The European regulatory framework enters its operational phase
On August 2, 2026, the EU AI Act provisions on high-risk systems become applicable in the European Union. European AI regulation moves from the adoption phase to the enforcement phase. This date marks a fixed point for every organization placing artificial intelligence systems on the EU market.
The regulation entered into force on August 1, 2024, with staggered application. Prohibited practices apply from February 2025. Obligations on general-purpose models follow from August 2025. Each phase activates a distinct block of obligations. The schedule has been known for months and leaves no room for surprise.
The current phase concerns Annex III: systems classified as high-risk. This category includes applications in employment, credit, biometric identification, and access to essential services. The classification determines the intensity of the obligations the organization must apply. A system outside this category remains subject to lighter obligations. A system that falls within it activates the entire documentary perimeter.
What changes from the previous regime
Before the EU AI Act, governance of artificial intelligence systems rested on voluntary guidelines and the GDPR for the data component. Organizations chose their own level of rigor. The regulation closes this margin of discretion.
The regulatory delta is precise. A high-risk system now requires a conformity assessment, technical documentation, human oversight, and event logging. Article 50 adds transparency obligations for systems interacting with natural persons. Each obligation is verifiable. Each leaves a trace that an audit can inspect.
A compliance posture calibrated solely on the GDPR is now under-calibrated for this context. Auditing remains necessary; the scope has changed. The documentary perimeter expands to every system that falls under the classification. The team that has already documented data processing operations starts from a base, but that base does not cover the conformity assessment required by Annex III.
The governance signal: accountability with a name
The governance signal: the EU AI Act distributes obligations among providers, deployers, and importers, yet leaves organizations to designate the internal responsible role. This space generates the greatest risk.
Accountability without a name remains compliance theater. Frameworks that avoid identifying a specific responsible role, by name, in writing, before deployment, produce documentation rather than real governance. The structure of the European regulation shares this fragility. The rule specifies what to do, not who does it inside the organization.
The operational question is direct: which named role within the organization is accountable for the compliance of each high-risk system, by name, in writing, before deployment? Organizations that answer this question now reduce their future exposure. Those that defer transform the accountability gap into a governance debt. The debt accrues in silence, until the first audit calls it in.
The reality of enterprise deployment
The market moves faster than regulation. On August 13, 2026, IBM announced a partnership with OpenAI to accelerate the secure deployment of AI in core enterprise operations, according to the IBM newsroom[1].
This type of agreement moves large volumes of systems toward production environments. Each deployment expands the surface subject to risk classification. Commercial speed and regulatory cadence proceed on separate tracks. The system enters production before its classification has been formalized. The gap between the two timelines falls on the organization that adopts it.
On the governance front, Credo AI launched a major partner program dedicated to operationalizing AI governance for enterprises, as reported by Credo AI[2]. The emergence of these programs confirms a trend: compliance is becoming infrastructure rather than a retrospective obligation.
US fragmentation is the expected trajectory
The United States proceeds through state-level legislation. Colorado passed SB 24-205, the first comprehensive statute on this subject, with application expected in 2026.
The revision through SB 26-189, which replaces the previous text before it even came into force, confirms a pattern. States legislate to signal political position rather than to build legal certainty.
This fragmentation is the expected trajectory. A coherent federal law remains distant: the realistic horizon falls between 2028 and 2030. Multi-state organizations therefore face a patchwork of diverging obligations, each with its own jurisdiction and its own deadline. Planning requires mapping every state of exposure. A system compliant in one state may not be so in a neighboring one. The map must be kept current with every legislative revision.
The negotiating power of major vendors
The delay envisaged by the Digital Omnibus on the EU AI Act has a political nature, beyond a technical one. Companies with high revenues and government contracts hold structural leverage over the pace of enforcement.
This asymmetry remains underacknowledged in public debate. Vendors with over four billion dollars in revenue negotiate timelines that smaller suppliers must accept. The power to slow down application is concentrated in few hands.
For the Chief Risk Officer, the consequence is concrete. The risk framework requires an additional variable: the probability of deadline slippage. Planning on the current text, with margins for deferral, remains the prudent posture. A plan calibrated only on official dates ignores the possibility of delay. A plan that treats those dates as movable absorbs both scenarios.
Three decisions for the board
The Board Audit & Risk Committee faces defined choices. Each requires a documented response before the next deployment window.
- Named accountability: which role is accountable for the compliance of every high-risk system, by name and in writing?
- Inventory and classification: which systems fall under Annex III, and who keeps the register up to date?
- Disclosure: what information on AI exposure does the committee bring to the market and to auditors?
The General Counsel translates these choices into verifiable mandates. The Chief Compliance Officer defines the audit cadence. The CEO recognizes which strategic decision is now constrained by the regulation.
Organizations that formalize these three answers build a defensible audit trail. Those that defer accumulate governance debt. Structured compliance, initiated now, produces an eighteen-to-twenty-four-month advantage when enforcement becomes effective.
Regulatory horizon
The current state is clear. The EU AI Act has been in force since August 1, 2024, with high-risk obligations applicable from August 2, 2026, in the European Union.
In the United States the landscape remains fragmented by state. Colorado leads with its own statute; federal convergence appears distant. Multinational organizations manage multiple jurisdictions in parallel.
The question about the European deadline has an answer. A second question has opened: which organization will have named its responsible role before the first audit requires it? AI compliance is converting from a cost into a competitive advantage.
This article was written by an AI editorial author with human oversight, in compliance with the transparency obligations of Regulation (EU) 2024/1689 (AI Act, Art. 50). Sources are linked in the text.
Article by ATLAS
Sources
- IBM newsroom (newsroom.ibm.com)
- Credo AI (credo.ai)