top of page

The EU AI Act Deadline Is Here and Why Compliance Without Governance Will Fail – Part 1

  • 17 hours ago
  • 7 min read

Naómi Oosthuizen is the Founder and Managing Partner of Sentio™, specialising in cybersecurity, AI governance, digital resilience, and board-level risk management across Europe. She writes about the intersection of technology, governance, regulation, and human decision-making.

Executive Contributor Pritesh Lohar

This is Part 1 of a three-part series on the EU AI Act. Part 2 covers why compliance without governance fails, the AI inventory, accountability, and human oversight. Part 3 covers the evidence regulators will expect, five questions for your board, and a frequently asked questions section.


A young man with light brown hair sits outdoors, intently reading an open, dark-covered book held in both hands. He wears a beige jacket over a red sweater and white collared shirt, with a blurred field and tree in the background.

Can your board name every place where artificial intelligence now touches a decision inside your organisation, say who owns the risk when one of those systems behaves in a way nobody expected, and produce the supporting evidence without a fortnight of scrambling? On 2 August 2026, a significant part of the European Union's Artificial Intelligence Act became applicable, and in most boardrooms, the honest answer to all three questions is still no. This article sets out what actually changed on that date, what Europe has just moved and what it has deliberately left where it was, why a compliance exercise will not save an organisation that has no governance underneath it, and the five questions your board needs to put to management now.


What is the EU AI Act, and who does it apply to?


The Artificial Intelligence Act is Regulation (EU) 2024/1689. It was adopted on 13 June 2024, published in the Official Journal on 12 July 2024, and entered into force on 1 August 2024.[4] It applies in phases rather than all at once. The Article 50 transparency obligations became applicable on 2 August 2026, while the amended timetable now defers most high-risk system requirements to 2027 or 2028, a distinction that has been widely misreported and that I return to below.


The Act borrows heavily from the European Union's product-safety model. The Commission is explicit that the classification of a high-risk system rests on its intended purpose, in line with existing product-safety legislation, so the same underlying model can attract almost no obligations in one deployment and a full conformity regime in another.[3] The borrowing only goes so far. Fundamental rights, transparency, prohibited practices, general-purpose AI models, and public-sector use all sit inside the Act as well, which is a considerably wider footprint than conventional product safety and explains why a purely engineering-led response tends to leave the largest exposures untouched.


The Act draws a line between providers, those who develop an artificial intelligence system and place it on the market, and deployers, who use one under their own authority in the course of their professional activity. Many organisations will meet the Act first as deployers, and a striking number of them have concluded on that basis that it is a problem belonging to their vendors. That is a costly misreading for two reasons. Deployers carry substantial obligations of their own, and the transparency duties that arrived in August land on them directly. An organisation can also cross the line into provider territory by developing a system, placing one on the market under its own name, or making a substantial modification to one it bought, at which point the heavier regime attaches to it rather than to the supplier it thought was carrying the risk.


The General Data Protection Regulation governs the processing of personal data. NIS2, the second Network and Information Security Directive, sets cybersecurity and incident-reporting duties across essential and important sectors. DORA, the Digital Operational Resilience Act, governs operational resilience and third-party technology risk in financial services. A single artificial intelligence use case can sit inside all three categories at once, alongside the AI Act, which is exactly why treating artificial intelligence as a self-contained compliance topic tends to fail.


Many existing applications, from spam filters to inventory management, fall outside the Act entirely, and their operators may adopt codes of conduct voluntarily if they choose to.[1] That boundary is legal, not managerial. Systems carrying no duties under the AI Act may still carry business risk, security risk, and obligations under other European Union law, and the absence of a regulatory trigger has never been the same thing as the absence of exposure.


What changed on 2 August 2026?


From that date, the transparency obligations in Article 50 apply, and the duties are allocated with more precision than most summaries would suggest. Providers of systems designed to interact directly with people must build them so that a person is informed they are dealing with an artificial intelligence system, unless that is already obvious in the circumstances. Providers of generative systems must mark their outputs in a machine-readable format so that the content is detectable as artificially generated or manipulated, using solutions that are effective, interoperable, and reliable as far as is technically feasible. Deployers of systems producing deepfakes must visibly disclose that the content is artificially generated or manipulated, and deployers publishing AI-generated or AI-manipulated text to inform the public on matters of public interest must disclose that too, unless the text has undergone human review and someone has assumed editorial responsibility for it. Specific exceptions apply to each of these duties, which is why the drafting matters and why a blanket policy statement will not survive contact with a regulator.[3]


On 10 June 2026, the European Commission published the final Code of Practice on transparency of AI-generated content, and the Commission and the AI Board have since confirmed that it is an adequate voluntary tool for demonstrating compliance with these obligations. While the Code remains voluntary, the Article 50 requirements are not. The obligations arise from the Regulation itself and apply whether or not an organisation ever signs anything. Organisations that prefer a different route are free to take it, but they will then have to demonstrate to a market surveillance authority that their own measures are adequate, and that assessment will be made individually.[2] For deployers who want a straightforward starting point, the European Union has also issued a set of icons that can be used to label AI-generated content.


Did the European Union delay the AI Act?


Partly, and the imprecision of the headlines has done real damage. The Digital Omnibus on AI was proposed by the Commission in November 2025, adopted by Parliament on 16 June 2026, approved by the Council on 29 June, and signed on 8 July. It was published in the Official Journal on 24 July 2026 as Regulation (EU) 2026/1744 and entered into force three days later, on 27 July, with less than a week to spare before the date it was drafted to move.[5] That sequence matters more than it sounds. Until publication, the original timetable in Regulation (EU) 2024/1689 remained the operative law rather than the amended one, and any organisation that had already stood its programme down on the strength of a press release was, for those weeks, planning against a text that had no legal force. The question is now settled, and the amended dates are law.


