From 2 August 2026, another large part of the EU Artificial Intelligence Act becomes enforceable.

Across Europe, lawyers have prepared notes. Consultants have prepared invoices. Compliance teams have prepared inventories. Managers have prepared to ask whether the free chatbot used by an intern counts as “high risk.”

Somewhere, an Excel file has already become authoritative.

It contains fourteen columns, three different meanings of “owner” and a drop-down menu that does not include the answer anybody needs.

Europe is ready.

The law is real

The AI Act is not merely a press release. It creates rules for providers and users of AI systems, with different obligations according to the type and level of risk. Some provisions already applied. From 2 August, the Commission's AI Office and national authorities begin enforcing further rules, including transparency requirements for certain AI systems and AI-generated content.

This matters.

AI can influence recruitment, access to services, safety, policing, credit, public information and many other decisions that affect real people. “The algorithm did it” is not an acceptable system of accountability.

Rules are necessary.

The comedy begins when organisations translate rules into internal life.

Policy first, knowledge later

The standard response will be familiar.

A policy will be drafted before anyone maps how AI is actually being used. Training will explain approved terminology. A central register will be created. People will be asked to declare systems they do not recognise as AI and not declare tools they use every day because those look like ordinary software.

The organisation will then possess a policy about a reality it has not yet observed.

Meanwhile, staff will continue using AI quietly because it helps them write, translate, search, summarise, code or analyse. Some use will be sensible. Some will be reckless. The official inventory and the actual organisation will begin drifting apart before the first annual review.

This is how compliance theatre starts: the record becomes cleaner while the reality becomes harder to see.

Five questions before the matrix

Before adding colours, risk scores and approval levels, an organisation needs plain answers:

  • Where is AI already being used?
  • Which decisions or outputs can affect people, money, safety or rights?
  • What information is being given to the system?
  • Who checks the result, and what does “check” mean in practice?
  • What happens when the system is confidently wrong?

These questions are less impressive than a governance framework. They are also harder.

They require talking to the people doing the work. They require admitting that some approved systems are poorly understood and some unapproved uses are useful. They require separating serious risk from institutional nervousness.

Do not outsource judgment to the law

A regulation can set duties. It cannot understand your operation for you.

An AI tool used to improve the grammar of an internal invitation is not the same as a system screening job applicants. A model suggesting spare-parts demand is not the same as one making a medical recommendation. The presence of AI is not the whole risk. Purpose, data, consequence, supervision and reversibility matter.

Organisations that treat every use as equally dangerous will create rules people bypass.

Organisations that treat every use as harmless innovation will eventually discover why the regulation was written.

The work is in the middle: know what the tool does, know where it is used, know who is accountable and know how failure is caught.

The spreadsheet is not the system

The EU has done what legislators do. It has created a legal structure.

Now thousands of organisations will do what organisations do. They will create an administrative structure around it.

Some of that structure will be useful. Inventories, responsibilities, testing, transparency and incident reporting are not bureaucracy by definition. They become bureaucracy when completing them replaces understanding the risk.

The test is not whether every row is filled.

The test is whether the organisation knows where AI can cause harm, whether people can recognise failure and whether somebody has the authority to stop it.

If the answer is yes, the spreadsheet may help.

If the answer is no, please ensure all mandatory fields are completed before Friday.

Current context and image credit

The European Commission states that, from 2 August 2026, the AI Office and national authorities begin enforcing further AI Act rules and new transparency requirements. Some provisions applied earlier, while timelines for certain high-risk systems have been adjusted.

European Commission: AI Act and application timeline →
European Commission: enforcement update →

Hero photograph: EU flags at the European Commission's Berlaymont building by Guillaume Périgois / Unsplash. Cropped for web display.

Original photograph →
Pressure changes shape. The work remains.

Reader discussion

Join the discussion

Comments are moderated. Disagreement and strong opinions are welcome. Spam, threats and personal abuse are not.