The EU AI Act has long been discussed as a piece of future regulation. By August 2026, however, the situation has changed. The EU AI Act has now been in force for two years, and a significant part of its obligations has already become applicable. The Act has also already been amended. Among other things, the AI Omnibus, which entered into force in July 2026, postponed the application dates of certain obligations concerning high-risk AI systems.
From a company perspective, the situation is twofold. Some obligations, such as the requirements concerning prohibited AI practices and transparency, already apply. By contrast, companies still have time to prepare for the most extensive obligations relating to high-risk AI systems. Nevertheless, companies should already map how they use AI, identify use cases that are specifically regulated, and ensure that their internal processes and contracts support compliance with the applicable requirements.
Which obligations under the AI Act already apply?
The first significant obligations under the AI Act became applicable in February 2025. These included, among other things, the provisions on prohibited AI practices. Obligations relating to AI literacy among personnel also began to apply. The AI literacy provision was eased in July 2026, but companies that provide or use AI systems are still required to take measures to support their personnel’s AI competence.
Since August 2025, providers of general-purpose AI models have been subject to specific obligations. This part of the regulation primarily concerns developers and providers of AI models. An ordinary company that, for example, purchases an AI tool available on the market or uses a ready-made third-party AI model as part of its own SaaS service will therefore generally not be directly subject to these obligations. The key is to identify the company’s own role in the AI value chain.
Another significant set of requirements became applicable at the beginning of August 2026: the AI Act’s transparency requirements. For example, in certain situations users must be informed that they are interacting with an AI system rather than a human. AI-generated or manipulated content is also subject to new requirements concerning its detectability and labelling.
When will the obligations concerning high-risk AI systems begin to apply?
One of the key areas covered by the AI Act concerns high-risk AI systems. These may include, for example, certain systems used in recruitment, employee evaluation, education, critical infrastructure or biometric identification.
However, the timetable for these systems has changed from the original schedule. The AI Omnibus, which entered into force in July 2026, postponed the application of the obligations concerning high-risk systems referred to in Annex III of the AI Act until 2 December 2027. For high-risk AI systems incorporated into regulated products, such as certain machinery and other physical products, the new deadline is 2 August 2028.
The additional time does not mean that companies should wait before starting preparations. Requirements imposed on providers of high-risk systems concern, among other things, risk management, documentation, data governance, logging, human oversight and conformity assessment. Deployers are also subject to obligations relating, for example, to following the instructions for use, ensuring human oversight, retaining logs in certain situations, monitoring the use of the system and reporting serious incidents. Companies should begin preparing these practical processes well in advance. Building processes afterwards is often significantly more difficult than taking the requirements into account already when developing a system or planning its deployment.
How should companies prepare for the AI Act in 2026?
A natural first step for every company is to determine where and how AI is being used within the organization. In many organizations, the use of AI has developed rapidly without any centralized overview. The marketing team may be using one tool, HR another, customer service may be testing an AI assistant, while at the same time a business unit is purchasing a new system with embedded AI functionality. From the perspective of the AI Act, these use cases may have very different implications.
In practice, one of the most common use cases encountered in companies relates to HR and recruitment. Particular care is needed here because AI used, for example, to assess or select job applicants or to evaluate employee performance may fall within the category of high-risk AI systems. A solution that appears to be an ordinary efficiency-enhancing HR tool may therefore create considerably broader obligations under the AI Act than the company initially expects. In addition to the requirements of the AI Act, other applicable legislation must naturally also be taken into account, including data protection and employment law requirements.
When mapping their use cases, companies should ensure that systems are used in accordance with their intended purpose. If a deployer makes a substantial modification to a system or changes its intended purpose so that the system becomes high-risk – for example, because it is unexpectedly repurposed for an HR use case – the deployer may be regarded as the provider of the system under the AI Act. An ordinary company using AI will generally not have the capabilities required to register the system, demonstrate conformity, maintain an extensive quality management system, or fulfill the other obligations of a high-risk system provider. These situations should therefore be identified and prevented in advance. Generally, for a high-risk use case, a company should procure a system that the provider has expressly intended for that purpose and appropriately registered as a high-risk AI system.
