That's the EU AI Act deadline most organisations are sprinting toward.
Here's what nobody is saying out loud:
Most teams will hit the deadline with documentation.
Not governance.
There's a difference.
Documentation says: "We have a human in the loop."
Governance proves: "Here is what the AI was authorised to decide. Here is
what it actually decided. Here is the evidence that existed at the moment
it acted."
Article 14 of the EU AI Act requires "meaningful human oversight".
Meaningful is doing a lot of work in that sentence.
A human who clicks approve in 3 seconds without context is not meaningful oversight.
A human who cannot stop the workflow before consequence is not in the loop.
A policy document that describes what should happen is not evidence of what did happen.
73% of production AI deployments are vulnerable to prompt injection.
Only 11% of organisations have implemented governance frameworks for AI agents.
Both statistics are from OWASP 2026.
Both will matter to regulators on 3rd August.
The organisations that survive regulatory scrutiny will not be the ones with the best policy documents.
They will be the ones who can open a workflow from last month and show:
What the AI was authorised to decide.
What it actually decided.
Who had authority to approve it.
What evidence existed before it acted.
That is not a compliance exercise.
That is verification architecture.
And most teams haven't built it yet.
2nd August is not the finish line.
It's the starting gun for enforcement.
Himanshu Vaghela
Junior Researcher, LumiRosh Research.

Top comments (0)