Businesses must start preparing for AI Act
Expert insight · 25 May 2026Artificial intelligence (AI) has, in recent years, evolved from experimental technology into an essential everyday work tool across many industries. Eleving Group is also increasingly using AI solutions in its business processes—in customer service, risk assessment, and process automation. At the same time, the rapid development of AI has increased the need for clear and sound regulations. For this reason, the European Union (EU) has adopted the new AI Act*, aimed at ensuring a safe, transparent, and trustworthy use of AI systems. Although discussions about certain implementation aspects and deadlines are still ongoing, the core requirements of the act are already clear, and companies should begin preparing for compliance in a timely manner.
The EU's AI Act establishes clear requirements regarding the supervision of AI system operations, data protection, algorithm transparency, accountability for automated decision-making, and system security. A unified EU-wide regulatory framework is necessary and should be viewed positively, as businesses need clear, consistent, and predictable “rules of the game”. At the same time, the regulation must also be practical and proportionate in its implementation so that it does not create an excessive administrative burden. Overly complex or unclear requirements may hinder innovation, which in turn could reduce the competitiveness of European companies in the global market.
One of the most significant challenges at present is the uncertainty surrounding the implementation timeline of the AI Act and the lack of detailed guidance. To give companies more time to prepare for the new requirements, the European Commission has proposed extending the application deadlines for certain provisions of the act as part of the so-called “Digital Omnibus” package. Currently, it is expected that the requirements for high-risk AI systems could become applicable from December 2, 2027, while for AI systems serving as product safety components—from August 2, 2028. However, this proposal has not yet been approved, and if the “Digital Omnibus” package is not adopted during the summer, the original deadline—August 2, 2026—will remain in force.
It must be understood that ensuring compliance with the AI Act requirements will be a time-consuming and complex process. In the case of high-risk AI systems, this includes system registration, risk classification, preparation of technical documentation, implementation of quality management mechanisms, and ensuring human oversight. Therefore, deadline extension should not be viewed as a reason to postpone preparations. Moreover, the sanctions for violations are particularly severe—depending on the type of infringement, fines may reach up to EUR 35 million or up to 7% of a company’s global annual turnover, whichever is higher. This exceeds the maximum penalty levels established under the General Data Protection Regulation (GDPR).
Although the final implementation deadline is still under discussion, companies must already begin preparing for stricter requirements related to AI governance, security, and transparency. In practice, this includes auditing AI solutions, identifying risks, developing internal guidelines, managing data quality, and strengthening employee competencies in the field of AI. It is expected that AI governance within companies will become similar to how data protection and cybersecurity are currently perceived—not as a one-time project, but as an integral and ongoing component of business risk management.
This is precisely why, alongside discussions at the European level, a more active national dialogue in Baltics is essential—bringing together supervisory authorities, businesses such as Eleving Group, and technology experts to address these issues collaboratively. The implementation of the regulation must be based on practical experience and a proportionate approach that simultaneously ensures a safe use of AI while avoiding unjustified obstacles to innovation.
Companies that already today deliberately build responsible AI governance and adapt their processes to the new requirements in a timely manner will gain a significant competitive advantage in the long term. These companies will achieve not only greater efficiency and a stronger ability to introduce innovations more quickly, but will also strengthen customer trust, reputation, and overall resilience in an increasingly strictly regulated digital environment.
Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence and amending Regulations (EC) No 300/2008, (EU) No 167/2013, (EU) No 168/2013, (EU) 2018/858, (EU) 2018/1139 and (EU) 2019/2144 and Directives 2014/90/EU, (EU) 2016/797 and (EU) 2020/1828 (Artificial Intelligence Act).
Get in touch
For media inquiries, please contact elina.dobulane@eleving.com.