Photo: Ekō (formerly SumOfUs) · CC BY 2.0 · source
The European Union is once again leading the way in digital regulation. Following GDPR, we now have the EU AI Act, the world's first comprehensive legal framework for artificial intelligence. And what's crucial for us? As of August 2, 2026, most of its provisions have come into effect, including key transparency rules and full enforcement powers for the European Commission and national authorities. This means one thing: those who have procrastinated must now act. The penalties for non-compliance are astronomical.
The EU AI Act was approved in 2024 and is being progressively implemented. Its goal is to ensure that AI systems in the EU are safe, transparent, ethical, and respect fundamental rights. The Act is based on a risk-based approach, meaning the level of regulation depends on the potential risk posed by the AI system. For companies, this means an obligation to actively assess the risk category of their AI tools and adjust internal processes accordingly. Prohibitions on unacceptable risk practices came into effect on February 2, 2025. Subsequently, obligations for providers of general-purpose AI (GPAI) models became applicable on August 2, 2025. The current date, September 28, 2026, falls within the period when key parts are already applicable, and supervisory authorities have full powers to enforce them.
The AI Act categorizes AI systems into four levels, which determine the extent of obligations:
Regardless of whether you are a provider of an AI system or merely a deployer, your company has obligations. Key areas include:
A European recruitment company deployed an AI system to score job applicants based on video interviews. The system evaluated candidates based on speech cadence and facial expressions. Following complaints of unfair treatment, an investigation was launched, and the system was classified as high-risk. The company had to revise the tool to include human oversight and document the model's decision-making process, as required by the AI Act. This example clearly demonstrates that even seemingly innocuous applications can have far-reaching impacts and require careful scrutiny.
The penalties for non-compliance with the EU AI Act are among the strictest in digital regulation, surpassing even GDPR.

In addition to financial sanctions, reputational damage and the forced withdrawal of non-compliant AI systems from the market are also risks. Reduced fine limits apply to small and medium-sized enterprises.
A proactive approach is crucial. Don't be caught off guard; start preparing as soon as possible. I recommend the following steps:
EU AI Act Readiness Checklist:
It's clear that implementing the EU AI Act is not a trivial matter. For many companies, especially those working with complex AI systems or operating in high-risk sectors (such as HR, finance, or healthcare), general advice is insufficient. In such situations, where in-depth analysis, auditing of existing systems, setting up specific risk management processes, or legal consultation is needed, engaging an experienced partner makes sense. At one-o-one.cz, we help companies with comprehensive AI governance and compliance solutions, so they can focus on innovation with the assurance that they comply with applicable legislation.
The EU AI Act is a reality, and its impact on businesses will be significant. It's not just another regulation but an opportunity to build trust in AI and strengthen your brand through an ethical and responsible approach. Proactive investment in compliance will pay off not only by avoiding fines but also by building trust with customers and partners. Ignoring these rules could have serious financial and reputational consequences. It's time to act.
Most provisions of the EU AI Act, including transparency rules (Article 50) and full enforcement powers, became applicable on August 2, 2026. Obligations for high-risk systems (Annex III) will apply from December 2, 2027, and for systems integrated into products (Annex I) from August 2, 2028.
High-risk AI systems are those with the potential to cause significant harm to health, safety, or fundamental rights. This includes AI in critical infrastructure, education, employment, financial services, or biometric identification. These systems are subject to the strictest requirements for risk management, human oversight, data quality, and technical documentation.
Not all content. Under Article 50 of the EU AI Act, you must clearly label AI-generated or manipulated content that could be mistaken for human creation, or if the interaction with AI is not obvious (e.g., chatbots). This applies to realistic synthetic media, deepfakes, and content informing the public.
Fines are tiered by severity. Violations of prohibited AI practices can incur fines up to €35 million or 7% of global annual turnover. Non-compliance with other obligations (e.g., for high-risk systems) up to €15 million or 3% of turnover. Providing incorrect information up to €7.5 million or 1% of turnover.
AI & MarketingAI Governance in Marketing: Steering Innovation, Ethics, and ComplianceLearn how to implement AI governance in marketing. This article explains pillars of responsible AI deployment, ethical challenges, and EU AI Act compliance. Get practical tips and a checklist.Zář 28, 2026
AI & MarketingCustom AI Agents: Moving from Experimentation to Measurable AdvantageGeneric AI tools are no longer enough. Learn how to build custom AI agents for marketing, integrate them into your stack, and achieve a measurable competitive edge. With real-world data and case studies.Zář 23, 2026
AI & MarketingGemini Ultra 2.0: How Google's New AI is Reshaping Marketing Analytics and PredictionGoogle Gemini Ultra 2.0 revolutionizes marketing analytics. Discover how multimodal AI and long context improve customer behavior prediction and transform ROI.Zář 20, 2026 AI audit and implementation for business owners. From diagnosis to deployment.
Get an audit