From August 2, 2026, most of the provisions of the EU AI Act apply, but this does not mean one identical obligation for every company. The scope of activities depends on the role of the organization, the purpose of the system and the level of risk. A company using a note-taking assistant has different responsibilities than a provider of a tool for selecting candidates or assessing access to basic services.

The best time to clean up AI is before implementation, not after an incident. The technology should have a business owner, a described purpose, access controls, data usage policies, and the ability to see what the system has done. The material below presents the technical and organizational action plan. It does not replace an individual legal opinion.

What changed on August 2, 2026?

The AI Act entered into force on August 1, 2024 and is applied in stages. Prohibited practices and the obligation of competence in the field of AI began to apply on February 2, 2025. Further obligations regarding general-purpose models entered into the next stage. From 2 August 2026, most of the remaining rules apply, with exceptions and specific deadlines provided for, among others, certain high-risk systems.

Therefore, a company should not base its decision solely on the phrase "AI Act is already in force" or "we still have time". You need to check the specific use case, the system launch date and the role of the organization.

First, determine the company's role

Responsibilities depend on whether the organization is a supplier, adopter, importer or distributor of the system. A company that creates its own AI product and offers it to customers usually has a broader scope of responsibilities than a company that uses an off-the-shelf service according to a vendor's instructions.

However, the role may change. Deeply modifying a ready-made system, changing its purpose or offering it under your own brand may affect the classification. This decision must be documented before work begins.

Risk model in AI Act

Practices prohibited

The regulation prohibits certain applications that pose unacceptable risks, including selected forms of manipulation, exploitation of people's vulnerabilities, social scoring and certain applications of biometrics. If an idea falls into this category, the implementation should not proceed to the production phase without detailed analysis.

High risk systems

This group may include systems used in specific areas, such as employment, education, critical infrastructure or access to essential services. Requirements include, but are not limited to, risk management, data quality, documentation, event logging, human oversight, accuracy, resilience and cybersecurity.

Transparency obligations

Some systems must clearly inform humans that they are interacting with AI. This applies to chatbots, for example, if the context doesn't make it obvious. Separate rules apply to specific synthetic content and deepfakes. The information should be understandable and shown at the right time, and not hidden only in the regulations.

Minimal risk

Many everyday applications, such as assisting with word processing or categorizing internal tickets, may be at a lower risk level. However, other regulations, contracts, business secrets, GDPR and basic security principles still apply.

AI systems registry: a practical first step

A company won't manage what it doesn't know about. The register should include not only centrally purchased applications, but also tools used independently by employees. For each use it is worth writing down:

  • tool name, vendor, version and process owner,
  • business goal and decisions influenced by AI results,
  • the company's role and initial risk category,
  • types of input and output data and storage period,
  • users, integrations and access levels,
  • method of human supervision, monitoring and reporting of incidents.

Secure AI implementation architecture

Minimize data passed to the model

You shouldn't send your entire customer base to an external service just because the integration allows it. The system should only transmit data needed for a specific task, remove identifiers where possible, and enforce a retention period.

Separate instructions from user content

Applications that use language models are vulnerable to prompt injection. A document downloaded from the Internet or a client message may contain an instruction that attempts to change the behavior of the system. The model should not independently access files, mail or payments without a layer of authorization and validation for each operation.

Use human supervision where results matter

The “accept” button is not sufficient oversight if the employee doesn't know the sources and doesn't have time to evaluate the response. The interface should show inputs, constraints, sources, and the ability to improve the output. For high-impact decisions, the machine cannot replace competent judgment without a proper basis and procedure.

Log events without persisting redundant data

The log should allow you to recreate the model version, user, time, important parameters and the result of the operation. This does not mean that all prompts containing personal data will be saved indefinitely. The scope of logs must be associated with the goal, risk and retention policy.

AI competencies of employees

The AI literacy obligation has been in force since February 2025. The training should correspond to real work. A person creating marketing content needs a different scope, a programmer integrating a model needs a different scope, and an employee who approves recommendations that influence customers needs a different scope.

At a minimum, this includes error and hallucination recognition, data protection, copyright policies, secure prompts, how to report an incident, and the limits of automation. The company should also specify which tools are allowed to be used.

90-day compliance implementation plan

  1. Days 1–30: inventory of tools, owners, data, contracts and use cases; stopping uses with unacceptable risks.
  2. Days 31–60: classification, AI policy, requirements for suppliers, access control, logging and employee training.
  3. Days 61–90: safety and quality tests, emergency scenarios, monitoring, incident procedure and production approval.

How does PixelShark support AI implementations?

PixelShark designs AI solutions for companies including access control, privacy, monitoring, human supervision and integration with existing systems. We are responsible for the technical layer and, together with the client's legal advisor, we translate the requirements into application functions, documentation and the maintenance process.

Contact us, if you are planning an AI assistant, document analysis, customer service automation or a model operating on company data and want to prepare the implementation safely from the first version.

Sources