EU
AI Act

The EU AI Act Is Here — What Software Companies Need To Know

The AI Act is now law

As of February 2, 2026, the first obligations under the EU AI Act became enforceable. If you’re building or deploying AI systems in the European market, this affects you regardless of where your company is incorporated.

What changed in February 2026

The Act rolls out in phases. February 2026 triggered the prohibited practices phase. These are outright banned:

  • AI systems that manipulate human behavior to impair free will
  • Social scoring systems
  • Real-time remote biometric identification in public spaces (with narrow law enforcement exceptions)
  • Emotion recognition in workplaces and education
  • AI that exploits vulnerabilities of specific groups

What you need to do right now

If you’re a SaaS company using AI features (recommendation engines, chatbots, content generation):

  1. Audit your AI features against the prohibited practices list. Most legitimate SaaS products won’t hit these, but document the audit.
  2. Assign an AI compliance officer internally. It doesn’t need to be a full-time role yet, but someone needs to own this.
  3. Update your privacy policy to mention AI processing and automated decision-making.

If you’re building high-risk AI (recruitment, credit scoring, medical diagnosis, critical infrastructure):

  1. Prepare your risk management system documentation
  2. Implement human oversight mechanisms
  3. Begin technical documentation and logging
  4. Register your system in the EU database (deadline: August 2026)

The enforcement reality

The CNIL, BfDI, and other EU data protection authorities now share AI Act enforcement with national market surveillance authorities. The first fines are expected in Q3 2026.

What’s coming next

  • August 2026: General-purpose AI model obligations (GPAI)
  • August 2027: All remaining obligations, including most high-risk AI requirements

The smart play: start now. The documentation burden for high-risk systems is comparable to GDPR’s Article 30 ROPA requirements. If you survived GDPR compliance, you can handle this.