Our article

The next phase of the AI Act: compliance and contractual issues starting August 2026

Lead

The implementation of the AI Act is taking place in stages, which is why many businesses still operate under the impression that the regulation is a future concern. This will become increasingly difficult to maintain after August 2, 2026. From this date, the regulation will apply as a general rule, with only specific elements remaining subject to later deadlines. Rules regarding prohibited AI practices and AI literacy obligations have been in effect since February 2, 2025; provisions concerning general-purpose AI models and certain governance rules apply from August 2, 2025; and longer transition periods apply to certain high-risk systems integrated into regulated products. Therefore, August 2, 2026, is not the starting point, but the beginning of a new, much more practical phase of compliance.

What happens on August 2, 2026?

The most significant change is that the general application of the AI Act begins on this date. This becomes particularly important for obligations related to high-risk AI systems, specific transparency requirements, and the operations of market participants. The European Commission's current official guidance continues to assume that the full application date of the regulation is August 2, 2026, with certain exceptions. While it is true that the Commission submitted a targeted amendment proposal in November 2025, and the European Parliament also addressed certain postponement and amendment issues in the spring of 2026, these proposals are currently still in the legislative process. For this reason, as of April 2026, it is still advisable to base planning on the dates set out in the current core regulation.

For Hungarian businesses, this means that from August 2026, the use of AI will be even less manageable as purely an IT or procurement issue. Compliance matters will then be genuinely intertwined with contracts, documentation, internal approval processes, HR, the compliance function, and, in certain cases, customer communication. This approach is also being followed with increasing consistency in analyses by international law firms.

Not all companies are affected in the same way

The logic of the AI Act is not sector-based, but role- and risk-based. A business that develops or places an AI system on the market is in a different position than one that uses a third-party solution for its internal operations or customer service. The regulation uses distinct categories for actors, such as provider, deployer, importer, and distributor. It is worth clarifying which role the company occupies at the very first step of compliance work, as a significant portion of the obligations follows from this.

Targeted preparation may be particularly justified for companies that:

  • use AI tools affecting employees or job applicants,
  • employ systems that support customer qualification, ranking, profiling, or risk assessment,
  • use automated decision support in customer service or complaint handling processes,
  • rely on AI for compliance, fraud, monitoring, or internal control functions,
  • offer their own AI-based products, modules, or features to customers.
"From the perspective of the AI Act, the first real question for most companies is not whether they use artificial intelligence, but in what role and in what risk category they do so."
Why will this also be a contractual issue?

For many businesses, the use of AI currently appears as the implementation of an IT tool. However, the application phase starting August 2, 2026, will make it more visible that the use of AI is, in fact, also a matter of contracts and liability. If a company uses an AI-based solution or integrates such an element into its own service, it must sooner or later clarify who bears which obligations regarding compliance, error risk, transparency, and cooperation. This is especially true if the AI tool affects employees, customers, or other business-sensitive decisions.

In practice, a general IP or liability clause is typically insufficient. In contracts involving AI, at least the following issues must be handled separately with increasing frequency:

  • exactly which AI system or AI function is being used,
  • who qualifies as the provider and who as the deployer,
  • who bears the compliance and infringement risk,
  • what human oversight is mandatory,
  • whether specific information regarding AI usage is required,
  • what level of cooperation is expected in the event of inquiries from authorities or clients.

This is not just a theoretical concern. If a company provides AI-supported services or uses AI in internal decision-making processes, the contract will later become one of the most important documents for assessing how well liability and compliance situations were addressed in advance. DLA Piper's early 2026 Hungary-focused summary also points to the fact that AI-related disputes are increasingly emerging at the intersection of compliance and liability issues.

What should you review at a minimum right now?

For most businesses, the right first step is not an oversized AI compliance project, but rather precise use-case and role mapping. International practice shows that companies must first map out where and in what form they are actually using AI, and which legal categories these uses fall under.

It is worth reviewing at least the following points:

  • which AI tools have actually been integrated into daily operations,
  • which of these affect employees, clients, or business-sensitive decisions,
  • what role the company assumes in relation to the given use case,
  • whether supplier and client contracts address AI-specific liability issues,
  • whether there is an internal approval, documentation, and human oversight system in place,
  • whether at least basic AI literacy or internal awareness measures have been implemented.
"From August 2026, in addition to technological issues, documentation, role definition, and contractual risk sharing will become truly significant in the legal assessment of corporate AI usage."
What is the Hungarian context?

In Hungary, the AI Act is a directly applicable EU regulation, so corporate obligations do not depend on whether there will be a full domestic transposition in the classical sense. At the same time, for Hungarian companies, the most important practical question today is usually not the details of the administrative procedure, but whether they even recognize which of their own use cases might fall within the substantive scope of the AI Act. Most compliance risks do not stem from a lack of knowledge of the law, but from the fact that AI usage remains informal, fragmented, and contractually underserved within the organization. This trend is highlighted by both international and Hungary-focused legal analyses.

Closing thoughts

The date of August 2, 2026, should neither be dramatized nor dismissed with the thought that "there is still time." The correct approach is to view it as a turning point from which many parts of the AI Act are no longer just a regulatory background to be prepared for, but a compliance framework that becomes more enforceable in corporate operations. Companies that have organized their basic use cases, roles, contractual relationships, and internal control points by then will be in a better position.

PLM Legal – Dr. Marcell Olajos Law Firm provides legal support to businesses in areas including commercial contracts, compliance, technology agreements, and regulatory issues. If your company uses AI tools in internal operations, HR processes, customer service, or the provision of business services, our firm can assist in the legal mapping of relevant use cases, the review of contractual and internal control issues, and the interpretation of the practical compliance aspects of the AI Act.