The EU AI Act establishes one of the world’s first comprehensive frameworks for AI governance. This guide explains the regulation’s risk-based requirements, what the latest Digital Omnibus amendments changed, and how organizations can use the revised timeline to build operational readiness for compliance.
Alexis Kateifides
Director, Regulatory Intelligence Enablement
August 10, 2026
In crafting its approach to artificial intelligence (AI) legislation, the European Union (EU) has opted for a horizontal legislative framework. The EU’s AI legal framework embraces an industry-agnostic perspective and is meticulously designed with nearly a hundred articles.
Here, we’ll look to provide a window into the EU AI Act. This piece of legislation is not just the first of its kind—but also a benchmark for global AI regulation, developed to help create a precedent in the rapidly evolving AI landscape.
Key Takeaways
The latest amendments to the EU AI Act represent an important milestone in the regulation implementation. While many organizations have focused on the revised compliance dates, the amendments send a broader message about how AI governance is expected to mature across Europe.
The most significant change is the revised application timeline for certain high-risk AI obligations. Obligations for stand-alone high-risk AI systems listed in Annex III will apply from December 2, 2027, while obligations for high-risk AI systems embedded in regulated products will apply from August 2, 2028.
The amendments also introduce additional prohibited AI practices relating to non-consensual intimate imagery and AI-generated child sexual abuse material. They also adjust the timing for certain transparency solutions for artificially generated content, reinforcing that disclosure and labelling requirements remain a near-term compliance priority.
Importantly, these changes do not alter the AI Act’s underlying risk-based structure. High-risk AI systems will still require governance measures such as documentation, risk management, human oversight, conformity assessment, post-market monitoring, and accountability.
The revised timeline acknowledges that effective governance depends on more than legislation alone. Organizations also need harmonized standards, implementation of guidance, conformity assessment procedures, and internal governance capabilities that translate legal obligations into repeatable business processes.
For privacy, legal, risk, and AI governance leaders, the additional implementation window should be viewed as an opportunity to strengthen governance rather than postpone preparation. Capabilities such as AI inventories, ownership, documentation, evidence collection, and cross-functional oversight remain valuable regardless of future regulatory adjustments.
The EU AI Act has now entered its implementation phase. While the regulation is in force, different obligations apply according to a phased implementation schedule that has been refined through the latest amendments.
The revised timeline aligns legal obligations with the practical work required to establish technical standards, guidance, conformity assessment procedures, and governance capabilities across organizations and regulators.
Organizations should continue preparing for compliance based on the revised schedule while recognizing that the underlying regulatory expectations remain unchanged.
| Requirement | Current Timeline |
| Existing prohibited AI practices | Already applicable under the AI Act’s phased implementation schedule |
| New prohibited AI practices introduced by the amendments | December 2, 2026 |
| Article 50 transparency obligations | August 2, 2026, subject to the relevant obligation |
| Transparency solutions for certain artificially generated content | December 2, 2026 |
| General-purpose AI obligations | Unchanged by the latest Omnibus amendments |
| Stand-alone high-risk AI systems listed in Annex III | December 2, 2027 |
One of the most significant outcomes of the amendments is not the revised timeline itself, but the recognition that AI governance requires operational infrastructure. Compliance increasingly depends on capabilities that remain useful as standards, guidance, and supervisory expectations evolve.
Organizations should not prepare only for a single compliance deadline. They should build repeatable governance processes for identifying AI systems, assigning ownership, classifying risk, documenting decisions, monitoring performance, managing third-party AI risk, and maintaining evidence over time.
This also changes how privacy and legal leaders approach compliance. AI governance is no longer a standalone legal exercise. It increasingly connects procurement, product development, security, engineering, risk, privacy, and business teams through common governance workflows.
Originally, the Act defined machine learning, the basis of AI systems, as “including supervised, unsupervised and reinforcement learning, using a wide variety of methods including deep learning.” The text includes an updated definition, which defines AI systems as “machine-based systems designed to operate with varying levels of autonomy and that may exhibit adaptiveness after deployment and that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments.”
The complexity of AI systems is a sliding scale, with more intricate systems requiring substantial computing power and input data. The output from these systems can be simple or mightily complex, varying with the sophistication of the AI in play.
