Skip to main content

On-demand webinar coming soon...


On-demand webinar coming soon...

Blog

Navigating the Next Phase of the EU AI Act

The EU AI Act establishes one of the world’s first comprehensive frameworks for AI governance. This guide explains the regulation’s risk-based requirements, what the latest Digital Omnibus amendments changed, and how organizations can use the revised timeline to build operational readiness for compliance.

Alexis Kateifides 
Director, Regulatory Intelligence Enablement 
August 10, 2026

Composite image with multiple EU flags in front of an office building on one side and the OneTrust logogram on the other.

On-demand webinar coming soon...

 

A Horizontal Approach: Standing Apart on the Global Stage

In crafting its approach to artificial intelligence (AI) legislation, the European Union (EU) has opted for a horizontal legislative framework. The EU’s AI legal framework embraces an industry-agnostic perspective and is meticulously designed with nearly a hundred articles.

Here, we’ll look to provide a window into the EU AI Act. This piece of legislation is not just the first of its kind—but also a benchmark for global AI regulation, developed to help create a precedent in the rapidly evolving AI landscape.  

Key Takeaways

  • The EU AI Act remains a leading global benchmark for risk-based AI governance.
  • The latest Digital Omnibus amendments revise the application timeline for certain high-risk AI obligations, with stand-alone Annex III systems moving to December 2, 2027 and high-risk AI systems embedded in regulated products moving to August 2, 2028.
  • The amendments provide additional implementation time, but they do not remove the AI Act’s core expectations around risk management, documentation, human oversight, monitoring, and accountability.
  • Transparency-related obligations continue to move forward, including updated timing for certain AI-generated content transparency solutions.
  • Organizations should use the revised timeline to strengthen AI inventories, ownership models, documentation, accountability, oversight, and evidence management across existing business processes.

 

What's New: the Latest EU AI Act Amendments

 The latest amendments to the EU AI Act represent an important milestone in the regulation implementation. While many organizations have focused on the revised compliance dates, the amendments send a broader message about how AI governance is expected to mature across Europe.

The most significant change is the revised application timeline for certain high-risk AI obligations. Obligations for stand-alone high-risk AI systems listed in Annex III will apply from December 2, 2027, while obligations for high-risk AI systems embedded in regulated products will apply from August 2, 2028.

The amendments also introduce additional prohibited AI practices relating to non-consensual intimate imagery and AI-generated child sexual abuse material. They also adjust the timing for certain transparency solutions for artificially generated content, reinforcing that disclosure and labelling requirements remain a near-term compliance priority.

Importantly, these changes do not alter the AI Act’s underlying risk-based structure. High-risk AI systems will still require governance measures such as documentation, risk management, human oversight, conformity assessment, post-market monitoring, and accountability.

The revised timeline acknowledges that effective governance depends on more than legislation alone. Organizations also need harmonized standards, implementation of guidance, conformity assessment procedures, and internal governance capabilities that translate legal obligations into repeatable business processes.

For privacy, legal, risk, and AI governance leaders, the additional implementation window should be viewed as an opportunity to strengthen governance rather than postpone preparation. Capabilities such as AI inventories, ownership, documentation, evidence collection, and cross-functional oversight remain valuable regardless of future regulatory adjustments.

 

Where the Act Stands Now

The EU AI Act has now entered its implementation phase. While the regulation is in force, different obligations apply according to a phased implementation schedule that has been refined through the latest amendments.

The revised timeline aligns legal obligations with the practical work required to establish technical standards, guidance, conformity assessment procedures, and governance capabilities across organizations and regulators.

Organizations should continue preparing for compliance based on the revised schedule while recognizing that the underlying regulatory expectations remain unchanged.

 

EU AI Act Implementation Timeline

RequirementCurrent Timeline
Existing prohibited AI practicesAlready applicable under the AI Act’s phased implementation schedule
New prohibited AI practices introduced by the amendmentsDecember 2, 2026
Article 50 transparency obligationsAugust 2, 2026, subject to the relevant obligation
Transparency solutions for certain artificially generated contentDecember 2, 2026
General-purpose AI obligationsUnchanged by the latest Omnibus amendments
Stand-alone high-risk AI systems listed in Annex IIIDecember 2, 2027

 

What Operational Readiness Means Under the Revised Timeline

One of the most significant outcomes of the amendments is not the revised timeline itself, but the recognition that AI governance requires operational infrastructure. Compliance increasingly depends on capabilities that remain useful as standards, guidance, and supervisory expectations evolve.

