Insights
The Impact Of The AI Act On Your Business

Quick navigation:
- What Is the AI Act?
- AI Act Compliance Timeline
- 5 Steps to AI Act Compliance
- Why Reliable Data Is More Important Than Ever
- Frequently Asked Questions
In August 2026, key provisions of the AI Act will come into effect. Many organizations believe this legislation only applies to AI providers, but companies that use AI, known as AI deployers, must also comply with a range of obligations.
To meet these requirements, you should start with the foundation: your data. Reliable data, clear data governance, and effective data management are essential for using AI safely, transparently, and responsibly. Organizations with a strong data foundation not only comply with the AI Act more easily, but also gain greater value from their AI applications.
What Is The AI Act?
The AI Act is the world’s first comprehensive AI legislation and provides the foundation for the responsible use of artificial intelligence within the European Union. Its objective is to encourage innovation, protect fundamental rights, increase transparency, and reduce risks. The AI Act applies not only to organizations that develop AI (providers), but also to companies that use AI (deployers) in areas such as marketing, HR, customer service, and product information.
AI Act: The 4 Risk Levels
The AI Act follows a risk-based approach and distinguishes between four different risk levels for AI systems and AI practices. A single organization may use multiple AI applications that fall into different risk categories. The applicable obligations depend on both the specific AI application and the organization’s role (provider or deployer).
| Risk | Examples | Consequences |
|---|---|---|
| Minimal risk | Spam filters, AI games | No obligations |
| Limited risk | ChatGPT chatbots, AI-generated content | Transparency obligations |
| High risk | HR, credit assessment, medical applications | Extensive compliance requirements |
| Unacceptable risk | Social scoring, manipulative AI | Prohibited |
-
Minimal risk AI systems with minimal risk have little to no impact on the safety or rights of users. Examples include spam filters, AI in video games, and simple recommendation systems. These applications are not subject to any specific obligations under the AI Act.
-
Limited risk
AI systems such as chatbots or AI that generates text and images must comply with transparency obligations. For example, people must be informed when they are interacting directly with an AI system. Providers of AI systems that generate audio, images, videos, or text must, in certain cases, ensure that this output is machine-readable and detectable as artificially generated or manipulated. When AI-generated content is reviewed, edited, and editorially approved by a human before publication, the same transparency obligations do not always apply.
-
High risk
High-risk AI systems are used in applications such as recruitment and human resources management, creditworthiness assessments, medical devices, and emergency triage. Providers are subject to obligations relating to risk management, data and data governance, technical documentation, conformity assessment, and monitoring. Deployers have different obligations, including following the provider’s instructions for use, implementing appropriate human oversight, and monitoring the system’s use.
-
Unacceptable risk
AI systems that pose an unacceptable risk threaten people’s safety or fundamental rights. Examples include social scoring and manipulative AI applications. These systems are prohibited within the European Union.
As a business, it is important to have a clear overview of all your AI practices and to understand which risk category each individual practice falls into, as well as how those risks are managed.
AI Act Compliance Timeline.
-
August 2024 – AI Act enters into force
The AI Act officially enters into force. From this point onward, the phased implementation of the European AI legislation begins.
-
February 2025 – Employees must have sufficient AI knowledge / AI training
The first obligations become applicable. Prohibited AI practices are no longer allowed. In addition, providers and deployers must take measures to support the development of AI literacy among employees and other individuals working with AI systems on their behalf.
-
August 2025 – Rules apply to GPAI
New rules come into effect for providers of General Purpose AI (GPAI), such as foundation models on which generative AI solutions are built. These providers must comply with additional requirements regarding transparency and documentation.
-
August 2026 – Transparency and enforcement
From 2 August 2026 onwards, the transparency obligations set out in Article 50 of the AI Act become applicable. Supervision and enforcement also begin for the provisions that are already in force. The core obligations for high-risk AI systems will become applicable at a later stage.
