Methodology · 3 MIN

EU AI Act 2026: what companies need to implement now

The EU AI Act has applied since August 2024 and is tightening in stages. What concretely lands on companies in 2026.

EU AI Act 2026: what companies need to implement now
LOCATION
Germany
AUTHOR
Aashwin Shrivastava
PUBLISHED
Jun 16, 2026
IMAGE
AI-GENERATED

This translation was produced automatically using AI. The German version is the editorially reviewed original.

The EU AI Act has been in force since 1 August 2024 and becomes applicable in stages. For most companies, the first task is not legal but organisational: an inventory of every AI application in use and its classification into a risk category. Only after that can you assess which obligations actually apply.

This piece places the risk-based approach in context, names the deadlines that count in 2026, and describes the first steps. It replaces no legal advice, but gives technical and organisational orientation.

01. The risk-based approach in four tiers

The AI Act does not regulate technology as such, but its use according to risk. It distinguishes four tiers.

  • Prohibited risk. Certain practices are banned, for example social scoring by public authorities. These bans have applied since February 2025.
  • High risk. Systems in sensitive areas such as personnel selection, credit lending, or critical infrastructure. Most obligations sit here.
  • Limited risk. Systems with a transparency obligation, for example chatbots, which must identify themselves as AI.
  • Minimal risk. The largest part of everyday applications, without special requirements.

The real work lies in honestly assigning your own applications to these tiers.

02. The deadlines that count in 2026

Applicability is staggered. The bans have applied since 2 February 2025, the obligations for general-purpose AI models since 2 August 2025. The date that matters for many companies is 2 August 2026, from which most obligations for high-risk systems take effect. For certain products with embedded AI, a longer deadline applies until 2 August 2027.

The official deadlines and texts can be found at the European AI Act overview. Anyone affected in 2026 should not start implementation only shortly before the deadline, because documentation and technical evidence need lead time.

03. What high-risk concretely means

If an application falls into the high-risk class, the AI Act requires, among other things, risk management, a traceable data basis, technical documentation, human oversight, and adequate accuracy along with logging. The common denominator of these requirements is traceability: a decision must be explainable and auditable.

For the architecture, a practical point follows from this. Systems whose processing takes place in-house and whose data flow is fully visible are easier to evidence than distributed calls to external services. Traceability is thus also an architecture topic, not only a legal one.

04. GDPR and the AI Act interlock

The AI Act does not replace the GDPR, it sits alongside it. Where an AI application processes personal data, both apply. In practice this is often an advantage, because many companies already know the GDPR structures, and the AI Act builds on comparable principles, such as purpose limitation, documentation, and data minimisation.

Especially for sensitive data, this strengthens the case for controlled operation. Which trade-off between local operation and the cloud makes sense is something we cover in On-premise vs. cloud LLM: when local AI is the right choice.

05. What companies should do now

The first steps are the same regardless of industry.

  1. Take inventory. Record all AI applications in use and planned, including ones bought in as part of third-party software.
  2. Classify. Assign each application to a risk tier and document the reasoning.
  3. Close the gaps. For high-risk applications, build up documentation, oversight, and logging.
  4. Clarify responsibility. Name a person who keeps the overview and tracks the deadline.

How this starting point fits into a larger plan is described in Introducing AI in the Mittelstand: a practical roadmap. Why control over the models you use matters here is covered in The Fable 5 lesson on sovereignty.

← Signals

Wayne Dyer

“If you change the way you look at things, the things you look at change.”