The EU AI Act Deadline Is Here and Why Compliance Without Governance Will Fail – Part 3
- 12 hours ago
- 8 min read
Naómi Oosthuizen is the Founder and Managing Partner of Sentio™, specialising in cybersecurity, AI governance, digital resilience, and board-level risk management across Europe. She writes about the intersection of technology, governance, regulation, and human decision-making.
This is Part 3 of a three-part series on the EU AI Act's 2 August 2026 deadline. Part 1 covered what the Act requires and what changed under the Digital Omnibus, Part 2 covered why compliance without governance fails, the AI inventory, and accountability.

What evidence will regulators, auditors, and boards accept?
Declarations are cheap. What the Act asks for, and what a serious board asks for, is a trail. Providers of high-risk systems must operate a risk management system across the entire lifecycle, eliminating or reducing identified risks through design as far as is technically feasible, implementing mitigation and control measures for the risks that cannot be eliminated, and providing the information and, where appropriate, the training that deployers need in order to use the system safely. They must also run a quality management system spanning the pre-market phase, covering regulatory strategy, design control, verification, testing, and technical specification, the post-market phase, covering quality control, serious incident reporting, and post-market monitoring, and a continuous phase, covering data management, communication with authorities, record-keeping and logging, resource management, and an accountability framework.[1]
Deployers do not escape this. Where Article 27 applies, and it applies to bodies governed by public law, to private operators providing public services, and to operators carrying out creditworthiness assessments or price and risk assessments in life and health insurance, the deployer must conduct a fundamental rights impact assessment before first use and notify the national authority of the results. Where a data protection impact assessment is also required, the two are conducted in conjunction rather than duplicated, which is a small piece of drafting that saves a great deal of duplicated effort in practice.[3]
Underneath the specific legal artefacts sits a simpler organisational question, whether the reasoning behind consequential decisions has been preserved. Effective governance produces approved purpose statements, data assessments, design decisions, test results, transparency notices, vendor assurances, the design of human oversight, monitoring thresholds, incidents, exceptions, and retirement decisions, and it produces them as a by-product of ordinary work rather than as a retrospective reconstruction. NIST asks for post-deployment monitoring plans covering user feedback, appeal and override, decommissioning, incident response, recovery, and change management, which is a fair description of what an auditor will eventually ask to see.[6] ISO/IEC 42001 offers a structured and auditable management-system approach for organisations that want to govern artificial intelligence through defined roles, processes, controls, monitoring, and continual improvement.[5] Certification is voluntary, and it does not by itself establish compliance with the AI Act, but the discipline it imposes is the discipline the Act assumes you already have.
Five questions for your board before August
None of these questions is technical, and all of them are answerable. The quality of the answers will tell you more about your exposure than any maturity dashboard.
Can we produce a complete and current inventory of every artificial intelligence system in use, including the ones we did not build and the ones we did not knowingly buy?
Does every material use case have a named, accountable business owner who would be identified by name in an incident report?
Are artificial intelligence risks integrated into our existing enterprise risk, privacy, cyber, data, procurement, and resilience processes, rather than isolated in a committee?
Can we demonstrate how human oversight works in practice, as distinct from how it is described in policy?
Can we produce evidence of decisions, monitoring, incidents, and exceptions without assembling it manually after the fact?
Frequently asked questions
Does the AI Act apply to us if we only use artificial intelligence rather than build it? Yes. The Regulation imposes duties on deployers as well as providers, and the transparency obligations arriving on 2 August 2026 extend to organisations that operate chatbots, publish deepfakes, or publish AI-generated text on matters of public interest. Deployers of high-risk systems must also use them in accordance with the instructions, monitor their operation, and assign human oversight to a person who is properly equipped to exercise it. Certain deployers, including public bodies and organisations assessing creditworthiness or pricing risk in life and health insurance, must additionally conduct a fundamental rights impact assessment before first use.[3]
Has the deadline been postponed? Some of it has. The obligations for high-risk systems move to 2 December 2027 for stand-alone systems and 2 August 2028 for systems embedded in regulated products, and a transitional grace period runs until 2 December 2026 for marking generative systems already on the market. The broader Article 50 transparency duties still apply from 2 August 2026 and were not deferred.[7]
Is the Code of Practice mandatory? No. It remains voluntary, although the Commission and the AI Board have confirmed that it is an adequate tool for demonstrating compliance with the relevant Article 50 obligations. Signing it gives an organisation a recognised route. Providers and deployers remain free to use another approach, provided they can demonstrate that their own measures are adequate. This will be assessed individually by the relevant market surveillance authority.[2]
Do we need ISO/IEC 42001? Not as a matter of law. ISO/IEC 42001 specifies requirements for establishing, implementing, maintaining, and continually improving an artificial intelligence management system. Certification against it is voluntary and does not, by itself, establish compliance with the AI Act.[5] What it does offer is a structured and auditable way to govern artificial intelligence through defined roles, processes, controls, monitoring, and continual improvement, which is precisely the capability the Act assumes an organisation already possesses.
What are the penalties? The consequences depend on what has been infringed, and the frequently quoted headline figure applies only to one tier. Member States must lay down effective, proportionate, and dissuasive penalties within the thresholds set out in the Regulation.[3]
Type of infringement | Maximum threshold |
Prohibited practices, and non-compliance with the requirements on data | EUR 35 million or 7 percent of worldwide annual turnover |
Non-compliance with any of the other requirements or obligations | EUR 15 million or 3 percent |
Supply of incorrect, incomplete, or misleading information to notified bodies or national competent authorities | EUR 7.5 million or 1.5 percent |
Small and medium-sized enterprises | The lower of the two applicable amounts, rather than the higher |
A potentially more immediate operational consequence is that an organisation that cannot evidence its decisions will find itself unable to answer a customer, an auditor, or a regulator at the moment when the answer is needed most.
