Executive Answer
On August 2, 2026, the EU AI Act begins enforcing high-risk AI obligations with fines up to 35M EUR or 7% of global revenue. A 2026 industry survey found that 78% of organizations have no AI inventory, no compliance owner, and no documentation in place. The eight Annex III high-risk categories - covering employment tools, credit scoring, biometrics, and critical infrastructure - are broader than most organizations assume. CISOs who build the five-step foundation (inventory, classification, named accountability, honest gap documentation, board briefing) before the deadline will face any regulatory interaction from a defensible position.
- August 2, 2026 - EU AI Act high-risk AI system obligations become enforceable (Regulation EU 2024/1689, Articles 9-15 and Annex III).
- 78% of organizations have not taken meaningful steps toward EU AI Act compliance - no AI inventory, no compliance owner, no documentation (clearact.net industry survey, 2026).
- 35M EUR or 7% of global annual turnover - maximum penalty for deploying a prohibited AI system (Article 5, EU AI Act).
- 15M EUR or 3% of global annual turnover - penalty for failing to meet high-risk AI system obligations, including risk management and oversight requirements.
- 8 categories of high-risk AI defined in Annex III - including employment tools, credit scoring, biometrics, critical infrastructure, and access to essential services.
On August 2, 2026, the EU AI Act starts enforcing high-risk AI obligations with fines up to 35M EUR or 7% of global revenue. According to a 2026 industry survey, 78% of organizations have no AI inventory, no compliance owner, and no documentation in place. CISOs have a narrow window to build the five-step compliance foundation that will separate organizations ready for regulatory scrutiny from those that are not.
August 2 is 18 days away. On that date, the EU AI Act begins enforcing its most consequential obligations: the rules governing high-risk AI systems. Fines reach 35 million EUR or 7% of global annual turnover for the most serious violations. A 2026 industry survey found that 78% of organizations have taken no meaningful steps toward compliance.
Most CISOs I speak with know the date. Fewer know which of their AI systems qualify as high-risk. And fewer still have a documented compliance program that would survive a regulatory audit. That gap is the problem this article addresses.
What follows is a practical action plan for CISOs who need to close the gap before August 2, and for those who need to explain the situation clearly to their board.
What the EU AI Act Actually Covers
The EU AI Act (Regulation EU 2024/1689) has been in force since August 2024. The first enforcement milestone came in February 2025, when prohibitions on the most dangerous AI applications took effect - things like social scoring systems, real-time remote biometric surveillance in public spaces, and AI that exploits psychological vulnerabilities.
August 2, 2026 is the second and larger milestone. It activates obligations for high-risk AI systems under Chapters III and IV of the regulation. These are not fringe use cases. High-risk AI under Annex III includes:
- Biometric identification and categorization systems
- AI managing critical infrastructure - energy grids, water systems, transport networks
- AI used in education and vocational training decisions
- Employment and worker management tools - including CV screening and candidate ranking
- Essential private and public services - credit scoring, insurance pricing, access to financial products
- Law enforcement applications
- Migration, asylum, and border control systems
- Administration of justice
The scope surprises most organizations when they run a proper inventory. An ATS (Applicant Tracking System) that uses AI to rank candidates is likely high-risk. A credit scoring model is high-risk. A tool that determines whether a customer qualifies for a loan or insurance product is high-risk. Many organizations are running these systems without realizing the regulation applies to them.
What "High-Risk AI" Compliance Actually Requires
Articles 9 through 15 of the EU AI Act spell out the obligations for high-risk AI systems. For deployers - meaning organizations using these systems in their operations, not just building them - the core requirements are:
Risk management system (Article 9). A documented process for identifying, analyzing, and addressing risks associated with each high-risk AI system. This must be maintained and updated throughout the system's lifecycle, not just at the point of deployment.
Data governance (Article 10). For providers developing high-risk AI, training data must meet quality criteria. For deployers using vendor systems, you need to understand and document the data practices of the systems you deploy.
Technical documentation (Article 11). Documentation describing the system's intended purpose, capabilities, limitations, and performance must be maintained and available to authorities on request.
