AI & Automation

The EU AI Act is now being enforced: what does it mean for your business?

20 August 2026

By Toby Beevers

If your business uses AI, the conversation is starting to move beyond which tools are useful and into how those tools are being used, managed and explained.

The EU AI Act became broadly applicable on 2 August 2026, with the European Commission's AI Office and national authorities beginning enforcement of key provisions. Some requirements were already in force, while others — particularly those covering certain high-risk AI systems — will apply later.

For many small and medium-sized businesses, this does not mean suddenly building a large compliance function. But it does make something increasingly important: businesses need to understand where AI is actually being used.

What is the EU AI Act?

The EU AI Act is a risk-based framework for regulating artificial intelligence.

Rather than treating every use of AI in the same way, it applies different requirements depending on the type of system and the risk associated with its use.

At one end are prohibited AI practices considered unacceptable because of their potential impact on people's rights and safety. There are then high-risk applications, including certain uses of AI in areas such as employment, education, critical infrastructure and biometrics.

There are also specific transparency requirements for certain AI systems, while most AI applications considered minimal or no risk are not subject to additional rules under the Act.

That distinction matters.

Using an AI assistant to help draft an internal document is very different from using an AI system to assess candidates for employment. Businesses need to understand the use case, not simply whether something has "AI" written on the product page.

What changed in August 2026?

Several important parts of the regulatory framework have now reached the enforcement stage.

From 2 August 2026, new transparency requirements under Article 50 apply. Depending on the system and how it is used, these include requirements around informing people when they are interacting directly with AI and identifying certain AI-generated or manipulated content.

There are specific requirements covering areas such as deepfakes, emotion recognition, biometric categorisation and some AI-generated material relating to matters of public interest.

The Commission and national authorities have also begun exercising their enforcement powers under the Act.

This follows earlier requirements. Prohibited AI practices and AI literacy provisions started applying in February 2025, while obligations relating to providers of general-purpose AI models began applying in August 2025.

The important point for businesses is that the AI Act is not a single deadline. Different obligations apply at different stages.

What about high-risk AI?

This is an area where the timetable has changed.

Following the EU's AI Omnibus simplification measures, rules covering high-risk systems in areas such as employment, education, biometrics, critical infrastructure, migration and border control are due to apply from 2 December 2027.

Rules covering high-risk AI embedded in certain regulated products are due to apply from 2 August 2028.

That gives organisations operating in these areas more time to prepare, but it should not be interpreted as a reason to ignore the issue until the deadline.

Understanding whether an AI system could fall into a higher-risk category can influence procurement, data, documentation, oversight and vendor decisions being made today.

What should SMEs be doing now?

For most SMEs, a sensible starting point is not a huge compliance project. It is getting visibility.

Start by understanding what AI is already being used across the business.

That may be harder than it sounds. Teams may be using general-purpose AI assistants, AI features embedded inside existing software, automated customer service tools or specialist applications without anyone maintaining a central view.

Once you understand that landscape, ask some practical questions:

  • What is each tool being used for?
  • What information is being put into it?
  • Does it interact with customers or employees?
  • Is AI influencing an important decision?
  • Who owns the process?
  • Is somebody checking the output?
  • Do people know when they are dealing with AI-generated material?

Those questions are useful even where a particular use case creates few regulatory obligations.

They are simply part of using AI responsibly.

AI literacy matters too

One part of the Act that is particularly relevant to everyday AI adoption is AI literacy.

The requirement for providers and deployers to take measures supporting AI literacy among staff has applied since February 2025, with supervision and enforcement provisions now in effect.

This does not mean everyone in a business needs to become an AI specialist.

It does mean businesses using AI should think about whether the people using it understand enough to do so appropriately. That could include understanding the limitations of AI outputs, when human review is needed, what information should or should not be entered into a tool, and how the organisation expects AI to be used.

Buying access to an AI platform and giving everybody a login is not an adoption strategy.

Governance does not need to mean bureaucracy

There is a risk that smaller businesses hear words such as "AI governance" and assume they need enterprise-scale policies, committees and paperwork.

Usually, the better approach is proportionate governance.

Know which AI systems you use. Give them an owner. Understand what data they handle. Document important use cases. Set sensible rules for employees. Review higher-risk applications more carefully. Make sure there is appropriate human oversight.

The level of governance should reflect what the AI is actually doing.

An internal productivity tool and an AI system influencing recruitment decisions should not automatically be treated in the same way.

This is also a technology strategy issue

Regulation is one reason to get a clearer picture of AI use, but it is not the only one.

Without visibility, businesses can easily end up paying for overlapping tools, putting sensitive information into systems without enough thought, automating processes that were already poorly designed, or relying on AI-generated outputs without clear accountability.

A basic AI inventory and governance process can therefore support better technology decisions as well as regulatory preparation.

It moves the conversation away from "Which AI tool should we buy?" towards better questions:

  • Where could AI genuinely help?
  • What risks come with that use?
  • What data does it depend on?
  • Who needs to oversee it?
  • Is the business actually ready to adopt it?

That is a much stronger foundation for AI adoption.

Where should you start?

If AI is already being used across your business, start by mapping what is happening today rather than writing a policy nobody will read.

Understand the tools, use cases, people, processes and data involved. Identify anything that deserves closer attention. Then put proportionate controls around it.

The EU AI Act makes that work more important, but it is also simply good technology management.

Node9 helps SMEs assess where AI can genuinely add value, understand existing tools and processes, and build practical AI adoption roadmaps grounded in how the business actually works.

If AI is on your agenda but you are not sure what the next step should be, start with a conversation.


This article provides general information about AI strategy and the EU AI Act. It is not legal or regulatory compliance advice.

Further reading