Organizations should not prepare only for a single compliance deadline. They should build repeatable governance processes for identifying AI systems, assigning ownership, classifying risk, documenting decisions, monitoring performance, managing third-party AI risk, and maintaining evidence over time.

This also changes how privacy and legal leaders approach compliance. AI governance is no longer a standalone legal exercise. It increasingly connects procurement, product development, security, engineering, risk, privacy, and business teams through common governance workflows.

 

AI: Breaking down the concept 

Originally, the Act defined machine learning, the basis of AI systems,  as “including supervised, unsupervised and reinforcement learning, using a wide variety of methods including deep learning.” The text includes an updated definition, which defines AI systems as “machine-based systems designed to operate with varying levels of autonomy and that may exhibit adaptiveness after deployment and that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments.”  

The complexity of AI systems is a sliding scale, with more intricate systems requiring substantial computing power and input data. The output from these systems can be simple or mightily complex, varying with the sophistication of the AI in play.

This broad definition covers a range of technologies, from your everyday chatbots to highly sophisticated generative AI models. But it’s important to note that not every AI system falling under the Act’s broad definition will be regulated. The Act plays it smart with a risk-based approach, bringing under its regulatory umbrella only those systems associated with specific risk levels.

 

AI Regulation: Calibrated to Risk

Here’s where it gets interesting. The EU AI Act has different baskets for AI systems. Some are seen as posing an unacceptable risk to European values, leading to their prohibition. High-risk systems, while not banned, have to dance to a tighter regulatory tune. It’s vital to remember that these risk categories aren't static; the Act is still in a draft stage, and as more changes come, these risk categories will likely be fine-tuned as well. 

 

EU AI Act risk levels 

The EU AI Act defines multiple levels of permissible risk: high risk, limited risk, and minimal risk. 

These are the levels of “permissible risk” that are allowed by organizations, however, “unacceptable risk” is a risk level which is not allowed by organizations at which point companies need to change their models accordingly.  

  • Unacceptable Risk — Social scoring systems, real-time remote biometric verification.
  • High Risk — Credit scoring systems, automated insurance claims . 
    For processes that fall into this bucket, companies need to conduct a conformity assessment and register it with an EU database before the model is available to the public. 
    Apart from this, these high-risk processes require detailed logs and human oversight as well.  
  • Limited Risk — Chatbots, personalization. 
    For limited risk processes, companies need to ensure that they’re being completely transparent with their customers about what AI is being used for and the data involved.  
  • Minimal Risk — For any processes that companies use that fall into the “minimal risk” bucket, the draft EU AI Act encourages providers to have a code of conduct in place that ensures AI is being used ethically. 

 

Pyramid graphic showing the levels of permissable AI risk areas defined by the EU AI Act and what the act requires organizations to do to address these areas of risk. Starting from the lowest level: Minimal risk areas require a code of conduct; limited risk areas need transparency; high risk areas need conformity assessments; and at the top level are areas that are considered unacceptable.

 

Conformity assessments 

Of these risk levels, high-risk systems will pose the highest compliance burden on organizations, as they’ll have to continue to meet obligations for conformity assessments. Conformity assessments (CA) require companies to ensure that their “high-risk” systems meet the following: 

  • The quality of data sets used to train, validate and test the AI systems; the data sets must be “relevant, representative, free of errors and complete.”
  • Detailed technical documentation.
  • Record-keeping in the form of automatic recording of events.
  • Transparency and the provision of information to users.
  • Human oversight.

This assessment is mandatory before a high-risk AI system is made available or used in the EU market. It ensures that AI systems comply with EU standards, particularly if there are significant modifications or changes in intended use. The main responsible party for CA is the “provider” –the entity putting the system on the market. However, under certain circumstances, the responsibility can shift to the manufacturer, distributor, or importer, especially when they modify the system or its purpose. 

 

Who performs a CA? 

The CA can be done internally or by an external “notified body.” Internal CAs are common as providers are expected to have the necessary expertise. Notified bodies come into play particularly when an AI system is used for sensitive applications like real-time biometric identification and does not adhere to pre-defined standards. 

During an internal CA, the provider checks compliance with quality management standards, assesses technical documentation, and ensures the AI system's design and monitoring are consistent with requirements. Success results in an EU declaration of conformity and a CE marking, signaling compliance, which must be kept for ten years and provided to national authorities if requested. 

For third-party CAs, notified bodies review the system and its documentation. If compliant, they issue a certificate; otherwise, they require the provider to take corrective action. 

 

How often should you perform a CA? 

Conformity assessment isn't a one-off process; providers must continually monitor their AI systems post-market to ensure they remain compliant with the evolving draft EU AI Act. In cases where a notified body is involved, they will conduct regular audits to verify adherence to the quality management system. 