Transparency and information provision (Article 13). High-risk AI systems must be designed to allow deployers to interpret outputs and enable appropriate human oversight. The system's limitations and the conditions under which it may fail must be documented.
Human oversight (Article 14). Deployers must assign qualified individuals to oversee the system, with the authority and capability to intervene or override outputs. This is not a generic "AI ethics officer" requirement. It means a named person with specific responsibility for each system.
Fundamental rights impact assessment (Article 27). Deployers in the public sector, and private deployers in specific sectors, must complete a fundamental rights impact assessment before deploying a high-risk AI system.
None of these requirements can be satisfied by pointing at an AI ethics policy. They require documented processes, named individuals, and evidence of ongoing operation.
The 5-Step CISO Action Plan
With 18 days remaining before August 2, the window for a comprehensive compliance program is closed. What is still achievable is building the foundation that demonstrates good-faith compliance efforts and creates a defensible position for post-August regulatory interaction. Here is what to prioritize.
Step 1: Build the AI inventory. Before any classification or compliance work, you need to know what AI systems your organization is running. This includes internal builds, vendor software that includes AI features, SaaS platforms with embedded AI, and AI tools purchased by individual business units without central IT involvement. Shadow AI is common. Most organizations discover deployments during this exercise that leadership did not know about. The inventory needs to capture: system name, vendor, intended purpose, who owns it, what data it processes, and who makes decisions based on its outputs.
Step 2: Classify against Annex III. For each system in the inventory, run the Annex III classification. Does it touch biometrics? Employment decisions? Credit or insurance pricing? Critical infrastructure? The classification determines which systems require full high-risk compliance and which do not. Many organizations find they have three to eight high-risk AI systems when they run this exercise honestly.
Step 3: Assign named accountability. For each high-risk system, a specific person must be named as responsible for human oversight. This is not a committee or a department. The regulation contemplates an individual who has the authority and capability to intervene in the system's operation when needed. This is the step most organizations skip. A policy document without named individuals is not compliance.
Step 4: Document what you have, honestly. For each high-risk system, document the current state against Articles 9-15 requirements. Where documentation exists, consolidate it. Where it does not, note the gap. Regulators making enforcement decisions after August 2 will look at whether an organization had a genuine compliance program underway versus no effort at all. An honest gap analysis with a remediation timeline is a significantly stronger position than no documentation.
Step 5: Brief the board. The EU AI Act places legal accountability on the organization. That means the board needs to know: which high-risk AI systems the organization operates, what the compliance status is, what the open risks are, and who is responsible. This briefing should become a quarterly agenda item alongside cyber risk reporting.
What 78% of Organizations Are Missing
The clearact.net industry survey finding - 78% of organizations have taken no meaningful steps toward compliance - points to three specific gaps that appear consistently.
The first is the inventory gap. Organizations simply do not know what AI systems they are running. This is partly a Shadow AI problem: business units deploy AI tools without involving IT or legal. It is also partly a vendor problem: AI features arrive inside existing software products through updates, without explicit procurement decisions. The inventory does not exist, so nothing else can be built on top of it.
The second is the accountability gap. Even organizations that have governance policies in place typically cannot name who is responsible for each high-risk AI system's compliance. The policy names a department or committee. The EU AI Act requires a person. That distinction becomes critical when something goes wrong.
The third is the documentation gap. Risk management systems, fundamental rights impact assessments, technical documentation - these are not retrospective exercises. They need to be in place before the system operates. Organizations that deploy an AI system and document it afterward are not compliant; they are creating records after the fact.
The Brussels Effect: Why Non-EU Companies Are Also Affected
The EU AI Act has extraterritorial reach that mirrors the GDPR approach. If your AI system is placed on the EU market, used by EU-based deployers, or affects people located in the EU, the Act applies regardless of where your organization is headquartered.
For US and Israeli companies operating in Europe, this means the August 2 deadline is not a European internal matter. A US-based HR software vendor whose product is used by European companies to screen job applicants is providing a high-risk AI system under the EU AI Act. The vendor's obligation is to ensure the system meets Articles 9-15 requirements. The deployer's obligation is to ensure the vendor has done so.
