EU AI Act After 2 August 2026: A Practical Guide for Companies Using AI Agents
The EU AI Act (Regulation (EU) 2024/1689) reached full application on 2 August 2026. If your company uses AI agents - whether for customer support, document processing, marketing content generation, or internal workflow automation - part of this regulation already applies to you. The question is not whether the EU AI Act matters; for most organizations using AI in any professional capacity, it does. The real questions are which requirements are active right now, which are coming in 2027 and 2028, and what steps your company should take today.
This article is structured around three practical concerns that business leaders, CTOs, and product owners typically raise: Does this law apply to our company? What role do we play under the regulation? And what do we actually need to do? The answers are more manageable than the headlines suggest - but only if you understand the phased timeline and the logic of risk classification.
This article is technical guidance, not legal advice. For interpretation specific to your situation, consult qualified legal counsel.
Does the EU AI Act Apply to Your Company?
The EU AI Act applies broadly - and not only to companies headquartered in the European Union. The regulation covers any organization that places an AI system on the EU market, operates an AI system within the EU, or whose AI-generated outputs are used by people in the EU. This extraterritorial logic mirrors how the GDPR works: your physical location is irrelevant if your AI system reaches EU users.
A quick self-assessment covers three questions:
- Do any of your AI systems interact with users based in the EU?
- Do any of your AI systems process data belonging to EU residents?
- Are the outputs of your AI systems used to make decisions about EU residents?
If you answer yes to any of these, the EU AI Act applies to at least some of your AI operations. A SaaS platform with EU clients, a marketing agent producing content for EU audiences, or an HR agent that evaluates candidates from EU countries - all three scenarios fall under the regulation. The European Commission offers an official EU AI Act Compliance Checker (currently in beta) as a preliminary self-assessment tool, though it does not substitute for legal analysis.
The EU AI Act Timeline: What Is Active Now and What Comes Later
The EU AI Act is a phased regulation. Understanding the timeline prevents both unnecessary panic about obligations that do not yet apply and dangerous complacency about requirements that are already in force. The schedule has four key milestones for companies using AI agents.
Already in force before August 2026:
- February 2025 - Prohibitions on nine categories of unacceptable AI use took effect. These cover manipulation techniques that exploit psychological vulnerabilities, social scoring systems used by public authorities, and real-time biometric identification in public spaces for law enforcement purposes. If your systems fall anywhere near these categories, you should have addressed this already.
- August 2025 - Requirements for general-purpose AI (GPAI) models took effect. This applies primarily to model developers and foundation model providers, not to companies that consume model APIs.
Active from 2 August 2026:
- Article 50 transparency obligations are now fully in force. Any company that deploys an AI system that interacts directly with people must disclose that interaction is AI-driven. Machine-readable marking of synthetic content - AI-generated audio, images, video, and text of public interest - is also required. For systems placed on the market before 2 August 2026, a limited grace period for the machine-readable marking obligation only runs until 2 December 2026.
Coming next:
- 2 December 2027 - Most requirements for high-risk systems listed in Annex III (recruitment, biometric identification, education access, credit scoring, migration control) become mandatory.
- 2 August 2028 - Requirements for high-risk AI systems embedded in regulated products such as medical devices and transport equipment.
For most companies using AI agents in 2026, the critical obligation is Article 50. The high-risk Annex III requirements are coming - and preparation should begin now - but they are not yet legally required for most use cases.
Companies Outside the EU: How the Extraterritorial Reach Works
The EU AI Act applies to your company even if every employee, server, and office is outside the EU. The determining factor is whether your AI systems serve EU users or produce outputs that affect them - not where your company is registered or where your infrastructure runs. This is exactly how GDPR enforcement has worked, and EU AI Act enforcement is expected to follow the same logic.
Three practical examples illustrate the scope:
- A US-based SaaS company whose platform includes an AI chatbot used by EU customers falls under Article 50 transparency requirements for those interactions.
- A marketing agency outside the EU that uses AI agents to generate advertising content targeted at EU consumers must consider machine-readable marking obligations for that content.
- An HR technology company whose AI screening tool evaluates candidates based in the EU is operating a system that will likely fall under high-risk Annex III classification by December 2027.
The practical implication is that "we are not a European company" is not a compliance defense. If EU users interact with your AI systems, EU rules apply. The European Commission's regulatory framework overview covers the territorial scope in detail. For preliminary self-assessment, the official Compliance Checker linked above is a reasonable starting point.
