When No One Was Looking, the Rules Changed

Why the EU AI Act is already in effect – and why most organizations haven't noticed yet

By Monday morning, the presentation is already done. The numbers come from the dashboard, the summary from the AI assistant, the forecast from a model somewhere between the cloud and the data center. No one explicitly commissioned it. It was simply — there. This is not an exception. It's the new normal in most organizations today, and since February 2, 2026, that normal has a problem.


What is the EU AI Act — and who does it really affect?

The EU AI Act (Regulation (EU) 2024/1689) is the world's first comprehensive AI regulation. It applies to every organization that deploys, develops, or markets AI systems in the EU — regardless of where they are headquartered. Artificial intelligence didn't arrive in most companies — it slipped in. Not through projects with steering committees and go-live dates, but through updates no one noticed, features that simply worked, workflows that quietly optimized themselves.

The result: AI is now operational reality. But who is responsible for it, who monitors it, who stops it when in doubt — that's still an open question in most organizations.

The more self-evident AI becomes, the less it gets talked about. Not its limits. Not its assumptions. Certainly not accountability. Until now.

February 2, 2026: The date almost no one marked

February 2, 2026 didn't stop any systems. Didn't change any processes. Didn't trigger any alarms. But it shifted the standard by which everything is judged — retroactively, to everything already in use today. As of this date, core parts of the EU AI Act are now applicable: certain AI practices are prohibited, and companies must ensure that the use of AI is understood — not in the abstract, but in concrete operations.

As of February 2, 2026:

  • AI in use must be identifiable
  • AI in operation must be explainable
  • AI in decisions must be traceable

Not perfectly documented. Not exhaustively controlled. But consciously operated. The AI Act removes one comfortable line of defense: we don't quite know yet. Not knowing is no longer a neutral state — it's a gap someone will be asked to close.

Which AI practices are prohibited under the EU AI Act?

At first glance, the prohibited AI practices look like extreme cases: social scoring by public authorities, manipulative systems that exploit vulnerabilities, real-time biometric surveillance in public spaces. Hardly any company would claim to knowingly deploy systems like that.

But that's exactly the trap. AI rarely shows up as a clearly delineated system. It's embedded in recommendation algorithms, prioritization logic, personalization features — often bought, not built.

So exposure isn't a matter of gut feeling — it's a matter of proof. Proof that you can explain: which AI functions are in use, what they're used for, and why they don't fall under the prohibited practices. Without that overview, a gray zone opens up — and that gray zone is exactly where regulation starts to bite.

When AI becomes infrastructure: the three questions that can't be delegated

Take a system that's long since become part of daily operations: a forecast that prioritizes orders, consolidates metrics, and prepares decisions — run on the IT platform, developed by a vendor, used by the business unit, updated via software update. Until now, this setup was functional. And invisible. No one had to name the fact that AI was at work here.

The EU AI Act makes three questions unavoidable:

  • Which AI systems are actually in operation — not on the project plan, but in real use?
  • What are they used for — and where do their outputs take effect?
  • Who is accountable — once that effect becomes relevant?

These questions can't be delegated. Not to Legal. Not to Compliance. Not to later.

What does AI literacy mean under the EU AI Act — and why isn't training enough?

AI literacy is often confused with e-learning modules. Slides, certificates of attendance, a checkbox on the compliance list. In reality, AI literacy shows up at the moment of decision: when a forecast deviates unexpectedly — does someone follow it blindly, or does someone ask questions? When an AI system makes a recommendation — is it clear who owns it?

When a model delivers a result whose limits no one knows — does anyone even notice? AI literacy isn't built from knowledge about AI. It's built from working with it — at the point where decisions are being prepared, and someone is willing to actually carry them.

Operations run. The systems deliver. But who is responsible when one of them fails — and no one can explain why?

Which industries need to act fastest under the EU AI Act?

In regulated environments — financial services, healthcare, public administration — accountability has been part of operations for years. Decisions must be explainable to regulators, auditors, or political bodies.

Other industries aren't used to that. There, the result is often enough on its own. The EU AI Act shifts that comfort zone: what used to count as technical support now requires an explanation the moment it prepares a decision — regardless of industry.

A quiet turning point — with loud consequences

Not everything needs to be regulated. But nothing can stay unclear anymore.

The EU AI Act marks the shift from implicit trust to accountability that holds up under scrutiny. It doesn't arrive as a shock, but as a shift. Quiet — but irreversible. Anyone running AI today without being able to name it is sitting on a risk that keeps growing — quietly, in the background, just like the systems themselves.

Being accountable for AI means being able to run it

At M2, we accompany this transition not as a legal authority, but along a clear structure: from solid data quality through AI enablement to stable, auditable operating models.

Our focus isn't on abstract compliance, but on the question that actually matters: is your AI running reliably, scalably, and auditably? Only once data quality is secured, responsibilities are clear, and governance is technically anchored does what the EU AI Act requires actually emerge: operations that are explainable — not just on request, but by their own design.

Learn more

 

FAQ: The most common questions about the EU AI Act

This section answers the questions companies, IT leaders, and executives ask most often.

❓ When does the EU AI Act take effect for companies?
Since February 2, 2026, the first prohibitions and requirements of the EU AI Act have been in force. Obligations for high-risk AI systems will follow in stages through 2027. Companies shouldn't wait for later deadlines — the baseline requirements for transparency and accountability already apply now.

❓ Am I affected by the EU AI Act as a company if I don't develop my own AI?
Yes. The EU AI Act applies not only to AI developers, but to every company that deploys AI systems — including users of third-party solutions, SaaS tools with AI features, or purchased models. If you use AI in operations, you're potentially affected.

❓ Which AI practices are prohibited under the EU AI Act?
Prohibited practices include: social scoring by government bodies, manipulative AI systems that exploit vulnerabilities, real-time biometric surveillance in public spaces, and AI for emotion recognition in the workplace or in educational institutions. The full list can be found in Article 5 of the Regulation.

❓ What does AI literacy mean under the EU AI Act?
The EU AI Act requires companies to ensure that employees who use AI have sufficient knowledge and understanding — so-called AI literacy. In practice, this means employees must understand what the system does, what its limits are, and when human judgment is required.

❓ What is a high-risk AI system under the EU AI Act?
High-risk AI systems are those deployed in critical areas: HR decisions, credit lending, medical diagnostics, critical infrastructure, law enforcement, or education. These systems are subject to particularly strict requirements for documentation, transparency, and human oversight.

❓ What penalties apply for violations of the EU AI Act?
Violations of the prohibition provisions can result in fines of up to €35 million or 7% of global annual turnover. Other violations carry fines of up to €15 million or 3% of turnover. Reduced caps apply for SMEs.

❓ How does the EU AI Act differ from the GDPR?
The GDPR governs the protection of personal data. The EU AI Act regulates AI systems as such — regardless of whether personal data is being processed. The two frameworks complement each other but don't replace one another. An AI system can be GDPR-compliant and still violate the AI Act.

Related News