Skip to main content

Back to Insights Educational article

AI Compliance and Risk in 2026: What Actually Matters for a Mid-Market EU Operator

The EU AI Act is in force; most of what mid-market operators worry about is not the part that matters.

Last updated: May 24, 2026 Compliance

~11 min read Reading time 7 Sections Guide Long-form guide

01 Where we sit

What is actually in force right now

We run A&M Flow from inside the EU, so I read the AI Act with a European DPA inbox in mind, not a hypothetical California one. Here is the calendar that matters as of mid 2026. The text people keep arguing about is Regulation (EU) 2024/1689, the consolidated EU AI Act on EUR-Lex. It entered into force on 1 August 2024. The Article 5 prohibitions (social scoring, certain biometric categorisation, untargeted facial scraping) bit on 2 February 2025. The General Purpose AI rules under Chapter V started applying on 2 August 2025. The big block, high risk Annex III systems under Article 6, only becomes fully binding on 2 August 2026, and the rest of the Act reaches full application on 2 August 2027.

If you are running a B2B SaaS, a logistics outfit or an internal copilot built on top of OpenAI or Mistral, you almost certainly sit under the limited risk transparency duties in Article 50 plus GDPR. That is much narrower than what most consultancies are selling you a programme for. The Future of Life Institute keeps a clean tracker at artificialintelligenceact.eu if you want to confirm a specific obligation date without paying a law firm to do it for you. None of this is legal advice; if you sell HR software, credit scoring or anything touching Annex III, please talk to a lawyer.

The other date worth pinning to a wall is 2 May 2025, when the GPAI Code of Practice was released. It is voluntary, but model providers like OpenAI and Anthropic that sign it get a presumption of conformity under Chapter V. For you as a deployer that mostly translates into: ask your LLM vendor whether they have signed the Code, and keep the answer in your vendor file. It is a cheap piece of paper that closes a question auditors will eventually ask.

02 Two regimes

EU AI Act sits on top of GDPR, not instead of it

FIG. 01 – HOW THE TWO REGIMES OVERLAP GDPR vs EU AI Act for an LLM workflow

  • GDPR (2016/679) – EU AI Act (2024/1689)
  • What it polices – Processing of personal data – Design and use of AI systems by risk tier
  • Who enforces – National DPAs (UODO in Poland, Garante in Italy, CNIL in France) – AI Office in Brussels plus national market surveillance authorities
  • Hits LLM users via – EDPB ChatGPT taskforce report, Italian Garante's March 2023 block, training data complaints – Transparency duties (Art. 50), GPAI obligations on the model provider
  • Max fine – 4% of global turnover – 7% of global turnover for prohibited uses

The Garante shut ChatGPT down in Italy in March 2023 on GDPR grounds, not under any AI specific law, and that is still the most concrete enforcement event the European LLM market has lived through. The pattern I keep seeing in our pipeline is operators who are panicking about the AI Act while their actual exposure is a sloppy DPA with a US LLM vendor and no record of which prompts ship customer data abroad. The European Data Protection Board guidance lives at edpb.europa.eu and it is more useful for the next twelve months than any AI Act commentary.

03 Risk tiers

Where your system probably sits

FIG. 02 – ANNEX III HIGH RISK CATEGORIES What pulls a system into Article 6 high risk

  • Tier – Typical mid-market example – What you owe
  • Prohibited (Art. 5) – Workplace emotion recognition, social scoring, untargeted face scraping – Do not deploy. Fines up to 7% of global turnover.
  • High risk (Annex III) – CV screening, credit decisioning, education grading, critical infrastructure control – Risk management system, technical documentation, logs, human oversight, conformity assessment
  • Limited risk (Art. 50) – Customer support chatbot, AI generated images, voice cloning – Disclose to the user that they are interacting with AI or seeing synthetic content
  • Minimal risk – Internal RAG over your own docs, spam filter, AI in dev tooling – Voluntary codes only. Still owes GDPR and confidentiality.

Most things our prospects call AI sit in the bottom two rows. A copilot that drafts replies for a support agent is limited risk; the same copilot used to auto reject job applicants is high risk. That distinction is not in the model, it is in the deployment, and it is one of the better arguments for the framing in AI agents vs chatbots vs copilots when you scope a project.

04 Contrarian

Most AI governance committees are theatre

An opinion, not a regulation

I have sat in a few of these committees. They produce policy PDFs, a vendor risk template and quarterly minutes. None of that protects you if a regulator or a plaintiff asks where customer PII ended up. The only artefact I have seen that actually moves the needle is a current data flow diagram showing every place your LLM context window is assembled, what fields go in and where the response is logged. If you cannot draw that on one page, your governance committee is decoration.

The follow up question I get is whether this means policies are useless. They are not, but the order matters. A policy that references a system you have not actually mapped is the kind of paper a plaintiff's lawyer will enjoy reading back to you in deposition. Map first, then write a policy that matches the map, then form a committee to review proposed changes against the map. Done in that order the committee earns its keep. Done in the standard order it produces compliance theatre that creates exposure rather than reducing it. Most of the operators I talk to do not want to hear this because the committee has already been announced internally.

A specific example to make this concrete. A mid sized European retailer I will not name spent six months in 2025 building an AI ethics charter, a model risk taxonomy and a quarterly review cadence with three external advisors. The same team could not, when asked in week one of an actual incident, produce a list of which Slack channels had OpenAI integrations pointed at customer ticket text. Two of those integrations were running on a personal API key belonging to a former employee. The charter survived the incident, the personal key did not, and the regulator's questions were entirely about the second. The point is not that charters are wrong; it is that the order of effort was inverted relative to the actual risk.

