← Back to list

The EU AI Act Is Already in Force — And the Next Deadline Is Closer Than You Think

If you are building, deploying, or using AI in your organisation and you haven’t looked at the EU AI Act yet — August 2, 2026 is the date…

Simplebyrasika · 2026-05-23 10:27 · 0 claps · 6.5 min read
#artificail-intelligence #eu-ai-act #eu-ai-act-compliance #gen-ai-risk #ai
Open on Medium ↗
Wiki topics: AI · AI · General

The EU AI Act Is Already in Force — And the Next Deadline Is Closer Than You Think

If you are building, deploying, or using AI in your organisation and you haven’t looked at the EU AI Act yet — August 2, 2026 is the date you need to have in your calendar right now.

Not as a distant concern. As an active deadline.

The Act entered into force on August 1, 2024. The first prohibitions kicked in February 2025. General-Purpose AI requirements became mandatory in August 2025. And in just a few months, the full weight of the regulation lands on every organisation operating high-risk AI systems.

This article breaks down what the EU AI Act actually is, what it means for your organisation, and — practically — what you should be doing about it right now.

What the EU AI Act Actually Is

The EU AI Act is the world’s first comprehensive legal framework for artificial intelligence. It regulates AI systems based on the risk they pose — not the technology they use, and not the size of the company deploying them.

That last point matters more than most people realise. If your AI system operates in the EU — or produces outputs used in the EU — you are subject to this regulation. A startup in San Francisco. A SaaS company in Pune. A scale-up in Singapore. Location provides no safe harbour if your AI touches EU users or EU decisions.

The Act is built around a four-tier risk pyramid:

Unacceptable Risk — Prohibited Already banned as of February 2025. This includes AI systems that manipulate behaviour through subliminal techniques, social scoring by public authorities, predictive policing based solely on profiling, and emotion recognition in workplace and educational settings.

High Risk — Heavily Regulated The category most organisations need to focus on. High-risk AI includes systems used in employment decisions, credit assessments, education, law enforcement, essential public services, and biometric identification. Full compliance requirements apply from August 2, 2026.

Limited Risk — Transparency Obligations Systems like chatbots and deepfake generators must disclose that they are AI. These transparency obligations also become enforceable in August 2026.

Minimal Risk — No Specific Obligations Most AI applications — spam filters, recommendation engines, basic automation — fall here. No specific EU AI Act obligations apply, though good governance practice still makes sense.

The Compliance Timeline — Where We Are Right Now

Here is the enforcement timeline you need to understand:

August 2024    — EU AI Act entered into force
February 2025  — Prohibited AI systems banned
August 2025    — GPAI transparency requirements mandatory
                 National enforcement authorities operational
August 2026    — High-risk AI full requirements enforceable ← YOU ARE HERE
August 2027    — Legacy systems and remaining provisions
August 2027    — Full implementation for all GPAI already on market

We are currently sitting between August 2025 and August 2026. That window — right now — is your preparation period. Organisations that treat August 2026 as a distant date are making a serious mistake.

The European Commission has been clear: they intend to enforce this regulation on schedule. National AI authorities are already operational. Fines for high-risk AI violations reach €30 million or 6% of global annual turnover — whichever is higher.

What High-Risk Actually Means in Practice

This is where the confusion lies for most organisations. “High risk” sounds like it means dangerous consumer-facing AI. In reality, the Annex III list of high-risk categories covers a huge proportion of enterprise AI use cases:

Employment and HR — AI used in recruitment, CV screening, performance monitoring, promotion decisions, or redundancy selection is high-risk. If you use any AI-assisted HR tooling, this likely applies to you.

Credit and Financial Services — AI used in creditworthiness assessment is high-risk. This covers a wide range of fintech and banking AI applications.

Education — AI used to evaluate students, determine access to education, or monitor exam-taking behaviour is high-risk.

Essential Services — AI used in decisions about access to public services, benefits, or social care is high-risk.

Healthcare — AI used as a medical device or in clinical decision support is high-risk.

If your organisation operates in any of these sectors, or builds AI products sold into these sectors, the August 2026 deadline is your deadline.

What the Regulation Requires — The Core Obligations

For high-risk AI systems, the EU AI Act requires six things that every organisation needs to have in place:

1. Risk Management System A documented, ongoing process for identifying, assessing, and mitigating risks throughout the AI system’s lifecycle. Not a one-time assessment — a continuous programme.

2. Data Governance Documentation of training data — its sources, quality, biases, and how it was processed. Evidence that data governance policies exist and are followed.

3. Technical Documentation A complete system record for every high-risk AI: what it does, how it works, what data it uses, what its limitations are, and how it has been tested.