 

Engaging all players in the AI game 

The EU AI Act is not just handing out responsibilities to AI providers; it’s casting its net wider to include various actors in the AI lifecycle, from users to deployers. And its reach is not just limited to the EU; it has global ambitions, affecting entities even outside the EU, thus having implications that are worldwide. 

 

Fines: A significant deterrent 

With the EU Parliament's recent adjustments to the EU AI Act, the fines for non-compliance have seen a hike, now standing at a maximum of 35 million euros or up to 7% of global turnover. For context, these fines are 50% greater than that of the GDPR, which has maximum fines of $20M or 4% of global turnover, underlining the EU’s commitment to ensuring strict adherence to the EU AI Act.  

 

Charting the course towards regulated AI 

The EU AI Act is a bold statement by the EU, meticulously balancing the act of fostering AI innovation while ensuring that the core values and rights of society are not compromised. With the Act inching closer to its final stages of approval, it’s crucial for everyone in the AI space to keep an eye on its development.  

Whether you’re a provider, user, or someone involved in the deployment of AI, preparing for a future where AI is not just a technological marvel but also a subject of defined legal boundaries and responsibilities is imperative. This introduction offers a glimpse into the EU AI Act’s journey and potential impact, setting the stage for the deeper analysis that unfolds in the subsequent sections. So, buckle up and let’s dive deeper into understanding the nuances and implications of the EU AI Act together. 

 

AI Frameworks: A Global Perspective 

A landscape in flux: The global heat map of AI frameworks 

The global AI framework landscape underscores the imperative need for more cohesive international rules and standards pertaining to AI. The proliferation of AI frameworks is undeniable, calling for enhanced international collaboration to at least align on crucial aspects, such as arriving at a universally accepted definition of AI.  

 

Global map showing the different AI regulations and proposals from various major countries.

While international frameworks continue to evolve, the EU AI Act increasingly serves as a reference point for operational AI governance. Many organizations are aligning internal governance programs with internationally recognized frameworks while using the AI Act as the foundation for regulatory compliance across Europe.

Implementation is also becoming more operational at the Member State level. Spain’s proposed AI governance framework illustrates this direction by addressing supervisory authorities, enforcement mechanisms, regulatory sandboxes, and sector-specific oversight alongside the EU AI Act. As implementation progresses, organizations should monitor how Member States build the governance infrastructure required to supervise AI systems in practice.

 

Efficient future processes through AI

AI promises quicker, more efficient, and accurate processes in various sectors. For example, in insurance, AI has streamlined the assessment process for car accidents, optimizing a process that was once manual and lengthy. This example serves as a testament to AI's potential to significantly improve various aspects of business and everyday life. 

But engaging with AI is a nuanced dance, a careful balancing act between leveraging its unparalleled potential and navigating the associated risks. With its transformative and disruptive capabilities, AI invites cautious and informed engagement. 

Recognizing its transformative power while preparing for the challenges it brings to the table is essential for individuals and organizations alike as they navigate the dynamic landscape of artificial intelligence in the modern age.  
 

Weighing AI’s Pros and Cons in Business 

Risks: Transparency, accuracy, and bias 

Despite its myriad advantages, AI isn’t without substantial challenges and risks. For starters, some AI systems, which may be perceived as “black boxes,” have been the subject of intense scrutiny and debate over transparency issues. This concern is particularly salient with larger AI systems, such as extensive language models, where there’s a lack of clarity on the training data employed. This raises significant copyright and privacy concerns, which need to be addressed head-on.  

Furthermore, the struggle with ensuring the accuracy of AI systems persists, with several instances of erroneous AI responses and predictions documented. Notably, bias that may arise in AI systems—stemming from the prejudiced data they may be trained on—poses a risk of discrimination, requiring vigilant monitoring and rectification efforts from stakeholders involved.  
 

AI as solution: Turning risks into opportunities 

Interestingly, AI isn’t just a challenge; it is also a potential solution to these conundrums. For instance, AI can be leveraged to identify and mitigate biases within datasets. Once these biases are discerned, strategic steps can be taken to rectify them, ensuring that AI can be harnessed optimally to maximize its benefits while minimizing associated risks.  
 

Developing AI Governance: the Way Forward 

Laying the foundations for AI governance 

With the dynamic and complex AI landscape unfolding rapidly, there is an urgent need for legal and privacy professionals to lay the groundwork for robust AI governance and compliance programs. A wealth of existing guidance provides a preliminary roadmap for the essential requirements of such programs, with senior management's endorsement being a pivotal first step in this endeavor.  

