code4thought

The EU AI Act Keeps Moving: Is Your AI Governance Keeping Pace?

The EU AI Act has entered another important phase

02/09/2026
2 MIN READ  /
As of 2 August 2026, the transparency obligations under Article 50 apply, introducing specific requirements for certain AI systems and AI-generated or manipulated content.
In practice, this means organizations need to pay closer attention to how AI is presented and disclosed. Among other requirements:
  • people must be informed when they are directly interacting with certain AI systems, unless this is already obvious
  • providers of generative AI systems must enable AI-generated or manipulated content to be identified through machine-readable marking
  • deepfakes must be clearly disclosed and
  • AI-generated or manipulated text published to inform the public on matters of public interest must be labelled in certain circumstances.
The European Commission has published detailed guidelines clarifying how these requirements apply, including the respective responsibilities of AI providers and deployers, relevant exceptions and how compliance can be demonstrated.
For organizations using AI, this is another reminder that the Act is moving steadily from regulation to implementation and enforcement.
And transparency is only one part of the picture.
The EU AI Act introduces different obligations depending on the type of AI system, its role and its level of risk. As further provisions become applicable, organizations will increasingly need to understand not only where AI is being used, but what requirements apply and whether they can demonstrate that those requirements are being met.
What comes next?
The next major phase will bring high-risk AI systems much more firmly into focus.
From 2 December 2027, requirements for high-risk AI systems under Annex III will apply. These include AI systems used in areas such as employment and recruitment, education, access to essential services, biometrics, critical infrastructure, and migration and border control.
For providers and deployers of these systems, the requirements go considerably beyond transparency. They address areas including risk management, data governance, documentation and traceability, human oversight, accuracy, robustness and cybersecurity.
A further milestone follows on 2 August 2028, when the relevant high-risk requirements will apply to AI systems embedded in regulated products covered by Annex I.
There are also nearer-term transition points. For example, providers of certain synthetic-content systems already on the market before August 2026 have until 2 December 2026 to meet the relevant machine-readable marking requirements, while providers of general-purpose AI models placed on the market before August 2025 have until 2 August 2027 to comply with the applicable GPAI obligations.
The direction is clear: AI governance is becoming increasingly operational and increasingly connected to how AI systems actually perform and behave.
December 2027 may sound far away. Is it?
For organizations developing or deploying high-risk AI systems, the work required to achieve readiness can be substantial.
It starts with understanding which AI systems are in use, how they are classified and what role the organization has under the Act. From there, organizations need to assess existing governance and technical controls, identify gaps, implement remediation measures, establish the required processes and documentation, and generate evidence that their systems meet the applicable requirements.
Some of these activities—particularly technical testing, data governance, risk management, human oversight and ongoing monitoring—cannot realistically be treated as last-minute compliance exercises. They may require changes to the AI system itself, the processes around it and the way responsibilities are distributed across the organization.
So, while December 2027 may appear some distance away, a more useful question is:
How much of the work required to demonstrate readiness could your organization complete today?
What should organizations be doing now?
Know your AI landscape.
Build visibility over the AI systems, models and applications being developed, purchased or deployed across the organization—and understand how they are classified under the EU AI Act.
Assess regulatory and technical readiness.
Compliance is not only about policies and documentation. Depending on the system and applicable requirements, organizations need to consider how their AI performs in practice—including areas such as performance, fairness, transparency and robustness.
Identify gaps before they become compliance issues.
Assess existing systems and processes, prioritize risks and establish clear remediation actions rather than waiting for the next regulatory milestone.
Build for continuous assurance.
AI systems, their use and the regulatory environment evolve. Governance therefore needs mechanisms for ongoing monitoring, evaluation and auditing—not simply a one-off compliance exercise.
From compliance requirements to AI assurance
At code4thought, we approach EU AI Act readiness as both a regulatory and technical challenge.
Our EU AI Act Assurance service combines AI inventory mapping, regulatory compliance assessment, technical assessment and testing, risk assessment and mitigation, documentation support and continuous monitoring. Our proprietary iQ4AI platform adds the technical testing and recurring audit capabilities needed to evaluate AI systems beyond policies and documentation.
The objective is not simply to prepare for the next deadline. It is to establish the governance, evidence and technical assurance needed to deploy AI responsibly and with confidence as the regulatory framework continues to take effect.