The question in front of the board today
The question for boards is no longer whether they have an artificial intelligence policy. It is whether they can demonstrate, through decisions, ownership, controls, and evidence, that artificial intelligence is being governed as part of the enterprise rather than observed from the edge of it. Everything else, including the deadline, follows from the answer to that question.
If those five questions remain unresolved on your risk register, a structured readiness assessment is the fastest way to determine how large the gap really is. You can find out more about how we work at sentiodigital.com.
A confident answer to those five is worth more than a thick policy, and it is worth considerably more than an extension. The Digital Omnibus has bought time. It has not answered a single one of the five questions.
Literature review: What was drawn from each source
The table records the specific material taken from each source and where it is used, so that every factual claim in the article can be traced back to an identifiable passage rather than to a general impression of the literature.
Source | Type | Main pieces used | Where it is used |
Regulation (EU) 2024/1689 (Artificial Intelligence Act) | Primary legislation | Adoption on 13 June 2024, publication on 12 July 2024, and entry into force on 1 August 2024. The phased application timetable. The risk-based structure. The provider and deployer roles. Article 50 transparency obligations. | Sections 1 and 2 |
European Commission, Navigating the AI Act (frequently asked questions) | Official guidance | Classification of high-risk systems by intended purpose, aligned with existing product-safety legislation. The Article 50 duties as allocated between providers and deployers, with exceptions. Deployer duties on high-risk systems, including assigned human oversight and the right to an explanation. The fundamental rights impact assessment population, including life and health insurance, and the duty to notify the national authority. The three penalty tiers and the SME rule. | Sections 1, 2, 6, 7, 8, and the FAQ on penalties |
European Commission, Code of Practice on transparency of AI-generated content | Soft law instrument | Publication on 10 June 2026. Confirmation by the Commission and the AI Board that the Code is an adequate voluntary tool. The two sections, for providers and for deployers. The set of EU icons for labelling. The requirement that those complying by other means demonstrate that their measures are adequate. Commission guidelines on Article 50 still to follow. | Section 2 and the FAQ on the Code |
Digital Omnibus on AI (amending regulation, COM(2025) 836)** | Amending legislation | Formal adoption by the Council on 29 June 2026. Deferral of Annex III high-risk duties to 2 December 2027 and Annex I to 2 August 2028. The transitional grace period to 2 December 2026 for marking of generative systems already on the market. Deferral of national sandboxes to 2 August 2027. The new Article 5 prohibition, applicable from 2 December 2026. | Section 3 and the FAQ on postponement |
Deloitte, EU Artificial Intelligence Act Deep Dive | Practitioner analysis | The risk management system duties covering safety by design, protective measures, and information for safety. The quality management system spanning the pre-market, post-market, and continuous phases. The observation that systems carrying no obligations under the Act may still carry business, security, and other regulatory risk. Explicit notification for chatbots as an example of a limited-risk duty. | Sections 1, 7, and 8 |
Tabassi (2023), NIST AI Risk Management Framework (AI RMF 1.0), NIST AI 100-1 | Voluntary framework | The four functions govern, map, measure, and manage, with governance as a cross-cutting function. Integration of AI risk into enterprise risk management. GOVERN 1.6 on inventory mechanisms and GOVERN 1.7 on decommissioning. GOVERN 2.2 on training and GOVERN 2.3 on executive responsibility. GOVERN 6.1 and 6.2 on third-party risk. MAP 3.5 on human oversight processes. MANAGE 3.2 and 4.1 on monitoring. The warning that AI systems are often perceived as more objective than humans, and that human and machine pairings can amplify human bias. The statement that the framework does not prescribe risk tolerance and is voluntary. | Sections 4, 5, 6, 7, and 8 |
ISO/IEC 42001:2023 | Certifiable standard | The existence of requirements for establishing, implementing, maintaining, and continually improving an artificial intelligence management system. Used only to support the point that governance of this kind is meant to be operated and audited. | Section 8 and the FAQ on standards |
Read more from Naómi Oosthuizen
Naómi Oosthuizen, Interim Specialist, CISO & CIO
Naómi Oosthuizen is the Founder and Managing Partner of Sentio™, a European cybersecurity and governance advisory firm. With more than two decades of international leadership experience across financial services, government, and critical infrastructure, she specialises in cybersecurity, AI governance, enterprise risk management, and digital resilience. Through her writing, she explores the future of technology, governance, organisational behaviour, and digital trust.
References:
[1] Deloitte. (2024). EU Artificial Intelligence Act: Deep dive. Deloitte.
[2] European Commission. (2026a). Code of practice on transparency of AI-generated content. Shaping Europe's Digital Future.
[3] European Commission. (2026b). Navigating the AI Act: Questions and answers. Shaping Europe's Digital Future.
[4] European Parliament and Council of the European Union. (2024). Regulation (EU) 2024/1689 of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act). Official Journal of the European Union, L, 2024/1689, 12 July 2024.
[5] International Organization for Standardization. (2023). Information technology, artificial intelligence, management system (ISO/IEC 42001:2023). ISO.
[6] Tabassi, E. (2023). Artificial intelligence risk management framework (AI RMF 1.0) (NIST AI 100-1). National Institute of Standards and Technology.
[7] Digital Omnibus on AI. (2026). Regulation amending Regulations (EU) 2024/1689 and (EU) 2018/1139 as regards the simplification of the implementation of harmonised rules on artificial intelligence (COM(2025) 836, adopted by the Council on 29 June 2026). European Union.










