You’ve been meaning to look at the EU AI Act properly for months. Then August 2 came and went, enforcement went live, and you’re still not sure whether it applies to your firm — or what “compliant” even looks like if it does. You’re not alone.
78% of organisations assessed in Vision Compliance’s April 2026 readiness report had not taken meaningful steps toward AI Act compliance — despite knowing the deadline was coming.
Why So Many Firms Are Behind
1. The scope confusion
Most managing partners hear “EU AI Act” and assume it’s a European problem for European companies. It isn’t. The Act has extraterritorial reach: any firm whose AI-driven output or service touches an EU client, an EU employee, or an EU end user is in scope, regardless of where the firm is headquartered. A US or UK advisory practice with a handful of EU clients is already a “deployer” under the law the moment it runs their work through an AI tool.
2. The deadline stack
The Act didn’t land as one date — it’s been arriving in waves since February 2025 (prohibited practices), through August 2025 (governance infrastructure, GPAI provider obligations), to August 2, 2026 (high-risk system obligations and full enforcement powers), with a final piece — the machine-readable content marking requirement — phasing in for pre-existing systems by December 2, 2026. Firms that weren’t watching closely lost track of which obligations were already binding versus still pending.
3. No inventory, no starting point
You cannot classify what you haven’t listed. The single most common reason firms are behind isn’t a lack of willingness — it’s that nobody has ever written down every AI tool actually in use across the practice, including the ones staff adopted quietly on their own. Without that list, a risk classification exercise has nothing to work from.
The technical file required under Article 11 isn’t a checklist you complete the week before an audit. It’s a body of evidence — design decisions, data governance, impact assessments — built over time. Firms starting that process in August are already behind the artefact, not just the deadline.
The Catch-Up Checklist
If your firm hasn’t started, or started and stalled, this is the order that gets you defensible fastest — not perfect, defensible.
Step 1: Inventory every AI system in use
List every tool touching client work, hiring, credit-related advice, or any decision affecting an EU person — including tools staff use informally. This is the step firms skip and the one regulators ask for first.
Step 2: Classify exposure against the risk tiers
For each tool, work out whether it’s unregulated, limited-risk (transparency obligations only), or high-risk (Annex III categories like creditworthiness assessment, employee evaluation, or hiring). Most day-to-day drafting, research, and document-review AI use with a human reviewing output stays out of the high-risk tier — but you need the classification on record, not assumed.
Step 3: Establish who owns this
Governance stalls when nobody has clear authority to enforce it. Name one person — not a committee — with budget and sign-off power over AI tool approval.
Step 4: Fix the highest-risk gaps first
If any system is high-risk, prioritise: human oversight built into the workflow, record-keeping, and an incident-reporting process. These are deployer obligations that already apply, whether or not you built the tool yourself.
Step 5: Check for the SME simplified pathway
If your firm has under 750 employees and under €150 million in annual revenue, you likely qualify for the Act’s simplified compliance framework — reduced conformity assessment fees, simplified technical documentation templates, and lighter quality-management obligations for microenterprises. Most accounting and consulting practices fall well within this threshold. Don’t build a big-enterprise compliance programme when a lighter one is available to you.
Step 6: Document as you go
Even an imperfect inventory and classification, dated and on file, is worth more to a regulator — or an acquirer’s due-diligence team — than nothing. Compliance gaps are now showing up as friction in M&A: firms with undocumented AI exposure are seeing deal delays of three to seven weeks in exclusivity, and valuation discounts of two to five percent in the mid-market, rising as high as fifteen percent where remediation threatens the deal thesis.
€35M or 7% — the maximum fine under the Act for the most serious breaches, whichever figure is higher, calculated against global annual turnover.
The Maths of Catching Up Late
A mid-sized advisory practice with, say, AU$8M in annual revenue is well inside the SME simplified threshold — meaning the actual compliance lift is an inventory, a risk classification, a named owner, and a documented policy, not a full ISO 42001-style management system. That’s realistically a two-to-four week project for a firm that commits to it, not a multi-quarter overhaul.
Compare that to the cost of not doing it: even a mid-market deal-delay of three to seven weeks, or a valuation haircut of a few percentage points, dwarfs the cost of the inventory exercise. And that’s before regulatory exposure enters the picture at all.
What Good Looks Like
A firm that’s caught up has a single, current list of every AI tool in use, a one-page classification against the risk tiers, a named governance owner with real authority, a written policy staff actually know exists, and a habit of documenting new tool approvals as they happen rather than after the fact. None of that requires a compliance department — it requires someone deciding this week is the week it starts.


Leave a Reply
You must be logged in to post a comment.