Provider vs. Deployer: Your Obligations Depend on Your Role
One of the most important distinctions in the EU AI Act is the difference between a provider and a deployer. These two roles carry very different compliance obligations, and most companies that use AI agents - but do not build foundation models - are deployers rather than providers.
Provider is defined as an organization that develops an AI system and places it on the market under its own name or trademark. Building a fine-tuned model on proprietary data and licensing it to other businesses makes your company a provider. Developing an AI system that you brand and sell as a product also makes you a provider.
Deployer is an organization that uses a ready-made AI system in the course of its professional activities. Connecting to the OpenAI API, the Anthropic API, or another commercial model to power an internal tool or customer-facing feature typically makes your company a deployer. The model developer is the provider; you are the deployer.
The critical nuance is substantial modification. If your company takes a third-party AI system and significantly modifies it - retraining it on proprietary data, substantially changing its intended purpose, or placing it on the market under your own brand as a distinct product - you may shift from deployer to provider under the regulation. The exact threshold for "substantial modification" remains subject to regulatory interpretation and is not yet fully defined in published guidance.
Deployer obligations are meaningfully smaller than provider obligations. But they are not zero. As a deployer, you are responsible for ensuring that the AI systems you use comply with applicable requirements in your context, including Article 50 transparency disclosures for your users.
A practical example: a company that purchases API access to a commercial LLM and builds a customer support agent on top of it is a deployer. The same company, if it fine-tunes that model on proprietary datasets and markets the resulting system under its own brand to third parties, is likely a provider for that product.
How to Classify the Risk Level of Your AI Agents
One of the most common misconceptions about the EU AI Act is that AI agents represent a special, automatically high-risk category of AI systems. They do not. The EU AI Act does not define "AI agent" as a risk classification. Risk is determined by what the system does and what consequences its decisions have - not by its technical architecture.
The regulation defines four risk levels:
- Unacceptable risk (prohibited) - Systems that manipulate behavior through subliminal techniques, enable social scoring by public authorities, or perform real-time biometric identification in public spaces for law enforcement. These were banned from February 2025.
- High risk - Systems listed in Annex III of the regulation. This includes AI systems used in recruitment and employee management, credit scoring, education access decisions, biometric categorization, critical infrastructure management, and migration control. High-risk systems face the most extensive documentation, testing, and oversight requirements.
- Limited risk (Article 50) - Systems that interact with people (chatbots, virtual assistants) or generate synthetic content. These carry transparency obligations: disclosure and content marking.
- Minimal risk - Most AI systems fall here. Spam filters, recommendation engines, and many internal automation tools. No specific EU AI Act obligations apply, though good engineering practice still matters.
Applying this to common AI agent types: a customer support chatbot is limited risk (Article 50 disclosure required). A document summarization agent for internal use is minimal risk. A content generation agent producing marketing materials is limited risk with content marking considerations. An HR agent that ranks or filters job applicants is high risk - even if the underlying technology is the same LLM API used in a minimal-risk agent.
The key diagnostic question is: does the agent's output directly influence a decision about a specific individual's rights, health, employment, or financial situation? If yes, the high-risk classification path should be examined carefully.
Multi-agent systems require additional attention. The EU AI Act does not yet have specific provisions for chains of agents - pipelines where one agent invokes another to complete a task. Current interpretation places responsibility for the entire pipeline on the deployer of the overall system. If your architecture includes multiple agents working in sequence, you should treat the combined system as the unit of compliance analysis.
Article 50 Transparency: What Is Required Starting 2 August 2026
Article 50 of the EU AI Act is the compliance reality for most companies using AI agents in 2026. These transparency obligations apply to providers and deployers of AI systems that interact with people or generate synthetic content. Violations carry fines of up to EUR 15 million or 3% of worldwide annual turnover, whichever is higher.
Article 50 contains two core obligations:
Disclosure of AI interaction
If your AI system is designed to interact directly with a natural person - a chatbot, a virtual assistant, an AI-powered support agent - that person must be informed they are interacting with an AI system and not a human. This disclosure must happen before or at the start of the interaction. The obligation applies unless the system's AI nature is obvious from context.
What constitutes sufficient disclosure: a clear, visible statement in the interface at the point of first interaction. Not buried in terms and conditions. Not appearing only on a documentation page. The European Commission's official FAQ on Article 50 transparency obligations provides practical guidance on what counts as adequate notice.
