August 2, 2026

EU AI Act 2026: The Complete Guide to Deadlines and Implementation for Businesses

Gernot Lepuschitz

By Gernot Lepuschitz

Chief Technology Officer

EU AI Act 2026: Der komplette Fristen- und Umsetzungs-Leitfaden für Unternehmen

38 min read

Share this post

After reading this guide, you’ll know: which requirements of the EU AI Act take effect and when, what changes the Digital Omnibus introduced in the summer of 2026, and what specific steps you need to take to build an audit-ready data foundation by the August 2026 deadline. This is not a legal opinion, but a practical roadmap—for professionals in compliance, finance, and IT security.

Key Points

  • The EU AI Act (Regulation (EU) 2024/1689) has been in effect since August 1, 2024, and is being phased in gradually. August 2026 is the next key milestone.

  • The Digital Omnibus on AI was signed on July 8, 2026, and postpones the obligations for high-risk systems: Annex III to December 2, 2027, and Annex I to August 2, 2028.

  • Starting August 2, 2026, the transparency obligations under Article 50 will apply unchanged—labeling of AI-generated content, deepfake disclosures, and chatbot disclosures. This deadline has not been postponed.

  • Starting December 2, 2026, new prohibitions (Art. 5) will take effect, as well as the labeling requirement for generated content, including for existing systems.

  • The fines remain as high as before: up to €35 million or 7% of global annual revenue for prohibited practices, and up to €15 million or 3% for violations of high-risk obligations.

  • In Germany, the Federal Network Agency coordinates oversight; in Austria, the Federal Chancellery does so in collaboration with RTR’s AI Service Center.

  • The real bottleneck is rarely the AI itself, but rather the data foundation: Article 10 requires verifiable data quality and data governance—precisely what cannot be established in a matter of weeks.

What is the EU AI Act? (As of August 2026)

The EU AI Act is the world’s first comprehensive law regulating artificial intelligence.

As Regulation (EU) 2024/1689, it has been directly applicable in all member states since August 1, 2024—without the need for national implementing legislation. It classifies AI systems according to risk and assigns tiered obligations accordingly. For companies in the DACH region, this means that any entity offering or operating AI in the EU is subject to the regulation, regardless of where it is headquartered (European Commission).

The framework follows four risk levels. Prohibited practices (such as social scoring) are banned. High-risk systems—for example, in personnel selection, lending, education, or critical infrastructure—are subject to the strictest requirements. Systems posing a transparency risk (chatbots, deepfakes) must disclose that a machine is involved. The vast majority of systems are considered low-risk and remain largely unregulated.

Important for understanding the effective date: The original plan set August 2, 2026, as the date on which nearly all core obligations—including those for high-risk systems—would take effect. This plan was amended by the Digital Omnibus on AI. The structure of the law remains intact; only specific implementation dates were postponed, not the substance of the law.

The Four Risk Categories in Detail

The entire logic of the AI Act hinges on risk classification. The obligations that apply to a company are determined not by the technology itself, but by its intended use. The same language model can pose a low risk when it pre-formulates emails, and a high risk when it helps make decisions on loan applications. That is why every implementation begins with classification.

Unacceptable Risk

Systems deemed a threat to fundamental rights are simply prohibited—such as social scoring by government agencies or manipulative systems that exploit the behavior of vulnerable groups. These practices have been banned since February 2, 2025; starting in December 2026, bans will also apply to the generation of non-consensual intimate images and depictions of abuse.

High Risk

This is the core of the regulation. A system is considered high-risk if it is used in one of the sensitive areas listed in Annex III—hiring, lending, education, critical infrastructure, law enforcement, migration—or if it is embedded as a safety component in a regulated product listed in Annex I. These systems are subject to the full set of obligations: risk management, data governance, technical documentation, human oversight, and conformity assessment.

Transparency Risk

Systems that interact with people or generate content must disclose that a machine is at work. This applies to chatbots, emotion recognition, and generative AI. These obligations take effect on August 2, 2026—which is why this date is so significant for the vast majority of companies.

Low Risk

The vast majority of all AI applications fall into this category—from spam filters to recommendation algorithms that do not involve personal data. The AI Act does not impose any specific obligations on these applications. Voluntary codes of conduct are possible but not required.

Risk Class

Examples

Basic Obligation

Unacceptable Risk (Prohibited)

Social scoring, manipulative systems, untargeted facial recognition, and—as of December 2026—NCII/CSAM generators

Prohibited. These systems may not be placed on the market or operated.

High Risk

Personnel selection, creditworthiness checks, education, critical infrastructure, law enforcement, migration (Annex III)

Risk management, data governance (Art. 10), documentation, human oversight, conformity assessment.

Transparency Risk

Chatbots, emotion recognition, deepfakes, generative AI

Disclosure and labeling requirements under Art. 50.

Low risk

Spam filters, AI in video games, recommendation algorithms that do not involve personal data

No specific obligations; voluntary codes of conduct are possible.

Source: Regulation (EU) 2024/1689; RTR – AI Service Center. As of July 2026.

For high-risk systems, the additional question arises as to who verifies compliance. For most use cases listed in Annex III, an internal conformity assessment conducted by the provider itself—documented and bearing the CE marking—is sufficient. For certain sensitive categories—such as remote biometric identification—as well as for systems embedded in products as defined in Annex I, however, the involvement of a notified body is mandatory, similar to the testing body for medical devices. This difference significantly impacts the lead time: An external assessment requires weeks to months of preparation time, which must be factored into project planning.

Who Does the EU AI Act Apply To? Providers, Operators, and the Long Arm of the EU

Two roles determine the scope of obligations. Providers develop an AI system or place it on the market under their own name; they bear the main burden—from conformity assessment to technical documentation. Operators use a commercially available system in a professional context; their obligations are more limited but still real—such as human oversight, intended use, and transparency toward data subjects.

