Back to Blog
Automation

AI in 2026: What the Trends and the New Rules Actually Mean for Your Business

Article spoiler:CES 2026 in January mapped where AI products are heading over the next few years. The EU AI Act reached full general app…We care about our clients, so we made a short takeaway from this article. Press to quickly get the point.

CES 2026 in January mapped where AI products are heading over the next few years. The EU AI Act reached full general application on August 2, 2026, making European AI regulation a current operational fact rather than a future calendar item. GLC's read on both: what deserves real attention, what belongs on the monitoring list without immediate action, and what the landscape looks like for SMBs over the next six to twelve months.

Two things happened in quick succession in the AI space in 2026, and they are worth considering together. In January, CES 2026 gave a clear picture of the product direction: agentic systems that take action, multimodal models that handle text, image, and audio in a single workflow, and edge AI running inference on-device. In August, the European Union's AI Act reached full general application. The regulation that has been referenced as a future constraint since 2024 became a present one on August 2, 2026.

For most businesses, neither development requires panic. Both require a clear picture of what is actually happening, and a sense of where the relevant decisions are.

What CES 2026 showed about where AI is going

The CES Tech Talk episode on AI trends and policy from January 9, 2026 highlighted what observers saw on the show floor: practical AI applications across industries, the emerging policy conversation around autonomous systems, and the gap between AI product ambition and regulatory readiness. Across the show, three technology directions were consistent enough to carry into 2026 planning.

Agentic AI with real tool access. The dominant shift at CES and across the industry in 2026 is the move from AI that responds to AI that acts. Systems can now plan steps, invoke external tools, update records, and loop until a task is complete. The applications in SMB workflows are concrete: ticket creation and routing, CRM updates, document drafting from structured data, support request classification. The relevant design constraint is equally concrete: any agent that can take actions with real consequences (spending money, contacting customers, modifying records) requires explicit permission limits, complete logging, and human approval gates for high-impact steps. The capability is real; the discipline required to deploy it safely is the part that takes work.

Multimodal models as the working standard. The AI tools available in 2026 handle text, images, audio, and increasingly video within a single system, and the business applications are straightforward: support workflows that handle attachments, document processing that pulls data from images and PDFs, training content that combines visual and written explanation, and sales analysis that combines call recordings with written summaries. This is less a trend to evaluate and more a baseline to incorporate into tool selection.

Edge AI for latency and data control. Running AI inference on-device or close to the data source rather than sending everything to a cloud endpoint reduces latency, reduces the volume of data leaving the organisation, and lowers ongoing cloud costs. For SMBs, the applications include offline functionality for field teams, local processing of sensitive documents, and faster response in customer-facing tools. The constraint is genuine: edge AI forces attention to hardware limits, battery and memory profiles, and update management that cloud-only deployments sidestep.

What the EU AI Act actually requires, and from whom

The EU AI Act (Regulation 2024/1689) entered into force on August 1, 2024. The general date of full application is August 2, 2026, which means the regulation's core provisions are now in effect. Prohibited practices became applicable in February 2025. General-purpose AI model provider obligations applied from August 2025. The broadest category of requirements, covering high-risk AI systems, reached full application as of August 2 this year.

The Act uses a risk-based framework. The regulatory obligation scales with the potential harm a given AI application can cause, and for most SMBs, the practical impact sorts into three categories.

Prohibited uses, relevant regardless of company size. AI applications for social scoring of individuals by public authorities, real-time biometric identification in publicly accessible spaces without specific authorisation, and manipulation of people's behaviour using subliminal techniques are prohibited under all circumstances. For the vast majority of SMBs, these categories are not in consideration, but it is worth confirming that any AI application being evaluated is not in contact with them.

High-risk uses, where the compliance work is concentrated. High-risk applications under the Act include AI used in hiring decisions (CV screening, interview assessment, performance evaluation), AI used in credit scoring or financial decisions that affect individuals, AI in educational assessment, and AI used to determine access to essential services. For SMBs using AI in any of these contexts, specific requirements apply: documentation of the system's purpose and design, human oversight mechanisms, transparency to the people affected, and data quality requirements for training and operational data. If your business uses AI in recruitment, credit evaluation, or employee performance management, August 2026 is the practical activation date for compliance review.