-
December 2027 – Rules for high-risk applications
From 2 December 2027 onwards, the core obligations for high-risk AI systems listed in Annex III become applicable. These include certain applications related to biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, and the administration of justice.
-
August 2028 – High-risk AI in regulated products
From 2 August 2028 onwards, the core obligations apply to high-risk AI systems embedded in regulated products covered by the relevant product legislation listed in Annex I of the AI Act, including certain medical devices, machinery, and toys.
AI Content Transparency From August 2026
Despite the postponement of certain parts of the AI Act, transparency remains a key priority. From August 2026 onwards, organizations are required to clearly identify AI-generated content, such as images, videos, and text, as AI-generated. This transparency obligation enables users to distinguish more easily between AI-generated content and content that has involved meaningful human input.
5 Steps to AI Act Compliance.
To prepare effectively for the AI Act, it is important to look not only at your AI solutions but also at the processes and data behind them. These five steps provide a solid foundation:
1. Inventory all AI applications Identify where AI is being used within your organization. Think beyond ChatGPT and include Microsoft Copilot, AI features in CRM, HR, and PIM systems, marketing tools, customer service solutions, and any other software that incorporates AI.
2. Determine the risk level Assess which risk category each AI application falls under. Does it present minimal, limited, or high risk? Or does it involve an AI practice prohibited under the AI Act? This determines which obligations apply to your organization.
3. Get your data in order A reliable data foundation is essential for compliant AI. Invest in data quality, clear governance processes, ownership, metadata, and data lineage to ensure AI systems work with consistent, up-to-date, and traceable information.
4. Establish an AI policy Define how AI may be used within your organization. Determine which AI tools are permitted, what data may be entered into them, who is responsible for AI usage, and which controls are required to mitigate risks.
5. Invest in AI literacy Ensure employees have the knowledge and skills needed to use AI safely and responsibly. Since February 2025, the AI Act has required organizations to invest in AI literacy. Training and awareness not only help employees remain compliant but also enable them to use AI more effectively and securely. From Regulation to Implementation
The AI Act defines the obligations organizations have, but leaves much of the practical implementation to them. A mature Data & AI Governance approach helps bridge that gap. With a framework such as the C2PA model, you bring AI, data, processes, and governance together in one coherent approach. This creates not only a solid foundation for compliance, but also for the safe, responsible, and scalable use of AI within the organization.
Why Reliable Data Is More Important Than Ever.
Despite what the name suggests, the AI Act is not only about artificial intelligence. A significant part of the legislation focuses on the quality of the data that AI systems are built on. Reliable data, transparency, traceability, documentation, governance, and human oversight form the foundation for responsible AI use. Poor or incomplete data can lead to unreliable AI outcomes and, where the AI Act sets specific requirements for data or data governance, increase the risk of non-compliance.
This is precisely why disciplines such as Master Data Management Master Data Management (MDM) , Product Information Management (PIM) and Data Governance play an important role. MDM ensures consistent and reliable master data across the organization, PIM manages and enriches product information for all sales channels, and Data Governance defines who is responsible for data, how it is managed, and how quality is monitored. Together, these processes ensure that AI systems have access to reliable, up-to-date, and well-managed data.
Poor data does not only result in unreliable AI outcomes but also increases the risk of non-compliance. When data is incomplete, outdated, or lacks traceability, it becomes more difficult to explain AI decisions, manage risks, or demonstrate compliance with the requirements of the AI Act.
Organizations that invest in a strong data foundation therefore not only comply with the AI Act more easily but also gain more value from their AI applications. Better data leads to better insights, more reliable AI results, and a solid foundation for deploying AI safely, responsibly, and at scale.
Frequently Asked Questions.
Is your organization prepared for the AI Act?
Safe and reliable AI use starts with well-organized data and clear governance. Squadra helps organizations build a future-proof data foundation, enabling AI to be deployed safely, responsibly, and at scale.
Curious how your organization can prepare for AI Act compliance? Get in touch with us and discover where the biggest opportunities and risks lie for your business.
