From 2 August 2026, the European framework for artificial intelligence applies across a much broader scope and competent authorities take a more active supervisory role. This does not mean that every use of a chatbot automatically becomes ‘high risk’. It does mean, however, that informal and unmapped AI use within an organisation is no longer sound management practice.

What applies today

The AI Act entered into force on 1 August 2024 and applies in stages. Prohibited practices and AI-literacy obligations have applied since February 2025, while governance rules and key obligations for general-purpose AI models followed in August 2025.

Most of the framework becomes applicable from August 2026, including transparency duties for certain forms of AI-generated content. Following changes introduced through the European AI Omnibus, some obligations for high-risk systems have later application dates. A broad statement that ‘the AI Act applies to everyone in the same way’ is therefore inadequate. The correct answer depends on the organisation's role, the system and the specific use case.

The first review is not legal. It is operational

Before determining which legal provision applies, the organisation needs a clear picture of actual use. Management often knows that ‘we use AI’ without knowing which employees use it, what data they enter, whether the output reaches a customer, or who reviews it.

A concise AI register can record the tool, provider, purpose, input data, responsible owner, human oversight and final audience. This mapping provides the basis for distinguishing low-risk support use from a process that materially affects people and decisions.

A practical six-point review

  1. Uses: which AI systems are used formally or informally, and in which teams.
  2. Role: whether the business develops, supplies, adapts or simply uses a third-party system.
  3. Data: whether personal, confidential, customer or otherwise protected data is entered.
  4. Human oversight: who checks accuracy and who carries final responsibility before an output is used.
  5. Transparency: whether the recipient must be told that they are interacting with AI or that specific content was artificially generated or altered.
  6. AI literacy: what practical guidance each team needs, based on the tool, role and risk of the use case.

What AI literacy means in practice

European guidance does not treat AI literacy as a one-off general seminar. Training should reflect users' knowledge, the context of use, the people who may be affected and the risks of the system.

For a small business, this may mean concise acceptable-use rules, examples of appropriate and inappropriate inputs, an output-review process and named responsibilities. A public or social-sector body may need a stricter distinction between support use, communication with citizens, and use that affects access to services or the assessment of individuals.

A realistic 30-day plan

  • Week 1: inventory tools and actual use cases.
  • Week 2: classify uses, data, owners and points of human oversight.
  • Week 3: prepare a concise AI-use policy and targeted team guidance.
  • Week 4: corrective actions, documentation and a scheduled review.

Official and selected sources

Links were reviewed on 27 August 2026. The official text always prevails for authoritative interpretation, together with appropriate professional advice where required.