Lower-risk uses, where transparency obligations apply but the full compliance burden does not. The largest category of SMB AI use, covering drafting tools, internal summarisation, customer service chatbots, content generation, marketing analysis, and internal workflow automation, falls outside the high-risk classification. For these applications, the primary obligations are transparency (users interacting with an AI system should know they are doing so) and avoiding the prohibited use cases above. The major AI providers whose APIs underpin most of these tools (OpenAI, Anthropic, Google) carry their own model-level compliance obligations for general-purpose AI.

Where to genuinely invest attention

Three areas warrant real investment of time and process, independent of what an SMB's specific AI use cases are.

Data governance. Which data enters AI systems, where it comes from, how long it is retained, and what happens to it after processing are questions that apply in every deployment. GDPR already required answers to most of these questions; the AI Act adds a layer that connects data quality to system accountability. Treating AI input data with the same discipline applied to any personal data processing is the practical baseline.

Transparency to users and employees. The obligation to inform people when they are interacting with an AI system, covering customer service, automated communications, and hiring processes, applies broadly under the Act and is increasingly expected by users independently of regulation. Building clear disclosure into AI-enabled workflows is both a compliance item and a trust investment.

Human oversight on consequential outputs. Any AI output that feeds into a decision with real consequences for a person or a business relationship should have a human review step. This is a design requirement in high-risk systems and a sensible operating principle in all others. The review step does not need to be exhaustive; it needs to exist and to be logged.

Where the noise-to-signal ratio is high

Not everything in the AI policy and trend landscape requires immediate action from an SMB.

The EU AI Act's enforcement infrastructure, including the national market surveillance authorities and the European AI Office established in 2024, is still building operational capacity. Enforcement focus in the near term will concentrate on high-risk systems in regulated industries. An SMB using an AI drafting tool or a customer support chatbot is not in the primary enforcement window.

Emerging technology categories discussed at CES 2026, including edge AI on consumer wearables, humanoid robotics, and fully autonomous vehicles, are genuinely interesting and will intersect with business operations over the next three to five years. They are not operational planning items for most SMBs in 2026.

General-purpose AI models and their output quality continue to improve quarter by quarter. Following every model release in detail is not a productive use of business time. Knowing which tier of model fits which class of task (the routing framework we covered in our GPT-5.6 article) is more useful than tracking individual capability benchmarks.

GLC's role in this environment

Part of the value GLC delivers to clients is following this landscape continuously so that a conversation with us produces a clear answer to the question "does this require action now, or is this a monitoring item?" We track product releases, regulatory timelines, and the gap between technical capability and real-world deployment, because that gap is where most SMB AI decisions are actually made.

If you want a practical read on whether your current AI use or planned AI implementation places you in a compliance category that requires attention, or if you want to evaluate which of the 2026 product trends applies to a specific workflow in your business, that is the kind of conversation that produces useful direction in under an hour. Get in touch


Sources: CES Tech Talk, "CES 2026: Reporting on the Future of AI Trends and Policy," January 9, 2026: ces.tech/ces-tech-talk. Innowise, "AI Trends 2026: Key Advancements, Innovations, and Future Insights," April 2026: innowise.com/blog/ai-trends. European Parliament, Regulation (EU) 2024/1689 (EU AI Act): artificialintelligenceact.eu.

Direct answers

  • The EU AI Act entered full general application on August 2, 2026, the most significant AI regulatory event in Europe this year, with direct consequences for any business using AI in hiring, credit, or high-stakes decisions
  • CES 2026 confirmed three product trends that are now in deployment: agentic AI with tool-calling capability, multimodal models handling text, image, audio, and video in a single system, and on-device edge inference that reduces cloud dependency
  • Most SMBs using AI for drafting, summarisation, support, and internal workflows fall well outside the high-risk classification; the compliance pressure is real but targeted
  • Where businesses genuinely need to invest attention: data governance, transparency disclosures to users, and human oversight on any AI output that affects a real decision with consequences
  • GLC follows the regulatory and product landscape so clients can focus on their core work, and we will tell you when something requires action and when it is background noise

Not sure if your AI use needs compliance attention?

We separate action items from background noise. Write to us — no call required.

EU AI ActAI regulationAI trends 2026agentic AISMB AI strategy

Share

XinWA
Get in touch

Let's talk business.

Ready to discuss your growth architecture? Fill out the form and we'll get back with an action plan within 24 hours.

You'll hear from us within 24 hours

We may save your answers in this browser as a draft until you send the form.