There is an important exception: if disclosure would compromise the legitimate purpose of the system in a law enforcement, security, or national defense context, the obligation may not apply. For standard business applications, the exception is narrow and does not apply.
Machine-readable marking of synthetic content
If your AI system generates synthetic audio, images, video, or text intended to inform the public on matters of general interest - think news summaries, political content, or public health information - that content must be machine-readable marked to indicate its AI origin. This is distinct from the AI disclosure requirement and applies at the content level rather than the interaction level.
The regulation does not mandate a single technical standard for machine-readable marking. C2PA (Coalition for Content Provenance and Authenticity) represents one established approach to content provenance that can serve this function, but it is an implementation option, not a legally required standard. Other technical approaches remain valid as long as they meet the machine-readability requirement.
There is also a deepfake-specific disclosure obligation: AI-generated content depicting real people in ways that could mislead the public must carry a visible disclosure of its synthetic nature. This applies regardless of whether the content concerns public interest matters.
For systems placed on the market before 2 August 2026, the machine-readable marking obligation specifically - and only that obligation - has a grace period until 2 December 2026. All other Article 50 requirements are in force from 2 August 2026 without transition.
Engineering Controls: Best Practices That Support Compliance
Beyond the legal text of the EU AI Act, there is a set of engineering controls that leading organizations implement when deploying AI agents. These controls are not all universal legal obligations under the EU AI Act for deployers in 2026 - some are best practices recommended by industry standards bodies, and some address high-risk requirements that become mandatory in 2027-2028. Understanding the difference matters: treating every best practice as an immediate legal obligation creates unnecessary overhead, while dismissing them as optional creates real risk.
AI system inventory
Before you can classify risk levels or assign compliance obligations, you need to know what AI systems your organization actually uses. This includes systems procured through official IT channels and systems that employees have adopted independently. Research consistently shows that approximately 49% of employees use unapproved AI tools at work - a pattern referred to as shadow AI. The EU AI Act does not recognize good-faith ignorance as a defense: if an AI system operating in your organization creates a compliance issue, your organization is responsible. A current inventory of all AI systems, including those used informally by teams, is the prerequisite for everything else.
Audit logging
Recording what AI agents do - the inputs they receive, the decisions they make, the actions they take - creates the evidence base needed to demonstrate compliance after the fact and to diagnose failures when they occur. For high-risk systems under Annex III (effective December 2027), logging is a formal requirement. For all systems, it is sound engineering practice that should be built in from the start.
Access control and least privilege
AI agents should have access to only the systems, data, and tools they need for their specific tasks. An agent that summarizes internal documents does not need write access to production databases. An agent that schedules meetings does not need access to customer financial records. Applying least-privilege principles limits the damage radius if an agent behaves unexpectedly or is compromised.
Human-in-the-loop for consequential actions
For actions that are irreversible or that carry significant consequences - sending external communications, executing financial transactions, deleting data, modifying production systems - a human approval step before execution is a meaningful safeguard. This is particularly important as AI agents become more autonomous. Building these checkpoints into your workflow architecture reduces the risk of costly mistakes and aligns with the EU AI Act's general human oversight principles, which are formal requirements for high-risk systems.
Agent-specific security risks
The OWASP Top 10 for Agentic Applications 2026, developed with contributions from more than 100 industry experts, researchers, and practitioners, identifies the most significant risks in AI agent deployments. Several are directly relevant to operational safety and compliance readiness:
- ASI01 Agent Goal Hijack - An attacker manipulates the agent's objectives through crafted inputs (prompt injection). Mitigation: strict limits on autonomous action cycles and controlled input validation.
- ASI02 Tool Misuse - The agent invokes legitimate tools with unauthorized parameters. Mitigation: parameter validation and explicit permission scoping.
- ASI07 Insecure Inter-Agent Communication - In multi-agent pipelines, agents communicate without authentication, enabling privilege escalation between agents. Mitigation: signed messages and explicit agent identity verification.
- ASI08 Cascading Failures - A failure in one agent propagates through the pipeline faster than human operators can detect. Mitigation: circuit breakers and blast-radius containment.
- ASI10 Rogue Agents - Agents drift from their intended behavior through context accumulation or external compromise. Mitigation: behavioral baselines, telemetry, and a documented kill-switch procedure.