The distinction is deceptive. Anyone who substantially modifies a purchased system, offers it under their own name, or uses it for a purpose other than the intended one can shift from the role of operator to that of provider—with significantly higher requirements. This happens more quickly than many companies realize, especially when fine-tuning language models. Clearly defining one’s own role is therefore not a mere formality, but the starting point for any effort estimation.

And the scope does not end at the EU border. The AI Act applies extraterritorially: It covers any company whose AI system is offered or used in the EU, or whose results are used in the EU—regardless of where the company is headquartered. A Swiss provider serving the DACH market, a U.S. corporation with European users: Both fall under the regulation. For the export-oriented DACH economy, this is the key takeaway—market access means compliance with regulations.

Providers of general-purpose AI (GPAI) base models—such as large language models on which other applications are built—constitute a separate category. As of August 2, 2025, these providers are subject to specific obligations: technical documentation, a summary of training data, copyright compliance, and—for models posing systemic risk—additional risk assessments and reporting requirements. For most companies in the DACH region, this is relevant indirectly: They are rarely GPAI providers themselves, but should actively request the relevant documentation from their model suppliers before deploying a model in a high-risk context.

How Today’s Timeline Came About: From Entry into Force to the Digital Omnibus

To properly contextualize the August 2026 deadline, it helps to look at how the regulation came about. The regulation entered into force on August 1, 2024, with a phased timeline: The bans and the AI competence requirement came first (February 2025), followed by the obligations for foundation models and the governance structure (August 2025). August 2, 2026, was intended to be the major deadline when nearly all remaining obligations—including those related to high-risk use cases—would take effect.

This plan came under pressure because the technical standards and guidelines that companies were supposed to follow had not yet been finalized. The European Commission therefore presented the Digital Omnibus on AI—a streamlining package—on November 19, 2025. Following a political agreement in May 2026, the European Parliament adopted the text on June 16, 2026; the Council gave the green light on June 29, 2026; and the agreement was signed on July 8, 2026.

The result is the timeline that applies today: The high-risk obligations are postponed to December 2027 and August 2028, while the transparency obligations remain set for August 2026. Important for practical purposes: The postponed dates will not become legally binding until publication in the Official Journal, which is expected in July 2026. Until then, the original deadline remains the formally applicable benchmark—a detail that matters most for companies that prematurely halted their programs.

The Digital Omnibus not only postpones deadlines but also simplifies the requirements. For smaller providers, the package provides for streamlined documentation templates. The conformity assessment for certain high-risk cases will be streamlined, and a more centralized point of contact at the EU level will be established to facilitate the previously fragmented coordination between national authorities. For companies, this means that the effort required per piece of evidence tends to decrease, but the substance of the obligation to provide evidence itself remains in place.

What the EU AI Act Means for the CCO, CFO, and CISO

The AI Act is not purely a legal or IT issue. It affects three leadership roles simultaneously—each with a different set of considerations. Whoever coordinates implementation should bring these three perspectives together early on, as they all draw on the same data.

For the Chief Compliance Officer: Demonstrability Over Intent

The CCO is responsible for ensuring that obligations are fulfilled and—crucially—can be demonstrated. The AI Act rewards documentation, not good intentions. An inventory of all AI systems, their assignment to a risk class, proof of data quality in accordance with Article 10, and a complete audit trail are the building blocks upon which an audit is based. The key question is: In the event of an audit, can we substantiate our claims? Without reliable master data, the answer is usually no.

In practical terms, this means that the compliance function must designate a data owner for each high-risk system early on—a specific individual who can answer questions during an audit, not a vague “IT department.” This clarity is still lacking in many organizations today.

For the Chief Financial Officer: Risk of Fines and Investment Logic

For the CFO, the AI Act initially represents a risk. Fines of up to 7% of global annual revenue are not a footnote but a factor that impacts the balance sheet. Added to this is the business side: according to Gartner, poor data quality costs an average of around $12.9 million per year—regardless of any regulations. Smart investment logic combines both: investing in a clean data foundation simultaneously reduces regulatory risk and operational costs. This is not a compliance expense, but an investment with a double return.

For budget planning, it is therefore worthwhile to anchor the data foundation not as a separate compliance item, but as part of the IT and data strategy. This allows the business case to be justified to the executive board not only through risk mitigation but also through efficiency gains in day-to-day operations.

For the Chief Information Security Officer: Data Integrity as a Security Issue

The CISO views the AI Act through the lens of integrity and control. Who is feeding what data into which model? Is the source verified? Is there “shadow AI” operating outside the governance framework? Data integrity here is not just a quality requirement, but a security requirement. Manipulated or uncontrolled input data can bring down a high-risk system. The AI Act thus formalizes what good information security requires anyway: control over the data flow from the source to the model.

A regular scan for unauthorized AI services—for example, via network or SaaS monitoring—therefore belongs in the same governance routine as traditional shadow IT detection. Both risks share the same root cause: a loss of control over data flows that no one has documented.

Why is the EU AI Act relevant in August 2026?

August 2026 is not a symbolic date, but the point at which the regulation will become practically noticeable for many companies for the first time. From then on, transparency obligations will take effect, and national supervisory authorities will gain their enforcement powers. For operators of chatbots or image generators, this is often their first direct encounter with the law. Four key figures show why this topic belongs on the agenda of CCOs, CFOs, and CISOs right now.

1. Preparation Is Lagging Behind Reality

The use of AI is exploding, but regulatory readiness is not keeping pace. According to Bitkom, 41% of German companies are now actively using AI—more than twice as many as in 2024 (17%)—and another 48% are planning to adopt it. At the same time, an earlier Bitkom survey found that only about a quarter of companies had even looked into the AI Act, and two-thirds said they needed help with implementation.

