On 2 August the bulk of the EU AI Act became applicable. And with that date came the question that has been repeating in board meetings ever since, always in the same tone: can they fine us 35 million? The short answer is that almost nothing from the headlines applies to an ordinary company, that what does apply is considerably more boring, and that even so, almost nobody can answer the one question that actually matters: what AI is running inside your company right now.
We are not a law firm and this post is not legal advice. We are the people who end up building what the rule demands: the inventory, the logs, the permissions, the who-can-install-what. And from that side you see something the legal summaries leave out: for an ordinary company, the AI Act is mostly an inventory problem. One thing at a time.
What actually happened on 2 August
Regulation (EU) 2024/1689 — the AI Act — never landed all at once. It applies in stages: prohibited practices and AI literacy from 2 February 2025; general-purpose models, governance, notified bodies and the penalty regime from 2 August 2025; and the remainder from 2 August 2026. That "remainder" was the main course: high-risk systems.
Six days before that date, on 27 July, Regulation (EU) 2026/1744 of 8 July 2026 entered into force, published in the Official Journal on 24 July: the so-called Digital Omnibus on AI. And that regulation moved the main course.
- →Stand-alone high-risk systems (Article 6(2) and Annex III: biometrics, employment, education, essential services, migration) move from 2 August 2026 to 2 December 2027.
- →AI embedded in regulated products (Article 6(1) and Annex I, Section A: machinery, lifts, aviation, medical devices…) moves to 2 August 2028.
This is where the confusion started. Half of Europe read "the AI Act has been postponed" and relaxed. The AI Act was not postponed: one part of it was — and precisely the part that most small and mid-sized companies were never in scope for anyway. What did land on 2 August is still standing.
Article 50, translated into your company
The transparency obligations in Article 50 were not deferred. They apply from 2 August 2026. Translated into things you actually see in a company:
- ✓The chatbot on your website (50.1): whoever provides it must design it so the person knows they are talking to an AI, unless that is obvious to a reasonably well-informed person. The bot pretending to be "Marta from customer service" no longer flies.
- ✓The content it generates (50.2): generative AI systems must mark their outputs in a machine-readable format as artificially generated or manipulated. That binds the model provider, not the intern writing the copy.
- ✓Emotion recognition or biometric categorisation (50.3): if you use them — and yes, there is HR and call-centre software that ships them without advertising it much — you must inform the people exposed. That obligation is yours as the deployer, not the vendor's.
- ✓Deepfakes and texts on matters of public interest (50.4): if you publish a generated or manipulated image, audio or video, you have to disclose it. And if you publish AI-generated text to inform the public on matters of public interest, likewise — unless it went through human review and someone takes editorial responsibility.
Breaching Article 50 carries fines of up to 15 million euros or 3% of worldwide turnover, whichever is higher — except for SMEs and start-ups, where Article 99(6) requires the lower of the two. The 35 million and 7% from the headlines belong to something else: the prohibited practices in Article 5, which have applied since February 2025 and which — unless you are doing social scoring or mass face-scraping — are not your problem.
Article 25: it only bites on high risk, but know which box you are in
Almost everyone puts themselves in the comfortable box: "I only use the tool, the vendor is the one on the hook." It is worth reading Article 25 before settling in there. It says a distributor, importer or deployer becomes a provider — with the Article 16 obligations — in three cases, and all three require high risk: if they put their name or trademark on a high-risk system already on the market; if they substantially modify it and it remains high risk; or if they change the intended purpose of a system — including a general-purpose one — so that it becomes high risk.
The move half the market makes — take a third-party model, put the company logo on it, call it "the [your brand] Assistant" and publish it on the website — does not make you a provider as long as that assistant is not high risk, and almost none are. We say so because the opposite is doing the rounds. But the day that same assistant starts screening CVs or scoring customers for credit, you are in Annex III and the box changes, with whatever label you stuck on it. That is the question worth having answered before someone asks you in writing.
