AI Act compliance SMB AI governance regulation

The AI Act Deadline Just Passed: What Applies Now

Rodrigue Le Gall | | 8 min read

The EU AI Act is the European regulation governing the use of artificial intelligence, and its most consequential deadline for companies that use AI took effect yesterday, August 2, 2026. The question is no longer “what should we have done before the deadline” — we covered that back in May in our piece on the August 2026 deadline — but “what applies now, and what happens if we are not ready.” The honest answer fits in one sentence: you cannot become compliant over a weekend, but you can demonstrate a trajectory. Here is what actually changed, including for US and UK companies that assumed this was somebody else’s problem.

First: This Applies to You Even If You Are Not in Europe

The AI Act is extraterritorial. It applies to any organization that places an AI system on the EU market, or whose AI system’s output is used in the EU — regardless of where the company is headquartered. If you sell software to European customers, run an EU subsidiary, process EU users through an AI-powered feature, or serve European clients from a US or UK office, you are in scope.

The practical consequence is blunt: a Chicago or Manchester company with EU revenue is now subject to obligations it may never have reviewed. And your European customers will ask you for evidence long before any regulator does.

What Actually Applies Since Yesterday

Nothing turned into a fining machine at midnight. What changed is that obligations previously carried by model providers now extend to you, the company using AI — the “deployer” in the regulation’s vocabulary.

For the vast majority of businesses: three obligations, not ten

The most common case by far is the company that is neither a provider nor a deployer of a high-risk system: it uses ChatGPT, Copilot, Claude or Gemini for drafting, summarizing, support, sales prep. For that company, the real obligation comes down to three things:

  1. AI literacy (Art. 4): the people using AI must understand what they are handling. A documented half-day session is enough to demonstrate effort.
  2. Transparency: tell customers when they are interacting with an AI, and disclose AI-generated or substantially AI-modified content when you publish it.
  3. A usage register: who uses what, with what data, under whose responsibility. It is the one document that holds the first two together.

That is it. No technical file, no conformity assessment, no CE marking. If that is your profile, August 2 is far less brutal than the spring conference circuit suggested.

For the minority genuinely exposed

The regime changes entirely if your AI touches decisions about people: resume screening, applicant scoring, employee evaluation, biometrics. There the obligations are concrete and auditable — a named human overseer, retained usage logs, notification of affected individuals, and actual application of the provider’s instructions for use. Same story if you embed a model in a product you sell: you move to the provider side, technical documentation included.

The Gap Between the Text and the Reality of Enforcement

Somebody has to say it plainly: no national authority has the capacity to audit three million European businesses on August 3. The market surveillance authorities designated by member states are staffing up gradually, with limited headcount and priorities that go first to high-impact files.

That does not make the text decorative. It means the risk to a small or mid-sized business is not a random inspection. It is triggered.

What actually triggers scrutiny

  • A complaint. A rejected candidate, an employee evaluated by an opaque system, a customer contesting an automated decision, sometimes a competitor. This is trigger number one.
  • An incident. A data leak through an unregistered tool, an AI assistant hijacked via prompt injection, generated content published without review. Incidents attract attention, and attention travels up the chain to your framework — or to its absence.
  • A vendor questionnaire. Not a regulatory action, but the practical effect is identical: produce evidence, fast.

Real Pressure Comes From Customers and Insurers First

This is what leadership underestimates most. The regulator may show up someday. Your enterprise customers are showing up now.

Since early 2026, vendor due-diligence questionnaires from large accounts include an AI section: which tools, what data, who supervises, do you have a written policy, do you train your people. In a competitive bid, a blank answer is not a fine — it is elimination. Cyber insurers moved the same way: a vague answer gets priced in as a higher deductible, a coverage exclusion, or a higher premium.

Put differently: the most likely penalty for a small business in 2026 is commercial, not administrative. And it lands much faster.

Where Do You Actually Stand?

The table maps the situations we see most often against real exposure and the action to schedule for September.

Your situationReal exposureAction from September
Office use of AI (drafting, summarizing), no sensitive customer dataLow1-page policy, half-day AI literacy, usage register
Customer-facing chatbot or published generated contentLow to moderateVisible transparency notice, documented human review
Customer data or contracts pasted into AI toolsModerateVerify no-training clauses, update your processing records
You sell to enterprise accounts or the public sectorModerate to high, but commercialBuild a presentable evidence pack before the next RFP
AI used to screen resumes, score applicants, evaluate peopleHigh, regulatoryNamed human oversight, logs, notification of individuals
AI model embedded in a product you sellHigh, you are a providerTechnical documentation, marking, product conformity analysis

Three of six rows lead to actions that take days, not quarters. That is the field reality, and it is considerably less alarming than the prevailing noise.

