

On August 2, 2026, most of the obligations under the EU AI Act came into effect, including the new transparency requirements. If your business uses a modern CRM platform, there is a good chance that AI is already running within your system: lead scoring, forecasting, chat agents, and content generation.
But do you know what the regulations actually require of you? Not as purchasers of the technology, but as users of it.
Many leadership teams treat the AI Act as something that only affects tech companies developing AI. That is a misunderstanding that could prove costly.
The AI Act is the world's first comprehensive AI regulation, and it is risk-based: the greater the risk the AI usage poses to individuals and society, the stricter the requirements.
The regulation has entered into force gradually:
February 2025: A ban on the most intrusive AI practices, and a requirement that everyone using AI must possess sufficient competence (so-called AI literacy).
August 2025: Requirements for generative AI models, i.e., the foundation models behind chatbots and assistants.
August 2, 2026: Most of the remaining obligations, including transparency requirements that customers must know when they are speaking to a chatbot, and the labeling of AI-generated content. The EU's simplification package (AI Omnibus), which entered into force on July 27, 2026, postponed the strictest requirements for high-risk AI systems until December 2, 2027.
The regulations apply in the EU and are incorporated into Norway via the EEA Agreement with national adaptations. If your business operates in the internal market or has customers in the EU, the requirements already affect you regardless.
You don't need to have "bought AI" to use AI. Modern CRM platforms come with AI features built into the standard product:
In addition, there is shadow AI: employees pasting customer data into ChatGPT or similar tools to write emails and summarize meetings.
Most businesses are therefore already AI users. And that is precisely the role to which the regulations attach obligations.
Many believe the AI Act only regulates the providers. In reality, the regulation distinguishes between providers, who develop AI systems, and users, who implement them in their own operations.
A Norwegian business using a CRM platform with AI features is typically a user. And users have independent obligations:
The applicable obligations depend on the risk category. Most CRM-related AI falls into the limited risk category, but there are exceptions.
Here, we take the liberty of challenging the reflex to send this to the legal department and wait for a report.
The requirements in the AI Act—data quality, documentation, human oversight, access control, and logging—are not primarily legal exercises. They are operational. And they overlap almost entirely with what you need anyway to get value out of AI.
Consider this:
There is, therefore, a direct link between compliance and value creation: Businesses that have control over their CRM data and processes become both regulatory-compliant and better at utilizing the AI they are already paying for.
Axaz CRM offers a review that gives you control quickly:
CRM Audit is a structured review of your entire CRM setup: data quality, adoption rates, integrations, security, and GDPR compliance, including a concrete assessment of where AI can replace manual steps today.
Wondering where your business stands? Book a no-obligation CRM coffee chat with us, and we will give you an honest assessment of your starting point.
This article is for awareness purposes and does not constitute legal advice. Its content is intended to make leaders aware of the practical implications of the AI Act and does not replace professional legal counsel. For specific legal assessments, you should consult with a lawyer.
