← Belian Advisory Get in touch
AI Risk & Governance

AI Governance Just Went Live — And Most Boards Weren't Watching

For three years, AI governance has been homework due at some point later. Frameworks to map against, standards to prepare for, deadlines that always sat comfortably over the horizon. That changed on August 2, 2026.

Since then, the EU has been actively enforcing binding AI rules for the first time. China has fined a dozen companies under its new AI companion regulation. A patchwork of US state laws has moved from statute books into daily compliance reality. What hasn't arrived, though, is the clean, single regime most organisations were quietly hoping for. What's landed instead is fragmented, staggered, and unforgiving of anyone who hasn't read the fine print.

What actually went live on August 2

The EU AI Act's transparency obligations under Article 50 are now being enforced by the European Commission's AI Office and national authorities. These rules are narrower than the Act's headline "high-risk" regime, but they touch far more organisations in practice. Any system that interacts directly with a person now has to make clear it's a machine. Deepfakes and synthetic audio, image, or video need disclosure. Emotion-recognition and biometric-categorisation systems have to tell the people exposed to them that they're being read.

If you provide a generative system, you now need machine-readable provenance — watermarking, metadata, cryptographic markers — built into your outputs as a design decision, not bolted on afterwards. The Commission finalised guidance on July 20 to settle scope questions that had left plenty of mid-sized companies unsure whether their customer-facing chatbot even counted. The AI Office added 38 staff on July 31, four days before enforcement began. Penalties reach €15 million or 3% of global annual turnover, whichever is higher — a ceiling built to matter even to the largest vendors.

Global AI Governance: Live vs. Deferred WHICH RULES ARE ACTUALLY BEING ENFORCED, AS OF AUGUST 2026 US — California SB 53 CA — Frontier model transparency ACTIVE — Jan 1, 2026 China — AI companion rules CN — Crisis intervention, data limits ACTIVE — Jul 15, 2026 EU AI Act — Article 50 EU-T — Transparency & disclosure duties ACTIVE — Aug 2, 2026 US — Colorado SB-205 CO — Algorithmic discrimination ACTIVE — in force EU AI Act — High-risk (Annex III) EU-H1 — Hiring, credit, law enforcement AI DEFERRED — Dec 2, 2027 EU AI Act — High-risk (embedded) EU-H2 — AI in regulated products, e.g. medical devices DEFERRED — Aug 2, 2028 TIMELINE AT A GLANCE 2026 2027 2028 CA CO CN EU-T EU-H1 EU-H2 Actively enforced Deferred, not cancelled
Four jurisdictions, six rules — the ones already live are not the ones most compliance budgets were built around.

The catch nobody's advertising

Alongside this enforcement launch, the EU also finalised its "Digital Omnibus on AI" — a package of amendments, agreed by the Council and Parliament on May 7, 2026, that pushes back the Act's heaviest obligations. High-risk requirements for stand-alone systems — the rules governing AI used in hiring, credit scoring, and law enforcement — now apply from December 2, 2027, more than a year later than planned. High-risk obligations for AI embedded in regulated products, like medical devices, slide to August 2, 2028. The stated reason is candid enough: national authorities weren't designated in time, and the harmonised technical standards needed to test compliance don't exist yet.

A deadline that moves is not a deadline that disappears. The conformity assessments, risk-management files, and human-oversight documentation you'll eventually need don't build themselves in the weeks before enforcement starts.

It's not just Brussels

China's first national rules for AI companion services took effect July 15, 2026, requiring emotional-distress detection, crisis-intervention capability, and limits on training with sensitive data drawn from companion conversations. Enforcement has been fast and public — twelve companies fined a combined 4.2 million RMB in the rule's first week, with ByteDance, Alibaba, and Tencent restricting or shutting down companion products rather than risk violating it.

In the US, the absence of federal AI legislation has pushed governance down to the states. California's SB 53 took effect January 1, 2026, and now applies to frontier model developers serving California residents. Colorado's algorithmic discrimination law, SB-205, runs on its own separate track. Neither waited for Washington, and neither is going away because a company happens to be headquartered somewhere else.

Most organisations aren't ready — even for what's already in force

A 2026 assessment spanning eight major industries found that 78% of organisations had taken no meaningful steps toward AI Act compliance. Over half had no basic inventory of the AI systems they actually operate. 74% had no designated owner or governance body for AI compliance. 61% had no process for producing the technical documentation regulators will ask for. Only about 35% of managers surveyed felt adequately prepared. And that's the state of readiness for the narrower transparency rules — not yet the full high-risk regime landing in 2027 and 2028.

What this means if you're not headquartered in Brussels

The practical task now isn't tracking one deadline. It's maintaining a live map of which rules apply where, which are enforced versus merely scheduled, and which team owns the evidence trail when a regulator — in Brussels, Beijing, or Sacramento — comes asking. Most SMEs building or deploying AI across borders don't have that map, because until this year there was nothing forcing them to build it.

This is exactly what an AI management system is for. Not a policy binder that gets updated once a year, but an operating model that already knows which system falls under which regime, who owns the documentation, and what evidence gets produced as a by-product of normal operations rather than assembled in a panic before an audit. Organisations running something like ISO 42001 aren't scrambling every time a new jurisdiction switches on enforcement — they're already producing most of what the regulator wants to see.

The 78% compliance gap is not a reason to relax. It's a head start for the 22% who close it first.


Belian Advisory helps SMEs turn this fragmented governance landscape into a single working operating model — built once, not rebuilt every time a new jurisdiction switches on enforcement. If you don't yet know which of these rules already apply to you, get in touch.