EU AI Act · Compliance Guide

AI Act compliance for small firms: what August 2026 really requires, and the tools you already pay for

The headlines said the AI Act got delayed. For the high-risk systems most small firms never build, that is true. For the AI you actually use every day, nothing moved. Those rules go live on 2 August 2026.

By Pedro Bandeira · 3DH Consulting · Updated July 2026 · 8 min read
Share
📄

Get this guide as a PDF

The full guide plus the Monday-morning checklist, offline-ready. Join the Pulse newsletter and download it.

Download PDF

You probably read that the EU AI Act got delayed. For the heavy stuff, the high-risk systems most small firms will never build, that is true. For the AI you actually use every day, it is not. The chatbot on your website. The assistant drafting your emails. The tool screening your CVs. None of that moved. Those rules go live on 2 August 2026. And here is the part nobody is selling you: you almost certainly already own the tools to meet them.

This is a business translation, not a legal brief. I am not a lawyer. What I am is someone who puts AI to work inside real companies and watches what happens when the whole thing gets left to the legal team without anyone who understands how the tools actually behave. So let me tell you which deadline moved, which one did not, and what to do about it with software you are probably already paying for.

⚠ The part that was not delayed

If your firm uses any AI, including off-the-shelf tools like ChatGPT or Copilot, you are a deployer under the Act. Transparency, AI literacy, and the day-one deployer duties apply from 2 August 2026. Those were not postponed. "The Act got delayed" is a misread of which deadline moved.

What moved in July, and what didn't

This summer the EU adopted the Digital Omnibus, a package that reshuffled the AI Act timeline. It pushed the high-risk deadlines out. The stand-alone high-risk systems now land at the end of 2027, the ones baked into physical products in 2028. Real relief, if you build those systems. Most firms do not.

What it left untouched is the part that reaches an ordinary business. Transparency. AI literacy. The duties you pick up the moment you use someone else's AI in your work. Those still start on 2 August 2026. So when someone tells you the Act got delayed, they are half right. About the half that was never going to touch them.

Date What applies Status
Feb 2, 2025 Prohibited AI practices banned. AI literacy required for staff who use AI. ● IN FORCE
Aug 2, 2025 General-purpose AI obligations active. Penalty regime begins. AI Office operational. ● IN FORCE
Aug 2, 2026 Article 50 transparency, the bulk of remaining obligations, and full enforcement. NOT delayed by the Omnibus. ● APPLIES
Dec 2, 2027 Stand-alone high-risk systems (Annex III: employment, credit, healthcare, education AI). Deferred by the Omnibus. ✓ DELAYED
Aug 2, 2028 Product-embedded high-risk systems (Annex I). Deferred by the Omnibus. ✓ DELAYED
📌 The Omnibus in one line

The Digital Omnibus was adopted in summer 2026 and is awaiting publication in the Official Journal. It moved the high-risk deadlines to fixed dates in 2027 and 2028. It did not move transparency, AI literacy, or the deployer duties. Those are the ones a normal firm actually touches.

The Act cares what you do, not how big you are

There is no headcount that gets you out of this. The Act sorts everyone by role. Build or brand an AI system and you are a provider. Use one in your work and you are a deployer. A twelve-person firm running ChatGPT is a deployer, and that is a legal role with real obligations, not a shrug.

Being small changes one thing. The fines are capped lower for SMEs, you pay the lower of the two figures instead of the higher, and you get access to regulatory sandboxes. That is the whole benefit.

Violation Maximum fine
Using a prohibited AI system €35 million or 7% of worldwide turnover
High-risk or transparency (Article 50) breach €15 million or 3% of worldwide turnover
Misleading information to authorities €7.5 million or 1% of worldwide turnover

For an SME the number is the lower of the two, not the higher. Smaller, yes. Still the kind of number that ends a small firm.

The four moments you have to say this is AI

Article 50 is the transparency rule, and it is the one that lands on a normal business. Take out the legal language and it comes down to a handful of moments where you have to tell people they are dealing with a machine.

Your chatbot has to say it is a chatbot. If something is answering questions on your site or handling intake, the person needs to know they are talking to AI, from the first message.

AI-generated content shown to the public has to be marked as AI. The machine-readable watermark is mostly the vendor's job, but you pick the vendor, so pick one that actually does it.

Deepfakes get disclosed. Publish AI-made images, audio, or video of real-looking people or events and you say, clearly, that it is artificial.

Published text on matters of public interest gets a label, with one exception that matters for a law firm. If a human reviewed it and a named person or organisation holds editorial responsibility, the labelling duty falls away. So your client alerts and your thought-leadership are fine, as long as a real person signs off on them.

