{"id":12965,"date":"2025-12-31T08:30:00","date_gmt":"2025-12-31T08:30:00","guid":{"rendered":"https:\/\/www.aura-node.com\/index.php\/2026\/05\/13\/remaining-sites-quality-refresh-20260603-aura-node-com-48-what-home-office-teaches-about-smartphone-buying-advice\/"},"modified":"2026-07-12T01:17:54","modified_gmt":"2026-07-12T01:17:54","slug":"the-eu-ai-act-in-2026-what-ordinary-software-buyers-should-check","status":"publish","type":"post","link":"https:\/\/www.aura-node.com\/index.php\/2025\/12\/31\/the-eu-ai-act-in-2026-what-ordinary-software-buyers-should-check\/","title":{"rendered":"The EU AI Act in 2026: What Ordinary Software Buyers Should Check"},"content":{"rendered":"<div class=\"codex-editorial-v5\" data-editorial-version=\"5.0\">\n<p class=\"codex-article-intro\">The EU AI Act affects software buyers less like a universal approval label and more like a set of duties tied to who supplies a system, who deploys it, what it does, and how much harm its use can cause. A writing assistant, customer-service bot, hiring screener, medical feature, and biometric identification tool do not sit in the same risk category. The presence of AI in a product name therefore says little about the checks a buyer should perform.<\/p>\n<p>The timing also matters. The regulation entered into force in 2024, and its obligations apply in stages, with an extended 2028 transition for specified systems embedded in regulated products. Several important rules are already applicable, while a large portion of the framework is scheduled to apply from August 2, 2026. This article translates the official framework into procurement questions for individuals and small organizations. It is practical buying guidance, not a legal opinion, and any purchase tied to employment, health, education, credit, law enforcement, or other regulated decisions deserves specialist review.<\/p>\n<section class=\"codex-editorial-section\">\n<h2>Start with the Act&#039;s phased calendar<\/h2>\n<p>The European Commission&#039;s AI Act overview records the main sequence: entry into force on August 1, 2024; application of prohibited-practice and AI-literacy provisions from February 2, 2025; governance rules and obligations for general-purpose AI models from August 2, 2025; and broad application from August 2, 2026. The Commission&#039;s current overview reports an extended transition until August 2, 2028 for high-risk AI systems embedded in regulated products, following political agreement on the AI simplification proposal. Providers of some general-purpose models placed on the market before their duties began also have transition arrangements.<\/p>\n<p>A calendar entry does not reveal which party carries each duty. The provider that develops or markets a system, the deployer that uses it under its authority, importers, distributors, and affected people have different roles. A consumer using an AI photo editor privately is not in the same position as an employer buying a tool to rank applicants. Before treating a vendor&#039;s compliance statement as relevant, write down the intended use, users, people affected, countries of operation, and any decision the output will influence.<\/p>\n<\/section>\n<figure class=\"wp-block-image size-large codex-editorial-image\" data-codex-image-slot=\"1\"><img width=\"696\" height=\"464\" src=\"https:\/\/blog.modern-me.com\/2026\/07\/editorial-v5-12965-1-675f32c085ec.jpg\" class=\"attachment-large size-large wp-image-14015 codex-editorial-image__media\" alt=\"Hands typing on a laptop displaying a software dashboard\" loading=\"lazy\" decoding=\"async\" srcset=\"https:\/\/blog.modern-me.com\/2026\/07\/editorial-v5-12965-1-675f32c085ec.jpg 1024w, https:\/\/blog.modern-me.com\/2026\/07\/editorial-v5-12965-1-675f32c085ec-300x200.jpg 300w, https:\/\/blog.modern-me.com\/2026\/07\/editorial-v5-12965-1-675f32c085ec-768x512.jpg 768w, https:\/\/blog.modern-me.com\/2026\/07\/editorial-v5-12965-1-675f32c085ec-1536x1025.jpg 