The Compliance Picture at Deadline
The EU AI Act's high-risk AI system requirements — covering documentation, human oversight, transparency, and accuracy standards for systems in sectors like HR, credit, healthcare, and critical infrastructure — reached their formal compliance deadline for large enterprises this month. A survey of 1,200 European companies conducted jointly by Deloitte, PwC, and Bureau Veritas found a more fragmented picture than regulators had hoped.
Only 19% of respondents reported full conformance across all applicable AI systems. 73% self-reported partial conformance — meaning technical documentation and risk management procedures exist but at least one system still lacks a completed conformity assessment or an appointed EU AI oversight contact. 8% acknowledged being materially non-compliant, mostly smaller enterprises that misclassified their AI use cases as low-risk.
Where the Gaps Are
The most commonly cited gaps were: (1) conformity assessments for AI-assisted HR screening tools, where 41% of companies said external notified-body capacity was insufficient to complete assessments before the deadline; (2) post-market monitoring plans, required for all high-risk AI systems and absent in 35% of cases; and (3) registration in the EU AI Act public database, which 28% had not completed.
Regulators have publicly stated that enforcement in 2026 will focus on the most materially non-compliant cases and sectors, rather than pursuing technical violations across the board. National market surveillance authorities in Germany, France, and the Netherlands are expected to publish enforcement priority lists by September.
Penalties and Outlook
Maximum fines under the Act are €30 million or 6% of global annual turnover. The survey noted that 61% of partially conformant companies expected to reach full conformance within six months, suggesting that most gaps reflect implementation timeline issues rather than design resistance.