Back to InsightsRegulatory Update

EU AI Act: What Audit Committees Need to Know in 2026

By BoardSight PracticeApril 9, 20268 min

EU AI Act: What Audit Committees Need to Know in 2026

This article reflects BoardSight's analysis and is not legal advice. Regulatory facts below were verified against Regulation (EU) 2024/1689 (EUR-Lex) and the European Commission AI Act timeline on 2026-07-22.

The Timeline: Phased Application (Updated for the 2025 Digital Omnibus)

The EU AI Act applies in phases. The 2025 Digital Omnibus package moved the high-risk dates back, so several widely-cited 2026 dates are now out of date:

  • 2 Feb 2025: Prohibitions on certain AI practices (Article 5) took effect.
  • 2 Aug 2025: Obligations for general-purpose AI (GPAI) models began.
  • 2 Dec 2027: Obligations for stand-alone high-risk systems in the Annex III areas (biometrics, critical infrastructure, education, employment, access to essential services, law enforcement, migration/border, administration of justice) apply. This was moved from the original August 2026 date by the Digital Omnibus.
  • 2 Aug 2028: Obligations for high-risk AI embedded in regulated products under Annex I (e.g., machinery, medical devices, lifts, toys).

If your company deploys AI affecting EU residents, map your exposure now — but calibrate your compliance deadline to the corrected 2027/2028 dates, not August 2026.

High-Risk AI: The Classification That Matters

The EU AI Act defines "high-risk" AI in Annex III. Systems are high-risk if they make or significantly influence decisions affecting:

  • Employment: Hiring, promotion, termination, task allocation, performance evaluation
  • Education: Admission, evaluation, proctoring
  • Credit & Essential Services: Creditworthiness/scoring, life & health insurance risk assessment, eligibility for public benefits
  • Critical Infrastructure: Safety components in the management of water, gas, electricity, and digital infrastructure
  • Law Enforcement, Migration & Justice: Certain policing, border-control, asylum, and judicial-assistance uses
  • Biometrics: Remote biometric identification, biometric categorisation, emotion recognition (where permitted)

The question isn't "is our AI high-risk?" It's "which specific systems fall inside Annex III?"

What High-Risk AI Requires

1. Deployer obligations (Article 26)

Article 26 sets the obligations of deployers of high-risk AI. It does not mandate a named "governance body." It requires deployers to: use the system in line with the provider's instructions; assign human oversight to competent, trained, resourced people; ensure input data is relevant and representative where the deployer controls it; monitor operation and keep the automatically generated logs; inform affected workers/representatives before putting a workplace system into use; and cooperate with authorities. In practice, meeting these duties requires an accountable internal oversight function — this is the second line — but the Act imposes the obligations, not a specific org chart.

2. Technical documentation (Article 11 + Annex IV)

High-risk systems must have technical documentation (architecture, training/validation data, performance, risk-management measures), user instructions, record-keeping/logging (Article 12), and incident records, maintained throughout the system's lifetime.

3. Conformity assessment (Article 43 + Annexes VI-VII)

Before a high-risk system is placed on the market, it must undergo a conformity assessment — internal control (Annex VI) or, for certain systems, third-party assessment via a notified body (Annex VII). (Note: Article 23 governs importers, not conformity assessment — a common mis-citation.)

4. Post-market monitoring (Article 72) & serious-incident reporting (Article 73)

After deployment, providers must run a post-market monitoring system (Article 72) and report serious incidents to the relevant market-surveillance authority (Article 73). (Note: Article 27 is the separate fundamental-rights impact assessment (FRIA) required of certain deployers; Article 28 concerns notifying authorities and notified bodies — neither is the post-market-monitoring provision.)

The EU AI Act doesn't just require governance — it requires documented, auditable governance, cited to the right provisions.

Transparency Requirements for General-Purpose AI

Providers of GPAI models face transparency obligations (from 2 Aug 2025): technical documentation, information for downstream providers, a policy to respect EU copyright law, and a public summary of training content. Providers of GPAI models with systemic risk face heightened duties (evaluation, adversarial testing, incident tracking, cybersecurity). Separately, Article 50 requires that people be informed when they interact with an AI system and that certain AI-generated content be labelled.

The Extraterritorial Scope: Why This Applies to You

The Act reaches providers and deployers established outside the EU where the AI system's output is used in the EU. If you have EU customers, or your AI affects people in the EU, you are likely in scope. Geography alone does not protect you.

What to Do Now

  1. Inventory all AI systems; flag those touching Annex III areas.
  2. Classify rigorously against Annex III; document the reasoning.
  3. Assign accountable oversight (the second line) for each high-risk system — roles, reporting lines, escalation.
  4. Baseline documentation (Article 11 / Annex IV) and logging (Article 12).
  5. Plan conformity assessment (Article 43) and post-market monitoring (Article 72) ahead of the applicable date.
  6. Stand up serious-incident reporting (Article 73).

Enforcement Risk (the correct figures)

Penalties under Article 99 are tiered — not a single 6% number:

  • Up to €35 million or 7% of total worldwide annual turnover (whichever is higher) for breaching the Article 5 prohibitions.
  • Up to €15 million or 3% for breaching other obligations, including high-risk provider and deployer duties.
  • Up to €7.5 million or 1% for supplying incorrect, incomplete, or misleading information to authorities.

(For SMEs and start-ups, the lower of the fixed amount or the percentage applies.) The earlier "6% / €30 million" figure was incorrect.

Alignment with Your Governance Stack

The Act's obligations map onto the Three Lines Model: technical documentation and logging (first line); deployer oversight, conformity, and incident governance (second line); independent assurance over the whole (third line). Adopting the Three Lines for AI makes these obligations easier to evidence — but the legal duties sit in the Regulation, not in any framework.

Next Steps for Audit Committees

  1. Which of our systems are high-risk under Annex III?
  2. Who is the accountable owner for Article 26 deployer obligations on each?
  3. Have we scoped conformity assessment (Art 43) and post-market monitoring (Art 72)?
  4. What is our legal exposure under the Article 99 tiers if we are non-compliant?
  5. Is our compliance plan calibrated to 2 Dec 2027 / 2 Aug 2028, not the withdrawn August 2026 date?

Sources: Regulation (EU) 2024/1689 (EU AI Act), Articles 5, 11-15, 23-28, 43, 50, 72-73, 99 and Annexes III-IV, VI-VII; European Commission, “Regulatory framework on AI” timeline (2025 Digital Omnibus). Verified 2026-07-22. Not legal advice.

B
BoardSight

The AI Oversight Practice from Cognitive Corp.

Standards

NIST AI RMF 1.0ISO/IEC 42001:2023EU AI ActCOSO ERM

BoardSight provides independent, board-ready oversight evidence and advisory support. It does not provide legal opinions, regulatory certification, statutory audit assurance, or a guarantee that an AI system is safe or compliant.

© 2026 Cognitive Corp. All rights reserved.

BoardSight · AI Governance · Three Lines for AI