At this stage, companies should establish a sufficient overall understanding of the AI systems they currently use or plan to use, their intended purposes, and the company’s role in relation to each system. This mapping can be used to identify potentially prohibited use cases, transparency obligations and high-risk applications, as well as to ensure that contracts support regulatory compliance.
In contracts, particular attention should be paid to the availability of necessary documentation, permitted uses, the use of data, change management, and responsibility for regulatory changes and the related costs. Measures supporting personnel’s AI literacy, such as training and internal guidance, should also be proportionate to the identified use cases and their risk classifications.
The time for waiting is coming to an end
The AI Act continues to become applicable in stages, and companies do not need to resolve every issue at once. By August 2026, however, the regulation is no longer something waiting on the horizon: it is already part of today’s compliance requirements. The European Commission and national authorities have begun enforcing the applicable obligations, and the next major deadlines are already in sight.
Companies should therefore ensure now that their use of AI, internal processes and contractual arrangements provide a sufficiently solid foundation for both current and upcoming obligations.
We are happy to assist with questions relating to the application of the AI Act, the assessment and risk classification of AI system use cases, and contracts concerning AI.

Katri Aarnio
Counsel
+358 50 306 2031
To receive our articles directly in your inbox, subscribe to Folks’ newsletter here.
Updated: Aug 5
Artificial intelligence has become part of everyday operations in many organisations. Some companies are already implementing a consistent AI strategy, while others are still at the beginning of their journey. The reality, however, is that many organisations already use AI extensively across different functions, either through tools selected by the company or through applications adopted independently by employees.
Many companies find themselves in a situation where they have not yet had time to establish a consistent policy for the use of AI. In some cases, guidance already exists, but it was drafted before the requirements of the EU AI Act became relevant. Now, at the latest, is the right time to ensure that the company’s AI practices and expertise are up to date. This is also critical for ensuring that personnel have the level of AI literacy required under the AI Act.
Why is an AI policy needed?
An AI policy is not merely a formality. It is a practical tool that enables a company to use AI responsibly and safely. At the same time, it helps the organisation respond to new regulatory requirements and creates the conditions for effective innovation.
Ensuring AI literacy: First, an AI policy supports the obligation to ensure an adequate level of AI literacy under the AI Act. Since February 2025, every organisation using AI has been required, to the best of its ability, to ensure that its personnel have a sufficient understanding of the risks, opportunities and potential harm associated with AI. A well-drafted AI policy is a key part of meeting this organisational and training obligation. The European Commission has also indicated that fines and other penalties may be more likely in cases where an organisation has failed to comply with the AI literacy obligation.
Encouraging responsible use: Clear rules encourage employees to use AI. When employees understand what is permitted and what is not, the use of AI can develop from cautious experimentation into systematic business improvement. A clear policy creates a sense of security that encourages employees to explore new ways of making their work more efficient without fearing that the use of AI could inadvertently breach contractual or regulatory obligations or cause other risks to materialise. In this way, an AI policy serves not only as a risk management tool but also as a tool for innovation.
Managing hidden use: An AI policy helps an organisation identify and manage undisclosed use and shadow AI. In many organisations, AI tools have been introduced through applications selected independently by employees. Where the use of AI is not identified, the related risks cannot be managed either. A policy makes the use of AI visible and enables the organisation to provide guidance on tools that employees adopt independently without separate approval. A complete ban on AI may not necessarily reduce risks. On the contrary, it may make it more difficult to provide employees with practical guidance on appropriate ways of working.
Protecting trade secrets and personal data: One of the most important functions of an AI policy is to establish clear boundaries for the use of trade secrets and personal data in connection with AI. When an employee enters customer data, internal plans or personal data into an AI tool, the information may spread beyond the organisation’s control. The policy should establish practical rules on what information may be used, under what conditions and in which environments. In this way, it protects the interests of both the company and its stakeholders.
Implementing the requirements of the AI Act: An AI policy helps an organisation put into practice the operating models and restrictions required under AI regulation. The AI Act imposes obligations particularly in relation to high-risk use cases, including requirements concerning data governance, the retention of logs, and the monitoring and oversight of use. Merely being aware of these obligations is not enough. They must be implemented in a way that makes them visible in day-to-day processes and decision-making. The policy acts as a bridge between legal requirements and practical work.