Today’s governance programs increasingly align with established frameworks such as ISO/IEC 42001 and the NIST AI Risk Management Framework. While these frameworks differ in scope, they reinforce common governance capabilities including accountability, documentation, risk management, human oversight, monitoring, and continuous improvement. Those capabilities help organizations build a governance foundation that can support EU AI Act readiness as standards and supervisory expectations evolve.

Engaging C-suite executives and ensuring they comprehend the magnitude and intricacies of AI's influence is crucial for fostering a culture of AI responsibility throughout the organization. This initiative transcends mere compliance, extending to building trust in AI applications – a cornerstone for successful business operations. 

 

Build Governance That Lasts Beyond the Next Deadline

Preparing for the EU AI Act extends beyond understanding legal requirements. Organizations increasingly benefit from building governance capabilities that continue to support compliance as regulations, standards, and guidance evolve.

Three capabilities deserve particular attention.

  • Know Your AI 
    Maintain an inventory of AI systems, identify business ownership, classify AI use cases, and understand where high-risk obligations may apply.
  • Embed Governance Into Existing Processes 
    Integrate AI governance into procurement, vendor assessments, product development, privacy reviews, risk management, and security workflows instead of creating separate compliance processes.
  • Build Evidence Continuously 
    Maintain documentation, governance decisions, monitoring records, risk assessments, and approvals throughout the AI lifecycle. Continuous evidence creates stronger regulatory readiness than documentation assembled immediately before compliance deadlines.

 

Practical steps towards an AI governance framework 

On the material front, organizations can use practical guidelines for ethical AI use. These guidelines are aligned with the AI principles from the Organization for Economic Cooperation and Development (OECD): 

  1. Transparency: Efforts should be directed towards demystifying AI applications, making their operations and decisions understandable and explainable to users and stakeholders. 
  2. Privacy Adherence: AI applications should respect and protect users’ privacy, handling personal data judiciously and in compliance with relevant privacy laws and regulations. 
  3. Human Control: Especially in high-risk areas, there should be mechanisms for human oversight and control over AI applications, ensuring they align with human values and expectations.
  4. Fair Application: Strategies for detecting and mitigating biases in AI applications should be implemented, promoting fairness and avoiding discrimination.
  5. Accountability: There should be comprehensive documentation and recording of AI operations, allowing for scrutiny, accountability, and necessary corrections. 

 

AI ethics policy: A critical element 

The establishment of AI Ethics Policies, informed by ethical impact assessments, is essential in navigating challenges and making informed, ethical decisions regarding AI use. For example, instead of outright blocking certain AI applications, ethical impact assessments can guide organizations in implementing nuanced, responsible use policies, especially for sensitive data. Ethical considerations should inform every step of AI application, from inception and development to deployment and monitoring. 

 

Inclusive AI governance: A size-agnostic imperative 

Importantly, AI governance is not an exclusive domain of large corporations with extensive resources. With AI use cases proliferating across various sectors, companies of all sizes will inevitably engage with AI, necessitating AI governance frameworks tailored to their specific needs and capacities. 

A few universal principles apply regardless of the company’s size. First, securing executive buy-in and adopting a multidisciplinary approach is imperative for successful AI governance implementation.  

Second, organizations should commence with high-level principles as a starting point, even if they are small or merely purchasing ready-made AI models. Training and upskilling employees across various functions, including procurement and technology, is also vital to understand and mitigate the risks associated with AI tools and applications. 

 

Embedding core governance principles 

Six core governance principles need to be embedded into AI governance programs: 

  1. Governance and Accountability: Establishing a structure for accountability, possibly through AI oversight committees or ethics review boards, is essential. Governance should be enforced throughout AI’s lifecycle, from inception to operation.
  2. Human Oversight: Adopting a human-centric approach, with trained human reviewers at various stages, is crucial for ethical AI application. 
  3. Fairness and Ethics Alignment: AI outputs should align with fairness and ethical standards, reflecting an organization’s culture and values. 
  4. Data Management: Implementing robust data management processes, tracking modifications to datasets and mapping data sources, is key for reliable AI systems. 
  5. Transparency Enhancement: Ensuring that AI decision-making processes are transparent and understandable is necessary for building trust and compliance. 
  6. Privacy and Cybersecurity: Addressing legal data processing requirements, conducting privacy impact assessments, and mitigating AI-specific cyber risks are imperative for secure and compliant AI applications. 

