Loading AI insights...
Ten weeks to August 2, 2026. What your enterprise is not doing — and what it must.
What the EU AI Act requires, when it applies, and who it applies to.
The question your board must answer before August 2.
If your organisation uses AI in hiring, performance management, credit decisions, insurance underwriting, or benefits assessment — you are almost certainly a high-risk AI deployer under Annex III.
The compliance question is not whether your vendor is compliant. It is whether your organisation has: inventoried its AI systems against Annex III, assigned qualified human oversight, established logging and incident reporting, and documented the conformity basis for each in-scope system.
Unanswered question: which function owns this, with what authority — and have they started?
Build compliance iteratively post-deadline. Bet on enforcement focus on egregious cases in 2026. Requires a credible documented programme.
Operational hold pending classification review. Eliminates new risk accumulation; disrupts embedded AI workflows.
Cross-functional inventory now. Prioritise employment and credit AI. Build documentation, oversight, and incident reporting before August 2.
Use Annex III as the single global framework. Higher upfront cost; avoids dual-framework overhead as UK, US state laws follow.
The highest-risk AI tools are likely ones IT does not know about — HR, finance, and sales SaaS adopted without procurement or legal review. The inventory must reach every function.
A vendor's EU AI Act documentation does not satisfy your organisation's independent obligations. Human oversight, logging, and incident reporting must be yours.
Most enterprises cannot currently detect an AI-specific serious incident, determine reportability, and notify the national supervisory authority in 72 hours. This requires a dedicated workflow.
German, French, and Dutch supervisory authorities have signalled that recruitment and performance AI is an early enforcement target. If you use AI in hiring or performance management, you are in the first wave.
One enterprise AI deployment, dissected every Tuesday. Written for executives who have to decide, not just read.