Only 2 days left: the next phase of the EU AI Act takes effect. There is a great deal of fearmongering surrounding the EU AI Act. However, one point needs to be clarified: while the Regulation does not require every company to appoint a “certified AI Officer,” it does impose several other mandatory requirements. These requirements may also affect your company even if you believe that it does not use AI—although, in practice, companies that use no AI at all are becoming extremely rare. And even then, the assessment and control of suppliers remains relevant. Delaying action is no longer a sensible strategy. 2 August 2026 is the next major milestone in the application of the EU AI Act. Companies should therefore be able to present at least a minimum level of documentation. This is also where the GDPR becomes relevant. An AI system may be considered low-risk under the EU AI Act while still creating significant data protection risks under the GDPR. Examples include AI-powered telephone assistants, chatbots, meeting transcription tools, CV-screening systems and generative AI tools. For this reason, every company using AI needs at least proportionate baseline documentation. You do not need to begin with a manual containing hundreds of pages. However, the approach of saying, “We do not know exactly who is using which AI tools,” is no longer sufficient—especially if the competent authority requests your documentation. What do companies need? Transparent, documented and controlled use of AI. This post provides general information and does not constitute individual legal advice. For more information—or support in preparing the required documentation—send me a private message. #EUAIAct #GDPR #AIGovernance #AICompliance #AIOfficer #DataProtection #ArtificialIntelligence #RiskManagement #CorporateCompliance #SME