Building trust among stakeholders: An AI policy also sends a message to external stakeholders. When a company can demonstrate that it uses AI in a considered and responsible manner, it builds trust among customers, business partners and authorities. Trust, in turn, strengthens the company’s reputation and distinguishes it positively from its competitors. An AI policy therefore serves simultaneously as a risk management tool, a training instrument and a strategic statement of responsible business conduct.
AI policy is an investment in a sustainable future
The use of AI introduces new types of risk, but it also creates enormous opportunities. A clear AI policy helps turn AI into a genuine business strength by enabling new forms of innovation while ensuring that the associated risks are managed appropriately.
Whether AI is already an essential part of the company’s daily operations or still at the experimental stage, now is the right time to ensure that internal guidance and training are up to date.

Katri Aarnio
Counsel
050 306 2031
To receive our articles directly by email, subscribe to the Folks newsletter here.
The Regulation on the transparency and targeting of political advertising (TTPA) will apply for the most part from 10 October 2025. Its purpose is to ensure that political advertising is carried out in a way that enables citizens to understand who is seeking to influence their political views, by what means and with what resources. The European Media Freedom Act (EMFA), in turn, seeks to increase transparency in advertising by public authorities and other public-sector entities. The European Media Freedom Act became applicable on 8 August 2025.
In this article, we examine the principal obligations under the new legislation, particularly from the perspective of advertising publishers, such as media companies, and advertising service providers, such as advertising agencies.
Main obligations for publishers and advertising service providers
The Regulation on the transparency and targeting of political advertising defines political advertising broadly. It covers not only advertising paid for by political parties and candidates, but also other advertising intended to influence the outcome of an election or referendum, voting behaviour, or a legislative or regulatory process. The media sector has sought to preserve the current position to a large extent by ensuring that editorial content and advertising concerning social and political issues are clearly excluded from the scope of the Regulation and from regulatory supervision.
Two categories of operators have a particularly important role in ensuring transparency in political advertising: publishers of political advertising and political advertising service providers. A publisher of political advertising is an operator that provides the space, platform or channel through which a political advertisement is made available to the public, such as a media company. A political advertising service provider, in turn, is an operator that designs, produces or otherwise facilitates political advertising, such as an advertising agency or a digital advertising technology company.
The obligations of service providers relate particularly to the design, financing and targeting of political advertising. The Regulation requires service providers to document all material information concerning the organisation of a campaign. This includes sources of funding, the objectives of the advertising, the definition of target groups and the technical solutions used for targeting. The service provider must provide this information to the publisher so that the advertisement can be approved in accordance with the Regulation.
Publishers have responsibilities at several levels. They must ensure that every political advertisement includes the transparency label required by the Regulation. The advertisement must clearly and immediately identify its sponsor, the nature and duration of the campaign, and any targeting techniques used. It must also clearly indicate where a more detailed transparency notice is available. The advertisement may direct users to the transparency notice through a link or QR code, for example.
To make publication of the transparency label and transparency notice possible, both publishers and political advertising service providers must use contractual arrangements to ensure that advertisers provide them with accurate information concerning matters such as the sponsors of the political advertisement and their background, as well as the election, referendum, legislative process or regulatory process to which the advertisement relates. In addition, publishers and service providers must maintain records of matters including the amounts received from each party in connection with political advertising.
Publishers and service providers must retain this information for at least seven years after the end of the campaign so that the authorities can subsequently review and assess compliance with the Regulation. Publishers must also report all political advertisements published online, together with the information required in the transparency notice, to the European repository. In addition, they must include in their management reports campaign-specific information on the amounts or other benefits received in full or partial consideration for the services provided, including the use of targeting and advertisement-delivery techniques.
Targeting of political advertising
A significant part of the new Regulation concerns the targeting of advertising. The Regulation prohibits the targeting of political advertising on the basis of sensitive personal data, meaning special categories of personal data under the General Data Protection Regulation, such as political opinions, religious beliefs or ethnic origin. Where other categories of personal data, such as age, gender or geographical location, are used for targeting, the targeting is permitted only if the personal data has been collected directly from the data subject and the data subject has given explicit consent to the processing of their personal data specifically for political advertising.