1536w, https:\/\/blog.modern-me.com\/2026\/07\/editorial-v5-12965-1-675f32c085ec-629x420.jpg 629w, https:\/\/blog.modern-me.com\/2026\/07\/editorial-v5-12965-1-675f32c085ec-150x100.jpg 150w, https:\/\/blog.modern-me.com\/2026\/07\/editorial-v5-12965-1-675f32c085ec-696x464.jpg 696w, https:\/\/blog.modern-me.com\/2026\/07\/editorial-v5-12965-1-675f32c085ec-1068x713.jpg 1068w, https:\/\/blog.modern-me.com\/2026\/07\/editorial-v5-12965-1-675f32c085ec.jpg 1800w\" sizes=\"auto, (max-width: 696px) 100vw, 696px\" \/><figcaption>Photo by cikstefan on Unsplash. <a href=\"https:\/\/unsplash.com\/photos\/person-wearing-long-sleeve-top-working-on-laptop-5p_7M5MP2Iw\" rel=\"noopener\" target=\"_blank\">Source image<\/a> under <a href=\"https:\/\/unsplash.com\/license\" rel=\"noopener\" target=\"_blank\">Unsplash License<\/a>.<\/figcaption><\/figure>\n<section class=\"codex-editorial-section\">\n<h2>Risk labels are about use, not marketing language<\/h2>\n<p>The Act uses a risk-based structure. Some practices are prohibited, including specified forms of manipulation, exploitation, social scoring, biometric categorization, emotion recognition, and identification, each with definitions and exceptions that matter. High-risk rules focus on listed systems and regulated-product safety components, including certain uses in employment, education, essential services, migration, justice, and biometrics. Many everyday tools fall outside those groups or are subject mainly to transparency obligations, but a familiar interface does not make a sensitive deployment low risk.<\/p>\n<p>Ask a seller to identify the product&#039;s claimed classification for the exact feature and use case being purchased. A useful answer should explain the role the seller assumes, the intended purpose stated in its documentation, restricted uses, and what changes if the customer configures the tool for another purpose. A badge that says responsible AI, EU ready, or compliant is not enough. The Act does not function as a general warranty that outputs are accurate, fair, secure, or suitable for every decision.<\/p>\n<p>Classification can change when a general tool is integrated into a consequential workflow. A text model sold for drafting may be low stakes in one setting, while a configured system that scores candidates or influences access to a service raises different questions. Capture prompts, connected databases, ranking logic, automation rules, and the point at which a human can intervene. Procurement review should cover the assembled system, not just the vendor&#039;s base model, because the buyer&#039;s configuration can create capabilities and risks absent from the demonstration.<\/p>\n<\/section>\n<section class=\"codex-editorial-section\">\n<h2>Check what people will be told<\/h2>\n<p>Transparency is a practical buying issue even when the system is not high risk. The Act includes duties for certain systems that interact directly with people and for synthetic or manipulated content, subject to detailed conditions and exceptions. A buyer should be able to determine when users are told they are interacting with AI, how machine-generated material is identified, what accessibility accommodations exist, and how a person can reach a human when the automated route fails.<\/p>\n<p>Request screenshots or a working demonstration of those notices rather than accepting a policy promise. Examine the notice on mobile, in embedded widgets, and in every supported language. Ask if an administrator can remove or alter it, whether exported text, audio, images, or video retain a detectable disclosure, and who is responsible for downstream labeling. For internal tools, document how staff learn the system&#039;s limits and escalation route. AI literacy is an operational practice, not a one-time checkbox in a vendor questionnaire.