Skip to content
56NorthExperts
All insights

EU AI Act

EU AI Act: what companies using Copilot, Agentforce or Joule must do now

Pascal Mennesson
By Pascal Mennesson

Founder, 56North · 1 October 2026 · 3 min read

Most large companies did not build their own AI models. They switched on Microsoft 365 Copilot, built agents in Agentforce, enabled Joule in SAP or Now Assist in ServiceNow. Under the EU AI Act, that does not make them bystanders: a company that uses an AI system under its own authority is a deployer, with obligations of its own. This article sums up what applies today, what was postponed, and where to start. It is general information, not legal advice.

Provider or deployer: which one are you?

The provider develops an AI system and places it on the market or puts it into service under its own name. The deployer uses it in its business. When you use Copilot as delivered, Microsoft is the provider and you are the deployer. The line moves when you build your own agent on a platform and put it into service under your name, for example a customer-facing assistant on your website: for that system, you may be considered the provider. That matters for the transparency rules below.

What already applies

  • Prohibited practices (since 2 February 2025). Some uses are banned outright, whatever the tool. For companies, the most relevant is emotion recognition in the workplace and in education, except for medical or safety reasons. Check that no HR or employee-monitoring feature does this.
  • Transparency (since 2 August 2026). Article 50 requires that people are informed when they interact with an AI system, unless it is obvious. Deployers must also disclose deepfakes, inform people exposed to emotion recognition or biometric categorisation, and disclose AI-generated text published to inform the public on matters of public interest, unless it has been reviewed by a person who takes editorial responsibility. In practice: a clear notice on every customer-facing chatbot or agent, and a rule for AI-generated images, video and audio.

What was postponed, and to when

The Digital Omnibus on AI, Regulation (EU) 2026/1744, entered into force on 27 July 2026. It moved the obligations for high-risk systems listed in Annex III to 2 December 2027, and for AI embedded in products already regulated under Annex I to 2 August 2028. It did not change the transparency rules.

Annex III covers uses that enterprise platforms make easy: screening job applications or evaluating employees (Workday, SAP SuccessFactors, Microsoft tools), credit scoring, access to education, some uses of biometrics. The same tool can be high-risk in one use and not in another: summarising a meeting is not screening candidates.

What a deployer of a high-risk system will have to do

From December 2027, Article 26 requires deployers of high-risk systems to:

  • use the system according to the provider's instructions;
  • assign human oversight to people who have the competence, training and authority to exercise it;
  • make sure the input data under their control is relevant and representative for the purpose;
  • monitor the system and report serious incidents;
  • keep the logs generated by the system for at least six months, where those logs are under their control;
  • inform workers' representatives and affected workers before using such a system at work;
  • inform people when a high-risk system is used to make, or help make, decisions about them.

Public bodies, and companies that score credit or price life and health insurance, must also carry out a fundamental rights impact assessment (Article 27).

Penalties

  • Prohibited practices: up to €35 million or 7% of worldwide annual turnover.
  • Most other obligations, including transparency: up to €15 million or 3%.

Where to start

  1. Make the inventory. List every AI system in use, including the AI features switched on in your existing software and the tools employees use with their own accounts.
  2. Classify each use, not each tool. Note who uses it, for what decision, and on whom.
  3. Name an owner for each system: a person, not a department.
  4. Close the transparency gaps now. That is the obligation in force today.
  5. Start the evidence file for any use that could be high-risk: design decisions, tests, oversight, incidents. Evidence produced after the fact convinces nobody.

This work needs people who know both the platform and the regulation. Our experts on Microsoft, Salesforce, SAP, ServiceNow and Workday are briefed on the obligations that apply to their scope. For the governance itself (inventory, classification, evidence), see 56North.

Questions and answers

Is a company that uses Microsoft Copilot subject to the AI Act?

Yes, as a deployer. Microsoft is the provider of Copilot; the company that uses it under its own authority has its own obligations, which depend on how it uses the tool.

When do high-risk AI obligations apply to deployers?

On 2 December 2027 for the uses listed in Annex III, such as recruitment and credit scoring, following Regulation (EU) 2026/1744. AI embedded in products regulated under Annex I follows on 2 August 2028.

Must a customer chatbot say it is an AI?

Yes. Since 2 August 2026, Article 50 requires that people are informed when they interact with an AI system, unless it is obvious from the context.

Sources

The 56North platform

Measure the AI you run. Prove you control it.

The 56North Cockpit lists the AI systems in service across your company, tracks them on five dials (reliability, costs, AI Act evidence, usage, reference data) and gathers the dated evidence the regulation requires.

Discover the 56North Cockpit

Need this expertise on your project?

Free to brief. A practice lead replies within one business day.

Request experts