AI Governance Just Went Live — And Most Boards Weren't Watching
For three years, AI governance has been homework due at some point later. Frameworks to map against, standards to prepare for, deadlines that always sat comfortably over the horizon. That changed on August 2, 2026.
Since then, the EU has been actively enforcing binding AI rules for the first time. China has fined a dozen companies under its new AI companion regulation. A patchwork of US state laws has moved from statute books into daily compliance reality. What hasn't arrived, though, is the clean, single regime most organisations were quietly hoping for. What's landed instead is fragmented, staggered, and unforgiving of anyone who hasn't read the fine print.
What actually went live on August 2
The EU AI Act's transparency obligations under Article 50 are now being enforced by the European Commission's AI Office and national authorities. These rules are narrower than the Act's headline "high-risk" regime, but they touch far more organisations in practice. Any system that interacts directly with a person now has to make clear it's a machine. Deepfakes and synthetic audio, image, or video need disclosure. Emotion-recognition and biometric-categorisation systems have to tell the people exposed to them that they're being read.
If you provide a generative system, you now need machine-readable provenance — watermarking, metadata, cryptographic markers — built into your outputs as a design decision, not bolted on afterwards. The Commission finalised guidance on July 20 to settle scope questions that had left plenty of mid-sized companies unsure whether their customer-facing chatbot even counted. The AI Office added 38 staff on July 31, four days before enforcement began. Penalties reach €15 million or 3% of global annual turnover, whichever is higher — a ceiling built to matter even to the largest vendors.
The catch nobody's advertising
Alongside this enforcement launch, the EU also finalised its "Digital Omnibus on AI" — a package of amendments, agreed by the Council and Parliament on May 7, 2026, that pushes back the Act's heaviest obligations. High-risk requirements for stand-alone systems — the rules governing AI used in hiring, credit scoring, and law enforcement — now apply from December 2, 2027, more than a year later than planned. High-risk obligations for AI embedded in regulated products, like medical devices, slide to August 2, 2028. The stated reason is candid enough: national authorities weren't designated in time, and the harmonised technical standards needed to test compliance don't exist yet.
It's not just Brussels
China's first national rules for AI companion services took effect July 15, 2026, requiring emotional-distress detection, crisis-intervention capability, and limits on training with sensitive data drawn from companion conversations. Enforcement has been fast and public — twelve companies fined a combined 4.2 million RMB in the rule's first week, with ByteDance, Alibaba, and Tencent restricting or shutting down companion products rather than risk violating it.
In the US, the absence of federal AI legislation has pushed governance down to the states. California's SB 53 took effect January 1, 2026, and now applies to frontier model developers serving California residents. Colorado's algorithmic discrimination law, SB-205, runs on its own separate track. Neither waited for Washington, and neither is going away because a company happens to be headquartered somewhere else.
Most organisations aren't ready — even for what's already in force
A 2026 assessment spanning eight major industries found that 78% of organisations had taken no meaningful steps toward AI Act compliance. Over half had no basic inventory of the AI systems they actually operate. 74% had no designated owner or governance body for AI compliance. 61% had no process for producing the technical documentation regulators will ask for. Only about 35% of managers surveyed felt adequately prepared. And that's the state of readiness for the narrower transparency rules — not yet the full high-risk regime landing in 2027 and 2028.
What this means if you're not headquartered in Brussels
The practical task now isn't tracking one deadline. It's maintaining a live map of which rules apply where, which are enforced versus merely scheduled, and which team owns the evidence trail when a regulator — in Brussels, Beijing, or Sacramento — comes asking. Most SMEs building or deploying AI across borders don't have that map, because until this year there was nothing forcing them to build it.
This is exactly what an AI management system is for. Not a policy binder that gets updated once a year, but an operating model that already knows which system falls under which regime, who owns the documentation, and what evidence gets produced as a by-product of normal operations rather than assembled in a panic before an audit. Organisations running something like ISO 42001 aren't scrambling every time a new jurisdiction switches on enforcement — they're already producing most of what the regulator wants to see.
The 78% compliance gap is not a reason to relax. It's a head start for the 22% who close it first.
Belian Advisory helps SMEs turn this fragmented governance landscape into a single working operating model — built once, not rebuilt every time a new jurisdiction switches on enforcement. If you don't yet know which of these rules already apply to you, get in touch.