If You Are Not Ready: Open a Dated File

You are behind, part of your team is out for the summer, and you will not recover six months of groundwork in three weeks. That is survivable, on one condition: do not stay documentarily silent. What protects a good-faith company is not perfect compliance, it is a demonstrable, dated trajectory.

Week 1 — Open the file

A compliance file, dated the day you open it, with a one-page memo: scope, named owner, planned timeline. That document is worth infinitely more than unwritten tacit compliance. It is what you will show a customer, an insurer, or an authority.

Weeks 2 to 4 — Map

An inventory of actual usage, including undeclared usage — that is usually where the real gaps hide, as we covered in our piece on Shadow AI. For each use: who, for what, with what data, at what risk level.

Weeks 4 to 6 — Prioritize the gaps

Not all gaps are equal. Handle what is externally visible first (customer transparency), then what is explicitly required in writing (AI literacy, register), then internal comfort items. At PIWA, we regularly see companies discover during mapping that they were already 80% compliant without knowing it, and that only the written trail was missing. The rest builds on the 10 AI governance guardrails.

Penalties, Without the Doom

The ceilings are real but badly read. Up to EUR 35 million or 7% of global annual turnover for prohibited practices, up to EUR 15 million or 3% for serious breaches, up to EUR 7.5 million or 1% for supplying incorrect information to authorities. At today’s rates that is roughly $38 million, $16 million and $8 million respectively. The frequently missed nuance: for SMEs and startups, the regulation specifies that the applicable amount is the lower of the two, and that proportionality must be considered. A good-faith documentation gap that gets corrected is nothing like a knowingly prohibited use.

Three Numbers to Remember

  • 3 real obligations for the large majority of small businesses: AI literacy, transparency, usage register. Not ten.
  • 4 to 6 weeks to build a credible trajectory file from zero, roughly $4,000 to $10,000 internally or with outside help.
  • The lower of the two amounts applies to SMEs in a penalty scenario — reading “7% of global turnover” onto a 20-person company misreads the text.

FAQ

The August 2, 2026 deadline passed and we have done nothing. Are we in breach?

Technically, if obligations apply to you and are unmet, you have a gap. Practically, nothing happens until there is a complaint, an incident, or a customer demanding evidence. What matters from here is being able to show that you started a dated compliance effort, with a named owner and a timeline. A good-faith company documenting its trajectory is in a very different position from one that has written nothing at all.

Does the AI Act apply to a US or UK company?

Yes, whenever you place an AI system on the EU market or the output of your AI system is used in the EU, regardless of where you are incorporated. Selling software to European customers, operating an EU entity, or serving EU end users through an AI feature all bring you into scope. In practice, the first party to ask you for evidence will not be a European regulator but a European customer running vendor due diligence. Treat it as a commercial requirement with a legal backstop, not the other way around.

Who actually enforces the AI Act?

Enforcement sits with national market surveillance authorities designated by each member state, coordinated at EU level by the Commission’s AI Office. These authorities do not run mass random inspections; they act on reports, on incidents, or in sectors deemed priority. For a small business, the odds of a spontaneous inspection in the coming months are low. The odds of an enterprise customer asking for proof are very high.

We only use ChatGPT and Copilot. What applies to us since August 2?

Three light obligations. First, AI literacy: your users must have received a minimum level of awareness training, and you must be able to evidence it. Second, transparency: if a customer interacts with an AI or receives generated content, they should be able to know it. Third, a usage register listing tools, purposes, data involved, and owners. Budget a few days of work, not a heavy compliance program.

How long does it take to catch up?

For a standard usage profile, plan four to six calendar weeks: one week to open the file and name an owner, two to three weeks to map actual usage, one to two weeks to close priority gaps and publish a policy. Real effort lands around five to ten person-days. That timeline fits comfortably into September and October, even with a team returning from summer break.

Next Step: Find Out Where You Actually Stand

The expensive part right now is not having a gap. It is not knowing which row of the table above you are in. A well-scoped AI audit answers that in days: inventory of actual usage, classification by risk level, gaps ranked by priority, and a dated file you can hand to a customer or an insurer.

Review your AI Act exposure — 30 minutes to place your business on the map, identify the two or three gaps that genuinely matter, and leave with a realistic plan for the fall.

Free checklist: 10 processes to automate with AI

Identify your company's automation potential in 2 minutes.

Download

The AI Brief — 3x per week

Essential AI news for business leaders. Free, no jargon.

Free, 3x per week. Unsubscribe in one click.

Take action

Ready to automate your repetitive tasks?

Discover what AI can realistically change in your business. In 2 hours, we identify your automation opportunities.

Free AI Checklist

10 processes to automate in your business

Download PDF