Insights

The Impact Of The AI Act On Your Business

AI is increasingly being used in marketing, customer service, HR, and product data. From August 2026 onwards, important provisions of the European AI Act will come into effect, introducing new obligations for organizations that develop and use AI. But what does this legislation mean for your business? And how can you ensure that you use AI safely, responsibly, and in compliance with the law? You’ll find out in this article!
Last modified on August 17, 2026 • 10 min read
Share article:
The Impact Of The AI Act On Your Business

 

Quick navigation:

 

In August 2026, key provisions of the AI Act will come into effect. Many organizations believe this legislation only applies to AI providers, but companies that use AI, known as AI deployers, must also comply with a range of obligations.

To meet these requirements, you should start with the foundation: your data. Reliable data, clear data governance, and effective data management are essential for using AI safely, transparently, and responsibly. Organizations with a strong data foundation not only comply with the AI Act more easily, but also gain greater value from their AI applications.

 

What Is The AI Act?  

The AI Act is the world’s first comprehensive AI legislation and provides the foundation for the responsible use of artificial intelligence within the European Union. Its objective is to encourage innovation, protect fundamental rights, increase transparency, and reduce risks. The AI Act applies not only to organizations that develop AI (providers), but also to companies that use AI (deployers) in areas such as marketing, HR, customer service, and product information.

AI Act: The 4 Risk Levels  

The AI Act follows a risk-based approach and distinguishes between four different risk levels for AI systems and AI practices. A single organization may use multiple AI applications that fall into different risk categories. The applicable obligations depend on both the specific AI application and the organization’s role (provider or deployer).

Risk Examples Consequences
Minimal risk Spam filters, AI games No obligations
Limited risk ChatGPT chatbots, AI-generated content Transparency obligations
High risk HR, credit assessment, medical applications Extensive compliance requirements
Unacceptable risk Social scoring, manipulative AI Prohibited

 

  • Minimal risk AI systems with minimal risk have little to no impact on the safety or rights of users. Examples include spam filters, AI in video games, and simple recommendation systems. These applications are not subject to any specific obligations under the AI Act.

  • Limited risk

    AI systems such as chatbots or AI that generates text and images must comply with transparency obligations. For example, people must be informed when they are interacting directly with an AI system. Providers of AI systems that generate audio, images, videos, or text must, in certain cases, ensure that this output is machine-readable and detectable as artificially generated or manipulated. When AI-generated content is reviewed, edited, and editorially approved by a human before publication, the same transparency obligations do not always apply.

  • High risk

    High-risk AI systems are used in applications such as recruitment and human resources management, creditworthiness assessments, medical devices, and emergency triage. Providers are subject to obligations relating to risk management, data and data governance, technical documentation, conformity assessment, and monitoring. Deployers have different obligations, including following the provider’s instructions for use, implementing appropriate human oversight, and monitoring the system’s use.

  • Unacceptable risk

    AI systems that pose an unacceptable risk threaten people’s safety or fundamental rights. Examples include social scoring and manipulative AI applications. These systems are prohibited within the European Union.

As a business, it is important to have a clear overview of all your AI practices and to understand which risk category each individual practice falls into, as well as how those risks are managed.

 

AI Act Compliance Timeline.  

  • August 2024 – AI Act enters into force

    The AI Act officially enters into force. From this point onward, the phased implementation of the European AI legislation begins.

  • February 2025 – Employees must have sufficient AI knowledge / AI training

    The first obligations become applicable. Prohibited AI practices are no longer allowed. In addition, providers and deployers must take measures to support the development of AI literacy among employees and other individuals working with AI systems on their behalf.

  • August 2025 – Rules apply to GPAI

    New rules come into effect for providers of General Purpose AI (GPAI), such as foundation models on which generative AI solutions are built. These providers must comply with additional requirements regarding transparency and documentation.

  • August 2026 – Transparency and enforcement

    From 2 August 2026 onwards, the transparency obligations set out in Article 50 of the AI Act become applicable. Supervision and enforcement also begin for the provisions that are already in force. The core obligations for high-risk AI systems will become applicable at a later stage.

  • December 2027 – Rules for high-risk applications

    From 2 December 2027 onwards, the core obligations for high-risk AI systems listed in Annex III become applicable. These include certain applications related to biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, and the administration of justice.

  • August 2028 – High-risk AI in regulated products

    From 2 August 2028 onwards, the core obligations apply to high-risk AI systems embedded in regulated products covered by the relevant product legislation listed in Annex I of the AI Act, including certain medical devices, machinery, and toys.

 

AI Content Transparency From August 2026  

Despite the postponement of certain parts of the AI Act, transparency remains a key priority. From August 2026 onwards, organizations are required to clearly identify AI-generated content, such as images, videos, and text, as AI-generated. This transparency obligation enables users to distinguish more easily between AI-generated content and content that has involved meaningful human input.

