ArticlesAI and automation
AI in business 2026: the AI Act's rules of the game and where the real benefits are
4 August 2026 · 5 min read

The EU’s AI Act became broadly applicable on 2 August 2026. Shortly before that, at the end of July, an amending regulation entered into force and postponed some of the obligations. The news coverage has been confusing, so here is a summary of what is in force right now — and what your company should get out of AI beyond the legal paragraphs.
What do you actually need to know about the AI Act?
The AI Act is an EU regulation that governs the development and use of AI on a tiered, risk-based scale. Most of the rules concern so-called high-risk systems, which are used for example in recruitment, credit decisions or critical infrastructure. For an ordinary company that uses AI to produce text, serve customers or make its own work more efficient, the obligations are considerably lighter.
The regulation has entered into force in stages. Prohibited practices, such as manipulating people and social scoring, along with the obligation to ensure staff AI literacy, have been in force since 2 February 2025. The rules on general-purpose AI models, such as large language models, took effect on 2 August 2025.
What changed on 2 August 2026, and what was postponed?
Under the original timetable, almost the entire regulation would have become applicable on 2 August 2026. In July 2026, however, the EU adopted the so-called digital omnibus regulation (EU) 2026/1744, which was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. It postponed the obligations for high-risk systems: the obligations for standalone high-risk systems, such as recruitment AI, begin on 2 December 2027, and those for systems embedded in products on 2 August 2028.
The transparency obligations, on the other hand, became applicable on schedule on 2 August 2026. In practice they concern every company that uses AI: people must be told when they are dealing with an AI, and content produced or edited with AI, such as a realistic-looking image or voice, must be labelled. The part concerning machine-readable marking of synthetic content was given a transition period until 2 December 2026 for models already on the market.
In Finland, supervision of the regulation was arranged through national laws that entered into force on 1 January 2026. Supervision is divided among several authorities by sector, and Traficom acts as the national single point of contact.
What obligations does an SME have right now?
If your company does not develop AI systems and does not use them for high-risk purposes, the list is short and manageable:
- Don’t use prohibited practices. These are extreme cases that an ordinary company won’t encounter in everyday work.
- Ensure staff AI literacy — meaning that the people who use AI in their work understand the possibilities and limits of the tools.
- Be transparent: tell customers when they are chatting with a bot, and label realistic-looking AI-generated content.
Transparency is the one that touches everyday work the most, so here is a concrete example. If your website has a customer service bot, it is clearly stated alongside it that the conversation partner is an AI. If a realistic-looking image or video is produced with AI for marketing, it is labelled as AI-generated. Ordinary text drafting or translation that a person reviews and publishes in their own name is not covered by the labelling obligation.
If, on the other hand, you are considering AI for recruitment, personnel assessment or other decision-making concerning people, it may count as high-risk use. The obligations begin on 2 December 2027, so there is time to prepare, but when making purchases it is already worth confirming that the vendor knows the requirements.
Where are the benefits of AI found in everyday work?
Regulation is a small part of the picture, and the bigger question is where AI is actually worth putting to work. In our experience, the benefits are rarely found in flashy experiments and most often in mundane, recurring tasks: drafting proposals and documents, routine customer service replies, meeting notes, retrieving information from your own systems and speeding up software development.
A good approach is the same as in any other development work: find a step that recurs often and takes time, try AI on it in a limited way, and measure whether it genuinely saves time. A successful experiment is expanded, a failed one is stopped. That way AI becomes one tool among others instead of disconnected theatre.
How do you get started in a controlled way?
Three things are worth doing: write down where AI is already used in your company, draw up a short set of ground rules for staff, and pick one clear use case to trial. This also fulfils the spirit of the regulation, since transparency and competence are exactly what the law requires.
The mapping stage often surprises: in many companies AI is used far more widely than management knows, because employees have adopted tools on their own. That is not a problem but a starting point, from which ground rules can build a managed whole without banning working methods anyone has found genuinely useful.
If you would like a sparring partner on what is worth automating in your company’s everyday work and what is not, Developit’s AI services help you find the areas where the benefit is real — and implement them so that the rules of the game are in order from day one.
Read next
Websites and graphic designIs your company found in AI search? The new visibility game for websitesRead the article
Tailored trainingAI Literacy Is Now the Employer’s Duty – How to Train Your Team RightRead the article
AV technology and live productionsA successful hybrid event: the technical checklist that keeps your stream aliveRead the article