0
← Journal index

AI / Wanderings 2026

Rulebook

The EU AI Act is already changing product design and procurement. A practical guide for founders to classification, evidence, trust and the new 2026 timetable.

By Martin Uetz7 min read
A luminous cube follows an amber route through transparent testing and review stations on a workbench.

On 27 July 2026, the EU's AI Omnibus entered into force. Two days before I wrote this, Europe changed the timetable of its own AI Act.

Rules for stand-alone high-risk systems, including many systems used in recruitment, education, credit and public services, now apply from 2 December 2027. Rules for high-risk AI embedded in regulated products move to 2 August 2028. The reason was practical: companies were approaching the old deadline without all the standards and guidance required to comply.

That episode says a great deal about European AI policy. The ambition is sensible. The machinery takes time.

The useful response for founders is to treat the Act as a product design discipline, provided Europe keeps implementation clear, common across countries and proportionate for smaller companies.

Start with the use case

The AI Act is easier to understand once you stop treating every use of AI as the same thing.

Most AI systems in Europe fall into the minimal or no-risk category. A spam filter, an AI-enabled game or an internal tool that summarises meeting notes will usually avoid the obligations applied to high-risk systems.

The picture changes when AI helps decide whether somebody gets a job, a place at university, access to credit, an essential public service or fair treatment at a border. It also changes for certain biometric applications and for AI used in some regulated products, including medical devices, when the product or its safety component requires third-party conformity assessment.

The same underlying model can sit inside a low-risk writing assistant and a high-risk recruitment product. The model matters. The purpose, people affected and consequence of an error matter more for classifying the system.

Founders therefore need four basic answers:

  1. What does the system do?
  2. Who is affected by its output?
  3. Does it recommend, rank or make a decision in a protected or sensitive area?
  4. Are we the provider, deployer, importer or distributor under the Act?

Write the answers down. A one-page classification memo prepared while the product is young is worth far more than a compliance archaeology project late in procurement.

The Act has already entered the building

Some obligations are already in force. Prohibited practices and the first AI literacy duties started applying in February 2025. Rules for providers of general-purpose AI models started in August 2025. Transparency duties under Article 50, including disclosures for chatbots and marking certain generated content, start on 2 August 2026. The new Omnibus gives some systems already on the market until 2 December 2026 to complete specific marking requirements.

Organisational work continues during the delay.

By July 2026, more than 230 companies had signed the Commission's voluntary AI Pact. The core pledges include an AI governance strategy, an inventory of systems that may be high-risk and AI awareness among staff. Model providers including Amazon, Anthropic, Google, Microsoft, Mistral and OpenAI have signed the voluntary General-Purpose AI Code of Practice, although participation differs by chapter.

These numbers will change. The behaviour behind them matters more. Companies are mapping systems, assigning owners, checking vendors, documenting data and deciding where human review belongs.

In regulated industries, those questions are also entering procurement. A bank, hospital or public authority wants to know which model you use, where its data goes, how you test errors, whether a person can override the system and what happens when the model changes.

Founders who can answer promptly will move faster than founders who send the questionnaire around the company and disappear.

Compliance can be part of the product

Compliance can become a tax on innovation. A small company can spend an absurd amount of time proving that it has thought carefully about a risk while a large company assigns the form to floor seven.

There is another commercial effect. Clear controls can reduce the work a customer must do before buying.

For a serious business-to-business AI product, the evidence pack should grow with the software:

  • the intended purpose and excluded uses;
  • the risk classification and reasoning;
  • model and vendor records;
  • data sources and retention rules;
  • test results, known limitations and failure cases;
  • logging, human review and override mechanisms;
  • version history and an incident contact.

This material helps with compliance. It also answers the buyer's security review, legal review and board questions. A founder who treats it as product documentation gains speed during a sale.

The Act can also give Europe a market advantage. One directly applicable framework is easier to design around than 27 unrelated national regimes. Common standards can make a compliance investment reusable. A product tested for European employment, health or industrial requirements can carry a credible trust signal into other markets.

That advantage depends on consistent enforcement and useful standards. Twenty-seven interpretations of one law would recreate the problem under a smarter logo.

Europe has corrected part of the burden

The July 2026 Omnibus is an admission that the original schedule moved ahead of the support system. It delayed high-risk dates, extended some simplified requirements from small and medium-sized companies to small mid-cap companies, expanded access to regulatory sandboxes and strengthened central oversight by the AI Office.

This is welcome. Rules without standards create expensive guessing.

The burden remains real. The AI Act sits beside data protection, consumer law, cybersecurity rules, product safety and sector regulation. A health startup can meet the AI requirements and still have several other legal mountains in front of it. A recruitment founder must think about discrimination and labour law as well as model documentation.

Large companies can employ teams to interpret the overlap. Small companies need common templates, fast answers from regulators and sandboxes that work at startup speed. The Commission's AI Act Service Desk and planned national sandboxes can help. Founders should judge them by response time and usable decisions. Webinar counts tell us little.

Europe should also resist paper compliance. A beautiful risk file cannot rescue a bad system. Testing, logging and human oversight have to work when a real person is denied a job or receives a wrong credit decision.

The American and Chinese comparison

The United States made its current preference explicit in the July 2025 AI Action Plan: remove federal barriers, accelerate infrastructure and drive adoption. China's mandatory rules for labelling AI-generated content took effect in September 2025.

So the familiar picture of regulated Europe, free-market America and unregulated China is too lazy. All three regulate. They choose different targets, institutions and speeds.

American founders currently receive a louder political signal to build first. Chinese companies already work under a national content-labelling standard that reached the market before Europe's Article 50. European founders receive a detailed map of unacceptable and high-risk uses, then wait for parts of the legend to be published.

Speed matters. Clear rules matter too, especially when AI enters hiring, healthcare, finance and public administration. Europe can turn compliance into reusable infrastructure: shared standards, testing tools, model evaluation, audit trails, data provenance, content marking and practical regulatory advice. Requiring each startup to invent these controls alone will waste the advantage.

This creates a market for companies that make the Act easier to follow. It also creates room for European vertical AI products whose selling point is evidence, control and suitability for a regulated workflow.

What I would do as a founder

Keep a live inventory of every AI system used in the product and inside the company. Include shadow tools discovered through staff conversations alongside software approved by management.

Classify the use case early and revisit the classification when features, models or customers change. A harmless assistant can become a high-risk decision system through one enthusiastic product update.

Choose vendors with documentation, data controls and change notifications. A cheap model becomes expensive when nobody can explain its training, retention or version history to a customer.

Build human review as a real workflow. State who reviews, what they can see, when they must intervene and whether they have authority to reverse the output.

Save the evidence while producing it. Test results, decisions, model versions and incidents are much easier to record now than reconstruct later.

Keep the effort proportionate. A low-risk internal tool does not need a miniature regulatory ministry. A product deciding access to work, credit, education or care deserves serious controls and specialist advice.

Long compliance manuals add little. Europe can win valuable markets by making advanced systems safe enough to use where mistakes damage lives and institutions.

Build something a European bank, hospital, school or public authority can buy without asking its lawyers to spend six months inventing the controls around it. That is a product advantage worth having.