2 December 2026: the date nobody wrote down
The Omnibus left two things hanging on an intermediate date that has gone unnoticed. First: generative AI systems already on the market before 2 August 2026 have until 2 December 2026 to implement the machine-readable marking required by Article 50(2). Second: the Omnibus added new prohibitions to Article 5 covering the generation of non-consensual intimate imagery and child sexual abuse material, with the same December deadline for the technical safeguards.
If you signed up for a content generator in 2025, the question for your vendor is specific and fits in one email: will your system mark outputs in a machine-readable format before 2 December? You want that answer in writing, and you want it now, not in November.
AI literacy is still there, and it is the cheapest thing in the regulation
Article 4 — AI literacy — has applied since February 2025, and the Omnibus reworded it: instead of a demandable outcome, it is now a duty to take supporting measures proportionate to technical knowledge and context of use, and the text clarifies that it does not require guaranteeing a specific level of literacy in any particular person. The Commission will publish compliance examples and the AI Office will issue recommendations.
Our reading, without frills: the legal bar was softened and the obligation was kept. It is by far the cheapest thing to comply with in the whole regulation — two hours of decent training and a one-page document on what can and cannot go into an AI chat — and it is the only item on this list that also saves you incidents. Don't leave it for last just because it is the soft one.
Spain: the agency exists, the law does not yet
An EU regulation is directly applicable: it needs no Spanish law to switch it on. But Spanish law is needed to designate authorities and set out the sanctioning procedure, and there we are running late. On 26 May 2026 the Council of Ministers approved the draft Organic Law on the good use and governance of AI — placing AESIA as the supervisory authority and echoing the regulation's fine brackets — it was published in the parliamentary gazette on 12 June and the amendment window closed on 30 June. As this article went out it was still going through Parliament.
Operationally: the obligation is real as of 2 August, the Spanish enforcement machinery is still being assembled, and that window is exactly the time you have to catch up without rushing. It is the same film we watched with NIS2, where the delayed transposition created a false sense of calm and then the big customers' questionnaires arrived before the regulator's; we wrote about it in NIS2 in Spain. The first one asking you for paperwork will not be the regulator: it will be your biggest customer.
The real problem is not legal: you don't know what AI you have inside
This is where the post stops being about regulation. None of the obligations above can be met — or even checked — without a list of which AI systems are used in your company, for what, with which data and who approved them. And that list almost never exists.
In February 2026, Microsoft's Cyber Pulse report put at 29% the share of employees who had already turned to unsanctioned AI agents for work tasks. It is worth reading the small print before using that number: it comes from a survey of 1,725 data security leaders run between 16 July and 11 August 2025 by Hypothesis Group and commissioned by Microsoft itself. It is a perception survey of senior people, not a measurement in real tenants, so treat it as an order of magnitude. In the environments we audit, the order of magnitude fits.
And note this is not just about people pasting data into a public chat. It is about agents: software that inherits the permissions of whoever installs it and acts on its own against your mail, your SharePoint and your documents. We already wrote about why a huge share of agent projects ends up cancelled; what we had not covered is that the ones that are not cancelled just stay there, ownerless and with no expiry date.
What we look at in a Microsoft 365 tenant
If the company lives in Microsoft 365 — most of our clients do — the inventory does not need inventing: it is in the admin centre, on the agent settings page. What we open, in this order:
- 1User access. Three options: all users, no users, or specific users and groups. The default is "all users". If nobody has touched it, everyone in your organisation can use agents. This is not a Microsoft bug: it is the factory setting, and almost nobody reviews it.
- 2Allowed agent types. It splits Microsoft-built agents, agents built by your own organisation, and agents from external publishers. That third box decides whether an employee can install third-party software that reads your documents. It is a business decision, not an IT one, and it should be taken deliberately.
