{"id":216,"date":"2026-06-26T20:56:41","date_gmt":"2026-06-26T18:56:41","guid":{"rendered":"https:\/\/anvaconsulting.eu\/ai-i-compliance-2026-sto-donosi-eu-ai-act-i-kako-se-pripremiti\/"},"modified":"2026-07-21T12:47:15","modified_gmt":"2026-07-21T10:47:15","slug":"ai-and-compliance-2026-what-the-eu-ai-act-brings-and-how-to-prepare","status":"publish","type":"post","link":"https:\/\/anvaconsulting.eu\/en\/ai-and-compliance-2026-what-the-eu-ai-act-brings-and-how-to-prepare\/","title":{"rendered":"AI and compliance 2026: what the EU AI Act brings and how to prepare"},"content":{"rendered":"<p>AI is no longer just a \u201ctool\u201d; it increasingly influences hiring, credit decisions, customer support, security and marketing. The EU AI Act introduces a framework of obligations and responsibilities for entities that develop, market or use AI systems. Those who prepare in time reduce regulatory risk and can more easily introduce AI into their processes.<\/p>\n<h2>Who is subject?<\/h2>\n<p>In practice, business entities are most often in the role of:<\/p>\n<ul>\n<li>deployer (user of AI systems) \u2013 uses AI in business processes<\/li>\n<li>provider (developer\/brand owner of AI) \u2013 develops or puts AI on the market under their own name<\/li>\n<li>or participant in the supply chain (integrators, distributors).<\/li>\n<\/ul>\n<h2>Risk classification: a key question<\/h2>\n<p>The obligations depend on the risk level of the AI system. Particularly sensitive are high\u2011risk systems (e.g., in certain areas of recruitment, education, healthcare, critical infrastructure). In practice the first step is to inventory AI tools and assess whether they fall into risk categories.<\/p>\n<h2>Governance: who \u201cowns\u201d AI?<\/h2>\n<p>Good AI compliance is not reduced to a single document. Best practice is to:<\/p>\n<ul>\n<li>appoint responsible persons (legal, IT\/security, HR, product)<\/li>\n<li>set rules for procurement and approval of AI tools<\/li>\n<li>introduce a registry of AI systems and their purposes.<\/li>\n<\/ul>\n<p><strong>Documentation<\/strong> and auditability (audit trail)<\/p>\n<p>Regulatory risk often arises when a business entity cannot prove:<\/p>\n<ul>\n<li>why a tool was introduced<\/li>\n<li>what data it uses; how quality and bias are controlled<\/li>\n<li>who oversees the outputs of AI (human oversight).<\/li>\n<\/ul>\n<p><strong>AI and GDPR: overlaps that are often overlooked<\/strong><\/p>\n<p>If AI processes personal data, GDPR obligations remain: legal basis, transparency, minimisation, retention periods, security and data subject rights. A particularly important question is automated decision\u2011making and profiling.<\/p>\n<p><strong>Practical preparation steps<\/strong><\/p>\n<ul>\n<li>List AI tools (including hidden ones in SaaS).<\/li>\n<li>Define their purposes and assess the risk level.<\/li>\n<li>Introduce an internal procedure for AI approval and vendor due diligence.<\/li>\n<li>Align contracts with suppliers (security, sub\u2011processors, data transfers).<\/li>\n<li>Update privacy notices and internal policies.<\/li>\n<li>Provide training for teams (HR, product, sales).<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>AI is no longer just a \u201ctool\u201d; it increasingly influences hiring, credit decisions, customer support, security and marketing. The EU AI Act introduces a framework of obligations and responsibilities for entities that develop, market or use AI systems. Those who prepare in time reduce regulatory risk and can more easily introduce AI into their processes. [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":214,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[2],"tags":[],"class_list":["post-216","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"acf":[],"_links":{"self":[{"href":"https:\/\/anvaconsulting.eu\/en\/wp-json\/wp\/v2\/posts\/216","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/anvaconsulting.eu\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/anvaconsulting.eu\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/anvaconsulting.eu\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/anvaconsulting.eu\/en\/wp-json\/wp\/v2\/comments?post=216"}],"version-history":[{"count":2,"href":"https:\/\/anvaconsulting.eu\/en\/wp-json\/wp\/v2\/posts\/216\/revisions"}],"predecessor-version":[{"id":219,"href":"https:\/\/anvaconsulting.eu\/en\/wp-json\/wp\/v2\/posts\/216\/revisions\/219"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/anvaconsulting.eu\/en\/wp-json\/wp\/v2\/media\/214"}],"wp:attachment":[{"href":"https:\/\/anvaconsulting.eu\/en\/wp-json\/wp\/v2\/media?parent=216"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/anvaconsulting.eu\/en\/wp-json\/wp\/v2\/categories?post=216"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/anvaconsulting.eu\/en\/wp-json\/wp\/v2\/tags?post=216"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}