ChatGPT to rewrite an email, Copilot to summarise a document, Gemini to search for information, or AI to generate visuals or analyse data… Generative AI has become part of everyday professional life.

In some cases, this has happened before companies have had time to clearly define the rules governing its use.

Since 2 August 2026, a new milestone has been reached: the EU AI Act is now broadly applicable, and new transparency requirements have come into force.

For businesses, the question is therefore no longer simply “Should we use AI?”, but rather: how can we use it in a controlled, secure and compliant way?

AI Act: What Changed in 2026?

The AI Act, the European Union’s regulation on artificial intelligence, follows a risk-based approach, with requirements proportionate to the level of risk associated with different AI systems and uses.

Its implementation is gradual.

Some provisions have already applied since February 2025, including rules on prohibited AI practices and AI literacy. Governance rules and certain obligations concerning general-purpose AI models have applied since August 2025.

Since 2 August 2026, the regulation has entered a new phase with its broader application and the introduction of transparency obligations, notably those set out in Article 50.

For organisations, this new stage makes the need to map and govern their AI uses increasingly concrete.

Transparency: Do AI-Generated Contents Need to Be Labelled?

This is one of the significant developments of summer 2026.

The AI Act introduces several transparency requirements depending on the type of system, the content generated and the organisation’s role.

Users must notably be informed when they are interacting directly with certain AI systems. Providers of systems that generate or manipulate content must also enable such content to be identifiable in a machine-readable format.

Under certain conditions, deepfakes must be disclosed as artificially generated or manipulated. Specific requirements also apply to certain AI-generated texts published for the purpose of informing the public on matters of public interest.

This does not mean that every email rewritten using ChatGPT or every illustration created with AI must automatically carry an “AI-generated” label.

The applicable obligation depends on the context, the type of content and how the system is being used.

For companies regularly producing content with AI, the right approach is therefore to identify the relevant use cases and establish appropriate transparency rules.

December 2026: Another Deadline to Anticipate

Not all requirements became applicable at the same time on 2 August.

A transitional period notably applies to certain generative AI systems placed on the market before 2 August 2026: their providers have until 2 December 2026 to comply with certain requirements concerning the marking and detection of AI-generated or manipulated content.

The regulatory timetable will continue to evolve, with obligations relating to certain systems classified as high-risk becoming applicable at a later stage.

For businesses, the challenge is therefore less about memorising every date and more about establishing AI governance capable of adapting to an evolving regulatory framework.

Do Your Employees Know the Rules?

The AI Act does not only concern legal, IT or compliance teams.

Since February 2025, providers and deployers of AI systems have been required to take measures to ensure a sufficient level of AI literacy among the people using these systems on their behalf, taking into account factors such as their knowledge, experience and the context in which AI is used.

This requirement reflects a very practical challenge: AI adoption cannot rely solely on individual initiatives.

Employees need to understand the limitations of the tools they use, maintain a critical perspective on AI-generated results and know the internal rules governing their use.

Awareness and training are therefore becoming essential components of a responsible AI strategy.

AI Governance: What Rules Should Companies Define?

Banning every AI tool is rarely an adequate response. Conversely, allowing each employee to freely choose their tools and practices can expose the organisation to new risks.

AI governance provides a common framework.

It can notably define:

  • authorised or recommended AI tools;
  • permitted, restricted or prohibited uses;
  • categories of data that may or may not be shared;
  • human validation requirements for AI-generated content;
  • applicable transparency obligations;
  • the responsibilities of different stakeholders;
  • best practices employees are expected to follow.

These rules can then be formalised in an AI usage policy or charter, supported by awareness and training initiatives.

The objective is not to slow down AI adoption, but to create an environment that enables organisations to benefit from AI while keeping its risks under control.

How Can Lùkla Support Your AI Adoption?

Implementing AI governance is about more than drafting a policy.

Organisations need to understand existing uses, identify risks, establish rules suited to their environment and, above all, ensure that employees understand and adopt them.

  • assessment and mapping of AI uses;
  • definition of governance and usage rules;
  • support in developing an AI charter;
  • awareness of risks and best practices;
  • employee training;
  • change management and support for AI adoption.

Our objective: enable you to integrate AI into your professional practices within a clear, understood framework tailored to your organisation.

AI Is Already Here. It’s Time to Set the Rules.

The gradual implementation of the AI Act highlights a simple reality: adopting AI is no longer just about choosing the right tools.

Companies now need to define how, why and under what conditions those tools can be used.

Governance, awareness, transparency, data protection and employee support are becoming essential components of controlled and responsible AI adoption.

Consent