AI Regulation · Pillar Guide

    EU AI Act Compliance for Founders and Operators

    The August 2026 deadline is closer than most companies think. Here is what that means.

    Back to Insights
    Johnathan Aloni, Adv. | Strategic Legal Advisor | Dublin / EU

    Why This Matters Now

    The EU AI Act is in force and its obligations are being phased in over time. On 15 June 2026, the European Parliament formally approved the Digital Omnibus on AI with 423 votes in favour. The new deadlines for high-risk AI are effectively confirmed, pending Council formal adoption and Official Journal publication.

    What did not move: Article 50 transparency obligations still apply from August 2, 2026. Chatbot and AI interaction disclosure, AI-generated content marking, emotion recognition disclosure, and deep fake labelling. Any company with AI-facing user interaction has live obligations in weeks, not months.

    The EU AI Act applies to companies established in the EU, and to companies outside the EU that place AI systems on the EU market or use AI systems whose output is used in the EU. If your product reaches EU users, the regulation applies to your company regardless of where you are incorporated.

    Five Things Companies Get Wrong About the EU AI Act

    1. Treating the August 2026 Deadline as the High-Risk Deadline

    The Digital Omnibus deferred high-risk AI obligations for standalone systems to December 2027 and for embedded products to August 2028. But August 2, 2026 is not irrelevant. Article 50 transparency obligations apply from that date without deferral. Companies that have stopped preparing because they heard the deadline moved are misreading what moved and what did not.

    2. Assuming the Regulation Does Not Apply to Non-EU Companies

    The EU AI Act applies to any company that places AI systems on the EU market or whose AI output is used in the EU. A US SaaS company with European customers, a founder outside the EU building a product for EU users, and an Asian manufacturer supplying AI components to EU integrators are all within scope. Incorporation outside the EU does not create an exemption.

    3. Misclassifying the AI System

    AI systems used for CV screening and recruitment decisions are commonly treated as high-risk under the AI Act. Credit scoring, access to education, and safety components in regulated products fall in the same category. Classification is not always intuitive and depends on the specific functionality, intended purpose, and context of use. Many companies discover their classification only when a large enterprise customer asks for their AI Act compliance documentation.

    4. Treating Compliance as a Documentation Exercise

    AI Act compliance is not a checklist to complete before a deadline. It is a governance question that affects product design, procurement, and commercial contracts. Sophisticated investors are already asking about AI governance during due diligence. Enterprise procurement teams are building AI Act readiness into vendor qualification. Companies that treat compliance purely as a legal cost are missing the commercial consequence of getting it wrong.

    5. Ignoring the Vendor and Supply Chain Dimension

    Most companies do not build their AI systems from scratch. They use foundation models, third-party APIs, and embedded components from external providers. The AI Act allocates obligations across the value chain: providers, deployers, importers, and distributors each carry specific responsibilities. A company that deploys a third-party AI system without understanding its own role in that chain is carrying compliance exposure it has not mapped.

    The Risk Framework: What the Regulation Actually Requires

    The EU AI Act structures obligations around four risk categories. Where a system sits in that framework determines what is required, when it is required, and who bears responsibility. The classification analysis is the starting point. Everything else follows from it.

    Prohibited Systems

    A small category of AI systems is banned outright. These include AI used for social scoring by public authorities, real-time biometric surveillance in public spaces with limited exceptions, systems that exploit psychological vulnerabilities or subconscious behaviour to manipulate decisions, and AI used to infer sensitive characteristics such as political opinion or sexual orientation from biometric data. The ban has been in force since February 2, 2025.

    High-Risk Systems

    High-risk AI systems carry the most demanding obligations: conformity assessments, technical documentation, logging and audit trails, human oversight mechanisms, and registration in the EU AI database. The categories cover AI used in employment and recruitment, access to education, credit and insurance decisions, critical infrastructure, migration and border control, and administration of justice. Following the Digital Omnibus, standalone high-risk systems under Annex III must comply from December 2, 2027. High-risk AI embedded in regulated products under Annex I has until August 2, 2028. Both dates are subject to Council formal adoption and Official Journal publication of the Omnibus.