<\/p>\n<\/section>\n<figure class=\"wp-block-image size-large codex-editorial-image\" data-codex-image-slot=\"2\"><img width=\"696\" height=\"464\" src=\"https:\/\/blog.modern-me.com\/2026\/07\/editorial-v5-12965-2-ece41c6ab8d2.jpg\" class=\"attachment-large size-large wp-image-14016 codex-editorial-image__media\" alt=\"Person working on a laptop during a software evaluation\" loading=\"lazy\" decoding=\"async\" srcset=\"https:\/\/blog.modern-me.com\/2026\/07\/editorial-v5-12965-2-ece41c6ab8d2.jpg 1024w, https:\/\/blog.modern-me.com\/2026\/07\/editorial-v5-12965-2-ece41c6ab8d2-300x200.jpg 300w, https:\/\/blog.modern-me.com\/2026\/07\/editorial-v5-12965-2-ece41c6ab8d2-768x511.jpg 768w, https:\/\/blog.modern-me.com\/2026\/07\/editorial-v5-12965-2-ece41c6ab8d2-1536x1022.jpg 1536w, https:\/\/blog.modern-me.com\/2026\/07\/editorial-v5-12965-2-ece41c6ab8d2-631x420.jpg 631w, https:\/\/blog.modern-me.com\/2026\/07\/editorial-v5-12965-2-ece41c6ab8d2-150x100.jpg 150w, https:\/\/blog.modern-me.com\/2026\/07\/editorial-v5-12965-2-ece41c6ab8d2-696x463.jpg 696w, https:\/\/blog.modern-me.com\/2026\/07\/editorial-v5-12965-2-ece41c6ab8d2-1068x711.jpg 1068w, https:\/\/blog.modern-me.com\/2026\/07\/editorial-v5-12965-2-ece41c6ab8d2.jpg 1800w\" sizes=\"auto, (max-width: 696px) 100vw, 696px\" \/><figcaption>Photo by glenncarstenspeters on Unsplash. <a href=\"https:\/\/unsplash.com\/photos\/person-using-macbook-pro-npxXWgQ33ZQ\" rel=\"noopener\" target=\"_blank\">Source image<\/a> under <a href=\"https:\/\/unsplash.com\/license\" rel=\"noopener\" target=\"_blank\">Unsplash License<\/a>.<\/figcaption><\/figure>\n<section class=\"codex-editorial-section\">\n<h2>Demand evidence that matches the intended use<\/h2>\n<p>For a consequential purchase, request documentation that names the model or service, intended purpose, known limitations, input requirements, evaluation methods, performance measures, human-oversight controls, and change-management process. High-risk systems can carry more formal documentation, logging, quality-management, registration, monitoring, and conformity obligations. Buyers should still verify scope: evidence for a general model or an earlier version does not automatically validate a customized workflow, local language, new data source, or later release.<\/p>\n<p>NIST&#039;s AI Risk Management Framework offers a useful voluntary lens even though it is not the EU law. Its govern, map, measure, and manage functions encourage buyers to connect testing with context and continuing risk control. Ask which groups and failure modes were evaluated, how often results are refreshed, and what threshold triggers withdrawal or human review. A polished average score can hide a serious error rate in the exact population or task that matters to the buyer.<\/p>\n<p>Contract terms should make ongoing evidence usable. Define notice periods for material model, data, subprocessor, or feature changes; rights to obtain logs and export records; cooperation during incidents; and a route to suspend affected functions. Check which promises are binding and which live only in marketing or documentation that the seller can revise unilaterally. A buyer who cannot identify the deployed version or receive change notices may be unable to tell when the evaluation supporting the original decision is obsolete.<\/p>\n<\/section>\n<figure class=\"wp-block-image size-large codex-editorial-image\" data-codex-image-slot=\"3\"><img width=\"696\" height=\"464\" src=\"https:\/\/blog.modern-me.com\/2026\/07\/editorial-v5-12965-3-50c48a69059f.jpg\" class=\"attachment-large size-large wp-image-14017 codex-editorial-image__media\" alt=\"Four coworkers reviewing information on a laptop together\" loading=\"lazy\" decoding=\"async\" srcset=\"https:\/\/blog.modern-me.com\/2026\/07\/editorial-v5-12965-3-50c48a69059f.jpg 1024w, https:\/\/blog.modern-me.com\/2026\/07\/editorial-v5-12965-3-50c48a69059f-300x200.jpg 300w, https:\/\/blog.modern-me.com\/2026\/07\/editorial-v5-12965-3-50c48a69059f-768x512.jpg 768w, https:\/\/blog.modern-me.com\/2026\/07\/editorial-v5-12965-3-50c48a69059f-1536x1024.jpg 1536w, https:\/\/blog.modern-me.com\/2026\/07\/editorial-v5-12965-3-50c48a69059f-630x420.jpg 