The EU AI Act Deadline Is Here and Why Compliance Without Governance Will Fail – Part 1
- 17 hours ago
- 7 min read
Naómi Oosthuizen is the Founder and Managing Partner of Sentio™, specialising in cybersecurity, AI governance, digital resilience, and board-level risk management across Europe. She writes about the intersection of technology, governance, regulation, and human decision-making.
This is Part 1 of a three-part series on the EU AI Act. Part 2 covers why compliance without governance fails, the AI inventory, accountability, and human oversight. Part 3 covers the evidence regulators will expect, five questions for your board, and a frequently asked questions section.

Can your board name every place where artificial intelligence now touches a decision inside your organisation, say who owns the risk when one of those systems behaves in a way nobody expected, and produce the supporting evidence without a fortnight of scrambling? On 2 August 2026, a significant part of the European Union's Artificial Intelligence Act became applicable, and in most boardrooms, the honest answer to all three questions is still no. This article sets out what actually changed on that date, what Europe has just moved and what it has deliberately left where it was, why a compliance exercise will not save an organisation that has no governance underneath it, and the five questions your board needs to put to management now.
What is the EU AI Act, and who does it apply to?
The Artificial Intelligence Act is Regulation (EU) 2024/1689. It was adopted on 13 June 2024, published in the Official Journal on 12 July 2024, and entered into force on 1 August 2024.[4] It applies in phases rather than all at once. The Article 50 transparency obligations became applicable on 2 August 2026, while the amended timetable now defers most high-risk system requirements to 2027 or 2028, a distinction that has been widely misreported and that I return to below.
The Act borrows heavily from the European Union's product-safety model. The Commission is explicit that the classification of a high-risk system rests on its intended purpose, in line with existing product-safety legislation, so the same underlying model can attract almost no obligations in one deployment and a full conformity regime in another.[3] The borrowing only goes so far. Fundamental rights, transparency, prohibited practices, general-purpose AI models, and public-sector use all sit inside the Act as well, which is a considerably wider footprint than conventional product safety and explains why a purely engineering-led response tends to leave the largest exposures untouched.
The Act draws a line between providers, those who develop an artificial intelligence system and place it on the market, and deployers, who use one under their own authority in the course of their professional activity. Many organisations will meet the Act first as deployers, and a striking number of them have concluded on that basis that it is a problem belonging to their vendors. That is a costly misreading for two reasons. Deployers carry substantial obligations of their own, and the transparency duties that arrived in August land on them directly. An organisation can also cross the line into provider territory by developing a system, placing one on the market under its own name, or making a substantial modification to one it bought, at which point the heavier regime attaches to it rather than to the supplier it thought was carrying the risk.
The General Data Protection Regulation governs the processing of personal data. NIS2, the second Network and Information Security Directive, sets cybersecurity and incident-reporting duties across essential and important sectors. DORA, the Digital Operational Resilience Act, governs operational resilience and third-party technology risk in financial services. A single artificial intelligence use case can sit inside all three categories at once, alongside the AI Act, which is exactly why treating artificial intelligence as a self-contained compliance topic tends to fail.
Many existing applications, from spam filters to inventory management, fall outside the Act entirely, and their operators may adopt codes of conduct voluntarily if they choose to.[1] That boundary is legal, not managerial. Systems carrying no duties under the AI Act may still carry business risk, security risk, and obligations under other European Union law, and the absence of a regulatory trigger has never been the same thing as the absence of exposure.
What changed on 2 August 2026?
From that date, the transparency obligations in Article 50 apply, and the duties are allocated with more precision than most summaries would suggest. Providers of systems designed to interact directly with people must build them so that a person is informed they are dealing with an artificial intelligence system, unless that is already obvious in the circumstances. Providers of generative systems must mark their outputs in a machine-readable format so that the content is detectable as artificially generated or manipulated, using solutions that are effective, interoperable, and reliable as far as is technically feasible. Deployers of systems producing deepfakes must visibly disclose that the content is artificially generated or manipulated, and deployers publishing AI-generated or AI-manipulated text to inform the public on matters of public interest must disclose that too, unless the text has undergone human review and someone has assumed editorial responsibility for it. Specific exceptions apply to each of these duties, which is why the drafting matters and why a blanket policy statement will not survive contact with a regulator.[3]
On 10 June 2026, the European Commission published the final Code of Practice on transparency of AI-generated content, and the Commission and the AI Board have since confirmed that it is an adequate voluntary tool for demonstrating compliance with these obligations. While the Code remains voluntary, the Article 50 requirements are not. The obligations arise from the Regulation itself and apply whether or not an organisation ever signs anything. Organisations that prefer a different route are free to take it, but they will then have to demonstrate to a market surveillance authority that their own measures are adequate, and that assessment will be made individually.[2] For deployers who want a straightforward starting point, the European Union has also issued a set of icons that can be used to label AI-generated content.