    Transparency Obligations (Article 50)

    Article 50 applies from August 2, 2026 and was not deferred by the Digital Omnibus. It requires disclosure when a user is interacting with an AI system rather than a human. It requires marking of AI-generated content in machine-readable form. It requires disclosure when AI is used for emotion recognition or biometric categorisation. It requires labelling of deep fake audio and video. Any company with AI-facing user interaction, AI-generated content, or AI-assisted communication has live obligations under this article in weeks. The watermarking obligation under Article 50(2) for systems already on the market before August 2026 has a transitional period until December 2, 2026.

    General Purpose AI Models

    Foundation models and large language models released for general use carry their own obligations under Chapter V of the Regulation. These include technical documentation, transparency to downstream deployers, and compliance with EU copyright law. Models classified as posing systemic risk face additional requirements including adversarial testing and incident reporting. GPAI obligations have been in force since August 2, 2025.

    For most companies, the immediate priority is twofold: understanding which category their AI systems fall into, and assessing Article 50 transparency exposure before August 2. A classification analysis that takes two to four weeks now is significantly less disruptive than one conducted under deadline pressure.

    How J.A. Consulting Works on This

    Most companies need two things before they can act on the EU AI Act: a clear picture of where their systems sit in the risk framework, and a realistic plan for what to do about it. The work starts with classification and builds from there.

    Classification Analysis

    A structured review of the AI systems your company develops, deploys, or uses, mapped against the EU AI Act risk categories. The output is a written classification analysis that identifies which obligations apply, when they apply, and what role your company plays in the AI value chain. This is the document that answers procurement questionnaires and satisfies investor due diligence on AI governance.

    Article 50 Transparency Readiness

    For companies with AI-facing user interaction or AI-generated content, this covers the specific obligations under Article 50 that apply from August 2, 2026. It includes a review of user-facing interfaces, disclosure mechanisms, and content marking requirements. The output is a gap analysis and a practical remediation plan that can be implemented before the deadline.

    Governance Documentation and Internal Framework

    For companies that have completed classification and need to build the internal infrastructure to support it. This covers internal AI policies, oversight mechanisms, logging requirements, and the documentation needed to demonstrate compliance to regulators, customers, and investors. Designed to function as a working system, not a folder of documents.

    Vendor and Contract Alignment

    For companies that deploy third-party AI systems or supply AI components to others. This covers the contractual obligations that flow through the AI value chain: what deployers must require from providers, what providers must disclose to deployers, and how to structure agreements with AI vendors and customers so that compliance obligations are properly allocated.

    For most companies at the consideration stage, the right entry point is the classification analysis. Everything else follows from knowing where your systems sit.

    View all services

    Go Deeper

    INSIGHTS

    The EU AI Act and Enterprise Sales

    Enterprise procurement teams are building EU AI Act readiness into vendor qualification. Companies that cannot demonstrate classification analysis and governance documentation are losing deals to competitors who can. This article covers what enterprise customers are asking, what they expect to see, and how to turn AI Act readiness into a commercial advantage.

    Read the full analysis →

    Resources

    FREE RESOURCE

    The EU AI Act Applies to You

    A practical guide to the EU AI Act risk framework, the updated compliance timeline, and what readiness looks like for founders and operators. Covers the Digital Omnibus changes and the obligations that still apply from August 2026.

    Download the guide →

    Most of my clients come to me after a close call.

    A few come before one.

    The second group sleeps better.

    If something is on your desk, I'd be glad to hear it.

    Book a 30-minute call
    J.A. Consulting
    J.A. CONSULTINGLegal. Strategy. Execution.

    Johnathan Aloni, Adv. | Strategic Legal Advisor | Dublin, Ireland

    Website content is informational and does not constitute legal advice or create an attorney-client relationship.

    J.A. Consulting | Legal. Strategy. Execution.

    © 2026 J.A. Consulting. All Rights Reserved.

    Admitted in Israel. Not admitted in Ireland.