
Financial risk assessment: why most organisations are measuring the wrong things
July 18, 2026
The proxy advisor reckoning: what the DOJ’s August 2026 move means for boards and CFOs Corporate
August 25, 2026The EU AI Act is now enforcing: what boards and CFOs need to address today
AI Governance / Regulatory Compliance | 6 min read | Raayzel Business Consulting
On 2 August 2026, the EU AI Act moved from regulatory framework to enforcement reality. The date that many organisations had been tracking as a future deadline is now in the past. What it brought with it is not a grace period or a soft launch. It is the activation of binding obligations, penalty powers, and a supervisory infrastructure that is already operational and looking for its first significant cases.
For boards, CFOs, General Counsel, and Chief Compliance Officers at organisations operating in or serving the European market, the question is no longer whether to prepare. It is how exposed the organisation already is and what needs to happen in the next ninety days.
This article sets out what the August 2026 enforcement milestone actually means, where the most significant governance gaps are appearing, and what a credible AI governance response looks like for corporate and enterprise organisations.
What changed on 2 August 2026
The EU AI Act has been applying in phases since February 2025, when prohibitions on unacceptable-risk AI practices first came into force. The August 2026 milestone is the most consequential phase of that rollout. Three specific enforcement mechanisms became operational simultaneously.
First, the full transparency obligations under Article 50 are now enforceable. Any AI system that interacts directly with individuals, including customer-facing chatbots, generative content tools, AI-assisted communications, and automated decision interfaces, must disclose its AI nature clearly. This applies regardless of the risk tier of the system.
Second, the European Commission’s enforcement and penalty powers over providers of general-purpose AI models are now active. The Commission can request documentation, run technical evaluations, demand corrective measures, restrict or withdraw a model from the EU market, and issue fines of up to 15 million euros or 3 percent of global annual turnover, whichever is higher. These powers are not prospective. They can be applied to AI deployments already in operation.
Third, and critically for enterprise organisations, the high-risk AI system obligations under Annex III are now the legally binding standard for systems placed on the market or significantly modified from this date. The Digital Omnibus proposal to defer some high-risk obligations to December 2027 has not been enacted into law. August 2026 remains the operative deadline, and legal and compliance advisors are consistently recommending that organisations treat it as such rather than build compliance programmes on a deferral that has not materialised.
What the penalty structure means in practice
The EU AI Act’s penalty regime exceeds GDPR in its upper tier. Violations of prohibited AI practices carry fines of up to 35 million euros or 7 percent of global annual turnover. Non-compliance with high-risk system obligations and general-purpose AI rules carry fines of up to 15 million euros or 3 percent of global annual turnover. Providing inaccurate information to authorities carries fines of up to 7.5 million euros or 1 percent of global annual turnover.
Legal experts monitoring enforcement patterns are expecting the first major regulatory actions before the end of 2026, targeting high-profile organisations in a pattern consistent with early GDPR enforcement. The organisations most exposed are those that cannot produce a basic inventory of the AI systems they are operating, the purposes those systems serve, and the risk classification rationale that determines their compliance obligations.
That last point is the one most organisations are underestimating. A documentation request from a national competent authority is not the beginning of a fine. It is the beginning of an inquiry. The outcome of that inquiry depends almost entirely on whether the organisation can produce coherent, evidence-based documentation of its AI governance. Organisations that can do so within a week are in a fundamentally different position to those that cannot.
The governance gap that August 2026 has exposed
Research conducted earlier in 2026 found that as many as 78 percent of organisations had not taken meaningful steps toward EU AI Act compliance as of April 2026. That figure is consistent with what is being observed in practice: most organisations have an AI policy, many have an AI working group or committee, and almost none have a complete, accurate inventory of the AI systems they are actually operating.
The gap is not primarily a technology problem. It is a governance problem. AI systems have been adopted at a rate that has outpaced the governance structures designed to oversee them. Procurement processes have brought AI tools into organisations without systematic risk classification. Employees have adopted AI-assisted workflows that are not visible to the compliance or legal function. Third-party providers have embedded AI into services that the organisation uses without formal assessment of whether those deployments meet the Act’s requirements.
The result is a compliance exposure that is invisible until it is not. The organisation believes it is operating within the regulatory framework because its formal AI policy says the right things. The actual AI deployment environment, across business functions, third-party integrations, and shadow AI use, looks materially different from what the policy describes.
What boards and CFOs carry personally
The EU AI Act is not only a compliance matter for technology and legal functions. It carries governance accountability that sits at board and C-suite level in a way that the regulation makes explicit.
