Aller au contenu principal
GenieFactoryGenie Factory
Frédéric Ramet

AI Act compliance for AI applications in 2026

The AI Act has been in force since 2025. Here is what SMEs and mid-market companies need to concretely do to bring their AI applications into compliance: obligations, documentation, governance.

AI Act compliance for AI applications in 2026

AI Act compliance for AI applications in 2026

By defining an AI usage policy, documenting your systems, and setting up governance with traceability. The AI Act is in force, but for most SMEs and mid-market companies, the obligations are simpler than you think.

What does the AI Act concretely require of SMEs and mid-market companies?

The AI Act classifies AI systems by risk level. Most AI applications deployed in SMEs/mid-market (chatbots, document assistants, analysis tools) are not high-risk systems. But they still have obligations.

The obligations that apply to (almost) everyone: transparency (inform the user that they are interacting with an AI), documentation (keep a record of what the system does and how), and human oversight (a human can intervene and correct).

What probably doesn't apply to you: the heavy obligations for high-risk systems (conformity assessment, EU registration, formalised risk management) concern AI systems used in recruitment, credit, justice, and critical infrastructure.

How do I know if my AI application is high risk?

By checking whether it falls into one of the categories in Annex III of the regulation. Typical enterprise cases: HR candidate scoring, credit assessment, surveillance systems. A document chatbot, a project scoping tool, a supply chain assistant are generally not high risk.

If in doubt, ask yourself: does my AI system make decisions that significantly affect the fundamental rights of a person? If not, you are probably in limited or minimal risk.

What are the 5 concrete actions to achieve compliance?

1. Write an AI usage charter. The first deliverable, the simplest. Who is allowed to use which AI tools? What data can be sent in a prompt? Who validates the outputs? Most SMEs/mid-market companies have nothing, and every prompt sent to an LLM is potentially a data leak.

2. Document your AI systems. For each AI application in production: what its objective is, what data it uses, how it works, who supervises it. Not a 200-page dossier, one system sheet per system. At GenieFactory, this documentation is automatically generated by the platform.

3. Set up traceability. Audit trail: who did what, when, with what data, with what result. This is the foundation of AI governance. Without traceability, no compliance, and no ability to correct errors.

4. Guarantee human oversight. A human must be able to intervene, correct, and override AI decisions. Systems with integrated human validation have 4× fewer critical incidents, compliance and performance align.

5. Train the teams. Companies that invest 25% or more of their AI budget in training achieve 2.4× more ROI. Training is not a nice-to-have, it is the #1 ROI multiplier and a compliance prerequisite.

The AI Act requires transparency and documentation. But it doesn't resolve the ownership question. Who owns the data processed by the AI? Who owns the trained model? Who owns the outputs?

At GenieFactory, the principle is clear: the client owns their data, their Knowledge Graph, and their applications. No lock-in, no dependency. Agentic transformation integrates AI Act compliance by design, complete audit trail, native RBAC, automatic documentation.

Fewer than 9% of SMEs have a registered intellectual property right. In a context where AI generates code, specs, and intangible assets, protecting those assets becomes a strategic issue.

Is the AI Act a constraint or a competitive advantage?

It's an advantage, if you integrate it from the start. European companies that build AI Act-compliant applications will have an advantage over those that must comply after the fact. It's the same scenario as the GDPR in 2018: those who anticipated were ready, those who panicked paid dearly.

80% of European companies have not yet adopted AI. Those that do now, within the regulatory framework, are building a structural lead.

Audit the compliance of your AI applications →


Related article: Enterprise AI without lock-in: keeping control

Frequently asked questions

What is the AI Act and who must comply?
The AI Act is the European regulation on artificial intelligence, in force since 2025. It applies to any organisation that develops, deploys, or uses an AI system on the European market, including SMEs and mid-market companies. It classifies AI systems by risk level (prohibited, high risk, limited risk, minimal risk) and imposes graduated obligations according to the classification.
What are the concrete obligations for a business AI application?
For most business AI applications (limited risk or high risk category), the key obligations are: document the system, trace decisions, maintain human oversight over critical actions, inform users that they are interacting with an AI, assess risks, and keep audit logs. An HR or scoring application shifts to high risk with enhanced obligations.
How do you document an AI application for the AI Act?
You need to produce a system sheet describing: purpose, training data, architecture, performance metrics, known limitations, bias mitigation measures, planned human supervision. This documentation must be kept up to date and accessible in case of audit. At GenieFactory, this sheet is automatically generated for each deployed AI agent.
What is AI Act traceability and how do you ensure it?
Traceability means recording each decision or action of an AI agent with context (input, reasoning, output, user, timestamp). It allows a decision to be reconstructed after the fact in case of incident or audit. Technically: structured timestamped logs, immutable storage, and a consultation interface for business users and auditors.
What is the risk level of my AI applications?
Most B2B AI applications (document automation, business assistants, bank reconciliation) are in limited risk: documentation obligations but no prior control. Applications that impact individuals (HR, credit scoring, surveillance, education) are high risk: mandatory conformity assessment before market launch. Uses such as social scoring or behavioural manipulation are prohibited.
Do you need a DPO or a dedicated AI Act officer?
The AI Act does not create an obligatory function equivalent to the GDPR DPO, but clear governance is expected. In practice: appoint an AI Act referent (often an expanded DPO or CISO), maintain a register of AI systems, review compliance annually. For a mid-market company with several AI systems, a dedicated function becomes relevant.
What are the sanctions for AI Act non-compliance?
Sanctions mirror the GDPR but are stricter: up to €35M or 7% of global turnover for prohibited practices, €15M or 3% for non-compliance with high-risk system obligations, €7.5M or 1% for incorrect information provided to authorities. National market authorities are competent.
How does GenieFactory help with AI Act compliance?
GenieFactory natively integrates AI Act requirements into the platform: auto-generated documentation for each agent, immutable audit logs, configurable human supervision per workflow, granular RBAC, and exportable system sheets for auditors. The client retains full ownership of the logs and documentation, stored on their infrastructure.
Does the AI Act apply to models like Claude, GPT-4, or Mistral?
Yes, foundation models (LLMs) are covered by specific obligations: publishing technical documentation, respecting copyright, transparency on training data. These obligations rest on the publishers (Anthropic, OpenAI, Mistral), but the company integrating these models into an application remains responsible for the compliance of the final system.