2. Basic obligations are being overlooked left and right

One example is the AI competency requirement (Art. 4), which has been in effect since February 2025. According to Bitkom’s 2026 study report “Artificial Intelligence in Germany,” 43% of companies have not yet offered any AI training at all. Starting in August 2026, authorities will be able to inspect precisely that—and “shadow AI,” such as the uncontrolled use of ChatGPT or Copilot, will become an obvious compliance risk.

3. Data quality is the silent cost driver

According to Gartner, poor-quality data costs companies an average of about $12.9 million per year—even before regulation comes into play. Under the AI Act, a business problem becomes a legal one: Article 10 makes data quality a verifiable requirement for high-risk systems.

4. AI projects fail because of the data, not the model

Gartner predicts that by 2026, organizations will abandon about 60% of their AI projects because they lack AI-ready data. At the same time, according to Gartner, around 80% of data and analytics governance initiatives will fail by 2027. Both figures point to the same root cause: The problem isn’t the algorithm, but the foundation on which it stands.

5. AI use has long been the norm—but governance usually isn’t

According to McKinsey’s “The State of AI,” 88% of organizations now use AI in at least one business function. The gap is clear: AI adoption is mainstream, but a corresponding data governance foundation to support it is the exception. It is precisely in this gap that regulatory risk arises—not through malicious intent, but through organic growth without accompanying structure.

Taken together, these five metrics paint a clear picture: AI adoption is growing faster than governance maturity, the costs of poor-quality data are real and high, and the August 2026 deadline will find a business landscape that, on average, is not yet ready. This is no cause for panic—but it is a clear call to action.

The Four Root Causes: Why Companies Are Still Unprepared Despite the Extension

The Digital Omnibus has given companies additional time. However, anyone who wants to make the most of this time must first understand why compliance programs fail in practice. From a CTO’s perspective, there are four structural causes—and none of them can be solved with yet another tool.

Cause 1: Fragmented Master Data Without a Single Source of Truth

In most companies, the same customer, supplier, or employee data is stored across a dozen systems—in CRM, ERP, HR software, and siloed Excel spreadsheets that have grown over time. There is no single truth, but rather twelve conflicting versions. An AI system trained or operated on this foundation simply cannot meet the requirement outlined in Article 10—relevant, representative, low-error data. Not because the model is weak, but because the input data is.

The result is twofold damage. From a regulatory standpoint, the system fails to demonstrate data quality; from an operational standpoint, the system makes decisions based on contradictory data. Both issues share the same root cause and the same solution—consolidation into a single source of truth. No additional model or tool can close this gap as long as the data foundation remains fragmented.

Cause 2: Lack of Data Lineage and Traceability

The AI Act requires not only good data, but also proof of it. Where does a dataset come from? Who modified it and when? What bias checks were performed? Without end-to-end data lineage and an audit trail, these questions cannot be answered. “We have a data warehouse” is not a valid response to Article 10—a warehouse aggregates data; it does not document its lineage. It is precisely this gap that stands out first during an audit.

The practical difference between aggregation and provenance documentation often only becomes clear in a crisis: A warehouse can show what value a dataset has today, but not why it has that value, who last modified it, or what the source data was. It is precisely this chain that Article 10 requires—and it is precisely this chain that is missing in most system landscapes that have evolved over time.

Reason 3: Governance as a Project Rather Than an Operational Model

Many organizations treat compliance as a one-time effort: a project, a report, a checkmark. However, the AI Act does not function as a snapshot. Article 10 requires that data analysis be repeated with every retraining; one-time compliance is not sufficient. Anyone who views governance as a completed project will already be out of compliance the day after the audit.

That’s why the “complete the project, check it off the list” mindset falls short. The AI Act requires a state of being, not a snapshot. In practice, this means that data stewardship must be embedded as a line-of-business responsibility, with clear roles and recurring review cycles. Governance is not a sprint, but an operating mode.

Cause 4: The “Tools Before Foundations” Mistake

The most costly and common mistake: Companies purchase expensive AI and compliance tools while their master data remains in disarray. This is like building a house on sand. No compliance dashboard can save a database that lacks reliable provenance, unique keys, and a golden record. First the foundation, then the tool—any other order results in costs without compliance.

In practice, this mistake often doesn’t become apparent until it’s too late: The new tool is up and running, the dashboards look impressive—until an audit asks about the underlying data sources and the sleek interface has nothing to offer. Retrospective consolidation of master data then costs twice as much: once for the unused tool, and once for the foundational work that was actually necessary.

Not an AI Problem, but a Data Governance Problem

At this point, it’s worth shifting our perspective, which will simplify the entire implementation process. The EU AI Act is usually discussed as an AI issue. In reality, it is largely a data governance issue. A language model provides probabilities; your master data provides facts. If the facts are incorrect, no model—no matter how good—will help—nor will any extension of the deadline, no matter how long.

A look at the text of the law confirms this. Article 10, paragraph 2, requires documented “data governance and data management practices” and specifically lists: design decisions, data collection and origin, data preparation (annotation, labeling, cleansing, updating, enrichment, aggregation), assumptions, suitability of the datasets, checks for bias, and measures to address it (Regulation (EU) 2024/1689, Art. 10). This is the language of master data management, not that of machine learning.

Paragraph 3 sets the quality standard: training, validation, and test data must be relevant, sufficiently representative, and—as far as possible—error-free and complete. These requirements are not met within the model itself, but in the data layer beneath it. Anyone who has a robust Golden Record has already completed the bulk of the work required under Article 10. Those who do not have one will need the entire deadline until December 2027—and that means the full time.

It’s worth taking a moment to review the eight areas listed in Article 10, paragraph 2—because each one is essentially a master data management discipline. Anyone familiar with them will understand why a data management tool is more effective here than a downstream compliance tool.

