AI Act: what changes on 2 August for your business
On 2 August 2026, the EU AI regulation reaches a key milestone. What it means if your business uses AI, without giving in to panic.
Updated on

On 2 August 2026, a new wave of obligations under the EU regulation on artificial intelligence — the “AI Act” — becomes applicable. If your business uses AI tools, even just ChatGPT or an assistant built into your software, the question deserves two minutes of attention. Good news: for most everyday uses, there is no reason to panic. Here is what really changes, and for whom.
The AI Act, in one sentence
Adopted in 2024, the AI Act is the world’s first comprehensive legal framework on AI. Its principle is simple: the more a use of AI presents a risk to people, the stricter the rules. The text does not classify technologies, but the uses you make of them.
Four levels of risk
- Unacceptable risk (banned since February 2025): general-purpose social scoring, manipulation… these uses are purely and simply prohibited.
- High risk: AI used for recruitment, access to credit, education, health or certain infrastructure. Heavy obligations.
- Limited risk: AI that interacts with people (chatbots) or generates content. Main obligation: transparency — say that it is an AI, flag generated content.
- Minimal risk: the vast majority of uses (an assistant that writes an email, summarises a document). No specific obligation.
What shifts on 2 August 2026
This date marks the general application of the regulation, 24 months after it entered into force. It is above all the high-risk strand that becomes binding: risk assessment, technical documentation, bias testing, human oversight and continuous monitoring.
An important point, often overlooked: the timeline was partly rearranged in 2026, and some high-risk deadlines were pushed back (to late 2027 for specific cases). Hence a rule of caution: check your situation at the official source rather than on a news headline.
“Am I concerned?” — the right question
The AI Act’s key distinction: are you a provider (you develop or place an AI system on the market) or a deployer (you use one)?
Most small and medium businesses are deployers. Their obligations are far lighter: use the tool in line with its instructions, keep human oversight, and inform the people concerned when required. The heaviest obligations fall first on the providers of the large models (OpenAI, Google, Anthropic, Mistral…), whose “general-purpose” rules have already applied since August 2025.
The real tipping point for an ordinary company is high-risk use. A concrete example: using AI to screen job applications brings you into it, with real obligations — human oversight, informing candidates, and no fully automated decision. The more decisions you entrust to AI agents, the more essential this oversight becomes.
Three useful habits right now
- Take stock of your AI uses: who uses what, for which task?
- Spot the sensitive uses (recruitment, employee evaluation, personal data) — these are the ones that call for vigilance.
- Document and keep a human in the loop: AI prepares, a person decides. It is both good practice and the spirit of the text.
Key takeaway
2 August 2026 is not a guillotine for those who use AI to write or summarise. It is a reminder: AI is entering a framework. For the vast majority of office uses, transparency and human oversight are enough. For sensitive uses — recruitment first among them — you need to get organised. In case of doubt, the CNIL publishes clear, regularly updated markers.
Sources
Frequently asked questions
Is my business concerned if it only uses ChatGPT?
For the vast majority of office uses (writing an email, summarising a document), you are at 'minimal risk', with no specific obligation. Most small and medium businesses are mere 'deployers': follow the tool's instructions, keep human oversight, inform the people concerned when required.
What really changes on 2 August 2026?
It is the general application of the regulation, 24 months after it entered into force. It is above all the 'high-risk' strand that becomes binding: risk assessment, technical documentation, bias testing, human oversight and continuous monitoring.
Which uses are considered 'high-risk'?
AI used for recruitment, access to credit, education, health or certain infrastructure. A concrete example: screening job applications brings a company into this category, with human oversight, informing candidates and a ban on a fully automated decision.
Do all high-risk deadlines fall on 2 August 2026?
No. The timeline was partly rearranged in 2026 and some high-risk deadlines were pushed back (to late 2027 for specific cases). Check your situation at the official source, such as the CNIL, rather than on a news headline.