Knowledge

EU AI Act: what changed on 2 August 2026.

The transparency obligations and those for high-risk systems now apply. They reach anyone selling into the European market, whether or not the company is European.

What came into force

Since 2 August 2026 the transparency obligations apply — covering interactions with conversational systems, generated content and the labelling of what is synthetic — along with the obligations for systems classified as high-risk.

The point that is usually missed: the Regulation follows the market, not the head office. A company outside the Union that places a system on the European market, or whose output is used in the Union, is covered.

How to tell whether a system is high-risk

Classification depends on the concrete purpose, not on the technology. Systems used in recruitment and worker management, in access to credit, in essential services, in education, and as safety components of products are among the more demanding categories.

This is a legal qualification, and your legal department or counsel is the one who makes it. What is technical — and where we come in — is being able to produce the evidence of how the system works once that qualification says the evidence is required.

What documentation you need

  • Technical documentation. System description, intended purpose, data used, architecture and known limitations.
  • Usage logging. A trail that allows you to reconstruct what the system received, what it decided and on what basis.
  • Human oversight. Evidence that effective human intervention exists where it is required, and not merely on paper.
  • Risk management and data quality. Documented assessment of the risks and of the suitability of the data used.
  • User information. When someone is interacting with an AI system, they have to know it.

Who supervises

Each member state designates a national market surveillance authority, typically coordinating a set of sectoral regulators. In Portugal that role sits with ANACOM, coordinating sectoral authorities. The structure is distributed: which regulator comes knocking depends on the sector the system is used in.

What to do now, in order

  • Inventory. Which AI systems exist in the organisation, including those that arrived inside tools you already licensed. The list is usually longer than expected.
  • Qualify. With legal support, determine which category each one falls into.
  • Check what is actually logged. In most cases the obstacle is not policy — it is that the system never stored what now has to be shown.
  • Close the technical gaps. Logging, oversight and documentation — built before anyone asks, because the past cannot be reconstructed.

We are not legal advisers and we do not perform the legal qualification of your case. We build the technical part: the logging, the traceability and the operating documentation your legal team needs to have in hand.

Frequently asked questions

Does this apply to us if we only use ChatGPT internally?

Transparency obligations can apply as soon as there is customer interaction or published content. High-risk obligations depend on purpose. The inventory is the first step either way.

We are a non-EU company. Are we covered?

If you place the system on the Union market, or if its output is used in the Union, yes. The test is the market, not where the company is based.

What is the most common gap you find?

Systems in production that never logged the context used to produce each answer. Without that there is no possible explanation, and the log cannot be created retroactively.

Want to know what your systems actually log?

We run a technical audit of what exists, what is missing and what has to be built — with a correction plan ordered by priority.

Book 20 minutes

See our AI in action — this assistant was built by us, with the same technology we sell.

← All services