630w, https:\/\/blog.modern-me.com\/2026\/07\/editorial-v5-12965-3-50c48a69059f-150x100.jpg 150w, https:\/\/blog.modern-me.com\/2026\/07\/editorial-v5-12965-3-50c48a69059f-696x464.jpg 696w, https:\/\/blog.modern-me.com\/2026\/07\/editorial-v5-12965-3-50c48a69059f-1068x712.jpg 1068w, https:\/\/blog.modern-me.com\/2026\/07\/editorial-v5-12965-3-50c48a69059f.jpg 1800w\" sizes=\"auto, (max-width: 696px) 100vw, 696px\" \/><figcaption>Photo by judmackrill on Unsplash. <a href=\"https:\/\/unsplash.com\/photos\/four-coworkers-smiling-around-laptop-at-table-Of_m3hMsoAA\" rel=\"noopener\" target=\"_blank\">Source image<\/a> under <a href=\"https:\/\/unsplash.com\/license\" rel=\"noopener\" target=\"_blank\">Unsplash License<\/a>.<\/figcaption><\/figure>\n<section class=\"codex-editorial-section\">\n<h2>Separate AI Act claims from privacy and security<\/h2>\n<p>AI Act readiness does not answer every data question. Identify what prompts, files, account data, metadata, feedback, and generated outputs leave the device; where they are stored; how long they remain; who can review them; and whether they train or improve any model. Check the privacy notice, contract, administrator controls, and deletion process for contradictions. A no-training toggle may still permit retention for security, abuse investigation, or service operation, so the underlying terms need to state the exceptions.<\/p>\n<p>Security requires its own evidence. Ask about access controls, multifactor authentication, encryption, tenant separation, audit logs, subprocessors, incident notification, export, and account closure. CISA and FTC consumer guidance provide sensible baseline controls, but regulated or confidential information may demand more. Test the promised controls in the actual subscription tier: a vendor may describe enterprise features that are absent from a consumer or small-business plan. Also ask what happens to stored content and integrations when a contract ends.<\/p>\n<p>Map legal and operational responsibility across integrations as well. A workplace suite may call a model provider, retrieval service, speech processor, analytics tool, and customer database during one interaction. The buyer needs to know which party receives each data type, which terms govern it, and who handles a deletion request or incident. Review permissions for connected drives and mailboxes; broad access can expose far more information than a single prompt. Disable unused connectors and require a fresh assessment before administrators add a new data source.<\/p>\n<\/section>\n<section class=\"codex-editorial-section\">\n<h2>A buyer checklist for the 2026 transition<\/h2>\n<p>A defensible purchase file should contain the intended use, risk classification rationale, applicable role, user disclosure, human escalation, data-flow map, evaluation evidence, release identifier, update notice process, incident contact, deletion route, and contract owner. Add a stop condition for unacceptable errors or an unannounced model change. For high-impact deployments, obtain qualified legal, privacy, security, accessibility, and domain review before launch. No checklist can convert a tool that is poorly matched to its task into a responsible purchase.<\/p>\n<p>The Commission&#039;s official AI Act page should be checked again immediately before procurement or publication. The regulatory calendar, Commission guidance, codes, standards, national enforcement arrangements, and vendor implementations can develop after this article&#039;s July 11, 2026 source review. Keep dated copies of the terms and documentation relied on, then schedule a review after major product updates. Compliance is not a permanent property inherited from a logo; it depends on the system version, contractual facts, configured use, and controls operating in practice. If a seller cannot explain an obligation, do not fill the gap with an optimistic assumption. Record it as an unresolved risk, narrow the planned use, or pause the purchase until qualified advice and verifiable evidence are available.