Beyond the deadline: Why AI governance, not tick-box compliance, will define enforcement readiness

Beyond the deadline: Why AI governance, not tick-box compliance, will define enforcement readiness

Nik Kairinos, CEO & Co-founder, RAIDS AI, says organisations must shift from deadline-driven compliance to long-term AI governance strategies to remain aligned with evolving EU AI Act requirements.

The General Purpose AI (GPAI) obligations under the EU AI Act came into force in August 2025 for models placed on the market after that date and marked a significant moment: the transition from high-level principles to concrete operational requirements.

For many the immediate reaction has been to interpret these obligations as another compliance hurdle to clear. But with the Commission’s enforcement powers relating to GPAI coming into effect in August 2026 this is a risky mindset.

The EU AI Act is being carefully regarded far beyond the EU. Not only is it the first comprehensive legal framework for AI but given the global nature of technology the scope of the Act is wide-reaching. Any AI model used in the EU regardless of where it originates from is covered. This means that AI providers that have customers or partners in the EU or organisations that use AI and have colleagues, partners, teams or stakeholders in the EU must ensure they are fully conversant with the Act. This includes being clear on which regulations they need to comply with and the timelines for each.

While the EU’s enforcement powers relating to GPAI models brought to the market after 2nd August 2025 come into force from August 2026 legacy GPAI models (those already on the market before August 2025) have until August 2027 to comply. Additionally and separate from the GPAI timeframe high-risk AI system obligations were due to apply from August 2026 but the Commission proposed delaying this to December 2027, a proposal which is still being negotiated. These changes show that the regulatory landscape continues to shift and organisations need to be ready to adapt accordingly.

What the GPAI rules actually require

GPAI obligations are not just about documentation and transparency. They signal the start of a regulatory environment where enforcement, legislation and scrutiny will steadily increase. Therefore the real challenge for organisations is building governance frameworks that can evolve alongside the regulation.

The GPAI provisions apply to providers of AI models placed on the market after 2nd August 2025 that are not limited to one specific purpose, competently perform multiple tasks and can be integrated into other systems. They introduce requirements designed to increase transparency, accountability and risk mitigation.

The obligations require organisations to demonstrate technical documentation and record-keeping to show how models are developed, trained and evaluated as well as provide clear information for downstream deployers on capabilities, limitations and intended use. Organisations also need to demonstrate how they identify and mitigate risk particularly where models could be integrated into high-risk systems and that they comply with copyright including measures related to the use of training data. Furthermore they need to show additional safeguards for systemic-risk models including advanced testing, incident reporting and cybersecurity measures.

The risk is that organisations having put the pieces in place to meet all these obligations consider the job complete.

Why tick-box compliance isn’t enough

Just as AI continues to evolve at pace the rules governing it will evolve too. This means the compliance standard is unlikely to remain static and that beyond their immediate compliance requirements organisations should reflect on the strategic implications of the AI Act. In this way they can make the move from deadline-driven compliance to long-term AI risk and governance readiness.

As noted guidance is continually evolving and companies that design governance around a fixed interpretation of today’s rules may find themselves non-compliant as specifications change. The early enforcement actions under GDPR provide a useful precedent: initial uncertainty followed by high-profile cases that clarified expectations and raised the stakes.

Treating AI compliance as a legal add-on can mean that it is treated in isolation and result in siloed processes disconnected from other functions such as procurement or risk management. This is dangerous because AI is proliferating in organisations quickly and a continuous holistic overview of how and where it is used is needed across different departments to ensure comprehensive compliance.

Indeed compliance and the connected potential for sanctions are only one dimension. The inability to accurately monitor AI could also result in public scrutiny and reputational damage with a knock-on impact on stakeholder, investor and customer trust the financial implications of which are far-reaching and difficult to calculate.

A strategic approach to AI governance is also important because the EU AI Act is not the only AI legislation in development. The US approach is far more patchwork – combining existing laws, new initiatives and non-binding principles such as the ‘Blueprint for an AI Bill of Rights’, while in the UK an AI Bill is still in the early stages. Those who have taken a holistic approach to understanding governance of their AI will likely be better placed to adapt to new legislation as it comes to fruition.

From deadline-driven compliance to governance readiness

So how can organisations practically move beyond deadline-driven compliance? A shift from reactive compliance to sustainable AI governance frameworks embedded at the board and operational levels is key.

Fundamentally AI governance must have executive ownership. CIOs, Chief Risk Officers and boards need defined accountability structures that extend across the AI lifecycle from procurement and development to deployment and monitoring. Not only does this give clarity of responsibility but it also signals to employees, stakeholders, partners and customers that governance and compliance are a core thread running through an organisation and everything it does.

These internal reporting and ownership structures are also important because AI systems are not static and frameworks must include mechanisms for ongoing monitoring, performance validation and risk reassessment which continually adapt to the systems they govern. Many organisations are continually changing and expanding how they use AI; models evolve, use cases expand and data changes. AI failures can happen quickly and without warning so users need to make sure that there is no lapse between deployment of a new model or a change to how it is used and is being monitored. Similarly organisations must also map their AI supply chains: which vendors provide models, what their compliance strategies and processes are and how that is documented and this also needs to be continually updated.

The frameworks that define AI monitoring also need to integrate with broader enterprise risk frameworks so that cybersecurity, data protection, operational resilience and AI risk are addressed cohesively.

As enforcement matures authorities are likely to scrutinise incident response processes and audit trails. Companies should be able to demonstrate not only that they identified risks but also how they mitigated them and what lessons were learned.

Beyond futureproofing for evolving regulations organisations that invest early in robust governance frameworks will not only reduce regulatory risk; they will gain a strategic advantage. As regulatory rules change they will have less to do in order to catch up. And as compliance becomes more important customers and other parties such as investors and partners will increasingly demand transparency about how AI systems operate.

The EU Commission’s enforcement powers in relation to GPAI models begin in August 2026 which include fines, model recalls and other regulatory actions. For CIOs and business leaders the central question is not whether they are ready for the deadline but whether their organisation can adapt as regulatory expectations evolve.

The organisations that treat AI governance as a strategic function not a regulatory afterthought will be the ones still scaling AI confidently when the first major enforcement actions land.

Browse our latest issue

Intelligent CIO Europe

View Magazine Archive