Governance frameworks as reference points
ISO/IEC 42001:2023 provides an international standard for AI management systems - a structured approach to continuous risk management, traceability, and supplier oversight across an organization's AI portfolio. ISO 42001 certification is not equivalent to EU AI Act compliance and does not automatically satisfy legal requirements, but it provides a mature organizational framework for AI governance that is compatible with the Act's expectations.
Similarly, the NIST AI Risk Management Framework, developed through an open process involving more than 240 organizations from industry, academia, and civil society, offers a practical Govern-Map-Measure-Manage cycle for managing AI risk continuously. It is a voluntary, non-binding framework - not a legal requirement and not specific to any jurisdiction - but it translates directly into operational processes that support compliance readiness.
Five Practical AI Agent Scenarios: What the EU AI Act Requires
Applying the EU AI Act's risk framework to concrete use cases makes the obligations clearer than abstract classification tables. Here are five common AI agent scenarios and what they mean for compliance in practice.
Scenario 1: Customer support chatbot
Risk level: limited (Article 50). The agent interacts directly with end users. You must disclose at the start of each interaction that the user is communicating with an AI system, not a human. No Annex III requirements apply. This is the most common scenario for companies that have already deployed AI-powered support tools.
Scenario 2: HR agent for resume screening
Risk level: high (Annex III, category covering employment decisions). This agent is likely to be classified as a high-risk system under the EU AI Act because its outputs directly influence decisions about individual employment. Full Annex III requirements - including technical documentation, conformity assessment, human oversight mechanisms, and registration - become mandatory by 2 December 2027. However, you should start building your AI system inventory and technical documentation now. Retroactive preparation is significantly more expensive than building in from the start.
Scenario 3: Content generation agent for marketing materials
Risk level: limited (Article 50). The agent generates synthetic content. Depending on the nature of the content, machine-readable marking may be required. If the content presents realistic synthetic media depicting real people, deepfake disclosure applies. For standard marketing copy, the requirements are lighter - but the marking obligation for content of public interest should be evaluated on a case-by-case basis.
Scenario 4: Internal document summarization agent
Risk level: minimal in most configurations. If the agent processes internal documents for internal use only and its outputs do not directly affect decisions about specific individuals, it likely falls in the minimal-risk category. Article 50 applies if EU residents interact with the agent directly. For a purely internal tool used by employees, the disclosure requirement does not typically apply to the employees themselves as the primary audience of the tool.
Scenario 5: Financial agent for credit evaluation or dynamic pricing
Risk level: likely high (Annex III covers credit scoring and financial risk assessment). This scenario requires careful legal analysis. A pricing agent that dynamically adjusts prices based on individual user characteristics may fall under high-risk classification. A credit evaluation agent almost certainly does. If you are operating agents in this space, the December 2027 deadline for Annex III compliance is not far away, and technical documentation takes time to build properly.
Company Readiness Checklist for EU AI Act
The following steps address the most important compliance actions for a company that uses AI agents in 2026. This is a practical starting point, not an exhaustive legal compliance program.
- Complete an AI system inventory. List every AI tool and agent your organization uses, including tools adopted by individual teams without central IT approval (shadow AI). Without this list, classification is impossible.
- Determine your role for each system. Are you a provider or a deployer? The answer depends on whether you developed the system or are using a system developed by someone else, and whether you have substantially modified it.
- Classify the risk level of each system. Use the four-level framework: prohibited, high-risk, limited-risk, minimal-risk. The key question for high-risk classification is whether the system's outputs directly influence decisions about specific individuals' rights, health, employment, or finances.
- Implement Article 50 compliance for limited-risk systems. Add clear AI disclosure statements to any user-facing interface where your AI agent interacts with people. Review your content generation workflows for machine-readable marking obligations.
- Begin preparing for high-risk Annex III requirements. If any of your AI systems are likely high-risk, start building technical documentation and human oversight processes now, in advance of the December 2027 deadline.
- Use the official Compliance Checker. The European Commission's EU AI Act Compliance Checker (beta) provides a structured self-assessment tool. It does not replace legal analysis but is a useful starting point for prioritization.
- Set up audit logging for AI agent actions. Record inputs, decisions, and outputs for every AI agent in production. Store logs with sufficient retention to support retroactive compliance verification.