 

image

 

5 Steps to AI Act Compliance.  

To prepare effectively for the AI Act, it is important to look not only at your AI solutions but also at the processes and data behind them. These five steps provide a solid foundation:

1. Inventory all AI applications Identify where AI is being used within your organization. Think beyond ChatGPT and include Microsoft Copilot, AI features in CRM, HR, and PIM systems, marketing tools, customer service solutions, and any other software that incorporates AI.

2. Determine the risk level Assess which risk category each AI application falls under. Does it present minimal, limited, or high risk? Or does it involve an AI practice prohibited under the AI Act? This determines which obligations apply to your organization.

3. Get your data in order A reliable data foundation is essential for compliant AI. Invest in data quality, clear governance processes, ownership, metadata, and data lineage to ensure AI systems work with consistent, up-to-date, and traceable information.

4. Establish an AI policy Define how AI may be used within your organization. Determine which AI tools are permitted, what data may be entered into them, who is responsible for AI usage, and which controls are required to mitigate risks.

5. Invest in AI literacy Ensure employees have the knowledge and skills needed to use AI safely and responsibly. Since February 2025, the AI Act has required organizations to invest in AI literacy. Training and awareness not only help employees remain compliant but also enable them to use AI more effectively and securely. From Regulation to Implementation

The AI Act defines the obligations organizations have, but leaves much of the practical implementation to them. A mature Data & AI Governance approach helps bridge that gap. With a framework such as the C2PA model, you bring AI, data, processes, and governance together in one coherent approach. This creates not only a solid foundation for compliance, but also for the safe, responsible, and scalable use of AI within the organization.

 

Why Reliable Data Is More Important Than Ever.  

Despite what the name suggests, the AI Act is not only about artificial intelligence. A significant part of the legislation focuses on the quality of the data that AI systems are built on. Reliable data, transparency, traceability, documentation, governance, and human oversight form the foundation for responsible AI use. Poor or incomplete data can lead to unreliable AI outcomes and, where the AI Act sets specific requirements for data or data governance, increase the risk of non-compliance.

This is precisely why disciplines such as Master Data Management Master Data Management (MDM) , Product Information Management (PIM) and Data Governance play an important role. MDM ensures consistent and reliable master data across the organization, PIM manages and enriches product information for all sales channels, and Data Governance defines who is responsible for data, how it is managed, and how quality is monitored. Together, these processes ensure that AI systems have access to reliable, up-to-date, and well-managed data.

Poor data does not only result in unreliable AI outcomes but also increases the risk of non-compliance. When data is incomplete, outdated, or lacks traceability, it becomes more difficult to explain AI decisions, manage risks, or demonstrate compliance with the requirements of the AI Act.

Organizations that invest in a strong data foundation therefore not only comply with the AI Act more easily but also gain more value from their AI applications. Better data leads to better insights, more reliable AI results, and a solid foundation for deploying AI safely, responsibly, and at scale.

 

Frequently Asked Questions.  

The AI Act is the first comprehensive European legislation on artificial intelligence. The regulation introduces rules for the development and use of AI systems, with the aim of stimulating innovation while limiting risks to safety and fundamental rights.
In many cases, yes. The AI Act may apply to organizations that provide, use, import, or distribute AI systems within the EU. Which obligations actually apply depends, among other things, on the organization’s role, the type of AI system, and its intended use.
The AI Act entered into force on 1 August 2024 and is being applied in phases. Since 2 February 2025, prohibited AI practices and the obligation to implement AI literacy measures have applied. Since 2 August 2026, transparency obligations under Article 50 apply and enforcement has started for provisions that are already applicable. The core rules for high-risk AI systems will follow on 2 December 2027 and 2 August 2028, depending on the type of system.
AI literacy means that employees have sufficient knowledge and skills to use AI responsibly and safely. Since February 2025, organizations have been required to ensure that employees who work with AI receive appropriate information and training. AI literacy covers the skills, knowledge, and understanding required to use AI systems in an informed way and to understand their opportunities, risks, and potential harm.
AI is only as reliable as the data it is based on. Poor or incomplete data can result in incorrect AI outcomes, a lack of transparency, and an increased risk of non-compliance. A strong data foundation is therefore essential for complying with the AI Act.
Master Data Management (MDM), Product Information Management (PIM), and Data Governance help organizations make data reliable, consistent, and traceable. As a result, they form an important foundation for AI applications that comply with the requirements of the AI Act.
Organizations that fail to comply with the AI Act risk enforcement measures and significant fines. In addition, insufficient governance, poor data quality, and irresponsible AI use can lead to reputational damage, legal risks, and unreliable AI outcomes.

 

Is your organization prepared for the AI Act?  

Safe and reliable AI use starts with well-organized data and clear governance. Squadra helps organizations build a future-proof data foundation, enabling AI to be deployed safely, responsibly, and at scale.

Curious how your organization can prepare for AI Act compliance? Get in touch with us and discover where the biggest opportunities and risks lie for your business.

Interested in this topic?
Please leave your contact details so we can get in touch.
Share article:
Interested in this topic?
Please leave your contact details so we can get in touch.