Preparing for the EU AI Act: A Practical Checklist for Legal, Sales and Revenue Teams
5-step checklist to prepare teams for the EU AI Act
August 2026: core transparency rules apply (e.g., disclosing AI interactions)
December 2027: new deadline for high-risk AI obligations
December 2026: machine-readable marking requirements apply to legacy generative AI systems
This article is for informational purposes only and does not constitute legal advice. The EU AI Act's requirements may vary depending on your role, your AI systems, and how they are used. Consult your legal team to assess how these obligations apply to your organisation.
The EU AI Act is the first comprehensive law governing artificial intelligence, and it reaches any company doing business in the EU, wherever that company is based. If your teams use AI to draft contracts, generate quotes, or handle customer communications, it applies to you.
Here's what changed recently. The original rules set 2 August 2026 as the date most high-risk obligations would take effect. On 27 July 2026, the EU's Digital Omnibus on AI entered into force and moved several of those deadlines. Standalone high-risk AI obligations now apply from 2 December 2027. Transparency rules for AI-generated content apply from 2 December 2026.
More time, yes. But the requirements themselves haven't softened much, and the work to get ready takes months. The teams that keep preparing through the extension will be ready. The ones that wait will be scrambling in 2027.
This checklist covers 5 practical steps to get you there.
Map AI Usage
Start by finding out where AI already touches your commercial process. Most companies underestimate this. AI shows up in more places than legal expects: contract drafting tools, quote generation, pricing recommendations, chatbots, email assistants, and the CRM features your reps use every day.
Make a list. For each use, note what the AI does, what data it touches, and whether a person reviews the output before it reaches a customer. You can't govern what you can't see, so this map is the foundation for everything that follows.
Strengthen Governance
Once you know where AI operates, put people in the right places. The Act cares a lot about human oversight, especially for decisions that affect individuals like hiring or creditworthiness.
Define who approves what. If an AI tool drafts a contract clause or recommends a discount, someone with authority should be able to review, change, or reject it before it goes out. Build those checkpoints into your approval workflows so oversight happens automatically, without relying on anyone to remember.
Standardise Documents
Inconsistent contract language is both a compliance risk and a drag on speed. When every deal uses slightly different terms, you can't track obligations, and you can't prove your AI is producing compliant output.
Approved templates and clause libraries fix this. They give your AI tools a controlled set of language to work from, which keeps contracts consistent and makes it far easier to show a regulator, or your own audit team, exactly what your systems produce and why.
Improve Transparency
The Act's transparency rules arrived first, so start here. As of 2 August 2026, you'll need to disclose when content is generated by AI and when someone is interacting with an AI system instead of a person. By 2 December 2026, providers of generative AI systems already on the market must also embed machine-readable markings in AI-generated content so it can be identified as such.
Keep records. Audit trails and version history let you show who changed what, when, and with which tool. If a contract or quote is ever questioned, that history is your evidence. It also speeds up internal reviews, because nobody has to reconstruct what happened from old email chains.
Align Teams
AI compliance falls apart when legal, sales, and revenue operations work from different playbooks. Legal owns the risk. Sales owns the speed. Revenue operations owns the systems that connect them. All 3 need the same view.
Get them in a room. Agree on which AI tools are approved, what the oversight rules are, and who owns each part of the process. Responsible AI adoption is a team sport, and the companies that do it well treat it that way from day one.
How Conga Helps
This is the kind of operational discipline Conga is built for. Our Document Automation and Contract Lifecycle Management (CLM) tools work from approved templates and governed clause libraries to help keep the language in your contracts consistent and controlled. Automated workflows put human approval exactly where you need it. And built-in audit trails capture the full history of every agreement, giving legal, sales, and finance the transparency the Act expects.
The result is a commercial process you can move fast in and still stand behind when someone asks how a decision was made.
Learn more about how Conga solutions can support your business.
Frequently Asked Questions
-
What is the EU AI Act and who does it apply to?
The EU AI Act is the first comprehensive law regulating artificial intelligence. It applies to any organisation that develops, deploys, or uses AI systems affecting people in the EU, regardless of where the company is based. For commercial teams, that includes AI used in contract drafting, quoting, pricing, hiring, and customer communications.
-
When do the EU AI Act deadlines take effect?
The timeline shifted in July 2026 when the Digital Omnibus on AI entered into force. Core transparency obligations, including disclosure of AI interactions, apply from 2 August 2026. The machine-readable content-marking requirement for generative AI systems already on the market before that date applies from 2 December 2026. Standalone high-risk AI obligations apply from 2 December 2027, and high-risk AI embedded in regulated products applies from 2 August 2028. Prohibited AI practices and general-purpose AI rules already took effect in 2025.
-
Does the EU AI Act apply to AI used in contracts and quoting?
It can. Most AI used to draft contracts or generate quotes won't be classed as high-risk, but transparency obligations still apply when AI generates customer-facing content or interacts with people directly. AI used in areas like hiring or credit assessment is treated as high-risk and carries stricter requirements. Mapping exactly where AI operates in your process is the first step to knowing which rules apply.
-
What does human oversight mean under the EU AI Act?
Human oversight means a qualified person can review, adjust, or override an AI system's output before it affects someone, particularly for consequential decisions. In practice, that means building approval checkpoints into your workflows so AI-generated clauses, pricing, or terms get a human sign-off before reaching a customer.
-
How can CLM and document automation support EU AI Act readiness?
CLM and document automation help by enforcing approved templates and governed clause libraries, so AI works from a controlled set of language to produce a more consistent output. Automated workflows route outputs to the right approver, and audit trails record the full history of every change. Together, that gives legal, sales, and finance teams the transparency and control the Act expects, while keeping deals moving.