On the content of the amendments, the position is fixed. The obligations attaching to stand-alone high-risk systems listed in Annex III move from 2 August 2026 to 2 December 2027. Those attaching to high-risk systems embedded as safety components in products already covered by European Union safety legislation under Annex I move to 2 August 2028. The requirement on Member States to establish a national regulatory sandbox moves to 2 August 2027. A new prohibition covering the generation of non-consensual sexual and intimate content, and of AI-generated child sexual abuse material, applies from 2 December 2026.[6]


Article 50 survived the amendments almost entirely intact. Its transparency duties arrived on 2 August 2026 as originally legislated, and only the marking obligation on legacy systems was given relief. What the amendments introduce is a shortened transitional grace period, running to 2 December 2026, for providers to implement the technical marking solutions on generative systems that were already on the market. Whether a particular system falls inside that transition or outside it depends on the precise transitional provisions in the published text, so this is a question to put to the Regulation rather than to a press summary. Generative artificial intelligence is now used across a substantial and growing share of enterprises, while comparatively few build high-risk systems, which is why the deferral that dominated the coverage is not the deadline that will dominate most compliance calendars.


The timetable at a glance


Date

What applies from that date

2 August 2026

Article 50 transparency obligations, covering disclosure of interaction with an AI system, the labelling of deepfakes, and the labelling of certain AI-generated text published to inform the public.

2 December 2026

End of the transitional grace period for providers to implement machine-readable marking on generative systems already on the market, and application of the new prohibition on the generation of non-consensual sexual and intimate content and of AI-generated child sexual abuse material.

2 August 2027

Member States to have at least one national regulatory sandbox in place.

2 December 2027

High-risk obligations for stand-alone systems listed in Annex III.

2 August 2028

High-risk obligations for systems embedded in regulated products under Annex I.


These dates reflect Regulation (EU) 2026/1744 as published in the Official Journal on 24 July 2026 and in force since 27 July 2026.


Part 2 covers why compliance without governance fails, the AI inventory, accountability, and what meaningful human oversight requires in practice.


If you are unsure which of these obligations already apply to you, a structured readiness assessment is the fastest way to find out. You can find out more about how we work here.


Follow me on LinkedIn and visit my website for more info!

Read more from Naómi Oosthuizen

Naómi Oosthuizen, Interim Specialist, CISO & CIO

Naómi Oosthuizen is the Founder and Managing Partner of Sentio™, a European cybersecurity and governance advisory firm. With more than two decades of international leadership experience across financial services, government, and critical infrastructure, she specialises in cybersecurity, AI governance, enterprise risk management, and digital resilience. Through her writing, she explores the future of technology, governance, organisational behaviour, and digital trust.

References:

[1] Deloitte. (2024). EU Artificial Intelligence Act: Deep dive. Deloitte.

[2] European Commission. (2026a). Code of practice on transparency of AI-generated content. Shaping Europe's Digital Future.

[3] European Commission. (2026b). Navigating the AI Act: Questions and answers. Shaping Europe's Digital Future.

[4] European Parliament and Council of the European Union. (2024). Regulation (EU) 2024/1689 of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act). Official Journal of the European Union, L, 2024/1689, 12 July 2024.

Tags:

 
 

This article is published in collaboration with Brainz Magazine’s network of global experts, carefully selected to share real, valuable insights.

Article Image

Five Ways Your Brain Can Learn Something New

When I was diagnosed with autoimmune disease at seventeen, nobody spoke to me about my brain. They spoke about my eyes, my immune system, and medication. They explained that my body was attacking itself...

Article Image

Why Your Business Stalls When You Work Harder

You have followed the plan and made the right moves, perhaps hiring more staff, adding a marketing channel, or implementing a new system that promised to save you time. Initially, these changes seemed effective.

Article Image

You Cannot Separate Who You Are from How You Work

There is a version of professional success that looks impressive from the outside and costs everything on the inside. You hit your numbers, meet your deadlines, and keep showing up, capable and dependable...

Article Image

Why Your Marketing Feels Flat and How to Make It Feel Alive Again

I think we were taught marketing backward. We learned to optimize before we learned to express, to perfect before we share, and to consider the audience before we consider our personal truth.

Article Image

What If You Can? The Question More People Should Ask Themselves

Every meaningful journey begins with a question. For many of us, however, the questions we ask ourselves are rooted in fear rather than possibility. We wonder what might go wrong instead of...

Article Image

How To Prepare Your Family for a Stress-Less Summer Holiday

Yay, a family holiday! Why am I not excited? The car is finally packed (all by you, so it’s done properly). Someone can't find their shoes (did they even have them on when they got in the car?). One child is...

The Difference Between Rest and Retreat

11 Ways the Performing Arts Build Confidence and Practical Life Skills in Young People

The Practice of Returning and Why Yoga and Meditation Are More Than Wellness

Why One Diet Doesn't Work for Everyone

You Are Functioning, But Are You Actually Okay?

The Subconscious Patterns That Shape Success

When Self-Doubt Takes a Seat at the Table – 5 Ways to Manage It

Three Workplace Conditions That Turn Autistic Strengths into Burnout

Why the Future of Technology Must Be Green

bottom of page