  • Design Decisions: The deliberate, documented choice of which data a system should use—not “whatever happened to be available.”

  • Data Collection and Origin: Where does each data record come from, and for what original purpose was it collected? The classic data lineage question.

  • Data preparation: Annotation, tagging, cleansing, updating, enrichment, aggregation—the core process of any master data management system.

  • Assumptions: What are the data actually supposed to measure and represent? These assumptions must be explicitly stated.

  • Suitability of the data sets: Have availability, volume, and fit for purpose been verified? A question of data quality, not the algorithm.

  • Bias assessment: Have potential biases been examined, particularly those that could lead to discrimination?

  • Bias mitigation: What measures have been taken and documented to reduce identified biases?

  • Gaps and shortcomings: What known weaknesses do the data exhibit—and how does the system handle them?

Seven of these eight points cannot be resolved within the model itself, but only in the underlying data layer. This is precisely where tools like the Goldright Agile Data Manager come into play: They create unique entities, documented provenance, and verified quality. What lawmakers call “data governance” is, in practice, the operating system of good master data management.

The strategic implication for C-level executives: The postponement is not a green light, but rather a window of opportunity to prepare. It extends the deadline precisely for the one task that cannot be completed in the short term—building a consistent, verifiable data foundation. Governance thus shifts from a cost factor to a competitive advantage: Those who get their foundation in order will not only be compliant but also AI-ready.

The Roadmap: Five Steps to a Audit-Ready Data Foundation

The following roadmap translates the deadlines into a practical sequence of steps. It is deliberately structured so that each step creates value on its own—even without regulation. The timeframes are based on the relevant deadlines.

Step 1: Take Stock of the AI and Data Landscape (by Q3 2026)

List every AI system in the company—including those used tacitly. Classify each system according to the AI Act risk class and assign high-risk candidates to the categories in Annex III. Document which data sources feed a system and who the provider or operator is. Without this inventory, any further action is like flying blind.

Specifically, this means maintaining a living list, not a one-time document. It should capture not only officially procured systems but also “shadow AI”—tools that have crept in via browser plugins or subscriptions without anyone’s approval. The most common mistake in this step is limiting the inventory to the IT department. Today, AI is found in marketing, sales, HR, and accounting. If you only ask IT, you’ll overlook half of it. In practice, a short, mandatory self-reporting form per department often yields more results than months of technical network scans.

Step 2: Establish the Golden Record—the Single Source of Truth

Consolidate the scattered versions of your master data into a single, verified Golden Record. This is the core: a central, consistent data record for each entity—customer, supplier, legal entity, employee—that both people and machines can rely on. Tools like Goldright’s Agile Data Manager are built precisely for this purpose: they create the semantic core that will later support every Article 10 audit.

This step is the most time-consuming—and the most valuable. It requires resolving duplicates, standardizing spellings, clarifying conflicting attributes, and assigning stable keys. The rewards extend far beyond compliance: A Golden Record improves reporting, sales, and every downstream analysis. That’s precisely why the investment is justified even without regulation—the AI Act merely makes it urgent.

Step 3: Establish Data Lineage and an Audit Trail

Ensure that every transformation—from raw data to a training-ready dataset—is logged: origin, timestamp, processor, and quality check. This audit trail is the currency with which you pay your regulatory obligations. It answers the questions raised in Articles 10, 12, and 17—documented origin, recording, technical documentation—without requiring your team to dig through archives in the event of an audit.

Step 4: Establish Governance as an Ongoing Operation

Establish data accountability as an ongoing operational responsibility, not as a project. Define roles (Data Owner, Data Steward), review cycles, and a maturity model against which to measure progress. Our data governance framework describes such an operational model based on a maturity model. The goal is a state in which compliance is a byproduct of normal operations—not the result of a special effort.

To provide a rough classification: At Level 1, individual departments manage their data in isolation, without common standards—the state in which most companies find themselves at the outset. Level 3 marks the point at which a golden record is established and data lineage is documented. Starting at Level 4, quality checks run automatically and are rule-based. Level 5 describes a self-learning governance system that proactively reports deviations before they become problems. For the Article 10 requirements, Level 3 is generally sufficient as a solid target for the first implementation phase.

Step 5: Implement transparency quick wins by August 2026

While laying the foundation, address the short-term obligations: label AI-generated content, identify chatbots as machines, and flag deepfakes (Art. 50). This can be done with manageable effort and delivers quick, visible compliance—while the underlying data work continues.

The order of these five steps is no coincidence. It follows the principle of “foundation before facade”: First, know what’s there (Step 1); then, organize the facts (Step 2); then, make them verifiable (Step 3); then, maintain the status quo (Step 4)—and, at the same time, tackle the tasks that can be accomplished quickly (Step 5). Anyone who reverses this order and starts by buying tools will produce reports on a mess they haven’t fixed. A realistic timeframe for reaching a robust state is twelve to twenty-four months—depending on the number and complexity of the systems involved.

You should be able to present this evidence in the event of an emergency

Regardless of how far along a company is in its roadmap, it’s worth conducting an honest assessment based on the documents that a market surveillance authority typically requests. If any of these are missing, that’s a concrete task, not an abstract concern.

  • AI system inventory with risk classification for each system and assignment to the provider or operator role.

  • Proof of data origin for all training, validation, and test data for high-risk systems (Art. 10).

  • Bias test report including date, methodology, and corrective actions taken.

  • Technical documentation in accordance with Annex IV, including system architecture and intended use.

  • Evidence of human oversight (Art. 14): Who can stop or override the system, and how is this logged?

  • Declaration of conformity and CE marking for high-risk systems in accordance with Annex III or I.

  • Training records demonstrating AI competence in accordance with Article 4 for all employees who work with AI systems.