This broad definition covers a range of technologies, from your everyday chatbots to highly sophisticated generative AI models. But it’s important to note that not every AI system falling under the Act’s broad definition will be regulated. The Act plays it smart with a risk-based approach, bringing under its regulatory umbrella only those systems associated with specific risk levels.
Here’s where it gets interesting. The EU AI Act has different baskets for AI systems. Some are seen as posing an unacceptable risk to European values, leading to their prohibition. High-risk systems, while not banned, have to dance to a tighter regulatory tune. It’s vital to remember that these risk categories aren't static; the Act is still in a draft stage, and as more changes come, these risk categories will likely be fine-tuned as well.
The EU AI Act defines multiple levels of permissible risk: high risk, limited risk, and minimal risk.
These are the levels of “permissible risk” that are allowed by organizations, however, “unacceptable risk” is a risk level which is not allowed by organizations at which point companies need to change their models accordingly.
Of these risk levels, high-risk systems will pose the highest compliance burden on organizations, as they’ll have to continue to meet obligations for conformity assessments. Conformity assessments (CA) require companies to ensure that their “high-risk” systems meet the following:
This assessment is mandatory before a high-risk AI system is made available or used in the EU market. It ensures that AI systems comply with EU standards, particularly if there are significant modifications or changes in intended use. The main responsible party for CA is the “provider” –the entity putting the system on the market. However, under certain circumstances, the responsibility can shift to the manufacturer, distributor, or importer, especially when they modify the system or its purpose.
The CA can be done internally or by an external “notified body.” Internal CAs are common as providers are expected to have the necessary expertise. Notified bodies come into play particularly when an AI system is used for sensitive applications like real-time biometric identification and does not adhere to pre-defined standards.
During an internal CA, the provider checks compliance with quality management standards, assesses technical documentation, and ensures the AI system's design and monitoring are consistent with requirements. Success results in an EU declaration of conformity and a CE marking, signaling compliance, which must be kept for ten years and provided to national authorities if requested.
For third-party CAs, notified bodies review the system and its documentation. If compliant, they issue a certificate; otherwise, they require the provider to take corrective action.
Conformity assessment isn't a one-off process; providers must continually monitor their AI systems post-market to ensure they remain compliant with the evolving draft EU AI Act. In cases where a notified body is involved, they will conduct regular audits to verify adherence to the quality management system.
The EU AI Act is not just handing out responsibilities to AI providers; it’s casting its net wider to include various actors in the AI lifecycle, from users to deployers. And its reach is not just limited to the EU; it has global ambitions, affecting entities even outside the EU, thus having implications that are worldwide.
With the EU Parliament's recent adjustments to the EU AI Act, the fines for non-compliance have seen a hike, now standing at a maximum of 35 million euros or up to 7% of global turnover. For context, these fines are 50% greater than that of the GDPR, which has maximum fines of $20M or 4% of global turnover, underlining the EU’s commitment to ensuring strict adherence to the EU AI Act.
The EU AI Act is a bold statement by the EU, meticulously balancing the act of fostering AI innovation while ensuring that the core values and rights of society are not compromised. With the Act inching closer to its final stages of approval, it’s crucial for everyone in the AI space to keep an eye on its development.
Whether you’re a provider, user, or someone involved in the deployment of AI, preparing for a future where AI is not just a technological marvel but also a subject of defined legal boundaries and responsibilities is imperative. This introduction offers a glimpse into the EU AI Act’s journey and potential impact, setting the stage for the deeper analysis that unfolds in the subsequent sections. So, buckle up and let’s dive deeper into understanding the nuances and implications of the EU AI Act together.
The global AI framework landscape underscores the imperative need for more cohesive international rules and standards pertaining to AI. The proliferation of AI frameworks is undeniable, calling for enhanced international collaboration to at least align on crucial aspects, such as arriving at a universally accepted definition of AI.
While international frameworks continue to evolve, the EU AI Act increasingly serves as a reference point for operational AI governance. Many organizations are aligning internal governance programs with internationally recognized frameworks while using the AI Act as the foundation for regulatory compliance across Europe.