<\/p>\n<ul>\n<li>Define the exact use, affected people, decision, operating region, and buyer role.<\/li>\n<li>Ask for a feature-specific classification and the evidence supporting it.<\/li>\n<li>Inspect disclosures, human escalation, accessibility, and synthetic-content labeling in the product.<\/li>\n<li>Map prompt, file, output, telemetry, retention, training, and deletion data flows.<\/li>\n<li>Record model changes, incidents, audit evidence, ownership, and a clear stop condition.<\/li>\n<\/ul>\n<\/section>\n<section class=\"codex-article-sources\" aria-labelledby=\"codex-sources-heading\">\n<h2 id=\"codex-sources-heading\">Sources and further reading<\/h2>\n<ol>\n<li><a href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/policies\/regulatory-framework-ai\" rel=\"noopener\" target=\"_blank\">European Commission &#8211; AI Act<\/a><\/li>\n<li><a href=\"https:\/\/www.nist.gov\/itl\/ai-risk-management-framework\" rel=\"noopener\" target=\"_blank\">NIST &#8211; AI Risk Management Framework<\/a><\/li>\n<li><a href=\"https:\/\/www.cisa.gov\/secure-our-world\" rel=\"noopener\" target=\"_blank\">CISA &#8211; Secure Our World<\/a><\/li>\n<li><a href=\"https:\/\/consumer.ftc.gov\/identity-theft-and-online-security\/online-privacy-and-security\" rel=\"noopener\" target=\"_blank\">FTC &#8211; Online security<\/a><\/li>\n<li><a href=\"https:\/\/digital-markets-act.ec.europa.eu\/index_en\" rel=\"noopener\" target=\"_blank\">European Commission &#8211; Digital Markets Act<\/a><\/li>\n<\/ol>\n<\/section>\n<\/div>\n<aside class=\"ctp-related-reading codex-related-reading\" data-codex-related-v5=\"1\" aria-label=\"Related reading\">\n<h2>Related reading<\/h2>\n<ul>\n<li><a href=\"https:\/\/www.aura-node.com\/index.php\/2026\/07\/08\/matter-1-6-thread-smart-home-update-2026\/\">Matter 1.6 and Thread: What the 2026 Smart Home Update Changes<\/a><\/li>\n<li><a href=\"https:\/\/www.aura-node.com\/index.php\/2026\/06\/18\/laptop-usb-c-charging-eu-common-charger-2026\/\">Laptop USB-C Charging in 2026: Ports, Power, and the EU Common Charger Rule<\/a><\/li>\n<li><a href=\"https:\/\/www.aura-node.com\/?p=12964\">Passkeys in 2026: What Happens When You Lose a Phone or Change Platforms<\/a><\/li>\n<\/ul>\n<\/aside>\n","protected":false},"excerpt":{"rendered":"<p>The EU AI Act is arriving in phases. Software buyers should check intended use, disclosures, data handling, human oversight, and evidence behind vendor claims.<\/p>\n","protected":false},"author":1,"featured_media":14014,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26,24],"tags":[],"class_list":{"0":"post-12965","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-industry-news","8":"category-tech-news"},"_links":{"self":[{"href":"https:\/\/www.aura-node.com\/index.php\/wp-json\/wp\/v2\/posts\/12965","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.aura-node.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.aura-node.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.aura-node.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.aura-node.com\/index.php\/wp-json\/wp\/v2\/comments?post=12965"}],"version-history":[{"count":6,"href":"https:\/\/www.aura-node.com\/index.php\/wp-json\/wp\/v2\/posts\/12965\/revisions"}],"predecessor-version":[{"id":14184,"href":"https:\/\/www.aura-node.com\/index.php\/wp-json\/wp\/v2\/posts\/12965\/revisions\/14184"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.aura-node.com\/index.php\/wp-json\/wp\/v2\/media\/14014"}],"wp:attachment":[{"href":"https:\/\/www.aura-node.com\/index.php\/wp-json\/wp\/v2\/media?parent=12965"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.aura-node.com\/index.php\/wp-json\/wp\/v2\/categories?post=12965"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.aura-node.com\/index.php\/wp-json\/wp\/v2\/tags?post=12965"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}