- Build human-in-the-loop checkpoints for irreversible actions. Before any AI agent executes an action that cannot be undone - deleting data, sending external messages, executing financial transactions - require human approval.
- Review vendor contracts for AI systems you use as a deployer. Confirm how compliance obligations are allocated between you and your AI system provider. Some obligations sit with the provider; some sit with you as deployer regardless of what the provider does.
Common Mistakes Companies Make with EU AI Act Compliance
Several patterns of error appear consistently across organizations approaching EU AI Act compliance for the first time. Recognizing them early prevents both unnecessary cost and genuine legal exposure.
Mistake 1: "We are not in the EU, so this does not apply to us." The extraterritorial scope of the EU AI Act matches GDPR logic. If your AI systems reach EU users, the regulation applies regardless of where your company is headquartered. US companies, companies from Eastern Europe, and companies from any other jurisdiction that serve EU customers are in scope.
Mistake 2: "AI agents are automatically high-risk under the EU AI Act." They are not. The EU AI Act does not define AI agent as a risk category. A customer support chatbot and a credit evaluation system can both be built using the same underlying LLM API. The chatbot is limited-risk; the credit system is high-risk. Risk is determined by purpose and consequence, not architecture.
Mistake 3: "High-risk requirements are postponed until 2027, so we can wait." Article 50 is already in force. If you have AI systems interacting with EU users, disclosure requirements apply now. Additionally, preparing for Annex III high-risk requirements takes significant time - documentation, conformity assessments, and process changes are not achievable in a few weeks.
Mistake 4: "We use ChatGPT or Claude - the AI provider handles compliance." As a deployer, you carry your own compliance obligations. OpenAI's compliance as a provider of the underlying model does not satisfy your obligations as the deployer who built a specific application on top of that model. Article 50 transparency disclosures, for example, are the deployer's responsibility.
Mistake 5: "Shadow AI is the employees' responsibility." The EU AI Act does not recognize institutional ignorance as a defense. If an AI tool used by your employees - with or without IT approval - creates a compliance issue, your organization is accountable. Discovery of shadow AI is a compliance obligation, not an optional housekeeping exercise.
Mistake 6: Treating all engineering best practices as immediate legal obligations. Not every technical control discussed in AI governance frameworks is a current legal requirement for deployers in 2026. Treating ISO 42001 certification or full NIST AI RMF implementation as legally mandatory conflates best practices with legal duties. The confusion creates either unnecessary cost or, paradoxically, a false sense of security when companies focus on frameworks rather than the specific obligations that actually apply to them right now.
Building AI Agents That Are Ready for Regulatory Scrutiny
Getting AI agent deployments right under the EU AI Act requires both technical precision and regulatory clarity. The work is not primarily about compliance documentation - it is about building AI systems that are observable, controllable, and transparent by design. Those properties serve your business interests independent of regulation: agents that can be audited are agents that can be trusted; agents with behavioral telemetry are agents that can be improved.
Webdelo works with companies to design and build AI agent architectures that incorporate the controls discussed in this article: structured AI use-case inventories, role and access control aligned with least-privilege principles, audit logging from day one, human-in-the-loop checkpoints for consequential decisions, content marking workflows, and technical documentation that supports Annex III preparation. We also help organizations understand which of their current AI scenarios fall under which risk tier - before they invest in compliance work that may not match their actual obligations.
A technical audit of your current AI scenarios is a practical first step. It identifies your role (provider vs. deployer), maps your systems to the risk framework, and prioritizes actions by both urgency and impact. The audit scope is limited and the output is specific - not a generic framework recommendation, but a clear picture of what applies to your company and what to do next.
If you are using AI agents in your business or planning to build them, contact Webdelo to discuss a technical AI audit or the architecture of a compliant AI agent system. We can help you understand where you stand and what to build next.
Frequently Asked Questions
Is a company outside the EU required to comply with the EU AI Act?
Yes, if its AI systems are used by people in the EU or if AI-generated outputs affect EU residents. The regulation's territorial scope mirrors the GDPR approach: the location of your company is not the determining factor; the location of the people your AI systems affect is.
Is an AI agent automatically classified as high-risk under the EU AI Act?
No. The EU AI Act does not define AI agent as a risk category. Risk level is determined by the purpose of the system and the consequences of its decisions. An AI agent that summarizes internal meeting notes is minimal-risk. An AI agent that ranks job applicants is high-risk. The architecture is irrelevant to the classification.
