Article

The AI governance readiness gap: what the data says, and shere to start

Most organisations aren't ready for the EU AI Act. See what PwC, EY, and Vision Compliance found, and the 5 steps to build AI governance now.
EU AI Act readiness
August 20, 2026
AI governance
AI regulation
AI risk management

The EU AI Act's transparency rules became enforceable on 2 August 2026, but the Digital Omnibus pushed high-risk obligations to December 2027. Despite the extra runway, PwC found only 14% of organisations are fully prepared, Vision Compliance found 74% have no designated AI compliance owner, and EY found 52% of banks name governance as their top AI adoption challenge. The fix starts with one step: build a single model and AI inventory, then classify, assign ownership, document, and monitor from there.

On 2 August 2026, the EU AI Act entered its toughest phase yet. Transparency obligations under Article 50 became enforceable. The AI Office and national authorities got active enforcement powers over general-purpose AI models. At the same time, the Digital Omnibus pushed the high-risk obligations for standalone AI systems (Annex III, covering credit scoring, hiring, and critical infrastructure) to 2 December 2027, and high-risk AI embedded in regulated products to August 2028.

For risk and compliance teams, that combination is confusing. Some obligations are live today. The hardest ones are delayed, but not cancelled. And a longer runway is easy to mistake for less urgency, when it should mean the opposite: more time to get the foundations right before the December 2027 deadline arrives.

What the numbers say

Most organisations are further behind than they realise. PwC's Responsible AI Survey found that only 14% of organisations consider themselves fully prepared for the EU AI Act, and a further 70% describe themselves as only partially prepared. That's not a small gap to close before December 2027. It's the majority of the market.

The reason readiness stalls so often comes down to something more basic than the regulation itself: nobody owns it yet. Vision Compliance's 2026 EU AI Act Readiness Analysis found that 78% of organisations had not taken meaningful steps toward compliance, and traced much of that back to a single root cause: 74% had no designated internal owner or governance body for AI compliance at all. Without a name attached to a model or use case, there's no one to classify it, document it, or defend it to a regulator.

Financial institutions are typically ahead of the general market on model governance, given decades of MRM discipline. Even so, EY's Responsible AI Pulse Survey found that 52% of banks name governance as their single biggest challenge in adopting AI. That's a sign that AI is moving into the organisation faster than the controls built for traditional models can absorb it, and that the gap isn't a compliance footnote. It's a structural one.

Why the Digital Omnibus delay doesn't change the answer

The postponement of Annex III high-risk obligations to December 2027 is real, and it's welcome breathing room for many teams. But three things haven't changed:

The organisations that use this window to build the foundations will meet the December 2027 deadline as a formality. The ones that wait will be doing in a few months what should have taken a year.

How to get started

You don't need to solve AI governance in one sweep. You need to build it in the right order.

1. Build one model and AI inventory. Every model, every AI use case, every owner, in one place. This is the foundation every other requirement sits on top of.

2. Classify risk before you document. Not every AI system is high-risk under the EU AI Act, and treating them all the same wastes effort. Classify first, then apply the right depth of validation and documentation to each tier.

3. Assign clear ownership. This is where Vision Compliance's research shows most organisations stall. Model owners, validators, and approvers need to be named, not implied.

4. Make documentation continuous, not a scramble. Technical documentation, validation evidence, and monitoring records should be generated as part of the model lifecycle, not assembled the week before an audit.

5. Monitor what's in production. Governance doesn't end at deployment. Ongoing model monitoring is what turns a compliance exercise into real oversight, and it's what regulators and internal auditors will ask to see first.

This is, in practice, what Model Risk Management already does well, and why AI governance and MRM are converging rather than running as separate disciplines. Yields brings model inventory, risk classification, validation, documentation, and monitoring into one platform, so AI governance doesn't mean starting from scratch. It means extending a structure that's already audit-ready by design.

The Digital Omnibus bought the market time. What PwC, Vision Compliance, and EY's numbers show is that most organisations haven't used it yet. That's the opportunity.

Frequently asked questions

What changed in the EU AI Act on 2 August 2026?

Transparency obligations under Article 50 became enforceable, covering AI-generated content disclosure, chatbot disclosure, and deepfake labelling. The AI Office and national authorities also gained active enforcement powers over general-purpose AI (GPAI) models. Fines for non-compliance can reach €15 million or 3% of global annual turnover, whichever is higher.

Did the EU AI Act's high-risk rules get delayed?

Yes. The Digital Omnibus, adopted as Regulation (EU) 2026/1744, moved the compliance date for high-risk standalone AI systems (Annex III, including credit scoring and hiring) to 2 December 2027. High-risk AI embedded in already-regulated products (Annex I, such as medical devices and machinery) was moved to 2 August 2028.

Are organisations ready for the EU AI Act?

No, most are not. PwC found only 14% of organisations are fully prepared, with a further 70% only partially prepared. Vision Compliance found 78% had not taken meaningful compliance steps, largely because 74% had no designated internal owner for AI compliance.

How should a financial institution start building AI governance?

Start with a single inventory of every model and AI use case, then classify each by risk level, assign named owners, generate documentation continuously as part of the model lifecycle, and monitor systems once they're in production. This is the same structure Model Risk Management already applies to traditional models.

Is AI governance the same as Model Risk Management (MRM)?

They overlap significantly. Both require an inventory, risk-based classification, validation, documentation, and ongoing monitoring across a system's lifecycle. Organisations with mature MRM practices can extend that structure to AI governance rather than building a separate function from scratch.

About the

Author(s)

Lotte Van Deyck Yields
Lotte Van Deyck
Head of Marketing

Start your AI Governance journey today

Related Articles

Article

Model Risk Classification in the Yields MRM Suite

Read more
Model Risk Classification in the Yields MRM Suite
Article

The consequences of IFRS9 on Model Risk

Read more
The consequences of IFRS9 on Model Risk
Article

Best Model Validation Automation Platform

Read more
Best Model Validation Automation Platform
No items found.