The European Commission states that the AI Act became broadly applicable on 2 August 2026, with enforcement powers active for the AI Office and national authorities. Article 50 transparency obligations also apply from 2 August 2026. Some high-risk obligations apply later: sensitive-area Annex III rules from 2 December 2027 and product-embedded Annex I rules from 2 August 2028 under the 2026 simplification timeline.
Six readiness domains organisations should be able to evidence
2026 regulatory and standards snapshot
12-question readiness scorecard
Score each item 0 = not started, 1 = partial/inconsistent, or 2 = evidence in place and owned. The maximum is 24. The downloadable CSV includes fields for owner, evidence link and review date.
- Do we maintain a current inventory of material AI systems and use cases?
- Does every material use case have a named business owner and technical/security contact?
- Have we documented our AI Act role and screened for prohibited or high-risk relevance?
- Have we identified the transparency duties that apply to each relevant system?
- Are users clearly informed when they are interacting with AI where required?
- Do we have documented rules for AI-generated or manipulated content where Article 50 is relevant?
- Have material suppliers been reviewed for data use, security, access, retention, incidents and exit?
- Are identity, permissions, logging and monitoring appropriate to the sensitivity of each use case?
- Is human review responsibility explicit for decisions, outputs or workflows that can materially affect people?
- Is role-based AI literacy training documented for relevant staff?
- Do we retain approvals, tests, exceptions and incident/corrective-action evidence?
- Do model, supplier, data or purpose changes trigger a defined reassessment?
0–8: foundational evidence is missing. 9–16: governance exists but is fragmented or inconsistent. 17–20: a managed baseline exists with material gaps to close. 21–24: a strong evidence baseline is in place — but system-specific legal, security and assurance work may still be required.
Methodology and limitations
- Source selection: primary official sources are preferred for legal timing and framework descriptions.
- Synthesis: SundAI converts those sources into six operational evidence domains and a 12-question self-assessment.
- No sample: no organisations were surveyed for this version, so the score bands are maturity heuristics, not peer benchmarks.
- No legal equivalence: a strong score does not prove AI Act compliance, ISO conformity or security effectiveness.
- Update discipline: the brief is dated because regulatory guidance and standards can change; verify material decisions against current primary sources.
Primary sources
- European Commission — AI Act application timeline
- European Commission — Article 50 transparency guidelines
- European Commission — Article 50 FAQ
- ISO — ISO/IEC 42001:2023
- NIST — AI Risk Management Framework
Reviewed 5 September 2026. SundAI interpretation is clearly separated from the underlying official sources.
Cite this brief
SundAI (2026), European AI Governance Readiness Brief 2026, version 1.0, reviewed 5 September 2026. https://sundaibot.com/resources/european-ai-governance-readiness-2026/
If you quote a legal date or obligation, cite the underlying European Commission or EUR-Lex source as well as this synthesis.
Turn the scorecard into an operating model
SundAI can help translate identified gaps into owners, evidence, controls and a proportionate implementation roadmap.
Explore AI Governance →