Share this webinar
Close your data and AI skills gap
We're the only platform uniquely engineered to advance data and AI skills across your entire organization. Let's explore a tailored program.
Book an Enterprise DemoDeadline Approaching: EU AI Act Compliance for High-Risk AI Systems
July 2026Your Presenter(s)

Jessica Eaves Mathews
Managing Attorney at Leverage Legal Group
Jessica leads Leverage Legal Group, a national boutique law firm helping businesses navigate trademark, IP, privacy, and emerging AI legal frameworks. With over 30 years of experience advising companies from startups to Fortune 500s — including work for DirectTV, Coca-Cola, and DreamWorks — she specializes in cross-border AI compliance across US, UK, and EU jurisdictions. Jessica also teaches lawyers how to ethically integrate AI into their practices.

Jason M. Loring
Partner at Jones Walker
Jason co-chairs the Privacy, Data Strategy and Artificial Intelligence team at Jones Walker, helping organizations build AI governance programs and navigate global data privacy regulations. He focuses on EU AI Act compliance, data protection risk, and the intersection of privacy and AI across international markets. Jason is a frequent writer and commentator on emerging AI legislation, including high-risk AI system requirements and cross-border compliance obligations.

Avani Desai
CEO at Schellman
Avani runs Schellman, a compliance services company, which audits the AI capabilities of OpenAI, Meta, and Walmart. She has two decades of experience as an executive in technology risk, cybersecurity, and compliance assessment.
Summary
The EU AI Act's next deadline lands this Saturday, August 2, and it's not the one most companies spent the past year preparing for.
A "digital omnibus," published the day before this webinar, pushed back the compliance timeline for high-risk AI systems while leaving a separate set of transparency rules untouched. In a DataCamp webinar, host Richie Cotton spoke with three compliance specialists: Avani Desai, CEO of audit firm Schellman; Jason M. Loring, a partner at Jones Walker who co-chairs the firm's privacy, data strategy, and AI team; and Jessica Eaves Mathews, managing attorney at Leverage Legal Group. They covered what changes this week, what doesn't, and what companies outside the EU still need to do about it: how the Act classifies AI systems by risk, who counts as a "provider" versus a "deployer," what penalties look like on paper versus in practice, and why a new staff literacy requirement got softened days before taking effect.
Key Takeaways
- The EU AI Act regulates how an AI system is built, trained, deployed, and changed over its entire lifecycle, not just the underlying model.
- Obligations depend on role: a provider builds or brands an AI system, a deployer uses someone else's system in its business, and a company can slide from deployer into provider by heavily customizing or white-labeling a model without realizing it.
- Transparency obligations, including disclosing AI-generated content, chatbots, and deepfakes, take effect on August 2 as originally planned.
- The general compliance deadline for high-risk AI systems has been delayed: standalone high-risk systems now have until December 2, 2027, and AI embedded in already-regulated products, such as medical devices or machinery, has until August 2, 2028.
- Fines can reach €35 million or 7% of global turnover for prohibited practices, but the panel argued that reputational damage, stalled procurement deals, and contractual exposure carry a bigger practical risk than the fines themselves.
- A last-minute amendment softened the Act's staff AI-literacy requirement from a guarantee of understanding to a good-faith effort, except for companies deploying high-risk systems, where stricter training obligations still apply in full.
- Legal experts recommend that even US-only businesses treat the EU AI Act as a best-practice baseline, since state AI laws increasingly follow its lead the way they once followed GDPR.
Deep Dives
A lifecycle law, not a privacy law
The panel opened by drawing a line between the EU AI Act and privacy regulations like GDPR. "The best way to say is the EU AI act regulates the life cycle of an AI system, not just the algorithm," Desai said, pointing to how it covers development, training, validation, market placement, deployment, monitoring, and modification. The Act also spreads responsibility across the supply chain, assigning different obligations to providers, deployers, importers, distributors, product manufacturers, and downstream integrators.
That distinction matters most at the provider-deployer line. A provider builds an AI system or puts it on the market under its own name. A deployer, in Mathews' words, "is a company that is using an AI system in their business," licensing a chatbot, an image generator, or a hiring tool built by someone else. The line blurs quickly. Mathews warned that "there are a meaningful number of deployers that can cross the line into being providers without realizing it because they are white labeling a model," heavily customizing it, or marketing its output as their own.
The Act's reach is global. Loring noted that a US headquarters offers no shelter: the law applies based on a targeting test similar to GDPR's, so any organization reaching EU individuals needs to work out where its systems fall in the classification framework, asking, as he put it, "is it even subject to the act? Right? Is it in scope?" before assuming a compliance path.
Four risk tiers, one central question
Rather than regulating AI technology broadly, the Act sorts specific use cases into four risk tiers. At the top sit prohibited practices, banned outright under Article 5 since February 2025: social scoring, manipulative techniques, exploiting vulnerable people, and untargeted facial-image scraping. Desai called these the uses that "when you read it, you just kinda feel like that's a little bit creepy."
Below that sits high-risk AI, split into two routes. The first covers AI embedded in products already regulated under EU safety law: machinery, medical devices, toys, vehicles. The second covers standalone systems used in eight specific areas: biometrics, critical infrastructure, education and vocational training, employment and worker management, access to essential services like credit and insurance, law enforcement, migration and border control, and administration of justice. Mathews explained that these two routes now carry different deadlines: August 2028 for embedded products, December 2027 for standalone high-risk systems.