This list is intentionally designed as a self-assessment, not as a comprehensive legal checklist. Anyone who cannot substantiate more than two of the seven points should prioritize Roadmap Steps 1 through 3 before addressing detailed issues.

How to Set Up Your Team for This

A program of this size rarely fails because of technology, but rather because of organizational issues. A small, cross-functional steering group has proven effective instead of a single person in charge: someone from compliance or legal who leads the regulatory interpretation; someone from IT or data management who is responsible for the golden record and technical implementation; and a sponsor from senior management who ensures priority and budget allocation. Without this third party, the program remains a specialized topic that regularly takes a back seat to more urgent matters in day-to-day operations.

The group does not need its own full-time team, but it does need a set rhythm—such as a monthly update on the status of the roadmap steps, measured against the milestones in the timeline table.

Is Your Data Foundation Ready for Article 10?


The roadmap shows the way—but where exactly does your company stand today? Our AI Data Foundation Check provides you with a clear assessment of your current master data maturity in just 15 minutes and identifies specific areas for action.

  • Assessment score for all data dimensions

  • Ready-to-use roadmap

  • 100% free

Best Practices: What Really Works in DACH

Experience bridges the gap between the letter of the law and its implementation. The following principles have proven effective for companies that view regulation not as a burden, but as an opportunity to streamline their operations. None of these points is new in and of itself—the impact comes from applying them consistently as a whole, rather than implementing individual measures in isolation.

Foundation Before Features

Invest first in clean master data, then in AI applications. Every euro spent on an AI tool built on poor-quality data will later multiply the effort required for corrections—conversely, a consolidated data foundation pays dividends for every future AI project, not just the current one.

Use the Time Saved, Don’t Wait

The postponement to 2027/28 creates real leeway—but a governance program needs all of this time. Anyone who doesn’t start until 2027 will be too late. Realistic programs allow for twelve to eighteen months to thoroughly consolidate master data.

Take Operator Responsibilities Seriously

Most DACH companies are operators, not providers. Actively request the EU declaration of conformity, technical documentation, and proof of notification from your AI suppliers—in writing, with a deadline. A supplier who cannot provide these documents is a risk in and of itself.

Automate compliance

Manual record-keeping does not scale. Rule-based data quality and an automated audit trail transform repetitive verification work into a background process that runs automatically with every retraining, rather than having to be reassembled from scratch for each audit.

Take a Consolidated Approach to Regulation

The AI Act isn’t the only one. The GDPR, NIS2/NISG, and CSRD all access the same database. A common foundation supports multiple regulatory frameworks simultaneously—that’s the real lever.

Establishing a Common Language Between Business Units and IT

Compliance, business units, and IT often fail to understand each other because they use different terms for the same entity. A standardized data glossary—defining what a “customer” is, what a “contract” is—is often the most underestimated yet most effective measure.

Communicate externally what has long been standard internally

Transparency requirements, such as AI labeling, are also a matter of trust with customers. Companies that communicate early and clearly where AI is being used report fewer inquiries and greater acceptance than those that only disclose this information upon request.

The common thread: Compliant companies are rarely those with the largest compliance budgets, but rather those with the cleanest data foundations. For them, governance is not an end in itself, but an enabler—the foundation upon which AI can be reliably deployed in the first place.

Fines, Liability, and Oversight: Consequences of Violations

The AI Act provides for a tiered system of sanctions based on the severity of the violation. For those responsible in the financial sector, the scale of the penalties is significant, as the upper limits are calculated based on global group revenue—not local earnings.

  • Up to €35 million or 7% of global annual revenue (whichever is higher) for violations of the prohibited practices under Article 5.

  • Up to €15 million or 3% for violations of most other obligations, including the high-risk requirements and data governance obligations under Article 10.

  • Up to €7.5 million or 1% for providing false, incomplete, or misleading information to authorities.

For small and medium-sized enterprises, the maximum amounts are capped on a pro-rata basis, so that the penalty does not exceed revenue to the point of threatening the company’s survival. This mitigates the absolute amount but does not change the principle: The burden of proof for compliance lies with the company, not with the regulatory authority. Anyone who cannot document that their data meets the requirements bears the risk.

In addition to the fine, there is civil liability. If a flawed high-risk system leads to damage—such as a discriminatory credit decision—claims for damages may arise. The chain of evidence then leads directly to the data set: Was it representative? Was it verified? Was its origin documented? A robust audit trail here provides not only compliance assurance but also protection against liability.

From the CFO’s perspective, a simple comparison is worthwhile: Consolidating master data in advance is a predictable, budgetable investment. A fine or a claim for damages after the fact is not—neither in terms of amount nor timing. Those who treat data quality as a forward-looking investment rather than a reactive emergency measure transform an incalculable risk into a calculable cost.

Who is in charge? Regulatory oversight in Germany and Austria

The AI Act leaves market surveillance to the member states, which need their own implementing laws for this purpose. In Germany, the AI Market Surveillance and Innovation Promotion Act (KI-MIG) governs this supervisory structure. The Bundestag passed the law on June 11, 2026; it is currently before the Bundesrat (as of July 2026). At its core is the Federal Network Agency, which serves as the central coordinating, market surveillance, and notifying authority. Within the agency, the Coordination and Competence Center for the AI Regulation (KoKIVO) is being established, featuring an AI service desk as the first point of contact and its own AI real-world laboratory. Sector-specific authorities will retain their respective responsibilities—such as BaFin in the financial sector, state media regulatory authorities regarding the labeling of media content, or the relevant specialized authorities for medical devices and machinery (Advisori; AI-MIG government draft).

In Austria, the Federal Chancellery coordinates efforts; the RTR’s AI Service Center serves as an information and advisory hub, while the Data Protection Authority is responsible for aspects related to fundamental rights, and sector-specific supervisory bodies (such as the FMA and KommAustria) also play a role. For DACH companies with locations in both countries, this means that the escalation chains differ; a program transferred from Germany does not apply one-to-one to Austria.

