The EU AI Act is no longer a distant policy headline. For businesses using AI, the useful question is now practical: which rules apply to this system, in this role, on this date, and what evidence supports the answer?
The timetable is staged
The Council of the EU says the majority of the Act’s rules became applicable on 2 August 2026. It also records later dates for specific provisions: transparency rules for synthetic content from 2 December 2026, standalone high-risk systems from 2 December 2027, and high-risk systems embedded in regulated products from 2 August 2028.
Those dates matter because “the AI Act applies” is not a complete compliance conclusion. A business still needs to establish whether it is a provider, deployer, importer or distributor; how the system is classified; and which obligations are active for that use.
A policy is not the same as evidence
A responsible-AI statement may describe intent. Buyers, regulators and affected people may need the operating record behind it: the system inventory, purpose, data sources, risk classification, human role, testing, incidents, supplier information and change history.
Start with an AI system register
Record what each system does, who owns it, the people affected, the data and models involved, the supplier relationship, where it operates and the current regulatory assessment. Include experiments that can reach real people or live data, not only systems already labelled “production”.
Define human authority
For decisions that affect candidates, customers or other people, record who reviews the output, what information they receive, whether they can change the result and how their decision is preserved. A nominal click-through is not the same as meaningful review.
Control suppliers and changes
Contracts and due diligence should establish what the supplier will disclose, how incidents are handled, how model changes are communicated and whether the buyer can test, pause or exit the service. A system can change even when the buyer’s interface looks identical.
A practical evidence pack
- AI system and use-case inventory
- Role and applicability assessment with a review date
- Data, model and supplier records
- Risk, testing and acceptance evidence
- Human oversight and escalation design
- Incident, monitoring and change-control records
- Public notices and affected-person routes where required
SOS treats regulation as one part of trustworthy operation. The commercial advantage comes from being able to show how the decision works, where the evidence came from and who remains accountable.
Sources reviewed
For the practical owner analysis, see the related SOS implementation guide.
Want your AI Act evidence position reviewed before a regulator or client asks first?
Book a compliance review