Skip to content
iclock 7 Minutes - Read Now
idate

Is Your EU AI Act Compliance Program Actually Ready?

Most compliance leaders can already speak fluently about the EU AI Act’s provisions and reach, but familiarity is not the […]

Jodie Fredericksen, J.D.
Jodie Fredericksen, J.D. Vice President of Data and Services, Ethisphere
Is Your EU AI Act Compliance Program Actually Ready?

Most compliance leaders can already speak fluently about the EU AI Act’s provisions and reach, but familiarity is not the same as readiness. That distinction matters now that several restrictions and obligations are already enforceable, with numerous additional obligations fall into later phased deadlines, some as late as 2028. The Act’s severe penalty structure — up to €35 million or seven percent of global annual turnover for infractions involving prohibited AI systems— puts compliance with the Act squarely within board-level risk territory. Now is the time to shift from monitoring this development to actively owning it, so here are some things to keep in mind.

1. This is a compliance expectation, not a technology rollout

The EU AI Act’s scope centers on four roles — providers, deployers, importers, and distributors. Deployer is the role that captures the vast majority of ordinary businesses: any organization using an AI system in its operations, even one it didn’t build, is a deployer. And the Act’s reach extends beyond EU-based organizations to any provider or deployer that uses the AI system’s output within the EU.

An initial reaction to the EU AI Act may be that compliance therewith is a responsibility sitting with IT and/or legal function(s), but the truth is, this responsibility should feature a multi-disciplinary background. The ethics and compliance function likely deserves to have a seat at this table, since it sees across areas such as privacy, third party programs, [what else?]  from an oversight perspective.

What to do: If no one has explicitly claimed cross-functional oversight of AI governance at your organization, assume the gap could surface as an ethics and compliance problem — whether formally assigned or not. Get ahead of that by proposing assignment of responsibility, rather than deal with a fragmented approach later. Before building new AI-specific processes from scratch, inventory where existing compliance controls might extend to cover AI-specific requirements, like data governance under Article 10 or technical documentation under Article 11.

2. Agentic AI blurs internal governance and external regulation

As agentic tools take on more autonomous, multi-step work – summarizing meetings, drafting follow-ups, pushing data into CRMs – organizations must reconcile two things at once: what the Act requires from an external regulation perspective, and what internal acceptable-use and permissions frameworks require internally. (Depending on the organization, this may ultimately be handled by E&C, IT, Legal, or some combination of the three.) Far from a standalone checkbox, the Act inputs into a broader governance structure that must also account for widely used (but unapproved) agentic tools.

What to do: Treat AI system inventories as living documents that capture not just standalone AI tools, but the AI features embedded inside platforms your organization already uses, such as meeting transcription, scheduling assistants, embedded copilots. These tools often arrive without a deliberate governance decision behind them.

3. Vendor risk just got a lot more technical

Most organizations don’t build their own AI; they buy it, embed it, or plug into a vendor’s model. Under the Act’s provider/deployer structure, most enterprises are deployers, which comes with its own due-diligence obligations: verifying the vendor’s conformity assessment, CE marking, and registration status. But that structure has a trap door. Organizations that customize or fine-tune a vendor’s model enough — even in ways that seem minor, like retraining on proprietary data — can reclassify them from deployer to provider, inheriting obligations such as conformity assessment, technical documentation, and registration on top of oversight and monitoring.

What to do: Update third-party risk questionnaires now to go beyond general security and privacy attestations and specifically request AI risk classification, training data governance practices, and conformity assessment documentation. Likewise, flag any planned fine-tuning or customization work for review before it happens, since it may quietly change which set of obligations your organization owns.

4. The EU AI Act reaches far beyond EU borders

Like the GDPR, the EU AI Act reaches beyond EU borders, applying to providers and deployers (regardless of the organization’s actual headquarters location) that produce AI output used within the EU. Therefore, if an EU-based company sends data to a U.S.-based AI provider and brings the output back for use in the EU, that U.S. provider is now within the Act’s scope, even without an EU office or presence. A U.S. company with EU customers, employees, or a single high-risk AI tool touching EU operations can be brought within scope without anyone in the organization realizing it.

What to do: Don’t rely on geography to rule your organization out. Map where your AI systems’ outputs are actually used, not just where the systems are hosted, developed, or headquartered.

5. The penalties rival GDPR’s and boards know it…or at least they should

Fines for the most serious violations, such as deploying prohibited AI systems, can reach €35 million or seven percent of global annual turnover, whichever is higher — a ceiling that exceeds even that of the GDPR. Lesser violations still carry real exposure: up to €15 million or 3% of turnover for most provider and deployer failures, and up to €7.5 million or 1% for supplying misleading information to regulators. That places EU AI Act exposure squarely in board-level risk territory.

Whether ethics and compliance, legal, risk, and/or other functions ultimately own the board reporting, ethics and compliance should ensure it has a seat at that table, given how much AI risk overlaps with third-party oversight, conduct risk, and existing compliance frameworks it may already manage.

What to do: If AI risk isn’t already a standing line item in your board risk reporting, add it now, before a regulator or an incident does it for you.

6. Organizations don’t have the time to stand still

In May 2026, EU negotiators reached a provisional agreement on a “Digital Omnibus on AI” package that pushed back several key compliance dates, however unevenly. Obligations for high-risk AI systems used in areas like employment, biometrics, and critical infrastructure, that were originally due August 2, 2026, have been deferred to December 2, 2027. Rules for high-risk AI embedded in regulated products, like toys or medical devices, now extend to August 2, 2028. The deadline for transparency labeling requirements for AI-generated content was pushed back to December 2, 2026. And the deadline for member states to stand up national AI regulatory sandboxes was pushed back to August 2, 2027.

At the same time, the amendments introduce a new prohibition, effective December 2, 2026, banning AI systems that generate non-consensual intimate imagery or child sexual abuse material. The one major piece that hasn’t moved is governance obligations for general-purpose AI models, which have already been in force since August 2025 and are untouched by these amendments.

The end result of all of this is a compliance calendar that keeps shifting, requiring ongoing reprioritization internally.

What to do: Compliance with the EU AI Act is not a “set a reminder and revisit next year” regulation. Assign a specific owner responsible for tracking regulatory developments and translating them into internal deadline updates on a recurring basis. Compliance monitoring functions are built exactly for this kind of ongoing regulatory tracking; use that muscle.

Where This Leaves You

Can your organization say, right now, which AI systems it runs, what risk tier each falls into, and who owns tracking them going forward? If not, that’s the gap to close first — everything else in this piece depends on having that answer. The EU AI Act is no longer a future problem. Parts of it are already in force, more is coming, and the runway keeps shrinking even when individual deadlines get pushed back. The organizations that get ahead of this are the ones that stop treating it as something to monitor and start treating it as something to own.