Compliance
AI Act: what applies from 2 August 2026
The EU AI Act reaches its broadest milestone on 2 August 2026. What changes for an SME or a firm, and the checklist to run now, ahead of CNIL guidance.
Published July 14, 2026 · Updated July 23, 2026
The EU's AI Act entered into force on 1 August 2024, but it applies in stages. 2 August 2026 remains a major stage: most of the text becomes applicable, transparency and the penalty regime included. The heaviest part, the high-risk regime, has however just been pushed to 2027 and 2028 by the omnibus adopted in late June. For most French businesses, the August date is still the one after which "we'll deal with it later" stops being a viable compliance policy.
Here's what already applies, what's coming, and what an SME or a firm can do starting now.
The timeline, in five stages
- 2 February 2025: the ban on prohibited practices (manipulation, social scoring, certain forms of emotion recognition at work...) and the AI literacy obligation (Article 4): businesses must ensure staff using AI systems have a sufficient understanding of them.
- 2 August 2025: obligations for providers of general-purpose AI models.
- 2 August 2026: general application of the Act, the transparency obligations (Article 50) - telling users they're interacting with an AI, or labelling certain generated content - and the entry into operation of the supervision and penalty regime.
- 2 December 2027: the full regime for high-risk systems under Annex III (recruitment, scoring, essential services...), originally due in August 2026.
- 2 August 2028: high-risk systems embedded in products that are already regulated (Annex I).
This timeline reflects the postponement enacted in June 2026: the "digital omnibus" package voted by the European Parliament on 16 June, then given the Council's final green light on 29 June, pushes back the high-risk obligations. Everything else holds: AI literacy already applies, and transparency and penalties do arrive on 2 August 2026.
Are you affected? Almost certainly - but not the way you'd expect
The Act distinguishes providers of AI systems (those who develop them and place them on the market) from deployers (those who use them professionally). An SME, an accounting firm, a notarial office are almost always deployers.
The good news: most everyday business uses - drafting, summarising, preparing entries, searching your own files - don't fall under high risk. The obligations that will most surely affect you lie elsewhere:
- AI literacy (Article 4), already in force: your teams using AI need training on its limits, on checking its output, and on what data can or can't be fed into it.
- Transparency (Article 50), applicable in August: your clients shouldn't believe they're talking to a human when it's a machine, and certain generated content must be identifiable as such.
- Governance of high-risk uses, if you have any: AI-assisted recruitment, credit scoring, and certain HR uses fall under Annex III and trigger deployer obligations (using the system as documented, human oversight, keeping logs), now due by December 2027.
Penalties under the Act run up to 35 million euros or 7% of global turnover for prohibited practices, and 15 million or 3% for most other breaches, with amounts scaled for SMEs. The scale alone justifies half a day spent taking stock.
The real risk in 2026: the AI you don't see
For a business owner or a DSI, the issue isn't the agent you chose, contracted and governed. It's shadow AI: the personal ChatGPT accounts and similar tools where your teams are already pasting client data, with no framework, no trace, and no one having signed off on any of it. You cannot comply with any regulation on uses you don't know exist.
This is also where compliance and sovereignty meet: AI running on your own instance, in France, with an audit trail and access rules, makes compliance demonstrable. Consumer AI used on the sly mostly makes the data leak demonstrable.
The checklist, while waiting on the CNIL
The CNIL hasn't yet published overall guidance on generative AI in business. That's no reason to wait: everything below will hold up whatever the final doctrine says.
- Inventory actual use, including the unofficial kind: who uses what, on which data, with which account.
- Write a short usage policy: approved tools, prohibited data, mandatory human review before anything is sent or signed.
- Train your teams (this is Article 4, and it already applies): model limits, hallucinations, sensitive data.
- Qualify your AI vendors: where the models run, under which jurisdiction, whether your data trains the model, whether an audit trail exists, whether there's a reversibility clause.
- Classify your uses: Annex III cases (HR, scoring...) handled first, with documented human oversight. Their deadline has moved to December 2027; the classification itself takes half a day, today.
- Keep a trail: retain the ability to say who did what with AI, on which file, and when.
Six points, none of which need a consulting firm. The first pays off fastest: most businesses find, at the inventory stage, uses they would never have approved in writing.
What we take from this
AI compliance isn't paperwork bolted on afterwards: it's a property of the architecture. Agents that run on your own instance, cite their sources, log their actions, and whose permissions you govern are compliant with the spirit of the Act by construction - and ready for its letter. It's how we build: governance isn't a contract option, it's the product.