What specifically does a company need to do before the end of 2026?
The primary obligation active from 2 August 2026 is Article 50 transparency: disclose to users that they are interacting with an AI system, and apply machine-readable marking to synthetic content of public interest. For systems placed on the market before 2 August 2026, the machine-readable marking obligation has a grace period until 2 December 2026. All other Article 50 requirements are in force immediately.
We use the ChatGPT API or Claude API - are we a provider or a deployer?
Typically a deployer. The company that developed the underlying model and offers it via API is the provider. You, as the company building an application on top of that API, are the deployer. The exception is if you substantially modify the model or place it on the market under your own brand as a distinct AI product - in that case, you may be considered a provider for that specific system.
What is the penalty for violating Article 50 transparency requirements?
Fines for Article 50 violations can reach up to EUR 15 million or 3% of worldwide annual turnover, whichever is higher. The EU AI Act also provides that enforcement authorities should apply penalties proportionately, particularly for small and medium-sized companies.
Do we need ISO/IEC 42001 certification to comply with the EU AI Act?
No. ISO/IEC 42001 is an international standard for AI management systems - a governance framework that supports systematic risk management across an organization's AI portfolio. Holding ISO 42001 certification does not automatically demonstrate EU AI Act compliance. It is a useful organizational reference, not a substitute for legal compliance analysis.
What should we do if employees are using AI tools that have not been approved by IT?
Conduct an inventory of all AI tools in use across your organization, including unapproved ones. The EU AI Act does not provide protection for institutional ignorance. If an AI system used by your employees - even informally - creates a compliance issue, your organization bears responsibility. Discovering and documenting shadow AI is a compliance task, not an optional exercise.
Frequently Asked Questions
Does the EU AI Act apply to our company if we are not based in the EU?
Yes. The EU AI Act applies to any organization whose AI systems interact with EU users, process data of EU residents, or produce outputs that affect decisions about EU residents - regardless of where your company is headquartered or where your servers are located. This extraterritorial scope mirrors how the GDPR works.
What specifically changed on 2 August 2026 under the EU AI Act?
Article 50 transparency obligations entered full force on 2 August 2026. Companies that deploy AI systems interacting directly with people must disclose that the interaction is AI-driven. Machine-readable marking of AI-generated audio, images, video, and text of public interest is also required. Systems placed on the market before this date have a limited grace period for content marking only, running until 2 December 2026.
What does Article 50 of the EU AI Act require from companies?
Article 50 has two core obligations. First, any AI system that interacts directly with people - such as chatbots or virtual assistants - must clearly inform users they are interacting with an AI. Second, AI-generated synthetic content (audio, images, video, text of public interest) must carry machine-readable markings identifying it as artificially generated. Violations carry fines of up to EUR 15 million or 3% of worldwide annual turnover, whichever is higher.
What is the difference between a provider and a deployer under the EU AI Act?
A provider is an organization that develops an AI system and places it on the market under its own name or trademark. A deployer is an organization that uses a ready-made AI system in its professional activities. Most companies that connect to third-party AI APIs are deployers, not providers. If a company substantially modifies a third-party AI system or markets it under its own brand, it may shift from deployer to provider status, with significantly greater compliance obligations.
How are AI agents classified under the EU AI Act risk framework?
The EU AI Act does not define AI agent as a separate risk category. Risk is determined by what the system does and what consequences its decisions have. A customer support chatbot is limited risk (Article 50 disclosure required). An internal document summarization agent is minimal risk. An HR agent that ranks or filters job applicants is high risk under Annex III. The same LLM API can power systems across all risk levels depending on use case.
What penalties apply for violating Article 50 transparency requirements?
Violations of Article 50 transparency obligations can result in fines of up to EUR 15 million or 3% of total worldwide annual turnover for the preceding financial year, whichever amount is higher. These fines apply to both providers and deployers who fail to meet the disclosure and content marking requirements.
What steps should companies take right now to comply with the EU AI Act?
Companies should start with an AI system inventory to identify all AI tools in use and determine which ones interact with EU users. Next, confirm Article 50 compliance: add AI interaction disclosures to any system that talks directly with people, and implement content marking for synthetic outputs. Clarify your role as provider or deployer for each system. For systems that may qualify as high-risk under Annex III, begin preparation now even though those requirements do not take effect until December 2027.