Another noteworthy detail concerns the timeline: As early as August 2, 2026, the European Commission itself will be able to take action against providers of AI foundation models posing systemic risk—in parallel with national oversight, which is still in the process of being established. Anyone operating as a GPAI provider or integrator will therefore be subject to a dual layer of oversight from the very beginning.

The EU AI Act within the Regulatory Framework: GDPR, NIS2, and CSRD

The AI Act does not exist in a vacuum. It is part of a dense network of European regulations, all of which draw on the same resource: corporate data. Addressing these regulations in isolation multiplies the effort required. Bringing them together on a common data foundation allows them to be managed with a single effort.

GDPR: The Overlapping Core

As soon as an AI system processes personal data, the AI Act and the GDPR apply in parallel. The AI Act does not replace the GDPR; it complements it. In practice, many of the requirements of Article 10 can be implemented through established GDPR mechanisms: purpose limitation, data minimization, access controls, and documentation. Those who have done their GDPR homework do not start from scratch with Article 10—provided that the underlying master data is consolidated.

NIS2 / NISG: Security as a Data Requirement

The NIS2 Directive—implemented in Austria as the NISG—requires affected companies to maintain a minimum level of cybersecurity and to comply with reporting obligations. The overlap with the AI Act lies in the integrity and traceability of data. An AI system is only as trustworthy as the data pipeline that feeds it. Access controls, logging, and proof of origin serve both regulatory frameworks simultaneously.

CSRD: Sustainability Data with Audit Requirements

The CSRD reporting requirement compels companies to disclose sustainability data of audit-ready quality. At its core, this is the same requirement as in Article 10, only applied to a different subject area: traceable origin, consistent definitions, and documented processing. Companies that have established robust data management for the CSRD already have the tools required by the AI Act.

The common denominator is always the same: consistent, verifiable data with a documented origin. A central “golden record” and a continuous audit trail form the infrastructure upon which the GDPR, AI Act, NIS2, and CSRD all rest. This is precisely what makes data governance a strategic lever: it is not a standalone measure for a single law, but rather the foundation for the entire regulatory framework.

This convergence is no coincidence but rather a deliberate policy choice: When designing national AI Act oversight, lawmakers themselves explicitly refer to existing structures from NIS2 and the DORA financial market regulations to avoid duplicate regulation. Companies that already comply with these regulations using a common data foundation have a structural advantage over those that treat each law as an isolated project.

EU AI Act 2026 at a Glance: Which Deadlines Apply When?

The following overview summarizes all relevant milestones—including the original dates and the dates currently in effect following the Digital Omnibus. The revised deadlines become legally binding as soon as the Omnibus is published in the Official Journal of the EU; it was signed on July 8, 2026 (Council of the EU; European Commission).

Milestone / Requirement

Original

Current

Who is affected

Effective Date of Regulation (EU) 2024/1689

Aug. 1, 2024

Legal Framework for All Stakeholders

Prohibited Practices (Art. 5) & AI Competence (Art. 4)

Feb. 2, 2025

Feb. 2, 2025 (effective)

All providers & operators

GPAI Model Requirements, Governance, and Sanction Rules

Aug. 2, 2025

Aug. 2, 2025 (in effect)

Providers of AI base models

Transparency Requirements (Art. 50): Labeling, Chatbot & Deepfake Disclosure

Aug. 2, 2026

Aug. 2, 2026 (unchanged)

Operators of Generative & Interactive AI

New Prohibitions (Art. 5: NCII/CSAM) & Labeling of Existing Systems (Art. 50, para. 2)

new / —

Dec. 2, 2026

Providers & operators of generative AI

National AI Real-World Labs (Sandboxes)

Aug. 2, 2026

Aug. 2, 2027

Member States

High-Risk Systems as Defined in Annex III (Autonomous)

Aug. 2, 2026

Dec. 2, 2027

Providers & operators of high-risk AI

High-Risk Systems as Defined in Annex I (Embedded in Products)

Aug. 2, 2027

Aug. 2, 2028

Manufacturers of Regulated Products

Sources: European Commission, Council of the EU (Consilium), Freshfields, Winston Taylor. As of July 2026.

Two key points to note. First: August 2, 2026, has not been “canceled”—the transparency obligations remain in place. Second: The postponement of the high-risk deadline is not a rollback, but rather a reprieve. The obligations themselves—risk management (Art. 9), data governance (Art. 10), record-keeping (Art. 12), and human oversight (Art. 14)—remain fully in effect.

When prioritizing internally, it’s worth examining the difference between the two high-risk deadlines. Annex III covers standalone software systems—such as a recruiting tool or a credit-scoring application—and takes effect in December 2027. Annex I concerns AI embedded as a safety component in products that are already regulated, such as medical devices or machinery; here, the longer deadline of August 2028 applies because these systems must also undergo product compliance procedures. To determine which of the two deadlines applies, ask: Is the AI system a standalone system, or is it part of a physical product that is already subject to CE marking?

Best-Practice Scenario: From Data Silo to Audit-Ready Foundation

Note: The following scenario is an illustrative example designed to demonstrate the process. It does not describe a specific real-world client and does not contain any actual metrics.

Initial Situation: A medium-sized financial services provider in the DACH region operates an AI-supported system for the preliminary review of loan applications—clearly a high-risk use case according to Annex III. Customer data is distributed across the CRM, core banking system, and several line-of-business applications. The same person exists in three separate records, with differing spellings and conflicting attributes. There is no documentation of the origin of the training data.

The trigger was an internal preliminary review as part of the AI Act inventory process, not an external audit. This is precisely the more advantageous timing: Those who identify their own high-risk systems have control over the pace and sequence of the remedial work. Those who wait for a regulatory authority or an incident to uncover the gap no longer have that control.

