The EU AI Act Is Now Enforcing — Here Is What Your Business Actually Needs to Do

The EU AI Act’s transparency enforcement rules went live on August 2, 2026. The European Commission’s enforcement powers are now active. If your business uses AI — in customer communication, in document processing, in any automated decision-making — you now have compliance obligations. Fines: up to €15 million or 3% of global annual turnover, whichever is higher.

This is not hypothetical. This is the most significant AI regulation to come into force in 2026 and it affects any business that serves EU or UK customers using AI tools.

What the EU AI Act Actually Requires From September 2026

Transparency Obligation — You Must Tell Users They Are Interacting With AI

If your business uses a chatbot, AI voice agent, AI email responder, or any AI-powered customer-facing system, you must now disclose this to users. The disclosure must be clear, upfront, and not buried in terms of service.

What this looks like in practice: A WhatsApp AI agent must include something like “You are now speaking with an automated assistant. Type HUMAN at any time to speak with a person.” A voice AI must identify itself as AI at the start of the call (unless the nature of the interaction makes this obvious). An email automation that appears to come from a named employee must be disclosed as automated if it constitutes an automated decision.

Risk Categorisation — Most SME Automations Are "Limited Risk"

The AI Act uses a tiered risk system. Most SME customer service, appointment booking, and document processing automations fall into the “limited risk” category — which primarily requires transparency disclosure and does not require the formal conformity assessments reserved for high-risk systems.

High-risk categories that affect more businesses than expected: AI used in recruitment or employment decisions, AI used in credit scoring or loan decisions, AI used in medical diagnosis support. If your automation touches any of these, the compliance requirements are significantly more demanding.

What Changed on August 2 vs What Is Still Deferred

Active from August 2, 2026: Transparency and disclosure obligations. GPAI model compliance (affects the model providers, not most SMEs directly).

Still deferred to 2027-2028: High-risk AI system conformity assessments. This was extended by the EU Digital Omnibus package, giving SMEs additional time.

The Three Things Wority Builds Into Every Automation for EU/UK Compliance

1. Disclosure language built into every customer-facing automation interaction.
2. Human escalation path clearly accessible in every AI-powered customer communication.
3. Audit logging of all automated decisions, retained for a minimum of 12 months in a queryable format.

These three elements are not optional add-ons at Wority — they are standard in every build for UK and EU clients.

What to Do This Week If You Are Already Running AI Automation

Step 1: Audit every customer-facing AI touchpoint. List every instance where a customer interacts with AI — chatbot, voice agent, email automation, WhatsApp bot.
Step 2: Add disclosure language to each. “You are speaking with an automated assistant” is sufficient for limited-risk systems.
Step 3: Confirm human escalation paths are visible and functional.
Step 4: Check your audit logs exist. If your current automation has no audit trail, contact your vendor immediately.
Step 5: For high-risk categories — consult a legal specialist before September 30.

The Silver Lining — Compliant Automation Is More Trusted Automation

Businesses that handle the EU AI Act correctly gain a trust advantage. A customer who knows they are talking to AI and has an easy path to a human is more confident than a customer who discovers the interaction was automated without their knowledge. Transparency builds trust. Build it in from the start.

Q1: Does the EU AI Act apply to UK businesses post-Brexit?

A1: The UK has its own AI regulation framework and did not adopt the EU AI Act directly. However, any UK business serving EU customers through AI-powered tools needs to comply with the EU AI Act for those interactions. The UK government has signalled plans for its own transparency requirements through the AI Safety Institute in 2026-2027.

Q2: What are the fines for non-compliance with EU AI Act transparency rules?

A2: For transparency obligation violations, fines can reach €15 million or 3% of total worldwide annual turnover, whichever is higher. For GPAI model violations: up to €15 million or 3% of turnover. For the highest-risk system violations: €35 million or 7%.

Q3: Does my WhatsApp AI bot need to disclose it is AI?

A3: Yes — under the EU AI Act transparency requirements active from August 2, 2026, any AI system that directly interacts with individuals must disclose its AI nature in a clear and understandable way. Your WhatsApp bot must identify itself as automated.

Q4: What is a "limited risk" AI system under the EU AI Act?

A4: Limited risk systems are those that interact with users but are not making consequential decisions about them (like employment or credit). Most customer service chatbots, appointment booking bots, and FAQ systems are limited risk, requiring disclosure but not formal conformity assessment.

Need EU AI Act compliant automation?

Every Wority build includes transparency disclosure architecture, human escalation paths, and audit logging as standard. 

Book a free compliance review call