HomeBlogAI & Trends
AI & Trends

AI Act: what applies since 2 August 2026 and the checklist for SMEs

The second major deadline of the European AI regulation passed this summer. Transparency obligations, high-risk systems, duties of companies that deploy AI tools: here is what really concerns you, what is still under discussion in Brussels, and a ten-point checklist.

Sylvie Wendkuni NITIEMA
Sylvie Wendkuni NITIEMAFounder & Data Scientist, DataSAI
Published 2 September 2026 10 min read - reads - comments
AI Act: what applies since 2 August 2026 and the checklist for SMEs
The regulation applies in stages; the August 2026 stage is the widest.
Table of contents
The essentials in 30 seconds
  • Since 2 August 2026 most of the regulation's obligations apply, including transparency for chatbots and generated content, and the high-risk regime.
  • A company that uses an AI tool (the "deployer") has its own duties, distinct from the provider's.
  • A partial postponement for some high-risk systems is being discussed in Brussels; do not build your plan on it.
  • For an SME, compliance comes down to an inventory, a classification and three documents. No more.

Where the timetable stands

The regulation entered into force in August 2024 and applies in stages. Prohibitions (social scoring, manipulation, emotion recognition at work) have been effective since February 2025, together with the AI literacy obligation for staff. Rules for general-purpose AI models followed in August 2025. 2 August 2026 marks the major stage: transparency, high-risk systems listed in Annex III, fully applicable penalties.

A point of honesty: at the time of writing, discussions exist in Brussels to postpone the application of some obligations linked to high-risk systems, as part of a broader simplification of digital legislation. Nothing is final. Our advice is to treat the timetable as written: what you put in place will never be wasted.

What really concerns you

If you use a chatbot or generate content

People must know they are talking to a machine, unless it is obvious. Generated content that could pass for authentic (images, audio, video) must be labelled as such. For a website with an assistant, a clear notice and a sentence in the first message settle it. For generated marketing content, an internal labelling policy.

If you use AI to recruit, evaluate or grant credit

These uses appear in the list of high-risk systems. Even if you did not design the tool, as a deployer you must use it according to its instructions, ensure real human oversight, keep logs, inform the people concerned and, in some cases, carry out a fundamental rights impact assessment.

2 Aug 2026
general application of the regulation, transparency and high risk included
up to 7%
of worldwide turnover for prohibited practices, 3% for other breaches
3
documents are enough for an SME to demonstrate diligence

If you buy AI from a vendor

Require the technical documentation, the instructions for use, information on training data where due, and a contractual clause on compliance with the regulation. A vendor that cannot produce them is transferring its risk to you.

The ten-point checklist

ItemWhat you need to have
1. InventoryThe list of all AI tools in use, including those used by employees
2. ClassificationFor each tool: prohibited, high risk, transparency, minimal risk
3. OwnerA named person for the topic, even part-time
4. AI literacyA documented awareness session for the staff concerned
5. TransparencyNotices on chatbots and labelling of generated content
6. Human oversightWho can stop or correct the system, and how
7. LogsRetention of usage records for high-risk systems
8. VendorsDocumentation and compliance clauses in contracts
9. Informing peopleEmployees and customers informed when a high-risk system concerns them
10. Annual reviewA set date to redo the inventory
An SME's three documents

A register of AI systems (one page per tool), a signed usage policy, and for each high-risk system an oversight sheet: who monitors, which indicators, what stop procedure. With these three pieces you demonstrate a serious approach.

The mistakes we see most

Workshop classifying AI systems in a company
Classification is done with business teams: they know what each tool is really used for.

The first mistake is believing the regulation only concerns those who develop AI. The second is forgetting tools quietly built into business software: automatic CV sorting in HR software, scoring in a CRM. The third is producing heavy documentation nobody will keep up to date, instead of a simple, living register.

"Compliance is not a binder. It is knowing, at any moment, which AI tools run in your company and who watches them."

Conclusion

The August 2026 stage makes the regulation concrete for almost every company, even those that never wrote a line of code. The good news is that for an SME the essentials take two weeks with an honest inventory and three short documents. The worst choice would be to wait for a postponement that is not secured.

FAQ

We only use ChatGPT and Copilot, are we concerned?

Yes, at least by the AI literacy obligation and by transparency if you publish generated content. These uses are minimal risk, the burden is light, but it exists.

What is a "deployer"?

Any company or organisation that uses an AI system under its own responsibility in the course of its activity. That is the case for almost every company today.

Do we need an AI officer like the DPO for GDPR?

The regulation does not require it, but naming an owner, even part-time, is the most effective way to move the topic forward. The DPO is often well placed.

What do we concretely risk in 2026?

National supervisory authorities are being set up and will start with information requests and formal notices. Financial penalties will first target serious breaches and prohibited practices.

AI ActComplianceRegulationHigh riskSME
Sylvie Wendkuni NITIEMA
Sylvie Wendkuni NITIEMA
Founder & Data Scientist · DataSAI
Over ten years in AI and data consulting (Big 4, telecoms, finance). She helps companies deploy AI in production and leads the DataSAI Academy.
Take action

Do your AI Act inventory in two weeks

Mapping of your use cases, risk classification, prioritised action plan and documentation ready for an inspection.

Book a free session →