Initially, the problem was technical rather than legal in nature. The model made decisions based on data whose quality no one could verify. Article 10, however, requires precisely this verification: representative, low-error data with documented provenance and verified bias.

The path forward followed the roadmap. First, a complete inventory of all AI touchpoints and data sources—including the line-of-business applications that had been developed outside the official IT landscape. Then, the consolidation of customer master data into a “golden record”—a unique, verified version per person, equipped with stable keys that all downstream systems could reference. This was followed by a continuous audit trail that logs every data movement: where the data record came from, when it was last verified, and who modified it.

The biggest organizational hurdle was not technical but cultural: the business departments, which had maintained “their” version of customer data for years, had to embrace a single, central source. This was only achieved once it became clear that the Golden Record made their work easier rather than controlling it—fewer coordination loops, fewer follow-up questions from other departments.

The key impact went beyond compliance. The consolidated foundation not only made the Article 10 documentation more robust; it also stabilized the model’s accuracy because conflicting input data was eliminated. Governance and model quality are two sides of the same data quality coin. That is the core of the message: Those who clean up their systems for the AI Act are, in the process, building a better AI foundation.

Three Lessons from This Scenario

  • The trigger matters less than the response. Whether the gap comes to light through self-assessment or external pressure—what matters is how quickly and systematically the consolidation is tackled afterward.

  • Consolidation is an organizational issue, not purely an IT project. In this scenario, the technical aspect was resolved more quickly than the cultural resistance from the line departments.

  • Compliance benefits and business benefits go hand in hand. The investment paid off twice—in the audit and in day-to-day operations. This makes it easier to justify than a mere compliance exercise.

Pitfalls: The Five Most Costly Misconceptions

Pitfall 1: “August 2026 is a done deal.”

The most dangerous misconception. The postponement applies exclusively to high-risk obligations. The transparency obligations under Article 50 remain in effect as of August 2, 2026. Anyone who has suspended their program based on the political agreement is creating a loophole—and risks being caught on the very obligation that is easiest to verify: a lack of labeling is immediately visible from the outside.

Pitfall 2: Putting Governance Work on Hold

The new deadline tempts companies to adopt a wait-and-see approach. But an audit-proof data foundation isn’t built in a matter of weeks. The postponed deadline actually extends the very task that takes the longest. Putting work on hold means squandering the head start you’ve gained—and facing the same time pressure in the first half of 2027 that the Omnibus Directive was actually meant to alleviate.

Pitfall 3: Buying the Tool Before Laying the Foundation

A compliance dashboard built on chaotic master data generates nice-looking reports about a broken system. The order matters: first the Golden Record, then the tool that monitors it. Otherwise, you end up with an additional system that also needs to be maintained and eventually consolidated itself.

Pitfall 4: Treating the AI Act and GDPR as separate issues

Both sets of regulations apply in parallel and access the same data. The EU AI Act does not replace the GDPR. Handling them in separate silos doubles the effort and risks contradictions—for example, when the GDPR’s retention period conflicts with the AI Act’s documentation requirement. A shared data foundation serves both and resolves such conflicts in one place.

Pitfall 5: Misjudging Your Own Role

Providers and operators have different obligations. Many companies consider themselves mere users, even though they slip into the provider role through fine-tuning or their own integration. Misjudging one’s role directly leads to obligations that are incorrectly scaled—in both directions: insufficient preparation when actually acting as a provider, and unnecessary effort when actually acting as an operator.

Pitfall 6: Waiting for the perfect solution

Some companies delay the launch because not every technical standard has been finalized yet. This confuses legal certainty in the details with the ability to act in principle. A Golden Record, documented data provenance, and an audit trail are valuable under any conceivable final standard. Waiting costs time that will be lacking later—acting based on today’s state of knowledge does not.

What pitfall are you overlooking right now?


The six pitfalls listed above are difficult to identify from within your organization. Our AI Data Foundation Check provides you with a clear assessment of your current master data maturity in just 15 minutes and shows where your greatest risk lies.

  • Evaluation score for all data dimensions

  • Ready-to-use roadmap template

  • 100% free

Conclusion: A Deadline Becomes a Foundation

The EU AI Act in August 2026 is not a single deadline, but a roadmap. Transparency requirements take effect now; the new prohibitions will follow in December 2026; and the high-risk requirements will take effect in December 2027 and August 2028. The Digital Omnibus has bought time—but only for those who use it.

The key insight is the simplest one: The most difficult part of the regulation is not an AI problem, but a data governance problem. Article 10 requires exactly what sound master data management already delivers—consistent, verifiable, and audit-proof data. Those who get their foundation in order will not only be compliant but also AI-ready. Governance is thus not a cost factor, but a competitive advantage.

Three questions summarize what matters most right now: Do we know which of our AI systems are high-risk? Can we verify the origin and quality of the underlying data for each of them? And is this an ongoing process or a one-time effort that will already be outdated by the time an audit takes place? Anyone who can answer all three questions with “Yes,” “Yes,” and “an ongoing process” has essentially already implemented the AI Act—regardless of what deadline is coming up next.

