Sprggun

Mobile Navigation Menu

The EU AI Act: Six months towards Minimal Defensible Position

1 October 2026

Emma Di iorio | CEO & Co-founder, Spriggun

Last week I moderated a session at the AI Regulation Forum in Brussels, with co-panellists from the European Commission (DG Connect), the AI Unit at the European Data Protection Supervisor (EDPS) and Coimisiún na Meán, Ireland's national media regulator. The conversation went beyond the text of the EU AI Act itself, into how enforcement, supervision and cross-border coordination are actually forming. For anyone advising a board on AI governance, this is where the practical questions sit right now.

The question I closed the session with was: what should organisations prioritise in the next six months? One of the key discussion points was around inventory; knowing what AI the organisation actually uses. This is an expected key topic, but many organisations are still running forward with significant human resource and spend on AI, with foundations made of sticks and no clear return on the investment; not just the financial case, but in whether AI is actually freeing capacity and making the organisation more effective. This article is my answer to the next six months, and inventory sits at the centre.

Let's begin with what the Act is trying to achieve. Strip away the recitals, the annexes and the classification system, and the core objective is narrow: reduce the risk of harm to the people affected by AI systems. The Act regulates use, impact and risk of harm, not technology for its own sake. Leadership that understands this will make better decisions about where to invest time and resource, than one that treats the regulation as a checklist imposed from outside.

Am I caught?

For any organisation established in the EU or EEA: yes. For any organisation outside the EU that places an AI system on the EU market, or deploys a system whose output reaches EU natural persons: also yes. The Act follows the same extraterritorial logic as GDPR; the regulation follows the impact, not the incorporation. A UK company whose customer-facing chatbot serves EU users is within scope. A US software provider whose product is used by an EU-based deployer is within scope; some of the largest US providers are positioning as though the Act does not apply to them - including the loud absence at the White House lunch on self-regulation this week - but where their systems are used by EU deployers or reach EU users, it does. For a business with EU customers, EU employees or EU-facing products: assume you are caught unless you can demonstrate otherwise.

The Act assigns obligations by role. A provider develops an AI system or places it on the market; a deployer uses one under its own authority; an importer brings a third-country system into the EU market; a distributor makes it available in the supply chain. Most organisations will be deployers, but the boundary is not always where they assume.

Even where the Act does not apply, much of the preparatory work is still worth doing. The inventory, the data mapping and the risk classification overlap with privacy, product liability, sector regulation and board fiduciary duties. The absence of specific AI legislation does not mean the absence of accountability for AI-caused harm; the goal is getting your house in order. In the EU, the Act does not sit alone. GDPR, NIS2, the Digital Markets Act, the Digital Services Act and sector-specific rules all apply to the same AI systems. A board that starts from what the business actually does builds the evidence once and deploys it across every regime it faces. For organisations operating across multiple EU Member States, a single consolidated framework - with specific national variations if required - is essential. A programme per Member State is not viable.

What is already live

The Digital Omnibus on AI - targeted amendments to the Act, adopted in July 2026 - pushed back high-risk system deadlines. The relief is real for many, but it did not defer everything. Three sets of obligations are already in force, and a fourth follows on 2 December 2026.

Prohibited practices have applied since February 2025. The Act bans a specific list of AI uses outright (under Art 5). The prohibitions most likely to catch private-sector organisations by surprise are emotion recognition - for example, a wellbeing tool that scores mood from camera data - or biometric categorisation by protected characteristics, such as a system that infers race or religion from facial or voice data. One of the main risks is shadow AI, for example a team using an off-the-shelf tool with features it did not specifically procure. A prohibited practices review is not optional, rather it is overdue.

The screening exercise is not a significant job, and it is a key priority: check each prohibited practice against actual AI uses, then confirm the position with function owners. The board receives a short paper: what was checked, what was found, what was stopped or confirmed as not in use. The concept of Minimal Defensible Position (MDP) - meeting minimum requirements across the legislation you're subject to - runs through this article, the goal for the next six months is not perfection.

AI literacy (Article 4) has also applied since February 2025. The Omnibus softened the wording, but the obligation remains: organisations must take measures to support AI literacy among staff who operate or use AI systems. Catch-all training is the starting point; tailored by function after that, prioritising those closest to the risk of harm. The Act sets the floor, not the ceiling. Fluency is broader than a training programme, and is needed cross-organisation; the board included.

A separate set of provider obligations for general-purpose AI models on the EU market has applied since August 2025. Most organisations are deployers, not providers, but the distinction is not always clean. The Commission's guidelines set a compute threshold at one-third of the original training resources; above it, a modifier becomes a provider. Any organisation fine-tuning, retraining or adapting a model should review its position.

Transparency and synthetic content obligations (Article 50) apply to deployers on separate deadlines. The transparency duty has applied since August 2026: where a system interacts directly with people, with the most common example a customer-facing chatbot.

The synthetic content marking obligation follows on 2 December: AI-generated text, images, audio and video must carry machine-readable metadata identifying them as synthetic; how much human editing removes that obligation is not yet settled. For many organisations, retrofitting this into existing content pipelines is a significant technical challenge. For both obligations, start with working out which systems are in scope.

