The clock is ticking. On August 2, 2026, the EU AI Act's high-risk provisions come into full effect. If your organization deploys AI systems that fall under Annex III — recruitment screening, credit scoring, medical diagnostics, critical infrastructure management, or any of the other eight high-risk categories — you have approximately five months to achieve compliance. The penalties for missing this deadline are not symbolic: up to EUR 35 million or 7% of global annual turnover, whichever is higher.
This is not a distant regulatory threat. It is happening now. This article provides a month-by-month action plan from March through August 2026, grounded in the specific legal obligations of Articles 6, 9-15, and Annex III of Regulation 2024/1689. Whether you are just starting or midway through your compliance journey, use this as your operational checklist.
What the August 2, 2026 Deadline Actually Requires
Let us be precise about what becomes enforceable. The August 2026 deadline applies to high-risk AI systems as defined in Article 6 and Annex III. If you are a provider (developer) or deployer (user) of these systems, you must have the following in place:
- Art. 9 — Risk Management: A documented, continuously updated risk management system that identifies, analyzes, estimates, and evaluates risks throughout the AI system's lifecycle. This is not a one-time assessment — it must be a living process.
- Art. 10 — Data Governance: Training, validation, and testing data must meet quality criteria. You must demonstrate that your data is relevant, representative, free of errors, and complete for the intended purpose.
- Art. 11 — Technical Documentation: Comprehensive documentation demonstrating compliance with all requirements, maintained before market entry and kept current. This includes system architecture, design choices, algorithms, data handling, and testing methodologies.
- Art. 12 — Record-Keeping: Automatic logging of the AI system's operations to enable traceability. Logs must be retained for a period appropriate to the intended purpose (minimum 6 months unless otherwise specified by law).
- Art. 13 — Transparency: Instructions for use that explain the system's capabilities, limitations, intended purpose, and human oversight requirements. Deployers must understand what the system does and does not do.
- Art. 14 — Human Oversight: Measures ensuring effective human oversight during operation. A qualified person must be able to understand, monitor, and override the AI system's outputs.
- Art. 15 — Accuracy & Robustness: The system must achieve appropriate levels of accuracy, robustness, and cybersecurity for its intended purpose, declared in technical documentation and instructions for use.
Not sure if your AI systems qualify as high-risk? Use our free AI Act Risk Classifier to check in under 5 minutes. For a detailed guide on how classification works, read our step-by-step AI classification guide.
The Digital Omnibus Factor: Should You Wait?
You may have heard about the Digital Omnibus Act — a European Commission proposal from February 2025 that, among other changes, would push the Annex III high-risk deadline from August 2026 to December 2027 for certain categories. This has caused some organizations to pause their compliance efforts. That is a mistake. Here is why:
- Not Yet Law: The Digital Omnibus is a proposal, not enacted legislation. It must pass through the European Parliament and Council — a process that typically takes 12-18 months. As of March 2026, it has not been formally adopted.
- Partial Scope: Even if adopted, the extension would only apply to Annex III high-risk categories — not to safety component AI systems (Article 6(1)), which remain under the August 2026 deadline regardless. If your AI is embedded in products covered by EU harmonization legislation (machinery, medical devices, vehicles), the original deadline stands.
- Market Expectation: B2B customers, investors, and partners are increasingly asking about AI Act compliance. Waiting for a potential extension signals that you are not taking governance seriously. Early compliance is a competitive advantage.
- Compliance Takes Time: Even with a December 2027 extension, the compliance work described in Articles 9-15 requires 6-12 months of sustained effort. Starting in late 2026 on the hope of a deadline shift leaves no margin for error.
Our recommendation: Treat August 2, 2026 as your binding deadline. If the Digital Omnibus passes and grants an extension, you will be ahead of schedule. If it does not, you will be compliant. Either way, you win.
Your 90-Day Action Plan: Month by Month
Here is the operational playbook. Each month has specific deliverables that build on the previous month's work. Adjust the intensity based on how many high-risk systems you operate and where you currently stand.
Month 1 (March-April 2026): Inventory and Classification
Goal: Know exactly what you have and where each system falls in the risk framework.
- Week 1-2: Build a complete AI systems inventory. Include every tool, platform, and service that uses AI — including third-party SaaS tools with embedded AI capabilities (your CRM's lead scoring, HR platform's candidate ranking, etc.).
- Week 3: Classify each system against Annex III categories. Use our Risk Classifier tool or work through the Compliance Guide methodically. Document your classification rationale for each system.
- Week 4: Prioritize: which high-risk systems need the most work? Rank by business criticality, compliance gap size, and complexity. This becomes your compliance project backlog.
Deliverables: AI system register, classification report with rationale, prioritized compliance backlog.
Month 2 (April-May 2026): Documentation and Risk Management
Goal: Establish the risk management framework and begin technical documentation for each high-risk system.
- Week 5-6: Implement a risk management system per Art. 9. This means: identify risks, assess likelihood and severity, define mitigation measures, and establish ongoing monitoring. For each high-risk system, document known risks, tested mitigations, residual risk levels, and who is responsible for ongoing risk monitoring.
- Week 7: Start technical documentation (Art. 11). Document system architecture, training data characteristics, intended purpose, known limitations, accuracy metrics, and validation results. If you use third-party AI (SaaS), request provider documentation — they are obligated to support your compliance under Art. 25.