Implementation is also becoming more operational at the Member State level. Spain’s proposed AI governance framework illustrates this direction by addressing supervisory authorities, enforcement mechanisms, regulatory sandboxes, and sector-specific oversight alongside the EU AI Act. As implementation progresses, organizations should monitor how Member States build the governance infrastructure required to supervise AI systems in practice.
AI promises quicker, more efficient, and accurate processes in various sectors. For example, in insurance, AI has streamlined the assessment process for car accidents, optimizing a process that was once manual and lengthy. This example serves as a testament to AI's potential to significantly improve various aspects of business and everyday life.
But engaging with AI is a nuanced dance, a careful balancing act between leveraging its unparalleled potential and navigating the associated risks. With its transformative and disruptive capabilities, AI invites cautious and informed engagement.
Recognizing its transformative power while preparing for the challenges it brings to the table is essential for individuals and organizations alike as they navigate the dynamic landscape of artificial intelligence in the modern age.
Despite its myriad advantages, AI isn’t without substantial challenges and risks. For starters, some AI systems, which may be perceived as “black boxes,” have been the subject of intense scrutiny and debate over transparency issues. This concern is particularly salient with larger AI systems, such as extensive language models, where there’s a lack of clarity on the training data employed. This raises significant copyright and privacy concerns, which need to be addressed head-on.
Furthermore, the struggle with ensuring the accuracy of AI systems persists, with several instances of erroneous AI responses and predictions documented. Notably, bias that may arise in AI systems—stemming from the prejudiced data they may be trained on—poses a risk of discrimination, requiring vigilant monitoring and rectification efforts from stakeholders involved.
Interestingly, AI isn’t just a challenge; it is also a potential solution to these conundrums. For instance, AI can be leveraged to identify and mitigate biases within datasets. Once these biases are discerned, strategic steps can be taken to rectify them, ensuring that AI can be harnessed optimally to maximize its benefits while minimizing associated risks.
With the dynamic and complex AI landscape unfolding rapidly, there is an urgent need for legal and privacy professionals to lay the groundwork for robust AI governance and compliance programs. A wealth of existing guidance provides a preliminary roadmap for the essential requirements of such programs, with senior management's endorsement being a pivotal first step in this endeavor.
Today’s governance programs increasingly align with established frameworks such as ISO/IEC 42001 and the NIST AI Risk Management Framework. While these frameworks differ in scope, they reinforce common governance capabilities including accountability, documentation, risk management, human oversight, monitoring, and continuous improvement. Those capabilities help organizations build a governance foundation that can support EU AI Act readiness as standards and supervisory expectations evolve.
Engaging C-suite executives and ensuring they comprehend the magnitude and intricacies of AI's influence is crucial for fostering a culture of AI responsibility throughout the organization. This initiative transcends mere compliance, extending to building trust in AI applications – a cornerstone for successful business operations.
Preparing for the EU AI Act extends beyond understanding legal requirements. Organizations increasingly benefit from building governance capabilities that continue to support compliance as regulations, standards, and guidance evolve.
Three capabilities deserve particular attention.
On the material front, organizations can use practical guidelines for ethical AI use. These guidelines are aligned with the AI principles from the Organization for Economic Cooperation and Development (OECD):
The establishment of AI Ethics Policies, informed by ethical impact assessments, is essential in navigating challenges and making informed, ethical decisions regarding AI use. For example, instead of outright blocking certain AI applications, ethical impact assessments can guide organizations in implementing nuanced, responsible use policies, especially for sensitive data. Ethical considerations should inform every step of AI application, from inception and development to deployment and monitoring.
Importantly, AI governance is not an exclusive domain of large corporations with extensive resources. With AI use cases proliferating across various sectors, companies of all sizes will inevitably engage with AI, necessitating AI governance frameworks tailored to their specific needs and capacities.
A few universal principles apply regardless of the company’s size. First, securing executive buy-in and adopting a multidisciplinary approach is imperative for successful AI governance implementation.
Second, organizations should commence with high-level principles as a starting point, even if they are small or merely purchasing ready-made AI models. Training and upskilling employees across various functions, including procurement and technology, is also vital to understand and mitigate the risks associated with AI tools and applications.
