The EU AI Act: What You Actually Have to Do Before August 2, 2026
Two things most companies get wrong about the EU AI Act: they think it's for someone else, and they think it's in the future. It's extraterritorial — if your AI touches an EU citizen, it applies to you, wherever you're headquartered. And parts have been law since February 2025. The big deadline is August 2, 2026, and "we only do low-risk AI" is the exact trap, because you still have to prove it.
There are two things almost every company gets wrong about the EU AI Act, and both of them are expensive.
The first: "we're in the US, it doesn't apply to us." Wrong. Like GDPR before it, the EU AI Act (Regulation 2024/1689) is extraterritorial — it applies to any organization deploying AI that affects EU citizens, regardless of where you're headquartered. If a European can use your product, you're in scope.
The second: "we'll deal with it before the 2026 deadline." Also wrong, because parts of it are already law. Since February 2, 2025, two requirements have been in force: every staff member who interacts with AI must have adequate AI-literacy training, and the outright-banned practices (social scoring, manipulative AI, exploiting vulnerable groups) are prohibited now. The thing you were planning to start worrying about next year has been quietly enforceable for over a year.
The deadline that matters
August 2, 2026 is the big one — full enforcement of the high-risk requirements: conformity assessments, risk-management systems, data governance, technical documentation, human oversight, and accuracy/robustness standards. If you operate any AI the Act considers high-risk — hiring and recruitment, credit scoring, anything in education, medical, law enforcement, or critical infrastructure — that's the date the real obligations land.
The trap is thinking you're exempt
The Act sorts every AI system into four tiers: unacceptable (banned), high-risk (heavily regulated), limited-risk (transparency required — your chatbot has to disclose it's AI, deepfakes have to be labeled), and minimal-risk (no specific requirements).
Most companies glance at that, decide "we're minimal-risk," and move on. That is the trap. Minimal-risk carries no special requirements — but you still have to be able to prove your systems are minimal-risk. "We didn't think it applied to us" is not a defense; demonstrating your classification is the obligation. And almost nobody has the thing that demonstration requires: a record of what their AI is actually doing.
It has real teeth
This isn't a guidelines document you can ignore. The penalties are structured like GDPR's bigger sibling: up to €35 million or 7% of global annual revenue (whichever is higher) for prohibited practices, and up to €15 million or 3% for high-risk violations. Percent-of-global-revenue is the phrase that should get this onto your roadmap.
What to actually do now
Not panic — sequence. Inventory every AI system you deploy and classify it by tier (you can't comply with rules you haven't sorted yourself into). Get the AI-literacy training in place, since that one's already overdue. And start the long pole now: the audit trail. Every high-risk requirement — human oversight, conformity, "prove it's minimal" — ultimately rests on being able to show what your AI said, when, and to whom. That record can't be reconstructed after the fact; it has to be running before you need it. August 2, 2026 is not when you start building. It's when you'd better already have.
We wrote the full EU AI Act compliance guide — risk tiers, every key date, the penalty structure — free, no gate. And the audit-trail-and-governance layer that turns "prove your AI is compliant" from a scramble into a button is exactly what Oethos does. Start with a readiness scan.