2 August 2026 marks a new point in the application of the European Union’s AI Act. The European Commission says that the AI Office and national competent authorities have begun enforcing relevant provisions, including obligations for providers of general-purpose AI models and new transparency requirements for certain AI systems. This is not news only for large technology companies. For businesses that sell, provide digital services, or participate in supply chains serving customers in the EU, the date changes how AI must be governed in products, processes, and contracts.
The scope needs to be stated accurately. The AI Act is EU law; a Vietnamese business does not automatically face every obligation simply because it uses an AI tool. Yet where a business puts systems, services, or content on the EU market, supplies an EU partner, or receives contractual compliance requests, questions from customers and partners become more specific. They will not only ask whether the business has a “responsible AI policy.” They will ask which systems contain a chatbot, which content has synthetic elements, who owns labelling, and where the business keeps its evidence.
From a year of preparation to a phase that can be checked
Obligations for providers of general-purpose AI models, or GPAI, began to apply on 2 August 2025. Under European Commission guidance, in-scope providers must maintain technical documentation, provide information to downstream system providers, establish a copyright-compliance policy, and publish a sufficiently detailed summary of training content. For models with systemic risk, obligations are higher in relation to evaluation, risk mitigation, and security.
From 2 August 2026, the Commission began full enforcement of these GPAI obligations, including through penalties. At the same time, Article 50 transparency requirements began to apply to certain systems: people must be informed when they are interacting with AI; deepfakes must be labelled; and AI-generated or altered content must carry machine-readable marks in in-scope cases. Application details include exceptions and depend on each party’s role, so a business should not turn an article into legal advice. From a management perspective, however, the date is clear enough to require a serious inventory.
What changes for managers: see AI system by system
Many organizations now have an enterprise-level AI-use policy: do not enter sensitive data, verify outputs, and do not use AI in place of a human approver. These principles remain useful, but they cannot answer operational questions on their own. A website chatbot, an internal content-drafting tool, a recommendation feature in a customer application, and a record-classification process have very different risks, users, data sources, and transparency obligations.
A practical approach is to build an AI register by system or use case, not only by provider name. For every entry, the responsible team should state the business purpose, users and markets served, underlying model or service, input data, outputs produced, potential synthetic content, approver, owning unit, and available evidence. The aim is not to add bureaucracy. It helps an organization answer quickly when a partner asks and exposes situations where a feature has reached the market without a clear owner.
| Management point | Question to ask | Evidence to keep |
|---|---|---|
| Market scope | Is the system supplied to users or customers in the EU? | Markets, customer groups, service terms, and legal contact. |
| User transparency | Do people know they are interacting with AI, and does synthetic content need notice or marking? | Interface design, notices, publishing rules, and pre-release testing. |
| AI supply chain | Is the business a provider, deployer, or merely a user of another party’s service? | Contracts, supplier material, model configuration, and allocation of responsibility. |
| Change control | Who reassesses when a model changes, data are added, or a market expands? | Change approval process, version log, and review record. |
Transparency is not just a line at the bottom of a screen
A common risk is to reduce transparency requirements to a generic notice. If a chatbot receives requests, the notice should appear when people can clearly understand that they are dealing with an AI system, not be buried in terms of use. If a business publishes images or audio generated or altered by AI, responsibility cannot rest only with the communications team. The organization needs to identify who checks asset origin, who decides when a label is needed, and how that information moves through versions when content is reused across channels.
The difficult cases are hybrid processes. A bulletin may be drafted by AI and then reviewed by an editor, while an illustration is entirely synthetic. The two situations differ in their risk of misleading audiences and should not be governed by one identical rule. Businesses need to interpret legal requirements through the role of the system and the way content reaches the public, then turn that interpretation into operating guidance for the people doing the work.
Example: a Vietnamese SaaS company serving European customers
A SaaS company adds a chatbot to its customer-support page and a call-summary feature for its sales team. The first step is not to write a new AI policy immediately. The team should create two separate use-case records: which visitors interact directly with the chatbot, whether notice is clear, who owns the response content, and when the interaction moves to an employee; then which data the summary feature uses, where summaries are stored, who can see them, and whether they leave the organization. Legal and technical teams then have a basis for assessing customer commitments and requirements for each market.
Three actions to complete in 30 days
First, inventory AI systems that are being supplied or that directly affect customers, users, and partners. Do not wait for a project to be called an “AI project”; include smaller features using foundation models, content-creation tools, and automations that make decisions or communicate externally.
Second, classify every use case by role and market. Business, technology, information security, and legal functions should do this together. A short spreadsheet with an owner for every row is often more useful than a long policy not tied to a particular system.
Third, select use cases likely to touch the EU or involve important customer commitments and test their evidence. Review interfaces, notices, supplier documents, customer terms, content-approval processes, and recordkeeping. Where gaps remain, record the action required, owner, and completion date rather than claiming that the organization is “compliant.”
Conclusion
The AI Act enforcement milestone does not require every business to become an expert in European law. It does send a clear management signal: AI is increasingly assessed through the ability to show how a system operates, informs users, and allocates accountability. Company-wide policy remains necessary, but practical value lies in a use-case register, change process, and reviewable evidence for each system. Businesses that build these three elements will be better positioned for market and partner requirements.
References
European Commission. (2026, July 31). Commission starts enforcing AI Act rules and new transparency requirements on 2 August. https://digital-strategy.ec.europa.eu/en/news/commission-starts-enforcing-ai-act-rules-and-new-transparency-requirements-2-august
European Commission. (2026, August 7). The enforcement framework of the AI Act. https://digital-strategy.ec.europa.eu/en/policies/enforcement-ai-act
European Commission. (2026). Transparency obligations under Article 50 of the AI Act. https://digital-strategy.ec.europa.eu/en/faqs/transparency-obligations-under-article-50-ai-act
European Commission. (2026). Guidelines on obligations for General-Purpose AI providers. https://digital-strategy.ec.europa.eu/en/faqs/guidelines-obligations-general-purpose-ai-providers