- 3Sharing and ownerless agents. The management rules let you bulk-reassign agents left orphaned when their creator left the company: they transfer to the previous owner's manager according to Entra ID. With one limitation worth knowing before you rely on it: that rule — like the sharing control — only covers agents built with Copilot Agent Builder, not everything in the tenant. If you have had staff turnover this year, look at that list anyway. There are usually surprises.
- 4The apps connected to the tenant, which is the door next to it and the one that causes the most grief. An agent or integration with granted consent keeps getting in even if the user has MFA; we explained it in the token that never asks for MFA.
Half an hour of clock time, and you walk out with the part of the inventory a console can give you. The rest — what people use outside the tenant, from the browser or from their phone — does not come out by auditing: it comes out by asking, and only if you ask without a telling-off face.
This week's checklist
- ✓Make the list. A spreadsheet is enough: system, what it is used for, what data it touches, who owns it, whether anyone approved it. Without this, nothing else can even start.
- ✓Review agent access in your tenant and decide explicitly who can install what. Deciding "leave it as it is" is also a decision, but make it knowing what the default is.
- ✓Check whether your website has a chatbot and whether it says it is a bot. It is literally a one-sentence change, and it is the most visible obligation you now have.
- ✓Write to the generative AI vendors you signed before August and ask about the 2 December machine-readable marking. In writing.
- ✓Check whether your HR, recruitment or call-centre software does emotion analysis or biometric categorisation. If it does, the people involved must be informed. That obligation is yours.
- ✓Two hours of training and one page of usage rules. The cheapest obligation and the least implemented.
What we would NOT do
- ✗Buy an "AI Act compliance seal". There is no mandatory certification for general AI use in an ordinary company. What exists is documentation and decisions taken. If someone sells you a seal for 3,000 euros, ask them exactly which standard they certify against.
- ✗Ban AI in the company. We have seen it and we know how it ends: people use it anyway, from their phone, on a personal account, with customer data. Banning without an alternative does not reduce risk, it moves it off your radar. Give people a tool they can work with and clear rules.
- ✗Freeze AI projects "until things get clearer". Things just got clearer: you have until December 2027 for the heavy part. That is time to do things properly, not time to skip them.
What is left on the table
On 2 August the 35-million fine did not arrive; the obligation to be honest about where you use AI did. The heavy part moved to December 2027 and August 2028. What is left on the table fits in one afternoon: say the bot is a bot, know which agents run in your tenant, ask your vendors about the December date, and train your people. None of that needs a lawyer; it needs someone to sit down and do it.
And if you got this far thinking "we don't use AI", open the admin centre and look at the list of installed agents. It is the two-minute check that has changed the conversation for us more often than any other. It is the same work we do in compliance and continuity and in AI automation: first know what is there, then decide what stays.
Sources (verified): Regulation (EU) 2026/1744 of 8 July 2026 (Digital Omnibus on AI), published in the Official Journal on 24 July and in force since 27 July — EUR-Lex and BOE (DOUE-L-2026-81147); new high-risk dates (2 Dec 2027 and 2 Aug 2028), the rewording of Article 4 and the Article 50(2) transition until 2 Dec 2026 — Cuatrecasas and Freshfields; text of Articles 4, 5, 25, 50 and 99 (including 99(6), the lower amount for SMEs) of Regulation (EU) 2024/1689 — artificialintelligenceact.eu; Spain's draft Organic Law on the good use and governance of AI, approved by the Council of Ministers on 26 May 2026 and still before Parliament — Spanish Ministry for Digital Transformation; agent settings and the default user-access value — Microsoft Learn; the 29% figure on employees using unsanctioned agents, Cyber Pulse report of February 2026 (Hypothesis Group survey of 1,725 data security leaders, 16 July to 11 August 2025, commissioned by Microsoft) — Microsoft Security Insider. This article is not legal advice.
Do you know what AI runs inside your company?
At everyWAN we build the inventory, the permissions and the logs the regulation takes for granted. No seals, no smoke: the list of what is there, who approved it and what stays.
Talk to everyWAN