Six core governance principles need to be embedded into AI governance programs:
Given the pace at which AI is evolving and its profound implications, organizations must proactively develop and implement AI governance programs. By adopting a set of core governance principles and practices, organizations can navigate the AI landscape responsibly, ethically, and effectively. These principles, informed by ethical considerations, legal compliance, and a commitment to transparency and accountability, will guide organizations in harnessing AI’s benefits while mitigating its risks, ultimately fostering trust and success in the AI-driven future.
As organizations delve deeper into the realm of AI, developing and implementing AI governance programs aligned with their values is paramount. These governance frameworks should not only ensure compliance with legal standards but also reflect the ethical commitments and values of the organizations.
Whether it's about making tough trade-offs between transparency and security or deciding on the ethical use of data, a values-driven approach to AI governance provides a reliable compass guiding organizations through the intricate landscape of AI applications and ethics.
The EU AI Act continues to establish a global benchmark for AI regulation, but the latest amendments reinforce an important operational lesson: effective governance depends much more than understanding regulatory text.
Organizations need governance capabilities that connect AI inventories, documentation, ownership, risk assessments, vendor oversight, monitoring, and evidence into a repeatable operating model.
As implementation progresses and Member States continue building supervisory structures, regulators are likely to place increasing emphasis on how governance functions across organizations rather than whether policies simply exist.
Organizations that invest in AI-ready governance today will be better positioned to adapt as standards evolve, supervisory expectations mature, and AI continues expanding across the enterprise.
To prepare for the revised implementation timeline, organizations should consider five practical steps:
Organizations preparing for the EU AI Act benefit from governance capabilities that connect AI inventories, documentation, risk assessments, approvals, monitoring, and evidence across the AI lifecycle.
OneTrust AI Governance helps organizations operationalize these capabilities by centralizing AI documentation, mapping AI systems and supporting data flows, automating governance workflows, evaluating systems against governance frameworks, and maintaining evidence that supports regulatory readiness across evolving AI regulations.
The EU AI Act is the European Union’s comprehensive regulation governing the development, placing on the market, deployment, and use of artificial intelligence systems. It establishes a risk-based framework that applies to different obligations depending on the level of risk an AI system presents.
The latest amendments revise the application timeline for certain high-risk AI obligations, introduce additional prohibited AI practices relating to non-consensual intimate imagery and AI-generated child sexual abuse material, adjust the timing for certain transparency solutions for artificially generated content, and address implementation issues such as regulatory sandboxes and overlaps with sector-specific legislation.
Under the revised implementation schedule, obligations for stand-alone high-risk AI systems listed in Annex III apply from December 2, 2027. Obligations for high-risk AI systems embedded in regulated products apply from August 2, 2028.
No. The additional implementation time is intended to support better operational readiness while standards, guidance, and conformity assessment processes continue to develop. Organizations should continue building governance capabilities such as AI inventories, ownership models, documentation, oversight, monitoring, and evidence management.
The regulation applies to a broad range of organizations involved in developing, placing the market, deploying, importing, or distributing AI systems in the EU. Certain obligations can also apply to organizations established outside the EU where their AI systems or outputs are used in the Union.
The GDPR governs the processing of personal data, while the EU AI Act governs AI systems based on risk. Organizations using AI systems that process personal data may need to comply with both frameworks, including requirements relating to transparency, lawful processing, data protection impact assessments, governance, and accountability.
Frameworks such as ISO/IEC 42001 and the NIST AI Risk Management Framework can help organizations establish governance capabilities including accountability, documentation, oversight, risk management, monitoring, and continuous improvement. These capabilities can support readiness for the EU AI Act as implementation guidance and standards evolve.
Organizations should establish AI inventories, define ownership, classify AI use cases, integrate governance into operational workflows, maintain documentation throughout the AI lifecycle, and build evidence that demonstrates how governance decisions are made and monitored over time.
Operational AI governance connects inventories, documentation, approvals, risk assessments, monitoring, vendor oversight, and human oversight into repeatable business processes. Embedding governance into existing privacy, legal, security, procurement, risk, and product development workflows helps organizations prepare for evolving regulatory requirements.