All issues
Modern Growth
Weekly Pipeline Gazette4 min read

EU Artificial Intelligence Act — are you legal?

Full 2026 AI compliance checklist


Four days ago, on the 2nd of August, the largest tranche of the EU's Artificial Intelligence Act started to apply. Almost nobody we've spoken to this week could tell us whether it touches them, and a fair few assumed Brexit had settled the question. It hasn't, and that's the part worth ten minutes of your Thursday.

Caveat first: we're a growth consultancy, not a law firm, and none of this is legal advice. Use it to work out whether you need to ask someone qualified. Where we're not certain, we say so rather than guessing.

Start with the bit people get wrong. The Act reaches past the EU's borders: it bites on businesses outside the Union where the output of an AI system is used inside it. A UK company with EU customers, EU-based staff, or EU prospects sitting in an outbound sequence can be in scope with no legal entity anywhere in Europe. The precise test is fiddly, and it's the first thing we'd send to a lawyer if you sell into Europe at all.

The timeline, and these dates we're confident about. The Act came into force on the 1st of August 2024. Bans on certain practices, plus a duty to make sure the people using AI in your business actually understand it, started on the 2nd of February 2025. Rules for general-purpose AI models, governance and penalties came in on the 2nd of August 2025. Then Sunday just gone.

Two things about that date. The transparency obligations under Article 50 apply from it. Meanwhile the high-risk rules that were also meant to arrive have been pushed back by an amending regulation, usually called the Digital Omnibus on AI, agreed in the spring and adopted over the summer: standalone high-risk systems now have until December 2027, and AI embedded in regulated products until August 2028. Treat those two as directionally right rather than gospel, because the omnibus moved fast and we'd want them confirmed against the published text before anyone relies on them.

The reassuring part, for most readers of this newsletter: if you run a small founder-led business with a chatbot, an outreach tool, a transcription service and something that drafts your copy, you're almost certainly a deployer of limited-risk systems rather than a provider of high-risk ones. The heavy machinery in the Act isn't pointed at you. Transparency is, and that's a much shorter list.

So, the checklist. Six things, and you can do most of them yourself.

  1. Write down every AI system that touches a person outside your company. Website chat, phone answering, outbound sequences that generate their own replies, AI notetakers on client calls, anything that scores or sorts applicants. Most founders find between four and nine and are surprised by two of them. You cannot comply with a list you don't have.

  2. Anything that holds a conversation must say it's software. Article 50 requires people be told they're interacting with an AI system, unless that's obvious from the context. In practice: a line at the top of the chat, a sentence in the voice greeting, a footer on automated replies. Plain language, not buried in your terms.

  3. Mark AI-generated content aimed at the public. Synthetic images, audio and video fall under the marking and disclosure rules, as does text published to inform the public on matters of public interest. A grace period into December 2026 is reported for the machine-readable marking of systems already on the market; check that before relying on it. Ordinary marketing copy, drafted by a model and edited by a human, isn't what this provision is chasing.

  4. Work out which side of the line you sit on: deployer, or provider. This one catches people. If you take a vendor's chatbot, put your own name on it and sell it on, you may have become a provider with a heavier set of duties. If you're simply using a tool a vendor sells you, you're a deployer. Anyone white-labelling AI as part of their offer should get this checked properly rather than assuming.

  5. Do something real about AI literacy, and write it down. The duty to make sure staff using these tools sufficiently understand them has applied since February 2025. An hour's session plus a one-page policy on what may and may not go into a model, dated and minuted, is proportionate for a team of eight.

  6. Ask your vendors for their paperwork. Every AI tool you pay for should be able to say what it does, what it does with your data, and how it meets the Act. A supplier who can't answer that in August 2026 has told you something useful.

On penalties we're deliberately not quoting figures. The regime is tiered, the top band is calculated against worldwide annual turnover, and smaller companies are treated more leniently than the headline numbers on LinkedIn suggest. Those amounts are easy to look up and easy to misquote, so look them up.

Do this before Friday. Just item one. Twenty minutes, a blank page, every AI system that speaks to a customer. Everything else gets easier once that page exists, and if you find nine of them with disclosure on none, you've found your weekend job.

If you'd like a second pair of eyes on what your stack is doing to your leads, commercially as much as legally, there's a 30-minute call on the site.

Ryan & Ali

Get next Thursday's

One letter a week. Unsubscribe in one click.

Every issue · Book a 30-minute call