ATAILA Newsroom · Budapest · 2026-08-11

Under the AI Act, you cannot account for what you do not operate

In early August the Hungarian business news site economx.hu published an overview — written by Ádám Vermes — that captures the moment the EU's AI regulation crossed from paper into enforcement, while most Hungarian companies cannot yet give an accurate picture even of their own AI use. As a company building a sovereign AI platform, we agree with the diagnosis. We would add one thing: most of the gaps the article lists are operational, not regulatory — and what you do not operate, you cannot account for.

What economx.hu reports

On 2 August 2026 the grace period ended: the regulation's transparency rules became applicable, and enforcement — in the article's words — has “switched on the AI police”. The practical consequences are concrete. A chatbot must make it clear that you are talking to a machine, at the latest when the first interaction begins. Providers of generative systems must ensure that the text, images, audio and video they create or modify are detectable in a machine-readable way. Deepfakes need dual marking: alongside the machine-readable mark, a warning that is clearly perceptible to a human. And AI-written text about politics, healthcare or consumer protection must be visibly labelled unless it goes through genuine human review or editorial control.

The deadlines do not end there, and the article specifically warns that the December date is widely misread. From 2 December 2026, AI systems that produce intimate content about real people without their consent, or that generate material depicting the abuse of children, become prohibited; the three-month grace period applies exclusively to generative systems already placed on the market before 2 August 2026. Full compliance rules for standalone high-risk systems have been postponed to 2 December 2027 — this covers recruitment and the management of workers, education and training, and lending and essential services. AI built into products covered by product-safety regulation must meet the detailed requirements from 2 August 2028.

The upper limit of the fines depends on the severity of the failure:

On Hungarian readiness, the article cites three numbers.

64%
of surveyed companies had no dedicated AI-ethics or governance body in operation (Deloitte Magyar AI Körkép 2025)
26%
of employees — no more than that, in another domestic survey — perceived a consistent corporate AI strategy at their workplace
77%
of chief executives have so far seen no demonstrable revenue growth or cost reduction from AI use (PwC Hungarian CEO survey, 2026)

The article ties all of this to a fourth phenomenon: shadow AI. Employees use chatbots, image generators and note-taking apps from personal accounts, while legal, IT and compliance cannot see what is happening. Oversight sits with the European Commission's AI Office at EU level and with the member states' authorities.

The urgency is justified — but the gap is not a policy gap

The description is accurate, and the urgency is justified too. We do not dispute the numbers, and we do not think the regulation is an overreach. What we would weight differently is the interpretation of the 64% figure.

The market mostly reads that gap as an organisational one: no committee, no policy, no designated owner. Those are indeed missing. But in our experience the bottleneck is not standing up the committee. It is that a company of 20–200 people, with the best of intentions, cannot answer four very simple questions: which model answered, from what data, who approved it, and where the data left the company. Those questions are answered not by a document but by a running system that logs.

That is why we think a consulting package on its own is half a solution. If AI use is scattered across personal accounts, even the best-written internal policy does not produce a single auditable line.

A policy records the intent. The evidence comes from operations.

And PwC's 77% is not a failure of AI but of delivery — we have written about that separately. The return does not come from a company “introducing AI”; it comes from one concrete, expensive, recurring workflow running in production, every day.

What ATAILA brings to this

For us, compliance is not a separate module: it follows from how the platform is built.

Data stays where the jurisdiction is

A prompt is data processing: when the text of a contract, a patient record or a financial statement goes into a model, that qualifies as a data transfer — even if all you see on screen is an input field. Our sovereign EU cloud therefore runs in an EU data centre, on our own hardware, with no American data processor on the route. It is not a rented-server arrangement: a sovereign environment built for production, with an identifiable operator and responsibility in writing.

What is not recorded cannot be proven

ATAILA Factory takes every application down the same path: sandbox, dev, uat, prod. Every promotion requires audited, role-based approval, secrets live in a vault rather than in code, and the full release history can be exported for the auditor. When an authority or a customer asks what ran in production on a given date and who approved it, the answer is a query, not a reconstruction.

Those four environments are not theory: our customer stories include a certification body that, after two years and two failed attempts — roughly HUF 20 million written off — got a working, modern application at the centre of its business from us in about two months, with four real environments. At the customer's request we do not publish their name.

Against shadow AI, an alternative works better than a ban

Employees do not reach for public tools out of malice; they reach for what is at hand. A private assistant running in the EU gives the same convenience as the public chatbots, but the conversation never leaves the platform and access can be managed. A company tool that people use voluntarily is worth more than a policy they route around.

Compliance is cheap when it is produced in one place

The market sells this in pieces: hardware here, a model there, an application, then consulting on top. With us, the infrastructure, the model serving, the application, the release process and the operations are in the same hands, for a fixed monthly fee, with no per-query billing. So logging, access management and data residency are not three separate projects the company has to assemble — they are the system's default state.

What we will not take over

We do not claim that moving to the ATAILA platform makes anyone AI Act-compliant. Compliance is a legal and organisational responsibility: the risk classification of your systems, user disclosure, the internal AI policy, employee training and the documentation remain the company's own. We are not a law firm, and we do not give legal opinions on whether a given use counts as high-risk.

What we provide is narrower and more concrete: the technical foundation without which compliance cannot be evidenced — known jurisdiction, a closed data path, an auditable release history and an operated system. If the policy exists but this foundation is missing, the document will not protect you. If this foundation is in place, writing the policy is a matter of weeks, not a year.

Nor do we claim that the deadline alone is a reason to migrate. If a company's AI use today amounts to generating a few pieces of marketing copy, it does not need a platform; it needs a half-day internal agreement. The right partner for us is the company with a recurring, expensive workflow on data it cannot put in a public cloud.

Start with the four questions

If you are mapping out where AI runs at your company, and on what data, and you cannot answer every one of those questions, there is something to talk about. We do not open with a demo; we open with the question of which of your processes already produces an auditable trail today, and which does not — the conversation is confidential and carries no obligation.

Get started →