The AI Act, Europe's law on artificial intelligence, was meant to apply in full from 2 August 2026. Six days earlier, Europe pushed the heaviest part to 2027. For anyone running innovation, little changes: when AI enters the company through the projects, you need to know which ones, who answers for it and how it was chosen. The City Green Light case shows how to do it without risking delays.

What actually changed on 2 August 2026 under the AI Act?

On 2 August 2026 one thing changed: transparency. These are the rules in Article 50 of Regulation (EU) 2024/1689, and they fit in three sentences.

  • If a person talks to a chatbot, they must know there is an AI on the other side.
  • If content is generated or altered by AI, it must be recognisable as such.
  • If a system reads emotions or categorises people, whoever uses it must inform the people involved.

From the same date Europe can also supervise, and fine, whoever builds the large general-purpose AI models, the ones that answer any question. The regulation treats them separately for a reason: those models are the basis of the ready-made AI tools companies buy.

The rest of the law was already in force and has not moved:

  • since 2 February 2025 the unacceptable uses of AI are banned, and whoever uses AI has to train their people;
  • since 2 August 2025 the rules for whoever builds the large models apply. What is new this year is that Europe can now fine them too.

For banned uses, fines go up to €35 million or 7% of worldwide turnover, whichever is higher (Article 99).

What was postponed, and until when?

The rules on "high-risk" AI systems were postponed, meaning the systems that make decisions about people. Regulation (EU) 2026/1744 decided it: published on 24 July 2026, in force since 27 July. There are two new dates.

  • 2 December 2027 for AI that selects staff, assesses students, decides on access to credit or essential services, identifies people, or runs critical infrastructure (Annex III).
  • 2 August 2028 for AI inside products that are already regulated, such as machinery and medical devices (Annex I).

The same regulation eased the training duty: it stays, but there is no longer a predefined level of competence to prove. And it added a ban on systems that generate intimate images without consent, from 2 December 2026.

The postponement moves a date; it does not cancel the work. Anyone using a high-risk system will still have to assess it, keep it under human oversight and manage incidents. They just have sixteen more months.

Why does the AI Act concern innovation managers?

The AI Act concerns innovation managers because AI enters the company through them, before it enters through IT. It comes in with the startup selected in a challenge, with the three-month pilot, with the tool a team tries without going through procurement. These are roads built for speed, and along those roads almost nobody stops to write down what kind of AI they are letting in.

The City Green Light case

Take a real case. City Green Light is an energy service company from Vicenza that designs and runs public lighting and smart city services for public administrations. The innovation team was already doing scouting and experiments. However, the information remained unstructured: a more precise structure was needed, with a clear direction for the work and a shared method.

With blendX the work started from the people: each part of the company was asked what it needed. Three priorities came out, and one of them was about data and AI. From there the search began: over 90 startups found and sorted, each with its own record saying what it does and which need it answers. The most promising ones went all the way to the first experiments.

Now look at the same thing through the AI Act. Many of those startups bring AI with them. If tomorrow the legal team asked for the list of AI systems used in the company, with an owner for each, anyone working across files and emails would have to rebuild it by hand, project by project. Anyone who, like City Green Light, has all the records in one place pulls it out straight away.

Governing AI in innovation processes means knowing, for every project, what AI is inside, what it is for, who answers for it and what criteria it was chosen with.

Which questions should you ask of every project that uses AI?

Every project that uses AI should be asked four questions, and the answers belong in the project record, not in a meeting.

  • Is there AI inside, and who provides it? A startup's solution often sits on a third-party model: write down which one.
  • What is it for, and who does it decide about? A tool that selects candidates or assesses a person's creditworthiness is "high risk". One that summarises documents is not.
  • Who answers for it in the company? A name, not a department.
  • What criteria did we choose it with? And where the decision to go ahead is recorded.

How do you govern AI without stopping projects?

You govern AI without stopping projects by asking those same four questions at these moments:

  • When a startup applies to an open innovation challenge: the form asks whether there is AI and what kind.
  • When a proof of concept becomes a pilot: you check what it is for and who answers for it.
  • When the tool actually goes into use: by then the answers to the four questions must already be written down, not something to dig up.

It is the same principle as innovation governance: criteria known in advance, decisions recorded with their reasons. In blendX every step is linked to portfolio data and keeps the history of decisions: it is what you see in the City Green Light case, from the startup portfolio to the PoC.

It applies to us too. NIXIE, blendX's AI, works with each customer's data kept isolated, never feeding public models, and backs every answer with the sources it comes from.

What should you do now?

Use the extra time to run the census calmly, before it becomes urgent. Here is what to do, in order:

  • List the open projects that use AI, including the stalled ones.
  • Add the four questions to the record new projects start from.
  • For projects already running, answer "what is it for, and who answers for it" at the next meeting where they come up.

Anyone who reaches 2 December 2027 with this work done will only have a list to keep up to date.

If your applications come in through a challenge or a call for ideas, that is the place to start. Our free guide The auditable call for ideas explains how to collect and assess them in a traceable, defensible way.

Sources

This article summarises the regulatory framework as of 24 September 2026 and is not legal advice.