 

Given the pace at which AI is evolving and its profound implications, organizations must proactively develop and implement AI governance programs. By adopting a set of core governance principles and practices, organizations can navigate the AI landscape responsibly, ethically, and effectively. These principles, informed by ethical considerations, legal compliance, and a commitment to transparency and accountability, will guide organizations in harnessing AI’s benefits while mitigating its risks, ultimately fostering trust and success in the AI-driven future. 

 

Value-driven AI governance 

As organizations delve deeper into the realm of AI, developing and implementing AI governance programs aligned with their values is paramount. These governance frameworks should not only ensure compliance with legal standards but also reflect the ethical commitments and values of the organizations.  

Whether it's about making tough trade-offs between transparency and security or deciding on the ethical use of data, a values-driven approach to AI governance provides a reliable compass guiding organizations through the intricate landscape of AI applications and ethics. 

 

Operational Readiness Is Becoming the Measure of AI Governance

The EU AI Act continues to establish a global benchmark for AI regulation, but the latest amendments reinforce an important operational lesson: effective governance depends much more than understanding regulatory text.

Organizations need governance capabilities that connect AI inventories, documentation, ownership, risk assessments, vendor oversight, monitoring, and evidence into a repeatable operating model.

As implementation progresses and Member States continue building supervisory structures, regulators are likely to place increasing emphasis on how governance functions across organizations rather than whether policies simply exist.

Organizations that invest in AI-ready governance today will be better positioned to adapt as standards evolve, supervisory expectations mature, and AI continues expanding across the enterprise.

To prepare for the revised implementation timeline, organizations should consider five practical steps:

  1. Identify and classify AI systems across the organization, including systems developed internally and those procured from third parties. 
  2. Assign ownership and accountability for AI use cases, documentation, approvals, monitoring, and escalation. 
  3. Integrate AI governance into existing workflows, including procurement, privacy reviews, product development, vendor risk management, security, and enterprise risk processes. 
  4. Maintain evidence continuously, including risk assessments, governance decisions, technical documentation, human oversight measures, and monitoring records. 
  5. Monitor evolving standards and guidance, including harmonized standards, Commission guidance, Member State implementation measures, and sector-specific expectations.

Organizations preparing for the EU AI Act benefit from governance capabilities that connect AI inventories, documentation, risk assessments, approvals, monitoring, and evidence across the AI lifecycle.

OneTrust AI Governance helps organizations operationalize these capabilities by centralizing AI documentation, mapping AI systems and supporting data flows, automating governance workflows, evaluating systems against governance frameworks, and maintaining evidence that supports regulatory readiness across evolving AI regulations.

 

Key Questions About the EU AI Act

 

The EU AI Act is the European Union’s comprehensive regulation governing the development, placing on the market, deployment, and use of artificial intelligence systems. It establishes a risk-based framework that applies to different obligations depending on the level of risk an AI system presents.

The latest amendments revise the application timeline for certain high-risk AI obligations, introduce additional prohibited AI practices relating to non-consensual intimate imagery and AI-generated child sexual abuse material, adjust the timing for certain transparency solutions for artificially generated content, and address implementation issues such as regulatory sandboxes and overlaps with sector-specific legislation.

Under the revised implementation schedule, obligations for stand-alone high-risk AI systems listed in Annex III apply from December 2, 2027. Obligations for high-risk AI systems embedded in regulated products apply from August 2, 2028.

No. The additional implementation time is intended to support better operational readiness while standards, guidance, and conformity assessment processes continue to develop. Organizations should continue building governance capabilities such as AI inventories, ownership models, documentation, oversight, monitoring, and evidence management.

The regulation applies to a broad range of organizations involved in developing, placing the market, deploying, importing, or distributing AI systems in the EU. Certain obligations can also apply to organizations established outside the EU where their AI systems or outputs are used in the Union.

The GDPR governs the processing of personal data, while the EU AI Act governs AI systems based on risk. Organizations using AI systems that process personal data may need to comply with both frameworks, including requirements relating to transparency, lawful processing, data protection impact assessments, governance, and accountability.

Frameworks such as ISO/IEC 42001 and the NIST AI Risk Management Framework can help organizations establish governance capabilities including accountability, documentation, oversight, risk management, monitoring, and continuous improvement. These capabilities can support readiness for the EU AI Act as implementation guidance and standards evolve.

Organizations should establish AI inventories, define ownership, classify AI use cases, integrate governance into operational workflows, maintain documentation throughout the AI lifecycle, and build evidence that demonstrates how governance decisions are made and monitored over time.

Operational AI governance connects inventories, documentation, approvals, risk assessments, monitoring, vendor oversight, and human oversight into repeatable business processes. Embedding governance into existing privacy, legal, security, procurement, risk, and product development workflows helps organizations prepare for evolving regulatory requirements.