The targeting of political advertising requires controllers to maintain more extensive documentation than under the GDPR alone. Among other things, the controller must carry out an annual risk assessment and adopt, implement and make publicly available internal policies describing how advertising-targeting techniques are used. The controller must also keep records of the use of those techniques and the mechanisms and parameters involved. Additional information must be provided in connection with the transparency label for each targeted advertisement to enable individuals to understand the logic and principal parameters of the techniques used. The new obligations will require digital advertising operators to develop new processes and technical solutions for managing the logic of targeting and ensuring its traceability.
Advertising by public authorities and public-sector entities
Under the European Media Freedom Act, public authorities and public-sector entities must make information on their annual public expenditure on state advertising publicly available in an electronic and user-friendly format. The definition of a public authority or public-sector entity can be considered to include central government administrative authorities, government agencies and institutions, state enterprises and off-budget state funds. It also covers state-owned companies in which the government exercises decisive control. Based on the wording of the legislation, the definition would also include cities and municipalities, including joint municipal authorities, wellbeing services counties and joint county authorities, as well as their subsidiaries and public enterprises. It would further include entities owned by municipalities or wellbeing services counties in which one or more municipalities or wellbeing services counties exercise decisive control.
These categories encompass dozens of different operators. Media companies therefore face the challenge of identifying all entities falling within the scope of the legislation so that they can inform users of their online services of the total annual amounts of public funds received for state advertising and the total annual advertising revenue received from authorities or public-sector entities in third countries. In addition to publishing this information on their own websites, media companies must report it to Traficom’s media service ownership database.
In Finland, information on state advertising is intended to be collected in the procurement data repository maintained by the State Treasury by using purchase invoice data from public authorities and public-sector entities. Information on state advertising, such as the amount of advertising purchased by each public authority or other public-sector entity from each service provider, would therefore be openly and publicly available through the repository. Once the repository is in place, individual authorities and other public-sector entities would not need to publish information on their advertising and public-notice expenditure themselves. At the same time, media companies would be able to verify more easily whether an advertiser qualifies as a public authority or public-sector entity under the European Media Freedom Act.
Conclusion
Although the objectives of strengthening democracy and increasing transparency in advertising are highly commendable, the media sector, among others, has taken a critical view of the new legislation. One concern is that publishing election advertising or state advertising may no longer be commercially viable for media companies because of the extensive disclosure obligations, heavy administrative burden and risk of sanctions. Should this happen, the legislation could have unforeseen consequences for the visibility of elections, electoral participation and the functioning of democracy, as well as for the operating conditions of advertising-funded media.
Because of the new obligations, global digital platforms such as Google and Meta have already announced that they will not participate in political advertising at all. Xandr and Microsoft had withdrawn from the market earlier. It remains to be seen whether election advertising will move from these platforms to domestic media, or whether voters will increasingly receive election-related information, misinformation, disinformation and advertising through platforms such as TikTok or X, even though those platforms have formally prohibited election advertising. According to a study by Faktabaari and CheckFirst, TikTok recommended misogynistic content and reinforced stereotypes in Finland in the run-up to the 2024 European Parliament elections. X has also been alleged to have used data concerning political opinions or religious beliefs for the microtargeting of political advertising. These platforms have therefore been alleged to exhibit precisely the kinds of problems that the new Regulation is intended to address. The transfer of political display advertising to domestic media is complicated by the fact that many Finnish publishers use advertising management systems provided by Microsoft or Google. In addition, current cookie consent mechanisms based on IAB Europe’s Transparency and Consent Framework (TCF) do not support the collection of the explicit consent required under the Regulation. What is clear is that the decisions made by global digital platforms, and regulation primarily intended to address problems arising on those platforms, will also have significant consequences for domestic media.
At Folks, we are happy to assist not only in navigating the complexities of the new legislation, but also in identifying the opportunities it may create.

Anna Paimela
Partner
+358 40 1648626
To receive our articles directly by email, subscribe to the Folks newsletter here.
