Estimated reading time: 7 minutes

Key Takeaways:

  • From 2 August 2026 most of the EU AI Act applies, including to companies that only use AI systems and do not build them.
  • The AI literacy obligation (Article 4) has applied since February 2025 and has no lower limit on company size.
  • Much of what the law asks of AI users (knowing which data a system sees, human oversight, being able to produce log files, transparency towards customers) overlaps with what a well-designed AI harness already does.
  • A harness is not proof of compliance. The formal steps (risk classification, documentation, where needed a conformity assessment by the provider) remain.
  • If your harness is in order, your main task for the AI Act is making demonstrable what already happens. If you work with loose prompts and uncontrolled tools, you still have to build both.

Table of Contents

  1. August 2026: the law takes full effect
  2. What the AI Act requires from users
  3. Four requirements, four parts of the harness
  4. What a harness does not cover
  5. How we can help
  6. Frequently asked questions
  7. Sources

August 2026: the law takes full effect

The EU AI Act has been in force since August 2024, but its obligations are phased in. The bans on certain applications and the AI literacy obligation have applied since February 2025. The biggest step follows on 2 August 2026: from that date the transparency obligations and the regime for high-risk systems under Annex III apply (AI Act implementation timeline).

For most companies that use AI in customer service, administration or knowledge sharing, the risk class is limited or minimal. The law still affects them: some obligations apply to all AI use, and the question "can you show what your AI does" lands on the table sooner than many business owners expect, for example through a customer, an insurer or a tender. We wrote earlier about what the AI Act means for midsize businesses.

A serious AI system consists of four parts: context, tools, orchestration and feedback. This article puts those four parts next to what the AI Act asks. The overlap is bigger than you would expect. What a harness is exactly and how those four parts fit together is covered in our overview article on the AI harness.

What the AI Act requires from users

The AI Act distinguishes between providers (who build an AI system or bring it to market under their own name) and deployers (who put it to use). The heaviest requirements sit with providers of high-risk systems. But even if you only use AI, there is homework (AI Act, Article 26):

  • AI literacy (Article 4). Everyone who works with AI on behalf of your company must sufficiently understand what the system can and cannot do. This obligation has applied since February 2025 and has no size threshold: it applies to the baker with a chatbot just as much as to a bank.
  • Use according to the instructions and human oversight. With high-risk systems you must use the system as the provider prescribes and have competent people supervising it.
  • Relevant input and log files. You must make sure the input data fits the purpose, and keep the automatically generated logs that are under your control, for high-risk systems at least six months.
  • Transparency (Article 50). People must know they are talking to an AI system, and AI-generated content must be recognizable as such where the law requires it.
Closed loop with four stations: context, tools, orchestration and feedback

Four requirements, four parts of the harness

Put this list next to the parts of a harness and you see they are largely the same questions.

Context and data control. The law wants you to know which data your system sees and whether it is appropriate. A harness enforces exactly that: for each agent it is defined which sources it may consult and which not. In our own harness we deliberately gave one of our three knowledge layers no AI access at all; a boundary like that can be explained to an auditor, a customer or a regulator in one sentence.

Tools and human oversight. The law asks for human control over decisions with consequences. In a harness that is a design choice in the toolset: our customer service agents may save a draft reply but not send it; a person sends it, after review. That is not an extra compliance layer on top of the system, it is the system.

Orchestration and traceability. Being able to produce log files means: being able to trace which step did what. A harness in which tasks run through specialized agents in clearly defined steps delivers that traceability by itself. One broad agent that does "everything" is not only harder to debug, it is also impossible to explain.

Feedback and demonstrability. The law expects you to intervene when a system does not do what it should. A harness with a working feedback loop (corrections are recorded, rules are enforced) shows that deviations are detected and processed. That is exactly the behavior supervisory frameworks want to see.

The AI literacy from Article 4 falls outside the technology, but not outside the approach: if you teach your team to work with agents, context boundaries and control points, that same program covers most of this obligation.

What a harness does not cover

Part of the obligations falls outside the scope of even a good harness. A harness makes your system auditable; it does not automatically make you compliant.

The risk classification of each application remains a separate step: you must assess (and record) which category a system falls into, and that judgment can turn out differently than your intuition. If you work with high-risk applications, there is a formal package of documentation and assessment requirements that largely sits with the provider, but that you as a user must make agreements about. And the GDPR continues to apply alongside the AI Act: a data processing agreement with your AI vendor and a legal basis for the data you process are not things the harness arranges for you.

The right summary is therefore: a harness makes you compliance-ready, not compliant. The difference between the two is a formal assessment, not a rebuild.

Wireframe stopwatch with a mint progress arc pointing at a deadline marker

How we can help

If you want to know where your AI use stands in relation to the AI Act, and whether your current setup can handle the questions that may come from August onwards, we include that in the AI scan.

If we build your AI systems together within AI in Business, auditability is part of the design from day one: context boundaries, human review on sensitive steps and logging are part of how we build, not a patch afterwards.

Book a free consultation if you want to know what needs to be in place for your organization before August.

Frequently asked questions

Does the EU AI Act also apply to small companies?

Yes. The AI literacy obligation (Article 4) has applied since February 2025 to every organization that uses AI, with no lower size limit. The heavier obligations depend on the risk class of the application, not on the size of your company.

Our AI applications are low risk. Do we still need to do anything?

Less, but not nothing. AI literacy always applies, and the transparency obligations (letting people know they are talking to AI, making AI content recognizable) apply from August 2026 to most chatbots and content generation.

Is an AI harness mandatory under the AI Act?

No, the law does not prescribe an architecture. But the requirements the law sets (data control, human oversight, logging, intervening when things go wrong) are hard to meet without a structure that looks a lot like one.

Are we compliant once our harness is in order?

Not yet. The harness delivers the auditability and the evidence; the formal steps (risk classification, documentation, agreements with providers, the GDPR side) are still needed. Compliance-ready is the honest term.

When does this need to be in place?

The AI literacy obligation already applies. The transparency and high-risk obligations apply from 2 August 2026. If you start with the harness questions now (which data, which controls, which logging) you have the summer to make it demonstrable.

Sources