EU AI Act: Where do things stand now, and what should companies pay attention to?
- Katri Aarnio

- 3 days ago
- 5 min read
The EU AI Act has long been discussed as a piece of future regulation. By August 2026, however, the situation has changed. The EU AI Act has now been in force for two years, and a significant part of its obligations has already become applicable. The Act has also already been amended. Among other things, the AI Omnibus, which entered into force in July 2026, postponed the application dates of certain obligations concerning high-risk AI systems.
From a company perspective, the situation is twofold. Some obligations, such as the requirements concerning prohibited AI practices and transparency, already apply. By contrast, companies still have time to prepare for the most extensive obligations relating to high-risk AI systems. Nevertheless, companies should already map how they use AI, identify use cases that are specifically regulated, and ensure that their internal processes and contracts support compliance with the applicable requirements.
Which obligations under the AI Act already apply?
The first significant obligations under the AI Act became applicable in February 2025. These included, among other things, the provisions on prohibited AI practices. Obligations relating to AI literacy among personnel also began to apply. The AI literacy provision was eased in July 2026, but companies that provide or use AI systems are still required to take measures to support their personnel’s AI competence.
Since August 2025, providers of general-purpose AI models have been subject to specific obligations. This part of the regulation primarily concerns developers and providers of AI models. An ordinary company that, for example, purchases an AI tool available on the market or uses a ready-made third-party AI model as part of its own SaaS service will therefore generally not be directly subject to these obligations. The key is to identify the company’s own role in the AI value chain.
Another significant set of requirements became applicable at the beginning of August 2026: the AI Act’s transparency requirements. For example, in certain situations users must be informed that they are interacting with an AI system rather than a human. AI-generated or manipulated content is also subject to new requirements concerning its detectability and labelling.
When will the obligations concerning high-risk AI systems begin to apply?
One of the key areas covered by the AI Act concerns high-risk AI systems. These may include, for example, certain systems used in recruitment, employee evaluation, education, critical infrastructure or biometric identification.
However, the timetable for these systems has changed from the original schedule. The AI Omnibus, which entered into force in July 2026, postponed the application of the obligations concerning high-risk systems referred to in Annex III of the AI Act until 2 December 2027. For high-risk AI systems incorporated into regulated products, such as certain machinery and other physical products, the new deadline is 2 August 2028.
The additional time does not mean that companies should wait before starting preparations. Requirements imposed on providers of high-risk systems concern, among other things, risk management, documentation, data governance, logging, human oversight and conformity assessment. Deployers are also subject to obligations relating, for example, to following the instructions for use, ensuring human oversight, retaining logs in certain situations, monitoring the use of the system and reporting serious incidents. Companies should begin preparing these practical processes well in advance. Building processes afterwards is often significantly more difficult than taking the requirements into account already when developing a system or planning its deployment.
How should companies prepare for the AI Act in 2026?
A natural first step for every company is to determine where and how AI is being used within the organization. In many organizations, the use of AI has developed rapidly without any centralized overview. The marketing team may be using one tool, HR another, customer service may be testing an AI assistant, while at the same time a business unit is purchasing a new system with embedded AI functionality. From the perspective of the AI Act, these use cases may have very different implications.
In practice, one of the most common use cases encountered in companies relates to HR and recruitment. Particular care is needed here because AI used, for example, to assess or select job applicants or to evaluate employee performance may fall within the category of high-risk AI systems. A solution that appears to be an ordinary efficiency-enhancing HR tool may therefore create considerably broader obligations under the AI Act than the company initially expects. In addition to the requirements of the AI Act, other applicable legislation must naturally also be taken into account, including data protection and employment law requirements.
When mapping their use cases, companies should ensure that systems are used in accordance with their intended purpose. If a deployer makes a substantial modification to a system or changes its intended purpose so that the system becomes high-risk – for example, because it is unexpectedly repurposed for an HR use case – the deployer may be regarded as the provider of the system under the AI Act. An ordinary company using AI will generally not have the capabilities required to register the system, demonstrate conformity, maintain an extensive quality management system, or fulfill the other obligations of a high-risk system provider. These situations should therefore be identified and prevented in advance. Generally, for a high-risk use case, a company should procure a system that the provider has expressly intended for that purpose and appropriately registered as a high-risk AI system.
At this stage, companies should establish a sufficient overall understanding of the AI systems they currently use or plan to use, their intended purposes, and the company’s role in relation to each system. This mapping can be used to identify potentially prohibited use cases, transparency obligations and high-risk applications, as well as to ensure that contracts support regulatory compliance.
In contracts, particular attention should be paid to the availability of necessary documentation, permitted uses, the use of data, change management, and responsibility for regulatory changes and the related costs. Measures supporting personnel’s AI literacy, such as training and internal guidance, should also be proportionate to the identified use cases and their risk classifications.
The time for waiting is coming to an end
The AI Act continues to become applicable in stages, and companies do not need to resolve every issue at once. By August 2026, however, the regulation is no longer something waiting on the horizon: it is already part of today’s compliance requirements. The European Commission and national authorities have begun enforcing the applicable obligations, and the next major deadlines are already in sight.
Companies should therefore ensure now that their use of AI, internal processes and contractual arrangements provide a sufficiently solid foundation for both current and upcoming obligations.
We are happy to assist with questions relating to the application of the AI Act, the assessment and risk classification of AI system use cases, and contracts concerning AI.

Katri Aarnio
Counsel
+358 50 306 2031
To receive our articles directly in your inbox, subscribe to Folks’ newsletter here.