4. Human Oversight Perhaps the most important requirement. High-risk AI systems must be designed and deployed so that a human being can understand, monitor, and where necessary override the system’s outputs. This is not optional and it cannot be delegated to another AI system.

5. Transparency Users must be informed when they are interacting with a high-risk AI system. The system’s capabilities and limitations must be disclosed.

6. Post-Market Monitoring Ongoing monitoring of the system’s performance in production — tracking accuracy, detecting drift, logging incidents, and reporting serious incidents to national authorities.

The Connection to ISO 42001

The EU AI Act does not prescribe how to implement these requirements. It tells you what the outcomes must be. ISO 42001 — the international standard for AI Management Systems — fills that gap.

ISO 42001 provides the framework, the documentation structure, and the governance mechanisms that organisations can use to demonstrate EU AI Act compliance. In practical terms:

The AI System Record in ISO 42001 is your technical documentation for EU AI Act purposes.

The AI Risk Assessment in ISO 42001 is your risk management system.

The human oversight requirements in ISO 42001 directly satisfy the EU AI Act’s oversight obligations.

Organisations that implement ISO 42001 properly will find themselves well-positioned for EU AI Act compliance — because the standard was designed with exactly these regulatory requirements in mind.

What You Should Be Doing Right Now

If you are reading this in 2026, you have months — not years — before enforcement begins. Here is the practical priority order:

Step 1 — AI Inventory Map every AI system your organisation builds, deploys, or uses. For each one, record: what it does, who uses it, what data it processes, and what decisions it influences.

Step 2 — Risk Classification For each system in your inventory, determine its risk tier. Is it prohibited? High-risk? Limited risk? Minimal risk? Document your classification and your reasoning.

Step 3 — Gap Assessment for High-Risk Systems For any system you classify as high-risk, assess your current state against the six requirements above. Where are the gaps? What documentation is missing? What oversight mechanisms don’t yet exist?

Step 4 — Document Your Governance Build your AI governance documentation: system records, risk assessments, data governance policies, human oversight procedures, incident response process.

Step 5 — Implement Monitoring Establish ongoing monitoring for each high-risk system. Define what you are measuring, at what frequency, and what triggers a review or escalation.

Step 6 — Assign Accountability Every high-risk AI system must have a named human being accountable for it. Not a team. A person. Assign that accountability now and document it.

The Reality Most Organisations Are Facing

Most organisations deploying AI right now have none of this documentation in place. Not because they are irresponsible — but because nobody handed them the structure, and building it from scratch while also building a product is genuinely hard.

The gap between where most teams are and where the EU AI Act requires them to be is not a technology gap. It is a documentation and governance gap. The AI is already working. The oversight framework that should surround it is not yet built.

That gap is closable. But it requires starting now.

A Practical Starting Point

If your organisation needs to build EU AI Act compliance documentation without starting from scratch, I have put together an AI Governance toolkit aligned with both ISO 42001 and EU AI Act requirements.

It includes three ready-to-use templates:

AI System Record — your technical documentation requirement, satisfied. AI Risk Assessment — your risk management system, structured and scored. AI Release Checklist — your human oversight and governance gates, built into every production deployment.

These three documents, completed properly for each of your high-risk AI systems, form the core of a defensible EU AI Act compliance position.

👉 **AI Governance Toolkit — payhip.com/SimpleByRasika**

Also available:

👉 Complete GRC Bundle — ISO 27001 + SOC 2 + ISO 42001 — for organisations that need to align AI governance with their existing security compliance programme.

The Bottom Line

The EU AI Act is not coming. It is here.

The prohibited systems are already banned. The GPAI requirements are already mandatory. The high-risk deadline is August 2026 — and organisations that wait until July 2026 to start will not be ready.

The organisations that come out of this well are the ones building governance habits now — documenting their systems, assessing their risks, assigning human oversight, and treating AI governance as an operational discipline rather than a compliance project.

Start now. The documentation is the hard part. And it does not have to be built from scratch.

Written by — GRC professional with 13+ years of experience across FedRAMP, IRAP, ISO 27001, SOC 2, and AI Governance. AI Governance templates and compliance resources at payhip.com/SimpleByRasika Full article library at medium.com/@simplebyrasika0


메타데이터
post_id
ada415df6e67
slug
the-eu-ai-act-is-already-in-force-and-the-next-deadline-is-closer-than-you-think-ada415df6e67
url
https://medium.com/@simplebyrasika0/the-eu-ai-act-is-already-in-force-and-the-next-deadline-is-closer-than-you-think-ada415df6e67
canonical_url
https://medium.com/@simplebyrasika0/the-eu-ai-act-is-already-in-force-and-the-next-deadline-is-closer-than-you-think-ada415df6e67
author_url
https://medium.com/@simplebyrasika0
status
ok
fetched_at
2026-06-09 15:37:30