The AI governance readiness gap: what the data says, and shere to start

The EU AI Act's transparency rules became enforceable on 2 August 2026, but the Digital Omnibus pushed high-risk obligations to December 2027. Despite the extra runway, PwC found only 14% of organisations are fully prepared, Vision Compliance found 74% have no designated AI compliance owner, and EY found 52% of banks name governance as their top AI adoption challenge. The fix starts with one step: build a single model and AI inventory, then classify, assign ownership, document, and monitor from there.
On 2 August 2026, the EU AI Act entered its toughest phase yet. Transparency obligations under Article 50 became enforceable. The AI Office and national authorities got active enforcement powers over general-purpose AI models. At the same time, the Digital Omnibus pushed the high-risk obligations for standalone AI systems (Annex III, covering credit scoring, hiring, and critical infrastructure) to 2 December 2027, and high-risk AI embedded in regulated products to August 2028.
For risk and compliance teams, that combination is confusing. Some obligations are live today. The hardest ones are delayed, but not cancelled. And a longer runway is easy to mistake for less urgency, when it should mean the opposite: more time to get the foundations right before the December 2027 deadline arrives.
What the numbers say
Most organisations are further behind than they realise. PwC's Responsible AI Survey found that only 14% of organisations consider themselves fully prepared for the EU AI Act, and a further 70% describe themselves as only partially prepared. That's not a small gap to close before December 2027. It's the majority of the market.
The reason readiness stalls so often comes down to something more basic than the regulation itself: nobody owns it yet. Vision Compliance's 2026 EU AI Act Readiness Analysis found that 78% of organisations had not taken meaningful steps toward compliance, and traced much of that back to a single root cause: 74% had no designated internal owner or governance body for AI compliance at all. Without a name attached to a model or use case, there's no one to classify it, document it, or defend it to a regulator.
Financial institutions are typically ahead of the general market on model governance, given decades of MRM discipline. Even so, EY's Responsible AI Pulse Survey found that 52% of banks name governance as their single biggest challenge in adopting AI. That's a sign that AI is moving into the organisation faster than the controls built for traditional models can absorb it, and that the gap isn't a compliance footnote. It's a structural one.
Why the Digital Omnibus delay doesn't change the answer
The postponement of Annex III high-risk obligations to December 2027 is real, and it's welcome breathing room for many teams. But three things haven't changed:
- The transparency and general-purpose AI obligations that took effect on 2 August 2026 are already enforceable, with fines up to €15 million or 3% of global turnover.
- Supervisors, including the EBA and national authorities, are already raising expectations for how financial institutions govern AI, independent of the Act's exact enforcement calendar.
- Building an AI inventory, a risk classification process, and audit-ready documentation takes months, not weeks. Starting in late 2027 is not a plan.
The organisations that use this window to build the foundations will meet the December 2027 deadline as a formality. The ones that wait will be doing in a few months what should have taken a year.
How to get started
You don't need to solve AI governance in one sweep. You need to build it in the right order.
1. Build one model and AI inventory. Every model, every AI use case, every owner, in one place. This is the foundation every other requirement sits on top of.
2. Classify risk before you document. Not every AI system is high-risk under the EU AI Act, and treating them all the same wastes effort. Classify first, then apply the right depth of validation and documentation to each tier.
3. Assign clear ownership. This is where Vision Compliance's research shows most organisations stall. Model owners, validators, and approvers need to be named, not implied.
4. Make documentation continuous, not a scramble. Technical documentation, validation evidence, and monitoring records should be generated as part of the model lifecycle, not assembled the week before an audit.
5. Monitor what's in production. Governance doesn't end at deployment. Ongoing model monitoring is what turns a compliance exercise into real oversight, and it's what regulators and internal auditors will ask to see first.
This is, in practice, what Model Risk Management already does well, and why AI governance and MRM are converging rather than running as separate disciplines. Yields brings model inventory, risk classification, validation, documentation, and monitoring into one platform, so AI governance doesn't mean starting from scratch. It means extending a structure that's already audit-ready by design.
The Digital Omnibus bought the market time. What PwC, Vision Compliance, and EY's numbers show is that most organisations haven't used it yet. That's the opportunity.
About the
Author(s)