The practical read: drafting a contract or a memo that a lawyer reviews is generally not a public transparency trigger. Your exposure there is confidentiality, where the client's data ends up, not a label. The label rules bite on the client-facing surfaces. The chatbot, the marketing, anything photoreal.

The Monday-morning checklist

No theory. Here is what a firm of twenty to a hundred and fifty people actually does.

You already own most of the answer

Here is the part that should make a managing partner exhale. Read that checklist again. Inventory, classification, transparency records, oversight, logging, data governance, retention. If your firm runs on Microsoft 365, you already own the machinery for almost all of it. It is sitting in your tenant, mostly switched off.

Purview Compliance Manager ships with a built-in EU AI Act template. It walks you through the assessment and exports the report an auditor wants to see. Purview DSPM for AI finds the AI already in use, including the shadow AI nobody told you about, and flags where data is oversharing. Auditing, retention policies, and eDiscovery cover the logging, the record-keeping, and legal hold over AI activity. And Azure and Copilot can be set to keep data inside the EU, through EU Data Zones and the EU Data Boundary, once someone configures it that way.

The honest limit

These tools give you readiness, not a certificate that says you are compliant. They produce the evidence and the controls. The legal judgment, the risk classification, the human oversight, that stays with you. Anyone who tells you a piece of software makes you compliant is selling you something. What the software does is turn a scramble into a system.

What it means by industry

⚖ Law Firms

  • Client intake or vetting AI can be high-risk
  • Human sign-off on any AI recommendation
  • Editorial ownership clears published AI content
  • Privilege raises the data-governance bar
  • Check vendor contracts for liability

🏦 Finance & Insurance

  • Credit and pricing AI is high-risk
  • Explainability: why was this decided
  • Bias testing on a schedule
  • Appeal route for affected people
  • Keep the audit trail

🏥 Healthcare

  • Diagnosis or treatment AI is high-risk
  • Clinical validation before deployment
  • Clinician oversight on outputs
  • Fold into existing MDR work
  • Document the training data

💊 Pharma

  • Discovery and trial AI is high-risk
  • Validate the way you already do
  • Audit trail and deviation control
  • Fold into your QMS
  • Aligns with FDA and MHRA frameworks

Five sentences that will cost you

"We're too small." Wrong test. It is about what you do, not how many of you there are.

"We only use ChatGPT." That makes you a deployer, and a deployer has duties. It is a role, not a loophole.

"The free version is fine for client work." Not when it lacks EU residency, admin controls, and audit logs, and you are holding privileged data.

"Data leaving the EU doesn't matter." It does, for this and for GDPR both, and it is a setting you can change.

"We'll write a policy." A policy you file once is not evidence. The Act expects something living.

Pedro's take

The firms that will feel August coming are the ones still treating AI as a thing they bought. The ones that will not are the ones who sat down, listed what they use, switched on the controls they already pay for, and wrote it down in a way they can keep current. That is a weekend of clarity, not a year of consulting.

Frequently asked questions

Is the August 2026 deadline cancelled?

No. The Omnibus moved the high-risk system deadlines to 2027 and 2028. The transparency obligations under Article 50, AI literacy, and the deployer duties still apply from 2 August 2026. The part that reaches an ordinary firm was not delayed.

We use ChatGPT or Copilot. Do we have to do anything?

Yes. Using someone else's AI in a professional context makes you a deployer, a defined role with real duties: transparency where it applies, human oversight, AI literacy, and data governance. The Act does not ban a vendor. It assigns you responsibilities.

What is the fastest way to start without a compliance team?

The inventory is free and it is the hardest part to skip. If you run on Microsoft 365, most of the evidence and controls the Act asks for are features you already pay for, waiting to be switched on and kept current. The bottleneck is rarely money. It is the decision to start.

Want a straight answer on where your firm stands?

That is the readiness assessment we run. What AI you are really using, what the Act asks of you, and how much of it your existing Microsoft licences already cover. No new platform to buy. Mostly switches to turn on, and a system to keep them honest.

Book a readiness call

Last updated July 2026. This article is for information only and is not legal advice. For formal compliance guidance, engage qualified AI and technology counsel. Key sources: the EU AI Act official text and implementation timeline (artificialintelligenceact.eu), the EU Commission Article 50 transparency FAQ, analysis of the 2026 Digital Omnibus (Freshfields, Gibson Dunn), and Microsoft Learn documentation for Purview and Azure EU data residency.

Download PDF Guide

Enter your email to download. You'll also get the weekly Pulse digest, signal only, no noise.

Unsubscribe anytime. No spam, ever.