CODY KELLER

August 2 is five days from when this publishes. That’s the date the EU AI Act’s major provisions — including the full requirements for high-risk AI systems — become applicable. If you’ve been tracking it as an upcoming deadline, it’s no longer upcoming.

We covered the strategic overview in April. This post is for the organizations that haven’t finished — or haven’t started — and need to understand what to do in the next week and what comes after.

What Actually Changes August 2

The EU AI Act has been rolling into effect in phases since it entered into force in August 2024. The August 2, 2026 date is the most significant milestone yet — it’s when the full requirements for high-risk AI systems apply to organizations that deploy or use them.

High-risk AI systems under the Act include systems used in employment screening and HR decisions, credit scoring and financial services, educational assessment, essential private and public services, law enforcement, border control, and administration of justice. If your organization uses AI in any of these contexts and serves EU residents, you are in scope — regardless of where your servers are located or where your company is headquartered.

The penalties for non-compliance with high-risk AI system requirements reach up to 30 million euros or 6% of global annual turnover, whichever is higher.

What You Can Still Do This Week

Realistically, organizations that haven’t completed their AI compliance work cannot become fully compliant in five days. What they can do is make a defensible start and document it.

Regulators, in the early phases of enforcement, look for evidence of good-faith compliance effort. An organization that has conducted an AI system inventory, begun risk classification, assigned ownership, and documented a remediation roadmap is in a materially better position than one that has done nothing — even if both are technically non-compliant on August 2.

This week’s priority list:

First, complete or finalize your AI system inventory. Every AI tool in use across the organization needs to be documented — not just what IT deployed, but what business units are using, what’s embedded in SaaS tools, and what vendor-provided AI is operating in your environment. If you haven’t done this, start today. An incomplete inventory is better than no inventory.

Second, run a prohibited practices check. The EU AI Act banned certain AI practices effective February 2025. Subliminal manipulation, social scoring, and certain biometric identification uses have been prohibited for over a year. If any of your AI systems fall into these categories, that exposure predates August 2 and needs to be addressed immediately regardless of your broader readiness.

Third, identify your high-risk systems. From your inventory, flag any systems that fall into the high-risk categories. These are the systems that require conformity assessments, technical documentation, human oversight mechanisms, and registration in the EU database.

Fourth, assign ownership. Someone needs to own EU AI Act compliance with authority to coordinate across legal, IT, and business units. If that ownership isn’t assigned, assign it today.

Fifth, document your current state and your remediation roadmap. When a regulator asks what you’ve done, your answer needs to be supported by documentation. A written inventory, a risk classification in progress, and a roadmap with milestones is a defensible compliance posture. Nothing on paper is not.

What Happens After August 2

Enforcement won’t immediately produce a wave of enforcement actions on August 3. Regulators are building their enforcement infrastructure and will initially focus on the most visible violations — particularly prohibited practices and high-risk systems in sensitive sectors like healthcare, finance, and employment.

The organizations most likely to be in early enforcement actions are those that have no compliance program at all and those operating AI systems in high-risk categories without the required technical documentation or human oversight mechanisms.

The organizations that will be positioned well in 12 months are the ones that complete their inventory and risk classification now, build their compliance program through Q3 and Q4, and treat August 2 as a start date rather than a finish line.

If You’re Already in Good Shape

If your organization has completed its AI system inventory, classified your systems against the four-tier framework, addressed prohibited practices, and has a technical documentation process underway for high-risk systems — you’re where you need to be. Your next priority is registering applicable high-risk systems in the EU database once registration requirements are operationalized, and maintaining ongoing compliance monitoring as the European Commission publishes implementation guidance throughout the rest of 2026.

The EU AI Act isn’t a compliance event. It’s a compliance program. The difference matters for how you resource it and how you maintain it as the regulatory guidance continues to develop.

Five days. Make them count.


Discussion Questions

  1. Has your organization completed an AI system inventory? If not, what’s the current state and what’s blocking completion?
  2. Have you conducted a prohibited practices check against your AI systems? Given that those provisions have been in effect since February 2025, has your organization assessed exposure retroactively?
  3. Who owns EU AI Act compliance in your organization? Is that ownership formal and documented, or informal and assumed?

Further Reading


Leave a Reply

Your email address will not be published. Required fields are marked *