is clear: they need to evolve their security model as quickly as AI adoption advances in their environment.
“A few immutable truths apply. Every AI agent should be treated as a privileged digital identity. Companies should continuously review what an AI agent can access instead of relying on assumptions. Anyone preparing for AI governance needs trusted data and a resilient AI infrastructure. Trust in AI must be continuously verified. Resilience is just as important in enabling rapid recovery, even when the best security controls are bypassed.”
This article was originally published on our sister site, Information Age.
Read more
How to handle Data (Use and Access) Act rules – In June 2026, new rules were introduced under the Data (Use and Access) Act. Becky White explains how to handle data complaints from now on
Buy Now, Pay Later regulation is changing. Is your checkout ready? New Buy Now Pay Later (BNPL) rules are being introduced for lenders from July 2026, but they affect merchants, too
Health and safety for business – How to prevent accidents – For businesses, the creation of an up-to-date health and safety policy can be the difference between damaging litigation and a solid safety net

