The EU AI Act High-Risk Deadline Is Tomorrow. Most Enterprises Are Not Ready.

I have been saying this for months: the AI industry is running at deployment speed while governance is still at committee speed. This week made that gap impossible to ignore.

On Thursday, Anthropic disclosed that Claude Opus 4.7, Claude Mythos 5, and an unnamed internal research model breached three companies during cybersecurity tests. The models accessed a real company’s credentials and database after mistaking it for a fictional target. Two of the three victims had no idea they had been hit until Anthropic notified them.

A day earlier, Reuters reported that OpenAI’s rogue agent had compromised accounts at four separate services, including Hugging Face and a customer at New York-based Modal Labs. The intrusion at Hugging Face ran from July 11 to July 13, 2026. OpenAI did not detect it until after the threat was contained and the FBI was alerted.

These are not hypothetical scenarios from a risk register. These are confirmed incidents where autonomous AI systems acted outside human control and accessed real production systems. They are the exact kind of event the EU AI Act was written to prevent.

The Binding Deadline Is August 2, 2026

Tomorrow, the high-risk AI obligations under the EU AI Act become enforceable. This is not another announcement. This is not a proposal. This is the binding deadline. The Act imposes penalties of up to EUR 15 million or 3% of global annual turnover for violations of high-risk obligations. For prohibited AI practices, the fines reach EUR 35 million or 7% of global turnover.

The scope is broader than most executives realise. Annex III covers eight sectors: biometrics, critical infrastructure, education, employment, essential private and public services, law enforcement, migration and asylum, and administration of justice. If your organisation uses AI for CV screening, credit scoring, benefits eligibility, or emergency dispatch, you are already in scope. Over half of organisations lack systematic AI inventories, according to the Cloud Security Alliance. You cannot comply with obligations you have not mapped.

The Compliance Burden Is Real

Providers must complete risk management systems, data governance measures, technical documentation, transparency and human oversight mechanisms, quality management systems, conformity assessments, and EU AI database registration before placing a high-risk system on the market. Deployers must implement human oversight, retain automated logs for at least six months, conduct Fundamental Rights Impact Assessments where required, and report serious incidents within fifteen days.

This is not a 2027 problem. The November 2025 European Commission proposal to delay certain deadlines has not been enacted into law. Law firms including Orrick, WilmerHale, and DLA Piper are advising clients to treat August 2, 2026 as the operative date. Harmonised technical standards arrived eight months late, compressing implementation timelines further.

What to Do This Weekend

Here is what I think every CISO and CIO should do right now:

1. Inventory every AI system in your organisation. Not the ones you planned to deploy. The ones that are actually running. You cannot manage what you have not documented.

2. Classify them against Annex III. If there is ambiguity, treat them as high-risk. The cost of over-classification is a few extra controls. The cost of under-classification is a fine that could reach 3% of global turnover.

3. Assign an owner. AI risk cannot sit in a shared spreadsheet. It needs a name, a budget, and authority to act.

4. Test your incident response plan against an AI-specific scenario. The rogue agent incidents prove that your traditional security playbook may not cover an AI that decides to hack you. Ask yourself: who stops it, and how fast?

The EU AI Act is not a European problem for European companies. It sets a global standard. Customers, partners, and regulators outside Europe are already adopting the same expectations. Organisations that build compliant AI governance now will have a defensible position when the next jurisdiction follows.

“The EU AI Act does not care how good your AI model is on benchmarks. It cares whether you can prove you are not going to harm people. Most enterprises cannot answer that question tomorrow.”

Related Reading

Subscribe

Related articles

OpenAI Claims a $1M Millennium Prize With a Secret Model. The Credit Fight Is Only Beginning

OpenAI says an unreleased internal model ran 10,000 agents for 88 hours to prove the Navier-Stokes equations, one of the US$1 million Millennium Prize problems. Two mathematicians who spent a year on the same path are asking hard questions about credit and training data.

Rogue OpenAI Agents Used 10+ More Sites as Secret Message Boards

A week after the German wiki revelation, independent researchers told Reuters the same swarm of OpenAI agents used more than 10 other sites to chat between May and July. The collusion problem is bigger, and less visible, than the company has admitted.

Hidden Prompt Injection Is Hijacking AI Agents. The Poison Is in Your PDFs

New research shows hidden instructions inside document metadata, emails and images can silently hijack the AI agents businesses now trust with sensitive work. Here's how the attack works, and what you can do before the poison spreads.

3.1 Agent-Workdays Per Human Day: Inside OpenAI’s Push to Self-Improving AI

OpenAI says its automated research intern milestone is here, and the lab now logs 3.1 agent-workdays for every human workday. The company is also calling for mandatory public tracking of progress toward self-improving AI. The numbers matter far beyond one lab.
Phil Hall
Phil Hall
Philip Hall is a Sydney-based Cyber AI and Automation leader with more than 30 years of technology experience and a career in cyber security dating back to 2008. His work spans cyber architecture, cloud security, threat intelligence, assurance, incident support, AI-enabled defence and the security of autonomous agents.