EU AI Act Compliance for Companies: What to Do Before 2 August 2026
Just over a hundred days remain until 2 August 2026. From that date, the main provisions of the EU AI Act become fully applicable, which means that AI use is no longer just an innovation question for many companies — it becomes a compliance, operational, and business risk question too.
This is why we are launching Harvey's EU AI Act blog now. Our goal is to show, in plain language but with a practical mindset, what the regulation means for Hungarian companies, who is affected, what obligations it brings, and how to prepare for compliance in time.
In the coming months, we do not want to write theoretical summaries, but practical materials that support enterprise AI adoption, AI audit, AI readiness assessment, and the development of AI governance. We pay particular attention to situations where the protection of business information is a key concern, and where our on-prem solutions help keep information in-house.
Why we focus on this topic
At Harvey's, AI is a core competence area. We have been working with AI-based solutions for years in a range of IT fields — from software development and testing to quality assurance and enterprise applications. Active LLM-based projects, internal professional events, training sessions, and conference appearances also shape our daily work.
We see that more and more Hungarian companies want to take advantage of the business benefits of artificial intelligence, yet many organisations still lack a clear operational framework for introducing these systems safely, transparently, and in a compliance-defensible way.
We firmly believe that AI Act compliance is not merely a legal task. It is a leadership, operational, and technological question as well. This is especially true when the organisation handles sensitive business data, operates in a regulated environment, or considers it important that information stays within the organisation.
The EU AI Act in brief
The EU AI Act — officially Regulation (EU) 2024/1689 — is the world's first comprehensive regulation on artificial intelligence. The European Union's aim is to ensure that AI use is safe, transparent, and respects fundamental rights, without standing in the way of innovation.
One of the regulation's most important features is that it takes a risk-based approach. This means not every AI system is subject to the same obligations: the higher the risk, the stricter the rules.
The 4 risk categories of the AI Act
The EU AI Act uses a risk-based approach: the greater the expected impact of an AI system on people's rights, safety, or life circumstances, the stricter the requirements. The regulation distinguishes four main categories.
1. Unacceptable-risk AI systems
These applications are prohibited. This may include, for example, social scoring, certain forms of subliminal manipulation, or certain biometric identification practices.
2. High-risk AI systems
This category may include uses such as CV screening, credit scoring, medical diagnostics, or AI systems affecting critical infrastructure. Stricter requirements apply to these in terms of documentation, controls, transparency, and conformity.
3. Limited-risk AI systems
These may include chatbots or generative AI solutions, where transparency obligations typically apply — for example, users must be informed that they are interacting with a machine-based system.
4. Minimal-risk AI systems
This category may include solutions like spam filters or AI-assisted video games. For these, the regulation does not prescribe any additional obligations.
Important: classification depends not only on the type of technology, but also on how and in what context the AI system is used. This means that even an AI solution that initially appears to be low-risk or limited-risk may fall under a higher risk classification if used in a process that materially affects people's rights, livelihoods, access, or safety.
That is why it is not enough to say that a given AI tool is "just a chatbot" or "just a support system". The real question is what decisions it supports, what data it works with, whom it affects, and what the consequences of its operation may be. This requires proper risk analysis to uncover the actual compliance and operational risks the AI system carries. This is an area where Harvey's has specific expertise: we support our clients from the angles of AI audit, AI readiness, and risk analysis, so that the classification and adoption of their AI systems rest on a solid foundation.
What is the risk for a company that is not prepared?
The fines can be significant.
- For prohibited AI applications: up to EUR 35 million or 7% of global annual turnover (whichever is higher)
- For other breaches: up to EUR 15 million or 3%
- For misleading information provided to authorities: up to EUR 7.5 million or 1.5%
Although the regulation applies a more proportionate fining approach to SMEs and startups, the real risk is not only financial. Non-compliance can also entail business, reputational, and partner-side risk. In the B2B market especially, enterprise and regulated-industry partners are expected to increasingly ask for evidence that a company's AI use is controlled and properly organised from a compliance standpoint.
Where does the regulation stand today?
The AI Act is not being introduced in one big "entry into force" moment, but gradually.
