EU AI Act, day two: what the first week after the deadline reveals about real readiness

On 2 August 2026 the EU AI Act took effect for high-risk AI systems. An ISACA survey found 61 percent of GRC directors had not yet identified their scope three weeks out. What the first 48 hours reveal, and where to start now.

Glass facade of an office building

On 2 August 2026 the first obligations specific to high-risk AI systems under the EU AI Act took effect, on the timetable set by the regulation. Forty-eight hours later the picture is unambiguous: most regulated organisations have not finalised their technical documentation, their conformity assessments are incomplete, and human oversight of the systems concerned remains formal rather than substantive. An ISACA survey published in late July 2026 found that 61 percent of GRC directors in organisations above 500 staff had not yet identified all their high-risk AI systems three weeks before the deadline. The EU AI Act is not a revolution under way. It is a revealer of how far behind AI governance actually is.

What the 2 August deadline actually imposes

It is worth stating what the deadline is not: it is not a date for total compliance. It is the date from which obligations on technical documentation, ex-ante conformity assessment and human oversight systems become enforceable for providers and deployers of AI systems classified high-risk under Annex III.

Systems in scope first: credit scoring tools, recruitment and candidate evaluation software, decision systems in essential public services, biometric analysis platforms used for access control, and critical infrastructure monitoring systems. For a European mid-market organisation in financial services, HR or business services, two to five production systems probably fall in scope without IT having formally documented them.

Penalties for non-compliant deployers of high-risk AI reach 15 million euros or 3 percent of annual global turnover. The European Commission has confirmed that first checks by national authorities are planned for the fourth quarter of 2026.

Three gaps the first 48 hours exposed

1. The inventory of high-risk AI systems is not finished. The difficulty is organisational rather than technical. High-risk AI systems are rarely labelled as such in existing asset inventories. A scoring module inside an ERP, an automatic matching feature in an applicant tracking system, a prioritisation algorithm in a ticketing tool: none of these get their own inventory record. An IBM Security study of 350 European companies published in June 2026 found 67 percent had no formal AI register in the sense of the regulation. Without an inventory, every compliance step hangs in mid-air.

2. The required technical documentation is underestimated in both volume and complexity. For each high-risk system the regulation requires a technical file covering: a detailed description of the system and its components, the training data and the quality criteria applied, performance and robustness test results, the human oversight measures in place, and logging and traceability procedures. For a system supplied by a third party, much of that documentation sits with the provider, but collecting and validating it falls to the deployer. Most GRC teams have neither the template, nor the process, nor the identified provider contacts to gather it.

3. Human oversight remains declaratory rather than substantive. Article 14 requires that high-risk AI systems allow competent human operators to understand the system's capabilities and limits, detect and correct failures, and intervene or stop the system. In practice, documented oversight procedures often amount to a ticked box in the supplier contract or a generic reference in the AI usage policy. The concrete check, can the operator actually understand a decision, spot an anomaly, and act on it, is rarely tested.

What the organisations ahead are doing

The organisations that anticipated, roughly 15 percent in the mid-market according to Forrester, share three distinctive practices.

They treat the AI inventory as a continuous process, not a one-off project. Every new system or significant update triggers an EU AI Act classification assessment, built into the purchasing and deployment process. That reflex, systematically asking whether a system takes or assists decisions with high human impact, is harder to instil than it sounds, and it is the foundation for everything else.

They consolidate EU AI Act obligations with existing GDPR and NIS2 work rather than running a third isolated programme. AI training data falls under GDPR. Oversight of AI providers falls under NIS2 for essential entities. AI audit logs fit into DORA traceability for financial entities. A converged approach cuts the documentation to produce by 40 to 50 percent, according to Deloitte analyses of the first EU AI Act compliance programmes in Europe.

They invest in training the human operators, not only in writing procedures. Substantive oversight under Article 14 requires operators to understand concretely what the system does, how it can be wrong, and when their intervention is needed. Half a day of targeted training per operator category, with exercises on real failure scenarios, produces more robust oversight than ten pages of documentation nobody reads.

Where to start now

If your organisation has not yet formalised its EU AI Act scope, this sequence delivers the most value in the first 30 days.

Start with a fast inventory, three questions per production AI system. Does this system take or assist decisions that directly affect rights or opportunities for individuals? Does it process biometric, health or otherwise sensitive data under GDPR? Is it used in critical infrastructure, financial services, employment or essential public services? Three consecutive yes answers signal a probable high-risk system.

Then ask your providers for their EU AI Act technical documentation. Compliant providers must be able to supply it on request. No answer within a reasonable time is itself a provider risk signal to record in your third-party register.

Presidio includes an EU AI Act classification module to map your AI portfolio, collect provider documentation, and generate the compliance register the regulation requires. See Presidio →

Conclusion

The EU AI Act does not wait. National authorities have announced first checks for the fourth quarter of 2026, and penalties for non-compliant deployers are significant. Beyond regulatory compliance, the delay across most organisations reveals a deeper problem: AI entered the organisation through purchasing and projects, and never passed through governance. The regulation is the occasion, and now the obligation, to correct that. Organisations that start now are not only building defensive compliance. They are building AI governance that will let them deploy new systems faster, with controlled risk.

In your current AI portfolio, how many systems have never been through a classification assessment?

A project? A question?

Contact us →