An assistant that summarizes meetings, software that ranks job applications, a chatbot that answers customers: behind the same “AI” label lie three uses, three risk profiles and different responsibilities. In September 2026, the issue is no longer simply choosing the best model. It is knowing who pays for its documentation, who checks its outputs and who answers for it when it goes off track. The AI Act is bringing artificial intelligence governance into budget decisions. There is one complication: the bill is split across IT, legal, human resources, procurement and business units.
A phased timetable, not an overnight regulatory overhaul
The European Union’s AI regulation entered into force on August 1, 2024. Its original timetable sets out several stages: bans on certain practices and an obligation to take measures to ensure sufficient AI literacy from February 2, 2025; provisions covering, among other things, general-purpose AI models from August 2, 2025; and application of most of the legislation on August 2, 2026. Certain obligations relating to high-risk systems embedded in regulated products are scheduled for August 2027.
These dates form the framework adopted in 2024, on which this analysis, set in September 2026, is based: they do not account for any potential subsequent legislative adjustments. Transitional arrangements also exist for certain systems and models already on the market. A company therefore cannot determine its deadline solely from the purchase date: it must examine its role, the intended use and any modifications made.
It would be a mistake to conclude that all software must undergo the same process. The AI Act takes a risk-based approach. An internal writing tool is not automatically a high-risk system. A tool intended to select job candidates, however, may fall into that category. Legal classification thus becomes the first worthwhile investment: it prevents both inadequate compliance and unnecessarily burdensome controls.
The first expense: knowing what you use
Before buying a governance platform, businesses need to look under the hood. Companies must identify the AI features in their software, the services teams subscribe to directly and their in-house developments. This work goes beyond an IT inventory: the same tool can be used to prepare a draft with no particular consequences or to guide a decision about an employee.
In practice, each use should have an owner, a stated purpose, identified users and a record of the data involved. The legal department cannot map all this on its own. Business units know how tools are actually used; IT knows how they integrate; procurement holds the contracts. The initial cost is therefore largely a coordination cost, often underestimated in pilot projects.
Provider or user: a costly dividing line
The regulation distinguishes, among others, between the provider, which develops or commissions the development of a system to market it or put it into service under its own name, and the deployer, which uses it under its authority. A customer company does not automatically inherit all the developer’s obligations. But nor can it assume that signing up for a subscription outsources all responsibility.
For high-risk systems, the provider must, among other things, establish risk management, prepare technical documentation, provide for logging and meet the applicable requirements before placing the system on the market. The deployer must, among other things, follow instructions, assign human oversight to competent individuals and monitor operation. Certain fundamental rights impact assessments apply to specific categories of deployers, not indiscriminately to all companies.
The dividing line can shift when an organization puts its name on a system, substantially modifies it or changes its intended purpose under the conditions set out in the legislation. Customizing a solution is therefore not always a simple IT purchase. Contracts must specify access to the necessary information, incident handling and the implications of an update. However, a commercial clause cannot erase a responsibility established by law.
Documentation, oversight, training: three ongoing budget commitments
Producing evidence, not just principles
An ethics charter is no substitute for instructions for use or the required technical materials. The companies concerned must fund the collection, validation and updating of evidence. Providers of general-purpose AI models have a specific framework, including documentation and information obligations, with additional requirements for models posing systemic risk. Buying a model does not, however, mean buying full compliance for the application built around it.
Providing the means for oversight
Governance requires procedures that work when production accelerates: who authorizes a new use, who can suspend it, who investigates a recurring error? Purely token human oversight is not enough. The person responsible for oversight must understand the system’s limitations and have genuine authority. This requires staff time, skills and sometimes changes to processes.
Tailoring training to use cases
The AI literacy obligation does not require the same universal certification for every employee. It calls for measures tailored to people’s knowledge, the context and the uses involved. A recruiter, a developer and a customer service adviser do not have the same needs. An appropriate budget therefore funds targeted training: recognizing a fabricated answer, avoiding the input of confidential data and understanding when to challenge an automated recommendation.
The real trade-off: scale up or walk away
For a finance department, the right question is not simply “how much does the AI Act cost?” but “which uses justify their total cost?” Integration, controls, training and the maintenance of evidence come on top of the license fee. A project that looks appealing in a demonstration may prove unprofitable if every output requires lengthy verification. Conversely, shared procedures can reduce the cost of subsequent deployments.
The risk of penalties reinforces this discipline: for certain infringements, the legislation provides for maximum fines of up to €35 million or 7% of global annual turnover, with specific rules for SMEs. But the commercial stakes could carry just as much weight. A provider unable to explain its system risks slowing down a tender process; a customer without an inventory risks discovering its dependencies at the worst possible moment. Documentation quality could therefore become a purchasing criterion.
What next? The next battle may be less about the number of models deployed than the ability to operate them sustainably. Companies would benefit from building a common foundation: a continuously updated inventory, assigned responsibilities, appropriate contractual clauses and proportionate training. Compliance guarantees neither performance nor the absence of errors. It can nevertheless become an infrastructure for trust, provided companies fund useful controls rather than a collection of files nobody reads.


