28 May 2026 · Updated: 28 July 2026
AI Act 2026 — a readiness checklist for the board
The general application of the AI Act (Regulation (EU) 2024/1689) starts on 2 August 2026. It also covers companies that “merely use” off-the-shelf AI tools. The adopted Digital Omnibus text provides later dates for the full high-risk obligations: 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems. Regulation (EU) 2026/1744 was published on 24 July 2026 and entered into force on 27 July 2026. Here are ten questions every board should be able to answer — and what to do with every “I don’t know”.
The amended Article 4 requires providers and deployers to take measures to support the development of AI literacy. It does not require them to guarantee a specific level of AI literacy. Article 50 has not been postponed. Read the regulation in EUR-Lex.
1. What uses AI, and where?
Start with an inventory: production systems, integrations, but also the private ChatGPT accounts and plugins that IT cannot see (“shadow AI”). Without that list, no risk classification makes sense.
2. Which systems are “high-risk”?
The AI Act classifies systems by risk. Most business uses are limited or minimal risk, but recruitment, scoring, or safety-relevant systems can be “high-risk” — requiring full documentation and oversight.
The adopted Digital Omnibus text moves the full obligations for Annex III systems to 2 December 2027, and those for Annex I systems to 2 August 2028. The amending regulation is already in force. Our Digital Omnibus analysis explains the changes and the duties that still apply from 2 August 2026.
3. Do employees have the required AI literacy?
Article 4 requires measures supporting the development of AI literacy. Their scope should reflect the people’s knowledge and experience, the context of use and the people affected. The provision does not set a guaranteed level.
4. Are we sure we use no prohibited practices?
Some bans have applied since February 2025 (Art. 5): social scoring, manipulative techniques, and emotion recognition at work and school, among others. Close this one first — a ban cannot be “documented” away; you simply must not break it.
5. Do people know they are talking to AI?
Article 50 requires transparency: a user must know they are talking to a chatbot, and AI-generated content (including deepfakes) must be labelled. Check every customer touchpoint — this is usually the cheapest compliance to implement.
6. Who oversees the system and can stop it?
The full obligations for high-risk AI systems include meaningful human oversight (Art. 14) — not a dummy button. The company must name a person who understands the system’s output, can challenge it, and can switch the system off before it does harm.
7. Where does the data come from, and what goes into the models?
Data quality and provenance decide both compliance and whether the model discriminates against anyone. The flip side: watch what employees paste into public models — personal data and company secrets should not leave the organisation unchecked (this is where the AI Act meets GDPR).
8. Which models (GPAI) do our tools run on?
Most companies use AI through general-purpose models (GPT, Gemini, Llama). Some obligations sit with their providers, but you are responsible for how you use them. You need to know which model sits under each tool, and on what terms.
9. Would we pass an inspection — and what do we do when AI fails?
The full obligations for high-risk systems include technical documentation and operating logs (Art. 11–12). Whatever the risk level, keep a simple procedure: who responds when the model is wrong, and how you report a serious incident. Compliance is a process, not a binder.
10. Who in the company owns AI?
Name an owner: the person or role accountable for AI oversight, decisions, and contact with the regulator. Check vendor contracts too — who takes on which part of compliance. Without clear accountability, every point above becomes nobody’s job.
Four terms you need to know
Deployer — an organisation that uses an AI system under its authority in a professional context, including off-the-shelf tools like ChatGPT. Most companies using AI are deployers and have their own AI Act obligations.
AI literacy (Article 4) — Article 4 requires companies to take measures to support the development of AI literacy among people operating AI. Their scope depends on knowledge, experience and context; the provision does not require a guaranteed level of AI literacy.
Human oversight (Article 14) — for high-risk AI systems there must be a person who understands how the system works, can question its output and — where appropriate — stop the system before it causes harm.
Shadow AI — AI tools used by employees outside the company’s knowledge and control (private ChatGPT accounts, plugins, automations). They increase data-leak risk and can make AI Act or GDPR compliance harder, especially where personal data or high-risk AI are involved.
What’s next
An EU AI Act compliance audit closes the inventory and classification topic within weeks and gives you an action plan right away. It is a working document, not a decorative binder. To run this checklist on your own systems, start with an audit.
Legal basis: Regulation (EU) 2024/1689 (the AI Act); articles cited: Art. 4 (AI literacy), Art. 5 (prohibited practices), Art. 14 (human oversight), Art. 50 (transparency), Art. 11–12 (documentation and logs).