For organisations using AI systems classified as high-risk under Annex III, including systems used in employment decisions, credit scoring, critical infrastructure management, or access to essential services, the board carries oversight responsibility for whether the required governance structures are in place. This includes risk management systems, data governance frameworks, human oversight mechanisms, and technical documentation. These are not IT deliverables. They are governance obligations.
The CFO carries specific exposure where AI systems affect financial reporting, credit assessment, or financial risk management. The accountability frameworks that already apply to financial reporting controls now extend to the AI systems that produce, inform, or automate those outputs. A CFO who certified the adequacy of internal controls over financial reporting without assessing whether AI systems affecting those controls are compliant with the Act is carrying an exposure that most finance functions have not yet quantified.
For General Counsel and Chief Compliance Officers, the notification timeline introduced by the regulation creates an immediate operational challenge. Following an AI-related incident, organisations may simultaneously face a 24-hour notification obligation under NIS2, a 72-hour obligation under GDPR, and a 15-day obligation under the AI Act, to three different authorities, with statements made in the first 24 hours potentially used in subsequent investigations by the others. That coordination requirement needs to be designed in advance, not improvised under pressure.
Where to start: three governance priorities for the next ninety days
Organisations that have not yet established a structured AI governance programme need to prioritise three things above all others in the period immediately following the August 2026 enforcement milestone.
The first priority is a complete AI inventory. This means identifying every AI system in use across the organisation, including systems embedded in third-party services, and documenting the purpose, the data it processes, the decisions it informs or automates, and the population it affects. This inventory is the foundation of every other compliance obligation under the Act. Without it, risk classification is guesswork and documentation is incomplete.
The second priority is risk classification with documented rationale. Every system identified in the inventory needs to be assessed against the Act’s risk tiers. For systems that might fall within Annex III high-risk categories, a written classification rationale referencing the Act’s criteria is the document that determines whether a regulatory inquiry results in a remediation window or an enforcement action. The rationale needs to be prepared now, not assembled under pressure when a documentation request arrives.
The third priority is governance structure alignment. The board, audit committee, and C-suite need a clear view of the organisation’s AI exposure, the compliance obligations that attach to current deployments, and the programme in place to address gaps. This is not a technology briefing. It is a governance update of the same kind that a material regulatory development in any other area of the business would require.
The connection to existing governance and controls frameworks
One of the most important observations for organisations with mature governance and compliance programmes is that the EU AI Act does not require an entirely separate compliance infrastructure. Its core requirements, risk management, data governance, human oversight, technical documentation, incident response, and audit trail maintenance, map directly onto the disciplines that well-governed organisations already apply to their control environments.
The Act’s requirement for a risk management system for high-risk AI is structurally similar to what a mature ERM programme already does. Its data governance requirements sit within the framework that GDPR compliance has already established. Its human oversight and audit trail requirements are the same disciplines that SOX compliance and internal audit already apply to financial processes.
The organisations that will achieve AI Act compliance most efficiently are those that extend their existing governance architecture to cover AI systems rather than building a parallel compliance programme from scratch. The governance infrastructure exists. What it needs is scope extension and updated risk assessment to include the AI systems that have been adopted since it was last calibrated.
The governance question boards should be asking now
The EU AI Act enforcement milestone has surfaced a governance question that boards and CFOs need to answer with precision rather than policy language: does the organisation know what AI systems it is operating, does it understand which of those systems create regulatory exposure under the Act, and does it have documented evidence of the governance it has applied to those systems?
Most organisations cannot answer all three parts of that question accurately today. The ones that move quickly to close that gap will be in a materially stronger position as enforcement develops through the remainder of 2026 and into 2027, both with regulators and with the institutional investors and enterprise clients who are increasingly asking the same questions.
The August 2026 deadline has passed. The compliance window has not closed. But the organisations that treat the enforcement milestone as a signal to begin rather than a deadline they have missed will find the gap significantly harder to close as regulatory scrutiny increases and the first enforcement actions establish the standards that will define the regime going forward.
Raayzel works with boards, CFOs, General Counsel, and compliance functions to assess AI governance maturity, design AI risk frameworks that integrate with existing control environments, and build the documentation and oversight structures that the EU AI Act and emerging UK AI governance expectations require. The work is advisory and execution-oriented, calibrated to the specific AI deployment profile and regulatory exposure of each organisation.
Stay ahead of the AI governance and regulatory compliance agenda.
Sign up for free insights and resources from Raayzel Business Consulting: https://lp.constantcontactpages.com/sl/sBV4psC/insights Book a free 30-minute consultation with Owais Raie, Compliance Partner at Raayzel: https://calendly.com/raayzelconsulting/30min