Key milestones
- 1 August 2024 — The AI Act formally entered into force in every EU Member State.
- 2 February 2025 — Rules on prohibited AI practices took effect, and AI literacy — ensuring staff have sufficient AI knowledge — became mandatory.
- 2 August 2025 — Rules for general-purpose AI models and governance provisions took effect.
- 2 August 2026 — The main provisions of the regulation become fully applicable. From this point, enforcement and sanctioning become significantly sharper.
- 2 August 2027 — Rules for high-risk AI systems embedded in regulated products also take effect.
What is the situation in Hungary?
In Hungary, the NMHH (National Media and Infocommunications Authority) carries out supervisory duties. The Hungarian Parliament adopted the national implementing rules of the AI Act in November 2025, detailing the NMHH's powers and procedural framework.
This means that for domestic companies, the AI Act is no longer a distant European regulatory issue, but a very real operational expectation that takes effect within a foreseeable time frame.
What does this mean in practice for Hungarian companies?
For most organisations, the biggest challenge is not reading the regulation but building it into daily operations.
A company needs to have visibility into, for example:
- what AI systems it currently uses,
- what risk category these may fall into,
- where controls are missing,
- whether internal policies are needed,
- who is accountable for decisions,
- and in which areas stronger data protection or operational controls are justified.
This is where the role of enterprise AI adoption, AI audit, AI readiness, and AI governance comes in. Without these, AI use can easily become fragmented: individual teams adopt tools while there is no uniform operating framework, no documented responsibility, and compliance considerations only surface afterwards.
This is particularly important where the protection of business information is a key concern. In such cases, as part of the AI strategy, it is worth considering which architecture best supports controlled operation at the given organisation. At Harvey's, in these situations we help keep information in-house with our on-prem solutions, so that the handling of corporate knowledge and sensitive data better aligns with the organisation's operational and compliance expectations.
What topics will we cover on the blog?
In the coming months we will cover topics that can provide practical help for Hungarian SMEs and enterprise decision-makers alike.
1. Practical AI Act compliance
Not in legal language, but from an operational perspective, we examine what an organisation actually needs to do. Who is responsible for what? When does a chatbot become a risk issue? Where do companies typically stumble?
2. AI risks and real-world cases
We present international and Hungarian AI incidents from which there are lessons to be learned. These help you understand that the root cause is typically not the technology itself, but missing controls, improper data use, or an inadequate operational framework.
3. AI standards and audit
We introduce the role of standards and frameworks such as ISO/IEC 42001 and ISO/IEC 23894, and how all this connects to AI audit, to AI officer or compliance roles, and to internal control mechanisms.
4. AI readiness and enterprise operations
We will also write about how to assess how ready an organisation is to apply artificial intelligence in a deliberate and responsible way.
5. Controlled AI adoption and on-prem support
We will also explore situations where a general AI tool is not enough, and where the organisation needs a solution that better supports the in-house handling of information and the controllability of operations.
Why is it worth acting now?
Many companies still consider preparation for the AI Act a task that can be postponed. The reality, however, is that for most organisations, preparation is not about producing a single document — it requires several interlocking steps:
- mapping AI usage,
- understanding the risks,
- establishing operational and compliance frameworks,
- and deciding which technological approach best supports the organisation's goals and data protection expectations.
The later this work begins, the harder it becomes to carry out in a structured and business-manageable way.
AI Act compliance is not just a matter for lawyers or IT teams. It is a company-wide task that requires strategic, operational, and technological decisions.
With Harvey's EU AI Act blog, our aim is to help Hungarian companies not only understand the regulation but also translate it into practical steps. We will write about AI risks, the role of AI audit, the development of AI governance, AI readiness questions, and also about the solution directions that support controlled enterprise AI adoption.
In our next article, we will show how it can be determined in a short time which risk category a company's AI systems fall into under the EU AI Act.
Would you like to assess how your organisation is affected by the EU AI Act?
Let's start with a joint review, an AI audit, or an AI readiness assessment.
Request a consultation Request an AI audit
Related resources
Try the AI Act risk classifier
Find out in 5 minutes which risk category your AI system falls into — free, 100% private, with a detailed PDF result.