“ If your data flow diagram does not show every place LLM context is built, your governance committee is decoration.

05 Outside the EU

The US and UK look like noise from inside the EU

The US still has no federal AI law. What it has is a patchwork: the NIST AI Risk Management Framework (a voluntary reference document at nist.gov), Colorado's SB 24-205 on consequential decisions which lands in February 2026, the New York City local law 144 bias audit requirement for automated hiring tools and a fair number of state AG enforcement actions under existing consumer protection statutes. The UK has gone the opposite direction with the pro innovation white paper approach and no horizontal Act so far.

For a Polish or German operator selling into the US, the realistic checklist is: meet NIST AI RMF in your documentation because RFPs ask for it, run a bias audit if you do automated hiring in NYC, and read Colorado before you ship credit, insurance or healthcare decisioning there. None of it changes what you owe under the AI Act at home.

06 Tooling reality

Governance platforms are not a substitute for plumbing

There is a growing market of AI governance platforms. Credo AI, Holistic AI and Fiddler AI are the names you will see most often in an RFP. They are decent inventory and policy tools, and Credo AI in particular has a sensible mapping from the AI Act articles to controls. None of them produce the artefacts that actually save you in an enforcement event. Those come from your engineering side: prompt and response logging with retention, a model registry that records which version answered which request, redaction at the gateway and a kill switch you have actually tested.

Talking to operators in production, the order I would buy in is: gateway logging first, model registry second, policy platform third. Most procurement teams do this backwards because the platform is the thing with the demo and the sales team. If you want a sense of how this fits into a delivery budget rather than a separate compliance line, the breakdown in what AI implementation actually costs puts compliance work where it usually belongs, inside the build, not bolted on.

A few concrete picks at the gateway layer worth knowing about. Cloudflare AI Gateway is free up to a generous limit and gives you logging, caching and basic redaction for most major LLM providers. Portkey and Helicone are paid tools in the same space with deeper observability and prompt management. For a regulated workload I would put logs into your own object storage with a retention policy you actually defined, not the vendor's default. Eighteen months is the floor I would defend for an Article 6 case; thirty six is what I would set if the use case touches employment or credit. None of these are governance platforms; they are plumbing, and the plumbing is what the regulator will ask to see.

07 How we work

How we would actually approach this for a mid-market EU operator

From the few we have deployed, the shape that works is: classify each system against Article 6 and Annex III in week one, write a one page data flow per system, put logging and redaction at a single gateway before you write any policy and only then go shopping for a governance platform if procurement insists. The total time for a mid-market estate of five to ten AI use cases is roughly four to six weeks of focused work, not a quarter of consultancy. The cost dwarfs whatever a single Annex III enforcement action would do to your insurance premiums, which is usually the framing that gets a CFO to sign.

One last note on scope. Most of the operators I talk to also have shadow AI: marketing using ChatGPT on personal accounts, sales pasting deal notes into Gemini, support staff copying tickets into Claude. None of that shows up in your inventory unless you ask. We treat the first week as discovery for shadow AI alongside the formal systems, because the legal exposure from a marketing intern pasting a customer list into a consumer account is identical to the exposure from a sanctioned deployment with a bad DPA. If you want to talk through your specific case, our contact page is the right entry point and the services overview shows where compliance reviews sit in a normal A&M Flow engagement. Still not legal advice; for anything in Annex III, please put a lawyer on the team early.

Related reading

Frequently Asked Questions

We are based in the EU and use OpenAI. Are we already breaking the AI Act?+ Almost certainly no, unless you are doing something in Annex III like CV screening or credit decisions. For a normal SaaS or support use case your obligations are Article 50 transparency plus GDPR. Talk to a lawyer if your use case is borderline. When does the high risk part of the AI Act actually bite?+ 2 August 2026 for Annex III high risk systems, with full application of the rest of the Act on 2 August 2027. The GPAI obligations on model providers already apply since 2 August 2025. Do we need a separate AI governance committee?+ Most mid-market companies do not. A named owner, a data flow diagram per system and gateway logging will protect you better than a committee that meets quarterly. The committee can come later once you have artefacts worth reviewing. Does GDPR or the AI Act win when they conflict?+ They are designed to stack rather than conflict. GDPR governs the personal data processing; the AI Act governs the system around it. So far the concrete enforcement against LLM use in Europe (Italian Garante on ChatGPT in 2023) has come from GDPR, not the AI Act. See our notes on partner selection for what to ask a vendor about both. Do we need a governance platform like Credo AI or Holistic AI?+ Only after logging and a model registry are in place. The platforms are useful for inventory and policy mapping; they do not produce the engineering artefacts that protect you in an enforcement event. Is anything in this article legal advice?+ No. This is an opinion piece from an EU-based AI delivery shop. For anything in Annex III, anything cross-border with the US and anything involving health, credit or employment decisions, get a qualified lawyer on the team.

ANM SOLUTIONS / CONTACT US

Need help applying this to your business?

We turn AI insights into measurable business outcomes. Tell us about your workflow and we'll show you the highest-impact place to start.

Related Articles

AI Adoption

The Hidden Cost of Not Using AI, Honestly Counted

The cost of ignoring AI is real but narrower than the doom pieces claim. A practitioner view on which workflows actually pay an efficiency tax, where the FUD is wrong and how to decide when to move.

Read article

Published: 2026-05-05 · Author: A&M Flow