Agent Platform { Artemis }
Agent Platform
Agent Platform { Artemis }
NEW

The AI-programmable foundation for building, scaling, and optimizing AI agents that work in production.

learn more
Enterprise Modules
For Service
AI AgentsAgent AI AssistanceAgentic Contact CenterQuality AssuranceProactive Outreach
For Work
Modules
Enterprise SearchIntelligent OrchestratorPre-Built AI AgentsAdmin ControlsAI Agent Builder
Departments
SalesMarketingEngineeringLegalFinance
Explore
Use Case Library

Find the right AI use case for your business

Recent AI Insights
Configured, not coded. The engineering discipline gap in agent development
Configured, not coded. The engineering discipline gap in agent development
AI INSIGHT
15 May 2026
Can Today’s AI Agents Survive Their Own Runtime?
Can Today’s AI Agents Survive Their Own Runtime?
AI INSIGHT
15 May 2026
What's new in AI for Work: features that drive enterprise productivity
What's new in AI for Work: features that drive enterprise productivity
AI INSIGHT
20 Feb 2026
Parallel Agent Processing
Parallel Agent Processing
AI INSIGHT
16 Jan 2026
Agentic AI Apps
AI Solutions
Pre-built Applications

Ready-to-deploy applications across industries and functions.

AI for Banking
AI for Healthcare
AI for Retail
AI for IT
AI for HR
AI for Recruiting
Application Accelerators

Leverage pre-built AI agents, templates, and integrations from the Kore.ai Marketplace.

Kore.ai Marketplace
Pre-built agents
Templates
Integrations
Tailored Applications

Design and build applications on our Agent Platform using our enterprise modules.

Platform
Agent Platform

Your strategic enabler for enterprise AI transformation.

Learn more
Enterprise Modules
AI for Work
AI for Service
Top Resources
From search to action: what makes agentic AI work in practice
The Kore.ai Agent Productivity Index 2026
Beyond AI islands: how to fully build an enterwise-wide AI workforce
QUICK LINKS
About Kore.aiCustomer StoriesPartnersResourcesBlogWhitepapersDocumentationAnalyst RecognitionGet supportCommunityAcademyCareersContact Us
Agent Marketplace
More
More
Resources
Resource Hub
Blog
Whitepapers
Webinars
AI Research Reports
AI Glossary
Videos
AI Pulse
Generative AI 101
Responsive AI Framework
CXO Toolkit
Private equity
support
Documentation
Get support
Submit RFP
Academy
Community
COMPANY
About us
Leadership
Customer Stories
Partners
Analyst Recognition
Newsroom
Events
Careers
Contact us
Microsoft Partnership
Agentic AI Guides
forrester cx wave 2024 Kore at top
Kore.ai named a leader in The Forrester Wave™: Conversational AI for Customer Service, Q2 2024
Generative AI 101
CXO AI toolkit for enterprise AI success
upcoming event

Ai4 is a leading annual AI conference in Las Vegas where business leaders, technologists, and innovators gather to explore real-world AI applications.

Las Vegas
4 Aug
register
Talk to an expert
Not sure which product is right for you or have questions? Schedule a call with our experts.
Request a Demo
Double click on what's possible with Kore.ai
Sign in
Get in touch
Background Image 1
Blog
AI
EU AI Act: a GDPR moment for artificial intelligence

EU AI Act: a GDPR moment for artificial intelligence

Published Date:
Last Updated ON:
July 22, 2026

Remember when GDPR (General Data Protection Regulation) landed in 2018? At first, most organizations had to get new consent banners, hire a Data Protection Officer, and rewrite their privacy policy. But looking back, it completely changed the business landscape.

The EU AI Act is that moment for AI, but this time the stakes are even higher.

With GDPR, regulators governed what you could do with people's data. With the EU AI Act, they are governing the systems that act on it. This means the days of unchecked, ungoverned AI running loose in enterprise systems are officially over.

The EU AI Act is Europe's framework for accountable AI, and its reach stretches well beyond Europe's borders. If you think being headquartered outside Europe means this does not apply to you, it is worth reading more carefully. The regulation follows the impact on people, not the location of the company building the system. A US bank with EU correspondent relationships or a global insurer with Lloyd's exposure — all of them are in scope.

The accountable era of AI begins

For the past few years, most enterprises have been deploying AI on their own terms. A pilot here, a proof of concept there, governance frameworks bolted on after the fact when someone raised a concern. That era is closing. 

We are entering the Accountable Era of AI. This means being able to document what your AI systems are doing, show evidence that they are being monitored and tested, assign a named human who owns the oversight question, and produce all of that to a regulator on demand.

