For two years, boards could treat the EU AI Act as something on the horizon, worth a briefing slide but not an agenda item. That period is over. The Act is in force, most of it now applies, and the remaining obligations have fixed dates. This piece walks through what a board actually needs to oversee, in the order it needs to happen.
One disclaimer first, and we mean it: we are engineers, not lawyers. Nothing here is legal advice, and any board taking the Act seriously should have counsel involved. What we can offer is the other half of the picture, because most of what compliance rests on in practice is operational fact, and operational facts are an engineering matter.
The timeline, checked against the legal texts
Every date below comes from the AI Act, Regulation (EU) 2024/1689, as amended by the Digital Omnibus on AI, Regulation (EU) 2026/1744:
- 1 August 2024: the AI Act entered into force.
- 2 February 2025: the prohibitions on certain AI practices (Article 5) and the AI literacy duty in Article 4 began to apply.
- 2 August 2025: the governance rules and the obligations for providers of general-purpose AI (GPAI) models began to apply.
- 2 August 2026: the Act's general date of application, including the transparency duties in Article 50 (for example, disclosing deepfakes and telling people when they are talking to an AI system).
- 2 December 2026: two new prohibitions added by the Omnibus apply, covering AI systems that generate non-consensual intimate imagery or child sexual abuse material. Generative AI systems already on the market before 2 August 2026 must also meet the Article 50(2) marking duty by this date.
- 2 December 2027: the high-risk obligations apply to the stand-alone use cases listed in Annex III (employment, credit scoring, education, and others).
- 2 August 2028: the high-risk obligations apply to AI that is part of products covered by the EU product-safety legislation listed in Annex I.
The last two dates are newer than the rest. The Digital Omnibus was adopted on 8 July 2026, published in the Official Journal on 24 July 2026, and entered into force on 27 July 2026. It moved the Annex III high-risk date from 2 August 2026 to 2 December 2027, and the Annex I date from 2 August 2027 to 2 August 2028.
It also rewrote Article 4. The original text required providers and deployers to take measures to ensure, to their best extent, a sufficient level of AI literacy among their staff. The new text requires them to "take measures to support the development of AI literacy" of their staff and others operating AI on their behalf, and adds that this "does not require providers or deployers to guarantee any specific level of AI literacy of any individual". The Commission and the Member States now also have to support companies in meeting the duty. So the obligation still exists and still sits with your company; it is now an obligation of effort rather than of result.
The penalties give the timeline its weight. Under Article 99, breaching the prohibitions can cost up to €35 million or 7% of worldwide annual turnover, whichever is higher. Breaching the deployer obligations for high-risk systems (Article 26) or the transparency duties (Article 50) can cost up to €15 million or 3%. For SMEs, the cap is whichever of the two amounts is lower; the Omnibus extends that treatment to small mid-caps for all fines except those for prohibited practices.
Notice the tense. The prohibitions and the literacy duty are not upcoming obligations to prepare for; they have applied for more than a year and a half. The high-risk phase is the one still ahead, and it is closer than a typical procurement and rollout cycle.
Why this is a board matter, not an IT matter
Boards do not administer compliance; they oversee it. But oversight requires the topic to be on the table, and the AI Act has three properties that put it there.
First, the exposure is legal and financial, with defined penalties, the same category of risk boards already oversee for data protection and financial controls. Second, the obligations attach to how AI is used across the organisation, not just to what the IT department buys. HR, marketing, finance, and operations can each create exposure independently. Third, the duty of oversight is hard to discharge over something no one has inventoried, which brings us to the practical list.
Five things boards should demand now
1. A complete AI inventory
You cannot govern what nobody has listed. Ask management for a register of every AI system in use (bought, built, and embedded in other products), plus the unofficial usage that every organisation has and few admit to. In our experience the inventory is where the surprises live: the list is usually longer than expected, and the riskiest entries are often not the official ones.
2. Classification against the Act's risk tiers
The Act regulates by risk: prohibited practices, high-risk systems, transparency duties for certain systems, and separate obligations for general-purpose models. Each inventory entry needs a classification and a stated rationale. Most companies will find that most of their usage (drafting, summarising, internal search) sits outside the high-risk category, but that finding has to be established and documented, not assumed.
Two examples that catch companies out. AI used to filter job applications, evaluate candidates, or monitor and evaluate employee performance is listed as high-risk in Annex III. And using AI to infer the emotions of people at work has been prohibited since February 2025, except for medical or safety reasons.
3. AI literacy treated as a live duty
Article 4 has applied since February 2025, and the Omnibus rewording did not remove it. In our view a single all-hands webinar is a thin way to discharge it. The organisation should be able to show who works with AI, what training they received, and that the training matches what they actually do with it. Boards should also apply the duty to themselves: a board overseeing AI risk needs enough literacy to ask the follow-up question, not just the first one.
4. AI in procurement and supplier oversight
Much of a typical company's AI use arrives through vendors, as AI features switched on inside tools the company already licenses. Procurement should be asking suppliers what AI their products contain, what role the company takes on when using it (in the Act's terms, usually "deployer"), and what documentation the supplier provides. A concrete sign of maturity: contracts that mention AI explicitly, rather than compliance by assumption.
5. Reporting lines and an evidence trail
Give the topic a named owner in management, a recurring slot on the board agenda, and a documentation habit: the inventory, the classifications, the training records, the approvals. If a regulator, auditor, or acquirer asks next year, the difference between a good answer and a scramble is whether the evidence already exists. We describe how to set this up below board level in AI governance for mid-sized companies.
Where governance meets engineering
Every item on that list rests on an operational substrate. An inventory is only current if systems access is controlled enough that AI cannot enter unnoticed. Classifications are only defensible if usage is logged. Training claims are only credible if you can show who has access to what. When we wire AI into client systems, the guardrails we build (scoped access, human approval on writes, an audit trail for every AI action) are the same mechanisms an AI Act compliance story stands on. Governance that ignores the substrate is a binder; the substrate without governance is undirected. Boards need both halves.
The question for your next meeting
The question is not whether your company uses AI; it does. The question is whether anyone can show you the list, the risk class of each entry, and the evidence behind both. If the answer is no, that is not cause for alarm. It is simply the work, and there is still time to do it before the high-risk phase begins in December 2027.
If you want an outside view of what is already in use, our AI audit starts with exactly that inventory and classification. For the literacy side, see our AI workshops and training.
Talk to us
If your board wants to know where the company stands before the next meeting, talk to us. Bring your lawyers; we will bring the engineering.