Why buying a tool does not work

The instinct, when faced with a regulation of this complexity, is to buy something: a governance platform; a compliance dashboard; a vendor risk tool. This is understandable, but generally premature. A tool only operates on what an organisation already knows; it cannot classify what has not been inventoried or surface shadow AI - AI adopted without the organisation's knowledge or approval. The starting point is knowing your business: which decisions does AI inform; what data feeds those systems; who is affected by the output. AI does not fix bad data; it scales it. Know Your Data and Know Your AI (KYD; KYAI). Without both, there is no firm foundation for anything that follows.

Third-party risk compounds this. A vendor's AI system is regulatory exposure for the buyer; the Act holds the deployer accountable, not the vendor. Most assume the vendor takes the regulatory burden, but contractual indemnities do not shift it.

The partial deadline delay is not a reason to pause

High-risk system obligation deadlines have been pushed back; for stand-alone high-risk systems - for example, AI used in recruitment, credit scoring, insurance underwriting, or access to essential services - to December 2027; and for systems embedded in regulated products to August 2028. The temptation is to treat this as a reason to wait. Waiting is a risk. Even as a deployer, applying an existing model to any of these high-risk functions will trigger mandatory Fundamental Rights Impact Assessments and extensive logging from December 2027. Most have not started reviewing their position.

Governance takes time to do properly once, and then build upon; it cannot be rushed before a deadline. AI-caused harm in 2026 is still caught by existing law: GDPR, product liability, anti-discrimination, fundamental rights and sector regulators. Most organisations have started one or two of the governance elements needed, and built them badly; a badly scoped element creates a discoverable record of knowing the obligation and not meeting it. The delay is preparation time, not waiting time.

The signal from regulators is collaboration before enforcement. This is to be welcomed. The codes of practice, the AI Pact and the regulatory sandboxes all invite meaningful engagement while the relationship is still forming. The AI Pact, currently an underused resource, invites voluntary commitments ahead of the legal deadlines, and participation signals willingness to engage. The inventory, the classification decisions and the board position on AI are key elements in demonstrating you know what you're doing, and haven't just picked up a boilerplate policy, using control-f to replace the org name. The paper shield protects the organisation that has done the work, and exposes the one that has described what should happen while doing something else. This matters commercially too; at least one party in the supply chain may already be asking for evidence, rather than the old assurances.

Six months towards Minimal Defensible Position

Q4 2026 and Q1 2027 offer a window of opportunity. These are the EU AI Act priorities specifically; a broader governance framework - ownership, policies, reporting - will need to sit alongside them.

Six priorities: two ongoing, four for immediate focus. These are not comfortable timelines; for most organisations, they are ambitious, but they need to be done.

Ongoing programme

  1. AI inventory, classification and role mapping. Every AI use across the organisation: its purpose; the data behind it; who it affects; its risk classification; and whether the organisation is a provider, deployer, importer, or distributor, including for any general-purpose AI models where the boundary is not always where organisations assume it is. There is no AI without data; there is no governance without knowing your AI. The foundation; everything else depends on it. Starts in Q4, deepens through Q1. Does not finish. Ever!

  2. AI literacy. Catch-all training rolled out in Q4; tailored by role and function through Q1 and beyond. Board and leadership upskilling is part of this, enabling everything else on this list and fulfilling the Article 4 mandate.

Priority actions

  1. Prohibited practices review. Screen the Article 5 list against actual AI uses. Verify with business units, not only the compliance function. Document the result. Board to sign-off. Make clear not permitted, company-wide. Already in force, low hanging fruit to reach comfort.

  2. Transparency obligations and synthetic content marking. Identify which systems trigger Article 50 disclosure and which outputs need machine-readable marking. The transparency duty is in force; synthetic content marking follows in December. For many organisations, the synthetic content requirement involves a significant technical change. Scope and prioritise the engineering work now.

  3. Board position on AI use. Expected outcomes; accepted risks; named ownership across functions; and reporting line to the board. The Act distributes obligations across provider, deployer, importer and distributor; a single “AI responsible” does not meet the requirement. The five elements of real governance describe what this framework needs. This is where budget decisions sit.

  4. Codes of practice alignment. Assess against the Commission's published codes of practice. Even though codes do not bind directly, they signal what a regulator will benchmark against. This is also where early thinking on high-risk system preparation begins; the Annex III deadline is December 2027.

Looking ahead, the next six months are strictly about foundations. The twelve months after that will shift toward high-risk compliance documentation, conformity assessment preparation, and managing the conduct risk questions that agentic AI is already raising. Use this foundational window to prepare for the extended EU deadlines: standalone high-risk AI systems (Annex III) require full compliance by December 2027, followed by product-embedded safety systems (Annex I) by August 2028.

The organisations that navigate this best will be the ones that put in firm foundations now, using them to build more easily and quickly in the future, with the “go slow to go fast” approach. Those that start now will have a settled position to build from; the ones that wait will find themselves trying to handle technical deployment and compliance simultaneously under intense regulatory pressure.


Emma Di Iorio is Co-Founder and CEO of Spriggun, a UK-based RegTech and AI governance advisory firm. A qualified solicitor with senior in-house and advisory experience, she writes and speaks internationally on AI, data, privacy, and web compliance.