JM20

Compliance · Regulation

The EU AI Act Takes Effect in August. Is Your Business Ready?

Most European SMBs don't know they're affected. Those using American AI tools may already be non-compliant.

June 2026 · 8 min read

In August 2026, the EU Artificial Intelligence Act moves from theory to enforcement. For most European small and mid-sized businesses, this isn't abstract regulation — it's a direct operational concern that affects which AI tools you can legally use, how you must document your AI systems, and what liability you carry if something goes wrong.

The problem is that most businesses haven't been paying attention. The AI Act has been discussed in policy circles for years, but the average SMB owner has been focused on running their business. That gap between awareness and enforcement is where the risk lives.

What the EU AI Act actually says

The EU AI Act classifies AI systems by risk level. Most of what SMBs use day-to-day falls into two categories: limited risk and high risk.

Limited risk systems — chatbots, recommendation engines, basic automation — must meet transparency obligations. If you're using an AI chatbot on your website, your customers must know they're talking to an AI. That's a relatively light requirement, but it's still a legal obligation many businesses are currently ignoring.

High risk systems — AI that influences employment decisions, creditworthiness, access to services, or anything touching personal data in consequential ways — carry significantly heavier requirements: documentation, human oversight mechanisms, accuracy testing, and in some cases registration with EU authorities before deployment.

The question isn't whether the regulation applies to you. If you're operating in the EU, it does. The question is whether the tools you're currently using were built with these requirements in mind.

The American AI tool problem

Here's what most businesses aren't thinking about: the majority of AI tools available today were built in the United States, for US regulatory conditions, with US data infrastructure.

GDPR Article 28 already requires that any data processor you work with meets specific contractual and technical standards. The AI Act adds another layer. When your AI tool processes customer data — queries, conversations, transaction history — on American servers, under American jurisdiction, you are already carrying compliance risk that most people haven't priced in.

The issue is architectural, not just contractual. A tool that routes your customer conversations through a US data centre is not GDPR-compliant by design, regardless of what the terms of service say. The AI Act compounds this by adding requirements around transparency, documentation, and oversight that were simply not part of the design criteria for most US-built tools.

This isn't a critique of American technology. It's a statement about what compliance by design actually means versus compliance by checkbox.

What changes in August 2026

The August 2026 deadline applies specifically to the high-risk AI provisions and the obligations on providers and deployers of general-purpose AI models. In practical terms:

For businesses deploying AI in customer-facing roles — automated support, lead qualification, document processing — you need to be able to demonstrate that you have human oversight mechanisms in place, that the AI's decisions can be explained, and that you maintain logs of consequential interactions.

For businesses using third-party AI tools — which is most businesses — you need to verify that your vendor meets the Act's obligations as a provider. If they don't, the liability can flow to you as the deployer.

For businesses that haven't documented their AI use at all — which is the majority of SMBs — August 2026 is the moment when informal adoption becomes a formal liability.

The three things you should do right now

  1. Inventory your AI exposure. Make a list of every AI tool your business currently uses. For each one, ask: where does the data go, who processes it, and what decisions does it influence? You may be surprised how long the list is once you include embedded AI in tools you already use — CRMs, email platforms, customer support software.
  2. Check your vendor's compliance position. For each tool on your list, look for their EU AI Act and GDPR Article 28 documentation. If it doesn't exist, or it's vague, that's a signal. A compliant vendor should be able to tell you exactly where your data is processed, under what legal basis, and what their obligations are under the Act.
  3. Separate what you control from what you don't. The cleanest compliance position is one where you own the infrastructure. Tools built on your own accounts — your own database, your own processing environment — give you full visibility and control. Tools that route through a vendor's shared infrastructure give you neither.

What this means for AI automation in practice

The AI Act doesn't mean you can't use AI. It means you need to use it deliberately, with documentation, with oversight, and with infrastructure that was designed for EU compliance rather than retrofitted after the fact.

For businesses considering AI automation for customer support, business intelligence, or internal workflows, the question is no longer just "does this tool work?" It's "does this tool comply, and can I prove it?"

The good news is that compliant AI automation is entirely achievable for SMBs. The key is building on infrastructure that keeps your data in the EU, that you own and control, and that was designed around these requirements from the start — not patched to meet them after the fact.

A practical note on timing

August 2026 is not a soft deadline. Enforcement mechanisms are in place, national supervisory authorities are being established across EU member states, and the fines — up to €35 million or 7% of global annual turnover for the most serious violations — are calibrated to be meaningful even for large companies.

For SMBs, the enforcement risk is lower than for large enterprises, but the reputational risk is not. A single data incident or compliance failure, publicised in the context of AI Act enforcement, is the kind of story that damages client trust in ways that take years to repair.

The businesses that act now — inventorying their tools, verifying their vendors, and building on compliant infrastructure — are the ones that will be able to move quickly on AI adoption as the regulation beds in, because they'll have the documentation and the architecture to prove they're doing it right.

JM20 is an AI agentic automation consultancy based in the EU. We build AI agents for European businesses on EU infrastructure — GDPR Article 28 compliant, EU AI Act aware, and designed so you own everything we build. If you're thinking about your AI compliance position, we're happy to talk it through for your specific setup.

Start with a Discovery →