Skip to main content

GOVERNANCE & SECURITY

The EU AI Act deadline moved. The accountability work did not.

The European Commission's current timeline shows that the AI Act is now broadly applicable, with transparency rules active from August 2, 2026, certain Annex III high-risk obligations from December 2, 2027, and Annex I product obligations from August 2, 2028. Organizations that deploy AI systems in EU environments must determine which provider and deployer obligations apply to their use case. The practical starting point is an inventory that supports classification, evidence collection, and a named accountability chain. This research covers what the frameworks require and where to start.

Research Area7 topicsGovernance & Security

THE REGULATORY LANDSCAPE

Three things that make AI compliance different from what most compliance teams have handled before

The frameworks are not theoretical. The deadlines are active, revised, and staggered. The gaps most organizations carry into the 2026 and 2027 compliance window are not technical - they are organizational.

Abstract regulatory landscape image showing overlapping jurisdictions converging on one compliance point.
Active challenge
Tap a challenge card to update this panel
Item 1 of 4

The EU AI Act is already partially in force

The Act applies in stages. Prohibited practices and AI literacy obligations began applying in February 2025, governance and general-purpose AI obligations in August 2025, and the broader Act became applicable on August 2, 2026. Transparency rules are active now. Certain Annex III high-risk obligations apply from December 2, 2027, while Annex I product obligations apply from August 2, 2028. Teams should verify the timeline and scope against the current Commission and EUR-Lex text before treating any date as a compliance conclusion.

WHAT THE FRAMEWORKS REQUIRE

The five categories of obligation that appear across EU AI Act, NIST AI RMF, and ISO 42001

Different frameworks use different vocabulary. The underlying organizational requirements converge on the same five categories. An organization that has addressed all five has a defensible compliance posture regardless of which framework an examiner applies.

Active requirement
Tap a requirement card to update this panel
Item 1 of 5

Inventory and risk classification

Know what AI systems exist in the organization, who owns them, and what decisions they influence. Classify each system by risk level - not by instinct but by the criteria the applicable framework specifies. For the EU AI Act, high-risk classification covers AI used in employment, credit decisions, education, and law enforcement. For Microsoft 365 environments, Copilot-assisted hiring screening or automated performance monitoring may fall within scope.

WHERE MOST ORGANIZATIONS STAND

The four gaps that appear in almost every enterprise AI compliance assessment

These are not speculative risks. They are the consistent findings from organizations that have run structured AI compliance assessments against the frameworks applicable to their environments.

Active finding
Tap a finding card to update this panel
Item 1 of 4

No AI inventory

The starting condition in most organizations is the same: no systematic record of what AI systems exist, who owns them, what data they process, and what decisions they influence. Copilot seats are provisioned, Power Automate flows with AI Builder components run in production, and third-party AI tools connect through approved connectors - all without appearing on any governance register. The inventory gap makes every downstream compliance requirement impossible to address systematically.

  • Identify all Microsoft 365 Copilot deployments, Copilot Studio agents, and Power Platform AI components
  • Catalog third-party AI tools connected through Microsoft Foundry or approved connectors
  • Document what data each system accesses, what decisions it influences, and who is accountable for its behavior
  • Classify each system against EU AI Act risk tiers: prohibited, high-risk, limited risk, minimal risk

THE APPLICABLE FRAMEWORKS

What each framework covers and who it applies to

These frameworks are not alternatives to each other. Most regulated organizations operating AI in 2026 are subject to more than one simultaneously.

Abstract compliance architecture image showing multiple framework layers forming one surface.
Active framework
Tap a framework card to update this panel
Item 1 of 7

EU AI Act

The AI Act is now broadly applicable, with certain Annex III high-risk obligations applying from December 2, 2027 and Annex I product obligations from August 2, 2028. Transparency rules apply from August 2, 2026, while prohibited practices and GPAI obligations began earlier. The Act applies based on the relevant provider, deployer, importer, distributor, and use-case facts, not simply an organization's headquarters. Microsoft Purview Compliance Manager provides an EU AI Act assessment template as a documentation starting point.

TIMING AND PRIORITY

Who needs to act now and what acting looks like

Abstract urgency image showing a narrow threshold before it closes.

Organizations that need to act now

  • Any organization that deploys Microsoft 365 Copilot or AI agents for users in EU member states - you are a deployer under the EU AI Act regardless of where your organization is headquartered
  • Any organization that uses AI in employment, credit, education, law enforcement, or another listed high-risk context should assess the relevant Annex III criteria and prepare for the obligations applying from December 2, 2027
  • Any organization subject to CFTC, SEC, FINRA, or ONC/CMS oversight that has deployed AI in regulated workflows without updating their governance documentation
  • Any organization that completed an AI compliance assessment before August 2025 and has not revisited it since - GPAI obligations changed the landscape materially in August 2025
  • Any organization that is evaluating Microsoft Agent 365 or an expanded Microsoft 365 agent footprint without first assessing the compliance implications of the new agent inventory, identity, data, and oversight surface
  • Note: The AI Omnibus entered into force on July 27, 2026. The current Commission timeline applies certain Annex III high-risk obligations from December 2, 2027 and Annex I product obligations from August 2, 2028. Transparency rules are already active from August 2, 2026. Organizations should document their compliance position against the current timeline and the specific use case.
Abstract governance image showing the first documented step in a compliance process.

What 'starting' actually means at this stage

  • An AI inventory is the first deliverable - not a compliance assessment, not a gap analysis. You cannot classify what you cannot see
  • Risk classification using EU AI Act Annex III criteria is the second step - applied by the framework's criteria, not organizational judgment
  • Microsoft Purview Compliance Manager's EU AI Act, NIST AI RMF, and ISO 42001 assessment templates provide structured starting points for documentation work
  • Colorado AI law: use the current Colorado Attorney General rulemaking page and enacted 2026 amendments when determining whether a high-risk automated decision-making use case is in scope. Do not carry the earlier June 30, 2026 date into a current compliance plan.
  • The time required for high-risk readiness depends on the system, provider or deployer role, evidence already available, and applicable conformity or monitoring duties. The current AI Act timeline provides additional transition time for certain Annex III and Annex I obligations, but transparency rules are already active. Document your compliance position against the current timeline and the specific use case.

FREQUENTLY ASKED

What compliance officers and CISOs ask when they start this work

Abstract disclosure image showing two operating records slightly out of alignment.

FURTHER READING

The AI Act's current timeline applies transparency rules from August 2, 2026, certain Annex III high-risk obligations from December 2, 2027, and Annex I product obligations from August 2, 2028. The compliance work is still an operating condition, not a one-time deadline exercise.

The Governance Gap covers enterprise AI governance on the Microsoft stack, including how the EU AI Act, NIST AI RMF, and Colorado AI Act apply to organizations deploying Copilot and agents in regulated environments. New editions publish every Tuesday.

Built on verified regulatory and Microsoft documentation
Written against published regulatory and vendor documentation
Updated as regulations and the Microsoft platform evolve