Back to blog

The EU AI Act: what the latest changes mean for your business

From the 2nd August 2026, new EU AI Act requirements will apply to businesses using AI.

The act states that if your organisation uses AI, you need to understand what AI tools are being used across your business, what data they’re handling and whether you have the right controls in place.

However, this latest phase of the act now means there’s now real accountability to how companies use and manage AI.

Here’s what’s changed, and what both your team and senior leaders need to know.

What’s changing?

Businesses using AI will have new transparency requirements to consider, including informing people when they’re interacting directly with AI and identifying certain AI generated or manipulated content.

If your business uses AI chatbots or creates images, audio or video using AI, you’ll need to understand whether these requirements apply to how you’re using these tools and what controls you have in place.

The requirement varies depending on the type of AI system being used. High-risk AI systems have separate requirements and later application dates.

For many organisations, the starting point is understanding what AI is being used across your organisation, what it’s being used for and what data is involved.

What questions should you be asking? 

AI is already being used across businesses, but do you know exactly how it’s being used across your organisation?

Without full visibility it can be difficult to understand which tools employees are using, what data is being shared and whether the right controls are in place.

If you’re not sure where your organisation stands, there are some simple questions you can start with:

  • Do you know which AI tools your staff are using?
  • Do you know what company data is being shared?
  • Do you have clear guidance around acceptable AI use?
  • Have your employees been trained to use AI responsibly?

The EU AI Act places importance on ensuring employees have the knowledge the need to use AI safely and responsibly.

Where should you start?

To use AI safely and effectively, it’s important to understand whether your organisation has the right foundations in place.

Gartner found that 63% of organisations either don’t have the right data management practices for AI or aren’t sure whether they do. The same research predicts that through 2026, six in ten AI projects will be abandoned because the underlying data simply wasn’t ready.

We’ve put together an AI readiness checklist to help you do just that.

The checklist covers four areas:

  • Data quality and accessibility: is your data accurate, accessible and ready for AI?
  • Governance and compliance: do you have the right policies, controls and oversight in place?
  • AI readiness: are your systems and people ready to use AI safely and effectively?
  • Strategic alignment: do you have a clear roadmap for AI adoption?

Get the free checklist here

What good AI looks like?

Effective AI governance means having a clear view of the AI tools being used across your organisation, the data those tools can access and the controls in place to manage their use.

AI use should be reviewed regularly. New AI tools can introduce new risks, so keeping track of how AI is being used is essential.

How can Arc help?

The first step to managing AI risk is understanding how AI is being used across your organisation.

If you’ve used our AI readiness checklist, you’ll have a clearer picture of where your organisation stands and where there may be gaps.

Arc can help you address those gaps, from understanding your AI environment to managing the security, compliance and data risks that come with it.

If you’d like to discuss your AI environment or even where you should start, our team is always here to help.