Photo: Ekō (formerly SumOfUs) · CC BY 2.0 · source
In 2024, the European Union became a pioneer in AI regulation by approving the landmark EU AI Act. While the Act officially entered into force in May 2024, its full implementation is staggered, and 2026 is a critical year for many businesses. While prohibitions on certain unacceptable AI systems have been in effect since late 2024, the main obligations for high-risk AI systems will largely become applicable by mid-2026. This means preparation time is running out, and companies using or developing AI must act swiftly.
The foundation for understanding your obligations is identifying whether your AI system falls into the 'high-risk' category. The Act primarily defines high-risk AI systems in two groups: AI systems used in products subject to existing EU harmonization legislation (e.g., medical devices, aircraft safety components) and systems used in eight specific areas with the potential to significantly impact fundamental rights or safety. These include critical infrastructure, education, employment, migration management, and systems for credit scoring and access to services.
It's not always black and white. For instance, an AI system for personalized marketing recommendations might not automatically be high-risk. However, if it affects consumers' access to essential services (e.g., selectively preventing them from seeing certain offers based on AI profiling), it could become so. It is precisely in these nuances that the greatest challenge lies.
Consider a mid-sized e-commerce company that uses an advanced AI system for personalizing product offerings to its customers. This system dynamically adjusts displayed products, prices, and recommendations based on purchase history, browsing behavior, and demographic data. In 2025, the company decided to prepare for the AI Act and conducted an internal audit. They found that while the system primarily boosted sales, in some cases where the AI model unintentionally excluded certain customer groups from accessing promotional offers or cheaper product variants, it could potentially be classified as high-risk.
Action Taken: The company had to redesign its algorithms to ensure transparency, non-discrimination, and the possibility of human oversight. They implemented a robust monitoring system that tracks the impact of personalization on different demographic groups and prevents unintentional exclusion. Processes for data logging and risk assessment were established. The entire preparation and implementation of these changes took approximately 10 months and required an investment of 150,000 EUR in software modifications and legal consulting.

Outcome: The company avoided potential fines (which can reach up to 7% of total worldwide annual turnover or 35 million EUR, whichever is higher) and gained a competitive advantage in trustworthiness and an ethical approach to AI. The implemented processes also improved data quality and personalization accuracy, leading to an 8% increase in conversions in the tested group.
If your company uses or develops AI, it's time to act. Here's a simplified checklist to get started:
Ignoring the EU AI Act is not an option. Inaction can lead to astronomical fines, reputational damage, and loss of customer trust. Even the regulatory investigation itself can be a significant burden for a company, both financially and in terms of time. What seems like a bureaucratic hurdle is actually an opportunity to strengthen ethical standards and build trust in AI. This is precisely where a general guide is no longer sufficient. With the implementation of the AI Act, companies often struggle with interpreting complex legal texts and translating them into practical technical and procedural changes. At one-o-one.cz, we assist clients with AI system audits, risk identification, and setting up compliance processes that not only meet legislative requirements but also support innovation and business goals.
Start with a thorough inventory of all AI systems within your company and conduct a preliminary assessment of their risk level. If you are unsure how to interpret the definitions of 'high-risk' systems for your specific use cases, or how to effectively set up compliance processes, consider consulting with experts specializing in this area. Don't wait until the last minute; a proactive approach always pays off in the long run.
AI & MarketingAdaptive AI Agents: How Real-Time Optimization is Reshaping MarketingAdaptive AI agents are revolutionizing marketing. Discover how real-time campaign optimization and hyper-personalization boost ROI and what it means for your strategy.Zář 4, 2026
AI & MarketingQuality Over Quantity: How AI is Reshaping SEO and Why Google is Fighting AI SpamDiscover why Google and Meta are tightening rules on AI content. Learn to avoid penalties and create AI-assisted content that truly succeeds in 2026.Zář 2, 2026
AI & MarketingMultimodal AI Rewrites the Rules: How to Generate Campaigns That Truly WorkNew multimodal AI models unify campaign creation across text, image, and video. Discover how they're transforming marketing and what it means for your brand.Srp 29, 2026 AI audit and implementation for business owners. From diagnosis to deployment.
Get an audit