Did the European Union delay the AI Act?
Partly, and the imprecision of the headlines has done real damage. The Digital Omnibus on AI was proposed by the Commission in November 2025, adopted by Parliament on 16 June 2026, approved by the Council on 29 June, and signed on 8 July. It was published in the Official Journal on 24 July 2026 as Regulation (EU) 2026/1744 and entered into force three days later, on 27 July, with less than a week to spare before the date it was drafted to move.[5] That sequence matters more than it sounds. Until publication, the original timetable in Regulation (EU) 2024/1689 remained the operative law rather than the amended one, and any organisation that had already stood its programme down on the strength of a press release was, for those weeks, planning against a text that had no legal force. The question is now settled, and the amended dates are law.
On the content of the amendments, the position is fixed. The obligations attaching to stand-alone high-risk systems listed in Annex III move from 2 August 2026 to 2 December 2027. Those attaching to high-risk systems embedded as safety components in products already covered by European Union safety legislation under Annex I move to 2 August 2028. The requirement on Member States to establish a national regulatory sandbox moves to 2 August 2027. A new prohibition covering the generation of non-consensual sexual and intimate content, and of AI-generated child sexual abuse material, applies from 2 December 2026.[6]
Article 50 survived the amendments almost entirely intact. Its transparency duties arrived on 2 August 2026 as originally legislated, and only the marking obligation on legacy systems was given relief. What the amendments introduce is a shortened transitional grace period, running to 2 December 2026, for providers to implement the technical marking solutions on generative systems that were already on the market. Whether a particular system falls inside that transition or outside it depends on the precise transitional provisions in the published text, so this is a question to put to the Regulation rather than to a press summary. Generative artificial intelligence is now used across a substantial and growing share of enterprises, while comparatively few build high-risk systems, which is why the deferral that dominated the coverage is not the deadline that will dominate most compliance calendars.
The timetable at a glance
Date | What applies from that date |
2 August 2026 | Article 50 transparency obligations, covering disclosure of interaction with an AI system, the labelling of deepfakes, and the labelling of certain AI-generated text published to inform the public. |
2 December 2026 | End of the transitional grace period for providers to implement machine-readable marking on generative systems already on the market, and application of the new prohibition on the generation of non-consensual sexual and intimate content and of AI-generated child sexual abuse material. |
2 August 2027 | Member States to have at least one national regulatory sandbox in place. |
2 December 2027 | High-risk obligations for stand-alone systems listed in Annex III. |
2 August 2028 | High-risk obligations for systems embedded in regulated products under Annex I. |
These dates reflect Regulation (EU) 2026/1744 as published in the Official Journal on 24 July 2026 and in force since 27 July 2026.
Part 2 covers why compliance without governance fails, the AI inventory, accountability, and what meaningful human oversight requires in practice.
If you are unsure which of these obligations already apply to you, a structured readiness assessment is the fastest way to find out. You can find out more about how we work here.
Read more from Naómi Oosthuizen
Naómi Oosthuizen, Interim Specialist, CISO & CIO
Naómi Oosthuizen is the Founder and Managing Partner of Sentio™, a European cybersecurity and governance advisory firm. With more than two decades of international leadership experience across financial services, government, and critical infrastructure, she specialises in cybersecurity, AI governance, enterprise risk management, and digital resilience. Through her writing, she explores the future of technology, governance, organisational behaviour, and digital trust.
References:
[1] Deloitte. (2024). EU Artificial Intelligence Act: Deep dive. Deloitte.
[2] European Commission. (2026a). Code of practice on transparency of AI-generated content. Shaping Europe's Digital Future.
[3] European Commission. (2026b). Navigating the AI Act: Questions and answers. Shaping Europe's Digital Future.
[4] European Parliament and Council of the European Union. (2024). Regulation (EU) 2024/1689 of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act). Official Journal of the European Union, L, 2024/1689, 12 July 2024.
[5] European Parliament and Council of the European Union. (2026). Regulation (EU) 2026/1744 of 8 July 2026 amending Regulations (EU) 2024/1689, (EU) 2018/1139, and (EU) 2023/1230 as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI). Official Journal of the European Union, L, 2026/1744, 24 July 2026.