Below high-risk sit systems with transparency obligations. These don't require the full high-risk control stack, but they do require telling users they're interacting with AI-generated or AI-manipulated content. Everything else falls into minimal risk. Desai cautioned that classification "can't be a one time label attachment to the model": it has to track the documented system boundary, including what data feeds it, what decisions it can influence, and whether a human reviews the output.
What the EU AI Act's August 2 deadline actually changes
Despite the delay to high-risk deadlines, the Article 50 transparency obligations still take effect August 2 as planned. Mathews walked through five scenarios that trigger a disclosure requirement. Chatbots and AI assistants must tell users they're talking to AI "either right at the start of or right before the start of that interaction," using a visible, persistent indicator rather than a line buried in a settings menu or terms of service. Her guidance for anyone running a conversational bot: "if you have a chatbot on your website that talks in a natural language, just assume it doesn't qualify for the exception."
The other four scenarios cover AI-generated marketing content, which needs labeling; emotion-recognition and biometric-categorization systems, which must disclose their use to the people being analyzed; deepfakes, where any AI-generated or AI-altered audio, video, or image of a real person needs a disclosure; and AI-generated text published for public information purposes, such as articles or white papers, unless a human has reviewed it and taken editorial responsibility.
Loring confirmed the split directly: "the deadline is still August 2" for the transparency rules, but "the general deadline for complying with the high risk regime is not August 2. That's all been pushed back" as a result of the digital omnibus published the day before the panel recorded.
EU AI Act high-risk requirements: the deadline moved, the work didn't
For companies building or deploying high-risk systems, the extra runway is not a reason to stop working. Deployers of high-risk systems carry affirmative obligations under Article 26: they must use the system according to the provider's instructions, assign human oversight to people with the authority and training to challenge the system, monitor its performance, and report serious incidents. Desai pushed back on a common shortcut: clicking approve after an AI system has already shaped the entire decision doesn't count as oversight. The person reviewing a decision, she said, needs enough information, authority, and time "to challenge the system."
Speaking as an auditor, Desai laid out five things her firm checks: a documented risk-management process covering intended purpose and failure modes; data governance covering lineage, labeling, and bias testing; technical documentation that can reconstruct which model version and data sources were used for a given decision; logging that captures model inputs, outputs, retrieval sources, and human overrides; and meaningful human oversight. Loring added that these obligations typically live in contracts too: agreements need to define roles, specify what happens when a provider changes its model, and build in the oversight mechanisms deployers must maintain.
Desai's advice for the extra time: build an AI inventory, test disclosure timing, and review third-party model contracts before the new deadlines arrive. As she put it, "I don't think anyone should view this as an extra year. I think you should view it as an opportunity to really mature your AI governance program."
EU AI Act penalties: the fines, and the bigger risk behind them
The Act's formal penalty structure has three tiers: up to €35 million or 7% of worldwide turnover for prohibited practices, up to €15 million or 3% for violations of core provider and deployer obligations, and up to €7.5 million or 1% for supplying misleading information to a regulator. Loring noted these are ceilings, not typical outcomes, since regulators weigh severity, duration, and intent before settling on a number.
The more consequential risk sits outside the fine schedule. Loring pointed to reputational and market damage as "the real impact, what happens in the market, into your reputation," particularly since AI governance expectations are still forming. Desai added that regulators can force a company to suspend or withdraw an AI system from the EU market entirely, and that enterprise buyers increasingly demand proof of AI governance during procurement, much as SOC 2 and ISO 27001 became standard requirements before them. A compliance gap can also surface as evidence in unrelated disputes, from employment discrimination claims to consumer protection complaints.
One requirement got easier just before taking effect. Article 4's AI literacy rule originally required companies to ensure staff had a sufficient understanding of the systems they use. A last-minute amendment changed that to a good-faith effort, with Mathews noting the new language means companies are "basically not required to guarantee any particular level of understanding," except for staff working on high-risk systems, where the stricter Article 26 training requirements still apply in full. Desai recommended role-based literacy over blanket annual training: board members need to understand governance risk, developers need to understand model drift and data leakage, and HR teams need to understand automation bias.
Connexe
webinar
AI Regulations to Watch Out For in 2026
Industry experts unpack the major AI regulations you need to know about in 2026. You’ll learn how to interpret existing frameworks like the EU AI Act, what new rules are on the horizon, and how to stay compliant and mitigate risk.webinar
The EU AI Act: How Will It Affect Your Business?
Dan Nechita, EU Director for the Transatlantic Policy Network, and Lily Li, Founder and Lawyer at Metaverse Law, explain what the legislation involves, how it will affect your business, and how to comply with the legislation.webinar
EU AI Act Readiness: Meeting Your Organization's AI Literacy Requirements
Anandhi, CRAIO at Esdha and Will, a Senior Associate at Ashurst, teach you how you and your organization can comply with the AI literacy clause of the EU AI Act.webinar
Understanding Regulations for AI in the USA, the EU, and Around the World
In this session, two experts on AI governance explain which AI policies you need to be aware of, how governments are treating AI regulation, and how you need to deal with them.webinar
US AI Regulations vs. The EU AI Act
Odia Kagan, a Partner at Fox Rothschild, and Julie Honor, a Counsel at Thompson Hine, outline what the EU AI Act and US AI regulations involve and how to comply with them.webinar
