EU AI Act: what changes for businesses
The key obligations of the European regulation and how to prepare now.
The European AI Act came into full force in 2026 after a phased transition period. For many businesses, the obligations remain unclear. Here are the essential points and priority actions to take.
The regulation takes a risk-based approach. Prohibited AI systems (subliminal manipulation, social scoring) are ruled out immediately. High-risk systems — AI in recruitment, credit, security, healthcare, critical infrastructure — face the heaviest obligations. Limited or minimal risk applications benefit from lighter requirements.
For high-risk systems, obligations cover six areas: complete technical documentation, training data traceability, human oversight, robustness and accuracy, risk management, and transparency toward users. These systems must be registered in the EU AI Act database before deployment.
Sanctions are dissuasive. A prohibited system infringement can reach €35 million or 7% of global turnover. For a non-compliant high-risk system: up to €15 million or 3% of turnover. National data protection authorities (such as France's CNIL) are the enforcement bodies.
First audit procedures were launched in early 2026 across several member states. They target primarily AI systems in HR, credit and surveillance sectors. Companies that have not yet mapped their AI systems are in a weak position.
Three immediate actions: (1) map all your AI systems in production and in project, (2) assess their risk level according to the AI Act taxonomy, (3) appoint an AI Officer (an emerging role, comparable to the GDPR DPO) to drive compliance.
The AI Act is not only a constraint. It is also a competitive advantage for companies that comply proactively: their AI systems carry an implicit trust label, easily valued with clients, partners and investors. Compliance is the new differentiator.
A reassuring point for most businesses: the majority of your AI uses fall under limited or minimal risk, not high risk. An internal writing assistant, a product recommendation tool or a support chatbot do not trigger the heavy obligations. The immediate stake is therefore less about documenting everything than about correctly classifying each system — and spotting the rare genuinely high-risk uses (HR, credit, biometrics, security) that do require serious preparation.
Transparency is the most cross-cutting and simplest obligation to implement: clearly informing people that they are interacting with an AI, and flagging AI-generated or manipulated content. Many companies can handle this in a few weeks, sending a signal of seriousness to their clients and partners well before enforcement deadlines.
Key takeaways
- Most of your uses fall under limited or minimal risk — the key is to classify them correctly.
- Three priority actions: map your AI systems, assess their risk level, appoint an AI officer.
- Proactive compliance is a commercial advantage, not just a constraint.
Your AI Act compliance plan in 3 steps
- 1
Map
Inventory all your AI systems in production and in project — the inventory is the prerequisite for everything else.
- 2
Assess risk
Classify each system by the AI Act taxonomy (prohibited, high, limited, minimal) and focus effort on high risk.
- 3
Appoint an AI officer
An emerging role, comparable to the DPO, to drive compliance, documentation and the relationship with authorities.
How Cardan-AI helps you
Let's secure your AI Act compliance
We map your AI systems, assess their risk level and build demonstrable governance — turning compliance into a trust advantage with your clients.
Audit my AI complianceAbout the author
Cardan-AI Intelligence
Our research and analysis unit, dedicated to applied AI for business, industry and regulatory compliance.
Let's talk about your next competitive edge
A 30-minute conversation to identify your most profitable AI use cases.
