How to Prepare Your Business for the EU AI Act (Without Being an AI Expert)

Pedro Colarejo
Head of R&D
8 min read • September 8, 2026
The main failure isn’t a lack of awareness; it’s treating this as a one-off audit rather than an ongoing process. Compliance in this case isn’t something you check off and are done with; it’s a habit you have to develop when assessing and deploying AI in the future.

Prepare Your Business for the EU AI Act
When companies hear about the “EU AI Act” they tend to think that it’s something that affects only companies like OpenAI or Google or those other organizations that create AI models. However, that is not true. If your business uses AI — especially in areas that can affect people, such as recruitment, credit, healthcare, or customer interactions — the AI Act may create obligations for you too. The positive point is that you don’t need a legal team or prior knowledge of machine learning in order to work out what is important. All you need is someone to explain it; that’s all. And that is precisely what this article seeks to do.
The EU AI Act does not prohibit the use of AI; rather, it divides AI applications into different risk categories, each subject to specific rules. A number of practices are completely forbidden. More importantly, if something can in any way affect a person’s rights, safety, or opportunities, it can be deemed “high-risk” and must meet certain obligations, such as keeping records, ensuring human oversight, and conducting monitoring. Most ordinary AI — for example, spam filters or product recommendations — has very few or no formal requirements. The important point isn’t to remember all of the law; it is to know where your particular application falls.
If your company develops an AI system and makes it available under its own name, you will generally be acting as a provider and will have significant responsibilities under the AI Act.
If, instead, your company uses an AI system supplied by someone else — for example, a recruitment platform, credit-scoring service or diagnostic assistant — you will normally be acting as a deployer. And deployers have responsibilities too. Buying a system from a vendor that claims to be “AI Act compliant” does not automatically make your own use compliant. Particularly for high-risk systems, organizations may need to follow the provider’s instructions, ensure appropriate human oversight, monitor how the system is used, and retain relevant logs.
In other words, AI compliance cannot simply be outsourced to the vendor.
This is information that you should know even if you’ve been delaying it: The EU adjusted the AI Act timetable in 2026, giving organizations more time to prepare for some of its most demanding requirements. The requirements for many high-risk AI systems, including those covered by Annex III, will apply from December 2027, while the high-risk requirements for AI embedded in regulated products, such as certain medical devices, will apply from August 2028.
That does sound like it gives you some breathing space, and it does. However, two measures are already in place and won’t be going away: the prohibition on the most harmful practices and the AI literacy requirements came into force in February 2025, and the rules applicable to general-purpose AI providers, along with the governance requirements, came into effect in August 2025. The transparency obligations, that is, the rule requiring people to be told that they are speaking to a bot, are still on schedule. Therefore, the delay only gives you time to address the most onerous, high-risk documentation, not a reason to completely ignore the law.
In practice, it takes most medium-sized companies a few months to map out every AI tool they are using, assess the associated risks, and amend their vendor contracts. It is much better to start now and have extra time than to be in a rush in late 2027 under pressure.
The main failure isn’t a lack of awareness; it’s treating this as a one-off audit rather than an ongoing process. A tool that is low-risk at the present moment can become high-risk the very moment it is used in a new decision. Compliance in this case isn’t something you check off and are done with; it’s a habit you have to develop when assessing and deploying AI in the future.
At LOAD, we prefer to build AI governance into the architecture from the beginning rather than treating compliance as something to add at the end. That means thinking about oversight, traceability, data, documentation and accountability while the system is being designed — not when someone asks for evidence six months later.
The result is not just easier compliance. It is an AI system that your organization understands, controls, and can confidently explain.
If you’re unsure about your business’s position, let’s work it out together.

Pedro Colarejo
Head of R&D