On August 1 2026 the EU AI Act is set to come into force for most businesses. But what’s included in the act, does it apply to you and when do in-house legal teams need to be concerned about it?
Those questions are exactly what we’re here to answer. The Act has broad reach, including beyond the European Union. But in practice, its scope is more targeted than the headlines first make out. The real challenge for teams isn’t just interpreting the law, but understanding where the organization might actually be exposed.
The EU AI Act is the first comprehensive legal framework governing artificial intelligence. Its aim is to make sure that AI systems are safe, transparent and aligned with fundamental rights, especially in high-risk use cases like employment, credit decisions and access to essential services.
Like GDPR, the Act has extraterritorial reach. It applies to both organizations placing AI systems on the EU market and organizations using AI systems whose outputs are used in the EU – no matter where that AI system is based or headquartered.
That means both US and UK-based companies could still have obligations under the Act, especially where AI is used in EU-facing products or services and contracts involving EU customers, suppliers or employees.
As for when it comes into force, there’s been a phased approach so far to the Act, and there are still moving parts – for example, proposed amendments in negotiations right now may push some high-risk AI obligations back to December 2027. For now, the 1 August 2026 date is the key date to work towards.
Despite its name, the Act doesn’t regulate “AI” as a whole, but specific use cases based on risk. So not all AI systems are in scope, and not all organizations will have the same obligations. We'll go into this more below.
Most in-house legal teams aren’t building AI systems, but they are buying them, implementing them and relying on their outputs, especially across legal, procurement and contract workflows. For example, nearly half of corporate legal departments now have access to generative AI tools, according to a 2026 report by Thomson Reuters.
Across a lot of organizations, AI is increasingly used in:
A lot of these capabilities sit inside contract lifecycle management (CLM) platforms or similar tools, often powered by general-purpose AI models.
On top of that, when questions start to surface around risk, accountability or compliance, they tend to land with legal. In this context, legal becomes the last line of defense, not just users.
While the headlines may make the EU AI Act seem like a broad, sweeping regulation, the strictest obligations only apply to a relatively narrow set of use cases. But at the same time, scrutiny around AI is expanding rapidly, far beyond those categories – even if it’s not showing up in legislation yet.
The Act categorizes AI systems by risk, with the heaviest obligations focused on “high-risk” use cases. In practice:
It’s important to note that "low risk" doesn't mean "no obligations." AI literacy requirements have been in force since February 2025, and AI-generated content labeling (images, audio, video and text) will be required from December 2 2026 regardless of risk category. If your team is using generative AI to produce anything client-facing, that deadline is worth having on your radar.
This means most organizations won’t face the same level of regulation across all AI use. But even where formal obligations are limited, expectations are rising quickly. Here are a few things to consider:
Recent enforcement shows a clear pattern: regulators are targeting the foundations of AI systems – data, transparency and decision-making.
While these are dramatic examples of enforcement and sit under existing frameworks like GDPR rather than the AI Act, they highlight what regulators are already focusing on:
Beyond data, regulators and courts are increasingly focused on how AI-driven decisions affect individuals. For example, cases involving Uber have challenged automated decision-making around driver management, with courts requiring greater transparency and more human oversight. In a series of rulings by the Amsterdam Court of Appeal, drivers argued that decisions such as dismissals were effectively completely automated, with so-called human review found to be purely symbolic.
This is directly aligned to meaningful human oversight, one of the core concepts in the EU AI Act.
For in-house teams, your AI tools may be making decisions around contract approvals, supplier evaluation and risk scoring. While those aren’t formally “high-risk” systems, the expectation is shifting: if AI is influencing your decisions, you need to be able to explain and challenge it.
A common misconception is that AI risk can be outsourced, but in practice, it’s the opposite.
Even where AI is embedded in third-party tools:
This is especially relevant in CLM and procurement workflows, where AI outputs may influence contractual decisions, and responsibility can’t just be pushed back to the provider. In other words, you might not be building the system, but you are still accountable for how you use it.
For most legal teams, the biggest pressures won’t be coming from regulators just yet, but from inside the business.
You’re probably already being asked questions like where you’re using AI, where you’re exposed and if you could defend it when challenged. Those questions are tied directly to board-level risk decisions, procurement decisions and customer and partner expectations.
Unlike regulatory timelines, this scrutiny is already here, and won’t be going anywhere any time soon.
The good news is that given the narrowness of the EU AI Act scope, you probably don’t need to do anything right this minute! But you may need to start looking into AI governance frameworks – so where do you start?
Keep up to date with the act's developments by following Summize on LinkedIn.