- Week 8: Establish data governance procedures (Art. 10). Audit training data for quality, relevance, representativeness, and bias. Document data sources, preprocessing steps, and validation procedures.
Deliverables: Risk management framework per system, initial technical documentation, data governance audit report.
Month 3 (May-June 2026): Operational Controls and Testing
Goal: Implement human oversight, logging, transparency measures, and conduct conformity testing.
- Week 9-10: Implement human oversight measures (Art. 14). Define who monitors each system, how they can intervene, and what triggers a human review. Create operating procedures and train designated personnel. Ensure override mechanisms work and are documented.
- Week 11: Set up automatic logging (Art. 12). Implement or verify that system logs capture inputs, outputs, confidence levels, and user interactions. Confirm retention policies meet the minimum requirements. Test log retrieval and audit trail completeness.
- Week 12: Conduct accuracy and robustness testing (Art. 15). Run validation tests, document results, and address any gaps. Prepare instructions for use (Art. 13) that clearly describe system capabilities, limitations, and required oversight.
Deliverables: Human oversight procedures, logging infrastructure, conformity test results, instructions for use.
Months 4-5 (June-August 2026): Review, Register, and Go Live
Goal: Finalize documentation, conduct internal audit, register in the EU database, and ensure ongoing compliance processes are operational.
- Week 13-16: Conduct an internal compliance audit against all Art. 9-15 requirements. Gap-check every deliverable. Have someone outside the project team review documentation for completeness and clarity.
- Week 17-18: Register high-risk systems in the EU database (Art. 49). Prepare and issue the EU declaration of conformity (Art. 47). Ensure CE marking is applied where applicable (Art. 48).
- Week 19-20: Activate ongoing monitoring. Your risk management system, logging, and human oversight must be operational — not just documented. Conduct a "fire drill" to verify that all procedures work under realistic conditions.
Deliverables: Completed compliance file per system, EU database registration, declaration of conformity, operational monitoring.
The Penalty Structure: What Non-Compliance Actually Costs
The AI Act's penalty framework is tiered by severity, and the numbers are designed to make compliance the obvious economic choice:
Prohibited AI Violations
EUR 35M / 7%
Of global annual turnover, whichever is higher
High-Risk Violations
EUR 15M / 3%
Of global annual turnover, whichever is higher
Misinformation / Reporting
EUR 7.5M / 1%
Of global annual turnover, for incorrect info to authorities
For SMEs, the fines are adjusted proportionally — but even the reduced amounts represent existential risk for smaller organizations. The Act also provides for reduced fines for startups and SMEs, but only if they have demonstrated good-faith compliance efforts. Having no compliance program at all is the worst possible position. Read our AI Act compliance checklist for SMEs for a practical starting framework tailored to smaller organizations.
Quick Wins: What You Can Do This Week
Even if your compliance program is behind schedule, these five actions can be completed within days and demonstrate material progress:
Run Every AI System Through the Risk Classifier
Use our free Risk Classifier tool to assess every AI system in your organization. It takes under 5 minutes per system and gives you a preliminary risk rating with tailored next steps. You will know immediately if you have high-risk exposure.
Create a Basic AI System Register
In a simple spreadsheet, list: system name, provider, purpose, data processed, risk classification, and compliance status. This register is required under Art. 49 and is the foundation of every other compliance activity.
Request Provider Documentation
For every third-party AI system you use, contact the provider and request their AI Act compliance documentation. Under Art. 25, providers of high-risk AI must furnish deployers with the information needed for compliance. Start these conversations now — providers are overwhelmed and response times are long.
Appoint an Internal AI Compliance Lead
Someone needs to own this. It does not have to be a full-time role, but there must be a named person responsible for coordinating AI Act compliance across the organization. Without ownership, compliance work stalls.
Review the Full Compliance Guide
Read our complete AI Act Compliance Guide end to end. It covers obligations by risk level, documentation templates, and practical checklists. Understanding the full scope now prevents costly rework later.
Need help meeting the August 2026 deadline?
Our AI Act compliance team has guided dozens of businesses through classification, documentation, and conformity assessment. We offer everything from a free risk check to full compliance support — and we start with understanding your specific situation before recommending any engagement.
View AI Act Compliance Services → | Visit the AI Act Hub →Ready to remove manual work?
Tell us which workflow slows the team down. We will map the automation path and the ROI case.
Book a Strategy CallAlso Read
- AROG AI at Infoshare 2026 in Gdansk: What We Took from the Innovation Stage
- AI Agent Readiness Assessment: A 2026 Scoring Framework for Business Processes
- EU AI Act Article 50 for Chatbots and AI Assistants: 2026 Transparency Checklist
- n8n Consultant: How to Scope, Hire, and Get Real ROI from Workflow Automation
- AI Automation Consulting: What It Includes, What It Costs, and How to Choose a Firm
- AI Automation ROI: How to Calculate and Prove Value to Your Board
- The Complete Guide to Business Process Automation with AI
- AI Agents vs Traditional RPA: Which Automation Approach Fits Your Business?
- 5 Free AI Tools to Assess Your Business Automation Potential
- How to Classify Your AI System Under the EU AI Act
- AI Act Compliance Checklist for SMEs
- How Much Does AI Act Compliance Cost?
- EU AI Act 2025: What Every Business Needs to Know
- 5 Business Processes You Should Automate With AI Today
- AI Audit vs AI Consultation: Which Does Your Business Need?




