Introduction
If AI regulation still flies under your radar, it’s about to make some serious noise. The EU AI Act is rolling out. Miss the boat and you’ll get more than just paperwork: delayed launches, surprise audits, and a few regulatory “surprises”—including fines of up to €35 million or 7% of global turnover for the worst violations, plus steep penalties for falling short on other requirements. Hefty numbers are already making headlines for those caught off guard.
But, this is also a rare opportunity to build trust, prepare your work for what’s next, and set the pace while others play catch-up.
In this article, we focus on what really matters, share what works, and help you sidestep the easy mistakes that could trip up your team when it matters most.
What’s Changing: The EU AI Act in a Nutshell
The EU AI Act is not a one-time, one-size-fits-all overhaul; it is rolling out in phases.
Major deadlines have arrived. AI practices were banned and literacy rules kicked in February 2025, and since August 2025, GPAI model providers have faced new requirements around data transparency and documentation. Following the GPAI Code of Practice is now standard.
This is where it gets serious: the biggest must-haves arrive on 2 August 2026, when high-risk AI systems must fully comply. Some systems – especially high-risk AI in regulated products – get a grace period of an extra year. So, think of 2 August 2027 as a no more excuses deadline.
The EU AI Act outlines four risk categories – a move designed to align the rules with the impact they have.
- Unacceptable risk – think social scoring or manipulative biometric systems, which are outright banned for use in the EU.
- High risk – it covers systems that affect safety or fundamental rights. Careful checks, human eyes, and openness are key here.
- Limited risk – when interacting with chatbots or similar AI-powered tools, users must be sure who (or more precisely, what) “speaks” on the other side.
- Minimal risk – spam filters, weather prediction bots, etc.: basic principles around fairness and monitoring apply here.
Grouping risks into these categories is a way of letting innovation grow safely, without giving high-impact systems a free pass.
Non-compliance carries real bite: fines reach up to €35 million or 7% of global annual turnover for prohibited AI practices, with €15 million or 3% for other violations like high-risk system breaches. Even misleading information to regulators can cost €7.5 million or 1%. The stakes are high, and enforcement is live.
Are You Audit-Ready?
By November 2024, Member States were required to publish the list of authorities or bodies competent for the supervision and enforcement of rules about protecting basic rights, whenever high-risk AI is in use.
Your company should adopt AI literacy as an all-encompassing initiative – not just as a new feature for the tech crew. Getting audit-ready for the EU AI Act is a team sport. Product managers, engineers, data professionals, and privacy experts all face new compliance responsibilities. Mapping your AI projects to official risk categories and gathering audit-required records is essential.
To move beyond theory:
- Build a central hub for documentation related to your AI systems: how each one operates, any decisions it makes, the data it was built on, and the risks it might pose. Think clear models and updates for staff and users alike.
- For full AI literacy, organize regular company trainings for the entire company, since an audit could tap anyone on the shoulder. Risk management means having real procedures in place for responding to issues.
- Review and update your documentation and training regularly to keep up with shifting rules and what’s considered best practice. Staying current means your team will spot new risks early and can adjust approach before any surprises land in the next audit.
So, ask yourself: If an auditor asked for proof of how you handle “high-risk” systems, can you show the documentation and explain the controls? Are all staff able to recognize and report concerns? If you’re checking “yes” on these questions and updating your practices regularly, you’re on the right track for 2026 – or maybe even beyond.
What Works for Real Teams?
One of the first steps you should take when tackling the requirements of the EU AI Act is a risk-mapping exercise using structured matrices. For this, the IAPP EU AI Act Compliance Matrix has become a go-to resource, as it essentially informs everyone – from providers and deployers to importers and manufacturers – of their respective obligations and which rules apply to high-risk and general-purpose AI. Use it to cross-reference your portfolio against Article-by-Article requirements, ensuring each system is classified, registered, and documented.
It is good to handle legacy system challenges by starting with the most “high-risk” AI systems. Fraud prevention or employment screening systems are often where companies implement new or improved compliance measures first, before applying them more broadly. After they’ve nailed it, they share their assessment templates and documentation know-how across the company.
To make EU AI Act compliance run smoother, deploy flowcharts and decision trees internally to clarify roles and responsibilities. Take a look at the Burges Salmon Navigating the EU AI Act Flowchart – widely used across industries to pinpoint the proper risk category and next steps for any AI system.
Bottom line: move beyond theory and build shared frameworks using proven tools and real business lessons. That way, the EU AI Act becomes not a stress test, but a cog in a smarter operational system.
- Follow the GPAI Code of Practice, as it has quickly become a reference for companies dealing with general-purpose AI. It lays out clear expectations for data transparency, copyright, and safety, keeping them updated so you can actually follow. The GPAI Code of Practice is a voluntary guide developed by industry and independent experts under the EU AI Office. Consider it a best-practices cheat sheet or a handy bridge for following the rules until the official standards arrive in 2027. If you are building or deploying large models, treating the GPAI Code of Practice as a living document and subscribing to updates from the European AI Office is a smart way to ensure you’re tracking evolving interpretations.
- Watch the calendar closely. Having in mind all the earlier-mentioned dates means being aware that 2025 through mid-2026 is crunch time for getting your records, risk assessments, and internal processes audit-ready. Refine your documentation, monitor workflows, and plan regular reviews of your compliance status. Start your conformity assessment now, as working backward from August 2026 isn’t only smart, but essential.
- Stay alert to guidance. Keep a close eye on updates emerging from national market surveillance authorities and the European AI Office. This is “a regulation in its infancy”, so early enforcement decisions, clarifications from the AI Board, and national-level interpretations will shape how requirements are applied in practice. Subscribe to official bulletins, join industry working groups, and budget time for your compliance lead to review updates.
One last thing: compliance isn’t a rush to the finish line – it’s more like regular vehicle maintenance. Make minor tweaks, stay curious, and treat AI governance as a shared project. That way, when the next round of standards drops in 2027, your team is ready, or even one step ahead.
Legal compliance is the baseline. But if you want your AI to thrive – not just survive – under the new rules, you need to know where the gaps are across your data, processes, and team. Use our AI Readiness Assessment to get a full picture of what’s working and what needs attention before 2026.

