Skip to content
House of Marka
ServicesMarketplacesWorkInsightsCompanyStart a project
All insights
Compliance & Trust2 min read

The EU AI Act in August 2026: A Compliance Checklist for Mid-Size Companies

High-risk obligations are landing now. What mid-market companies must do — inventory, classification, documentation, oversight — without a legal department.

August 2026 is the month the EU AI Act stops being a webinar topic. General-purpose AI obligations have been in force since 2025; now the high-risk framework starts biting, and enforcement applies to any company placing AI systems on the EU market — including US companies with European customers.

First: know which bucket you are in

Most commerce and SaaS companies discover they are deployers of AI (using models in products and operations), not providers (building foundation models). Deployer obligations are lighter but real. You may still cross into provider territory if you substantially modify a model or market it under your own brand.

Prohibited practices — manipulation, social scoring, most emotion recognition at work — have been enforceable since February 2025. If anything in your stack resembles these, that conversation cannot wait.

High-risk categories cover employment screening, credit scoring, essential services access and more. A recruitment-filtering feature inside an otherwise boring HR product is enough to qualify.

The mid-size company checklist

  1. Inventory every AI system in use. Including the ones marketing bought on a credit card. You cannot classify what you have not listed. In our audits, the inventory is always longer than the CTO's guess — usually by 2x.
  2. Classify against the Act's categories. Most systems land in "minimal risk" and need only transparency basics. Document the reasoning anyway; the reasoning is your defence.
  3. Transparency where users meet AI. Chatbots must be identifiable as AI. Synthetic content needs labelling. This is cheap to do and embarrassing to be caught skipping.
  4. Human oversight for consequential decisions. Anything touching employment, credit or access to services needs a designed human checkpoint — a real one, not a rubber stamp.
  5. Documentation and logging. High-risk systems need technical documentation, record-keeping and accuracy monitoring. If a regulator asks, the answer is a file you already have, not a project you start that day.
  6. Vendor terms. Your model providers' commitments on training data, incident reporting and copyright matter to your own compliance. Read the AI clauses before renewal, not after an incident.

The part US companies keep missing

The Act follows the market, not the company. A Delaware SaaS with EU customers is in scope. Penalties for prohibited-practice violations reach €35M or 7% of global turnover — GDPR taught everyone that Brussels enforces what it writes.

The good news: for most mid-size companies, honest compliance is weeks of structured work, not a transformation program. An inventory, a classification memo, a handful of transparency fixes and an oversight design — done properly once, then maintained.

We run exactly that as a fixed-fee sprint, engineering-led rather than billed-by-the-hour legal. Talk to us if August arrived faster than your compliance did.

Work with us

House of Marka is the applied-AI and commerce engineering studio of Marka Modern Retail Private Limited. We research, advise and then build — for merchants and enterprises in the US, UK and Europe.

Next step

Tell us what you are trying to build.

A short call, a written view on whether we are the right studio for it, and a plan you can act on either way.