The Brussels Effect - the documented tendency for EU regulations to become de facto global standards as multinational companies adopt a single highest-standard approach - is already operating here. Large enterprises with global operations are building EU AI Act compliance into their AI governance programs globally, because maintaining separate compliance postures by jurisdiction is operationally expensive.
After August 2: What Enforcement Looks Like
National supervisory authorities in each EU member state are responsible for enforcing the AI Act within their jurisdiction. Member states were required to designate their authorities by August 2025. Enforcement will initially focus on providers and deployers of high-risk AI systems in regulated sectors, where supervisory infrastructure already exists - financial services, healthcare, critical infrastructure.
Enforcement under new regulations typically begins with investigations triggered by incidents or complaints rather than proactive audits of every organization. The practical implication: the risk is highest for organizations that deploy high-risk AI systems and face a harm, complaint, or incident that draws regulatory attention. At that point, the question becomes whether you can demonstrate a functioning compliance program - not whether you filed a policy document.
For CISOs, this means the goal of the next 18 days is not perfect compliance. It is building enough of the foundation - the inventory, the classification, the named accountability, the documented gap analysis - that you can make a credible case for good-faith compliance efforts if enforcement attention comes your way.
I have been through enough regulatory deadlines to know that the organizations in the most trouble are not the ones with gaps - every organization has gaps. The ones in trouble are the organizations that cannot show they tried. An AI inventory completed in the next two weeks, a classification exercise that names three high-risk systems, and a board briefing on August 1 puts you in a fundamentally different position than a filed policy nobody has read. Start with the inventory. Everything else follows from it.
Related Expertise
Sources & Further Reading
- EU AI Act - Regulation (EU) 2024/1689 - Full text, Annex III high-risk categories, Articles 9-15 and 27
- NIST AI Risk Management Framework (AI RMF 1.0) - AI governance and risk management guidance
- European Commission - AI Act Regulatory Framework - Official implementation timeline and enforcement guidance
- ENISA - Artificial Intelligence Cybersecurity Challenges - EU agency analysis of AI security risks
- ISO/IEC 42001 - AI Management System Standard - International standard for AI governance programs
Related Articles
AI Governance Without Board Accountability Is Just a Document
Why most AI governance policies will not hold up under EU AI Act scrutiny, and what board-level accountability actually looks like.
Insider ThreatShadow AI: The Insider Threat Your Security Stack Can't See
Employees are pasting sensitive data into unapproved AI tools every day. This is also a EU AI Act inventory problem.
Frequently Asked Questions
What happens on August 2, 2026 under the EU AI Act?
High-risk AI system obligations under Articles 9-15 of the EU AI Act become enforceable. Organizations deploying AI in employment, financial services, biometrics, critical infrastructure, and other Annex III categories must have risk management systems, human oversight, fundamental rights impact assessments, and documentation in place.
What are the eight categories of high-risk AI under the EU AI Act?
Annex III covers: biometric identification, critical infrastructure management, education and training decisions, employment and worker management, essential private and public services (credit, insurance), law enforcement, migration and border control, and administration of justice. AI tools that rank job candidates or score creditworthiness commonly qualify.
What are the EU AI Act fines for non-compliance?
Prohibited AI system violations: up to 35 million EUR or 7% of global annual turnover. Failing high-risk AI obligations: up to 15 million EUR or 3% of turnover. For large multinationals, percentage-of-turnover calculations substantially exceed the fixed caps.
Does the EU AI Act apply to non-EU companies?
Yes. The EU AI Act applies to any organization placing AI systems on the EU market or affecting people in the EU, regardless of where the organization is headquartered. The extraterritorial scope mirrors the GDPR approach. US and Israeli companies operating in Europe or serving European customers are in scope.
What should a CISO do first before August 2, 2026?
Start with the AI inventory - list every AI system in use across the organization, including vendor software features and SaaS tools. From the inventory, classify which systems are high-risk under Annex III. Assign a named person responsible for each high-risk system's oversight. Document the current state honestly, including gaps. Brief the board on scope and status before the deadline.
Need help getting EU AI Act-ready before August 2?
I help organizations build AI compliance programs that hold up under regulatory scrutiny - inventory, classification, accountability structures, and board reporting. With 18 days to the deadline, the time to start is now.
Let's Talk