New benchmark data from 134 organizations shows ethics and compliance teams adopting AI faster than they can document, monitor, or measure it. The EU’s Digital Omnibus just pushed the AI Act’s high-risk deadline to December 2027. But the AI uses that E&C leaders consider to be riskiest in their own function sit inside the exact category that deadline covers, so some of that extra runway may belong to E&C too.
For most of 2026, August 2 was the date circled on every AI governance calendar in Europe. That was when the EU AI Act’s high-risk obligations were set to take effect.
That changed on July 27. The Digital Omnibus on AI, Regulation (EU) 2026/1744, entered into force that day, and it moved the goalposts for one specific category. Standalone high-risk systems under Annex III, which includes AI used in hiring and worker management, now have until December 2, 2027, not August 2, 2026. Where AI is embedded inside a product that EU product-safety law already covers, the date moves further out, to August 2, 2028.
Article 50’s transparency obligations still take effect on August 2, 2026. People must be told when they’re dealing with an AI system rather than a human, and synthetic audio, image, video, and text need machine-readable marking. Systems already on the market get a grace period on the marking requirement, until December 2, 2026. The Omnibus also added new prohibitions on AI-generated non-consensual intimate imagery and child sexual abuse material (CSAM). And the Act’s original bans, including using AI to infer emotions in the workplace, have applied since February 2025.
So the near-term date got narrower, and the bigger one moved 16 months out. Sixteen months sounds like breathing room, until you look at what E&C already told Ethisphere about its own AI use.
E&C’s Own Risk List Is Annex III’s Risk List
Ethisphere asked 134 organizations, most of them large and multinational, where AI is least appropriate or highest-risk in E&C work today. Three answers came back consistently: 1) privileged legal analysis, 2) investigation findings and disciplinary recommendations, and 3) employee monitoring.
The last two aren’t adjacent to Annex III. They’re inside it. Annex III’s employment category covers AI used to monitor and evaluate workers, and to make or materially influence decisions about them, including discipline. E&C leaders named those uses as their own biggest risk months before the Omnibus told anyone where the regulatory line would sit. That’s a good sign about judgment.
It’s a less comfortable sign about exposure. Annex III doesn’t just regulate the vendors selling monitoring software or HR platforms. It regulates deployers: whoever puts a high-risk system to use and controls how it operates. If E&C is running AI over investigation files or monitoring dashboards, and that tool qualifies as a high-risk system under Annex III, E&C isn’t only advising the rest of the business on its Annex III exposure. It may be a deployer with Annex III exposure of its own, which would make December 2027 E&C’s deadline too, not just IT’s or HR’s.
That distinction is worth a legal read on your specific tools before you repeat it externally. But it changes what this data means. It isn’t background context for a regulatory update. It’s an early read on how ready E&C is for obligations it may already own.
What Deployer Duties Actually Ask for, and What the Data Shows
Article 26 deployer obligations, the ones that phase in with Annex III, run on demonstrable human oversight, usage records, and worker notification. Not policy language. Evidence.
That’s where the numbers turn. According to Ethisphere research, written AI policies are close to universal (85% have one, 78% maintain an approved tools list), but only 21% require AI-generated content to be identified or labeled, and only 15% require documentation of AI-assisted work. Human review before AI output gets used is broadly expected, yet only 32% actually monitor or audit AI tool use. Just 5% measure AI’s impact with defined metrics, and 34% don’t measure it at all. Only 11% describe themselves as “very prepared” to answer a regulator, auditor, or board member about AI use in E&C workflows, and almost a quarter call themselves unprepared.
What his means is that there is a serious gap between doing something and being able to prove it happened, and proof is exactly what Article 26 asks for.
Article 50 sits a little differently. Its direct obligations fall mainly on providers of generative systems, and the deployer duties it does create are narrower: disclosing deepfakes, flagging AI-generated text published on matters of public interest, giving notice when emotion recognition or biometric categorization is in use. It doesn’t reach into E&C’s internal work product the way Annex III does. But the discipline it’s built around, labeling AI involvement and keeping a record of it, is the same muscle Annex III will require anyway. Building it now isn’t complying with a law that doesn’t quite apply yet. It’s building the one capability both dates eventually ask for.
Usage Is Outrunning the Paper Trail
None of this is happening because E&C has gone quiet on AI. 91% of E&C leaders say their team’s AI use increased over the past six months, and 52% say it increased significantly. Adoption inside the function still trails the rest of the organization: two-thirds of organizations report broad or advanced AI adoption organization-wide, against 21% inside E&C itself. The function is catching up on use. It hasn’t caught up on the scaffolding that makes that use defensible.
Regulatory Uncertainty Isn’t What’s Actually Holding Anyone Back
When asked what’s holding back responsible AI adoption, only 2% of respondents named regulatory uncertainty. The top answers were accuracy and hallucination risk, and confidentiality, privilege, or data exposure concerns.
The function most exposed to the AI Act isn’t, by its own account, waiting on Brussels. It’s waiting on trust in its own outputs and control over its own sensitive data. A deadline moving 16 months out doesn’t touch either one, and if some of E&C’s own highest-risk uses are Annex III deployer activity, that “relief” is really a delayed bill.
What E&C leaders should do now
- Find out where E&C is a deployer, not just an advisor. Map which of E&C’s own tools touch investigation findings, disciplinary recommendations, or employee monitoring, and get a legal read on whether any qualify as Annex III systems in their own right.
- Separate the two dates once you know that. Confirm what’s owed August 2, 2026, under Article 50 versus December 2, 2027, under Annex III. Different obligations, different owners, different stakeholders.
- Close the documentation gap first. It’s the cheapest of these fixes and the one that does the most for audit and board readiness right now.
- Make human review observable. Move it from “expected” to logged, sampled, and reportable.
- Start measuring now. Sixteen months is enough time to build a baseline for E&C’s own AI use, but not enough time to reconstruct one after the fact, especially if some of that use turns out to have been Annex III’s problem all along.
Read the full benchmark report for the complete findings, or explore how your organization compares by size, industry, and AI maturity in the interactive data tool.
Findings drawn from Ethisphere’s benchmark research on AI in ethics and compliance, based on responses from 134 organizations fielded from June – July 2026. Base sizes vary by question; percentages calculated on valid responses rather than the full sample.
Sources
- Digital Omnibus on AI enters into force today (Lewis Silkin)
- Regulation (EU) 2026/1744, Official Journal
- EU AI Act Omnibus Agreement — Postponed High-Risk Deadlines (Gibson Dunn)
- EU AI Act Transparency Obligations: Preparing for Compliance by 2 August 2026 (Sidley)
- Annex III: High-Risk AI Systems
- Article 26: Obligations of Deployers of High-Risk AI Systems
- Article 50: Transparency Obligations