Artificial intelligence (AI) is a key technology in the digital transformation and is already present in many products and processes today. Trust in the reliability, transparency and fairness of AI is so crucial for widespread use that the European Union has drafted its own regulation for AI: the EU AI Act. The regulation aims to set rules for AI systems, promote innovation and protect EU citizens.
With the Digital Omnibus on AI, the timeline was adjusted in the spring of 2026.
While transparency requirements (Art. 50(1)) will take effect in August 2026, the key high-risk requirements have been postponed, though their substance has not been weakened. The key message for companies remains: Those who establish robust AI governance early on, making the risks of AI systems manageable throughout their entire lifecycle, will gain a competitive advantage. With the right approach, they can improve the quality of their AI, demonstrate social responsibility, and take a leading role in the digital transformation driven by AI.
In order to be successful in the use of AI in the competitive European AI market, regulated organisations will need to comply with a wide range of regulations, build a culture of trust and ensure transparency throughout the AI lifecycle.
The EU AI Act is a regulation establishing harmonized rules for AI systems. AI systems are generally regulated based on their risks. Some systems are completely prohibited and others must meet certain requirements in order to be deployed. The EU AI Act entered into force on August 1, 2024, and will be implemented in several phases. Depending on the risk class, different deadlines apply within which organizations must comply with the requirements; noncompliance can result in significant fines and liability risks.
An overview of the current timeline (as of August 1, 2026):
The regulation focuses primarily on high-risk AI systems, which must meet comprehensive documentation, monitoring, and quality requirements. Users and providers of high-risk AI systems bear the brunt of these requirements. Furthermore, general-purpose AI systems, known as General Purpose AI (GPAI), are subject to stricter regulation. They must meet specific transparency requirements and ensure compliance with copyright law. If they also pose systemic risks, stricter rules apply regarding their quality and risk management, as well as reporting to government agencies. AI systems that interact directly or indirectly with humans are required to inform them about their use.
In addition to the general regulation of AI under the EU AI Act, there are other regulations that are relevant to AI use cases: horizontal regulations, such as the GDPR or the proposed EU Data Act, and vertical or sector-specific regulations.
The key to sustainable value creation with AI systems lies in successfully balancing quality, regulation, and scalability. To achieve this, recognized standards, best practices, and appropriate tools are necessary for the secure and efficient development and operationalization of AI systems. In particular, flexible data, risk, and lifecycle management systems are essential for successfully transitioning AI systems from the pilot phase to scaled operations.
At its core, trustworthy AI is nothing more and nothing less than the consistent implementation of tried and tested data science and machine learning best practices throughout the entire lifecycle of an AI system.
PwC has developed an AI Governance Introduction Framework that outlines an organization-specific AI governance and combines the concepts and principles of compliance management systems with the requirements of the EU AI Act. The first step is to prepare for setting up the necessary compliance and governance components and to develop a clear picture of the necessary measures for an organization’s use cases.
As the EU AI Act is expected to enter into force in 2024, planning for its implementation should start now. Early preparation of a holistic AI governance can give companies a competitive advantage in terms of time-to-market and quality of their (high-risk) AI systems. The requirements of the regulation are complex and organizations should in any case leverage existing compliance structures and best practices in machine learning.
In the long term, the ability to combine quality, compliance, and scalability in AI systems will determine success in the European market, particularly when competing against rivals in Asia and the United States. Interdisciplinary expertise is necessary to establish structures and processes for AI governance that are technically, legally, and organizationally fit for the future.
“Companies today have the opportunity to prepare for future regulatory requirements. By positioning themselves as pioneers, they can gain significant competitive advantages. This way, artificial intelligence ‘made in Germany’ can become a true hallmark, driving digital transformation in Germany forward.”
The EU AI Act regulates AI based on its potential risk. Companies must classify their applications early on: Some practices are prohibited, and high-risk systems are subject to extensive requirements regarding transparency, documentation, quality, and monitoring. An accurate classification is the foundation for all further measures and a prerequisite for meeting the phased deadlines by 2027/2028.
To comply with the requirements of the EU AI Act, companies need clear responsibilities, guidelines, and processes. A comprehensive AI governance framework creates transparency, reduces risks, and supports the sustainable use of AI technologies.
The requirements of the EU AI Act do not stand alone. They must be integrated with existing regulations such as the GDPR, the Data Act, or industry-specific regulations. An integrated compliance approach avoids duplication of effort and improves efficiency.
Early implementation of regulatory requirements boosts the trust of customers, business partners, and regulatory authorities. A structured overview of all use cases significantly simplifies portfolio and value management, allowing resources to be directed specifically toward value-adding applications. This enables companies to scale innovations more quickly and position themselves as pioneers in trustworthy AI.
Unlock the potential of AI innovation while ensuring compliance with the EU's AI Act. Discover how to transform regulatory requirements into strategic opportunities, aligning AI initiatives with your organization's goals. Our comprehensive guide reveals how to establish agile governance processes that drive both compliance and innovation. Learn to adapt your organizational structure, integrate compliance checks, and foster a culture of responsible AI use. Embrace the future of AI with a framework that balances ethical values, strategic objectives, and regulatory demands. Dive into the whitepaper to explore how AI governance can enhance your leadership and innovation capabilities.
Partner, Cybersecurity, Data Protection & IP Leader, Global Legal Business Solutions Network, PwC Legal
Tel: +49 171 7614597