Frequently Asked Questions About the EU AI Act 2026

Partially. The transparency requirements under Article 50 remain in effect as of August 2, 2026. The obligations for high-risk systems were postponed by the Digital Omnibus—to December 2, 2027 (Annex III) and August 2, 2028 (Annex I), respectively.
Only the effective dates for the high-risk obligations. Standalone high-risk systems under Annex III (e.g., recruiting, credit scoring) will apply starting December 2, 2027, while systems embedded in products under Annex I will apply starting August 2, 2028. The obligations themselves and the risk classes remain unchanged.
The transparency requirements: label AI-generated content, make chatbots recognizable as machines, and disclose deepfakes (Art. 50). In addition, the AI competence requirement (Art. 4), which takes effect in February 2025, and an inventory of all AI systems in use should be in place.
Austrian companies are directly covered—the regulation applies directly, without the need for national implementing legislation. Swiss companies are affected as third-country entities as soon as they offer AI systems on the EU market. Market access is the determining factor, not the company’s registered office.
In Germany, the Federal Network Agency is responsible for central coordination, supplemented by sector-specific authorities. In Austria, the Federal Chancellery coordinates efforts; the RTR’s AI Service Center serves as the point of contact, while the Data Protection Authority handles aspects related to fundamental rights.
Up to €35 million or 7% of global annual revenue for prohibited practices, up to €15 million or 3% for violations of high-risk obligations, and up to €7.5 million or 1% for providing false information to authorities. For SMEs, the maximum amounts are capped on a pro-rata basis.
For high-risk systems, Article 10 requires documented data governance practices and data quality: training, validation, and test data must be relevant, representative, and—as far as possible—error-free and complete, with documented provenance and checks for bias.
No. Both apply in parallel. If an AI system processes personal data, the AI Act and the GDPR apply simultaneously. In practice, many of the requirements under Article 10 can be implemented using established GDPR mechanisms such as access controls and documentation.
Operators use an AI system available on the market; providers develop or place it on the market. The obligations differ significantly. Note: Anyone who substantially modifies a system or uses it under their own name may assume the role of a provider—which comes with significantly stricter requirements.
Systems in sensitive areas of application listed in Annex III—such as personnel selection, creditworthiness assessments, education, critical infrastructure, law enforcement, or migration—as well as AI embedded as a safety component in regulated products listed in Annex I.
A comprehensive inventory: Which AI systems are in use, what risk class do they belong to, and what data sources do they draw from? Only on this basis can efforts be prioritized—and the process of building the data foundation begin.
Because the most demanding obligations (Art. 10) depend on the data set, not the model. A consistent, verifiable “golden record” fulfills the majority of these requirements. Without it, even the extended deadline will be tight.
As of August 2, 2025, specific obligations apply to general-purpose AI models: technical documentation, copyright compliance, and—for models posing systemic risk—additional risk assessments. For most DACH companies that use such models, the most important step is to request the relevant documentation from the provider.
National AI regulatory sandboxes are controlled testing environments where companies can test AI systems under regulatory supervision before they are required to be fully compliant. They are scheduled to be established in member states as of August 2, 2027, and are primarily aimed at innovative providers seeking regulatory feedback at an early stage.
Yes, in several respects: The maximum fines for SMEs are capped on a pro-rata basis, and the Digital Omnibus provides for simplified documentation requirements for smaller providers. However, the substantive data quality requirements under Article 10 generally apply regardless of company size.
There is no automatic penalty on the deadline itself—fines require a proceeding by the market surveillance authority. In practice, the risk usually begins with an inquiry or complaint that reveals gaps in documentation. Anyone who has missed a deadline should actively and documentedly close the gap rather than wait—a visible corrective action process is generally viewed more favorably than continued inaction.
Common triggers include complaints from affected parties, notable market observations by the authority, or random spot checks in particularly sensitive areas such as lending or personnel selection. Competitors or consumer protection organizations may also provide leads. A robust internal record-keeping system significantly shortens response times in each of these cases.

Sources

Europeam Commission: "AI Act – Regulatory framework and implementation timeline" - https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai (abgerufen: Juli 2026)

EU Consilium: "Artificial Intelligence: Council and Parliament agree to simplify and streamline rules (Digital Omnibus)" - https://www.consilium.europa.eu/en/press/press-releases/2026/05/07/artificial-intelligence-council-and-parliament-agree-to-simplify-and-streamline-rules/

EU AI Act - Article 10: "Data and Data Governance, Verordnung (EU) 2024/1689" - https://artificialintelligenceact.eu/article/10/

Freshfields: "EU AI Act unpacked #34: The final Digital Omnibus on AI." https://www.freshfields.com/en/our-thinking/blogs/technology-quotient/eu-ai-act-unpacked-34-the-final-digital-omnibus-on-ai-key-amendments-to-the-a-102nber

Gibson Dunn: "EU AI Act Omnibus Agreement – Postponed High-Risk Deadlines and Other Key Changes" - https://www.gibsondunn.com/eu-ai-act-omnibus-agreement-postponed-high-risk-deadlines-and-other-key-changes/

Gartner: "Data Quality – Why It Matters" - https://www.gartner.com/en/data-analytics/topics/data-quality

Bitkom Research: "Jedes vierte Unternehmen beschäftigt sich mit dem AI Act" https://www.bitkom.org/Presse/Presseinformation/Jedes-vierte-Unternehmen-beschaeftigt-mit-AI-Act

Bitkom: "Studienbericht „Künstliche Intelligenz in Deutschland“ 2026" - https://www.bitkom.org/sites/main/files/2026-02/bitkom-studienbericht-ki.pdf

Bundesnetzagentur: "Künstliche Intelligenz – KI-Verordnung und KI-Service-Desk." - https://www.bundesnetzagentur.de/DE/Fachthemen/Digitales/KI/start_ki.html

Advisori: "KI-MIG beschlossen: Was das AI-Act-Durchführungsgesetz für Unternehmen bedeutet" - https://www.advisori.de/blog/ki-mig-ai-act-durchfuehrungsgesetz-unternehmen

RTR – KI-Servicestelle: "AI Act – Behörden, Fristen und Transparenzpflichten (Österreich)" - https://www.rtr.at/rtr/service/ki-servicestelle/ai-act/AI_Act.de.html

McKinsey: "The State of AI 2025" - https://www.mckinsey.com/capabilities/quantumblack/our-insights/the-state-of-ai