The EU AI Act introduces a legal obligation to know what your AI systems are doing, to document it, to test it, and to be able to show your work to a regulator on demand. 

Here are four specific articles within the EU AI Act that define what compliance actually looks like in practice.

1 - Article 9: The risk lifecycle 

You need a documented risk assessment for every high-risk AI system you operate. The risk assessment is not a one-time exercise at launch. It needs to stay current as the system evolves — if the scope expands, if new data sources get added, if the system starts being used in ways that were not in the original design, the assessment needs to reflect that.

2 - Article 12: Reasoning-chain logging 

Your AI systems need to log what they did in enough detail that you could reconstruct a decision after the fact. A regulator examining an agentic credit system does not want to see the final decision. They want to see the reasoning chain that produced it: which data inputs were considered, what the confidence thresholds were, where a human could have intervened.

3 - Article 14: Substantive oversight

Every high-risk AI system needs a mechanism for a human to intervene and override. The regulator will ask to see records of the last three times you actually tested your human-override or “kill-switch” controls under realistic, live conditions. If those records don't exist, the mechanism doesn't count.

4 - Annex III: High-risk AI systems 

The Act defines a specific list of high-stakes AI use cases under Annex III. It covers the use of AI in critical infrastructure management, education grading, employment screening, law enforcement, biometric identification, and evaluating access to essential services like credit scoring and insurance.  

This means if your company uses AI for operational tasks like screening job candidates, establishing creditworthiness, or managing core digital infrastructure, you are likely operating a high-risk AI system.  

The threshold for being on this list is whether it meaningfully influences a decision that affects a person's access to employment, services, or essential life benefits.

Fines for non-compliance

Non-compliance with any of the above carries real financial consequences. The EU AI Act uses a three-tier penalty structure, where the tier that applies depends on which obligation is breached:

  • Violations of prohibited AI practices carry fines up to €35 million or 7% of global annual turnover, whichever is higher. 
  • Breaches of high-risk AI system requirements carry fines up to €15 million or 3% of global turnover. 
  • Providing incorrect or misleading information to regulators carries fines up to €7.5 million or 1% of turnover.

Digital Omnibus update: What it means for you

In June 2026, the Council of the EU gave final approval to the Digital Omnibus on AI — a legislative package designed to simplify the EU's digital laws. 

With this update, the enforcement deadline for most Annex III high-risk obligations has moved from August 2026 to December 2027, giving enterprises an additional 16 months.

The Digital Omnibus gave you more runway to build. But the question is whether you will use the runway to build or to wait.

It is tempting to look at that date, breathe a sigh of relief, and put it on next year's to-do list. But as an enterprise leader, that is a massive strategic trap, as the market is not waiting for 2027.

Procurement teams in regulated industries are already asking for documented governance evidence as part of RFP scoring. Several Tier 1 financial institutions now require Annex III classification and Article 14 oversight evidence from AI vendors before signing contracts. 

AI governance due diligence has become a standard line item in corporate mergers and acquisitions. An organization that cannot produce clean Annex III classification, tested oversight mechanisms, and logging that reconstructs decisions faces valuation questions in a deal room that can't be answered by citing a revised enforcement date.

And deployment velocity didn't move either. Research found that 56% of organizations spend between 6 and 18 months getting an AI project from intake to production, with 44% naming the governance process as the primary cause of delay. An organization that resolves its governance architecture now removes that friction from every deployment that follows. An organization that waits keeps paying that cost on every use case.

EU AI Act: Enterprise governance framework

Most leaders reading this already know they need some kind of governance plan. What's harder is knowing where to actually start. 

The EU AI Act governance framework below is drawn from Kore.ai's work with 450+ Global 2000 organizations on exactly this problem. It is designed to move your strategy from passive compliance to a durable operational position.

Move 1 - Assess where you stand

Before mapping your way forward, you have to know your starting line. These are the five real-world corporate archetypes; see which mirror reflects your organization today:

  • The Deferred Risk-Taker: You haven't started an explicit Annex III classification exercise yet. Internally, governance is still viewed as a cost center, and your team is quietly using the timeline delay as a reason to wait while competitors build. 
  • The Architecture Mismatch: Your existing IT policies are thorough, but they were built for static AI that recommends rather than acts. Your latest autonomous AI pilots are being treated as standard software updates rather than accountable lifecycle events under Article 9. 
  • The Fragmented Builder: You've mapped out your high-risk use cases, but your risk assessments haven't been updated since deployment. Your human-override workflows look great on paper, but they have never actually been stress-tested under live production loads. 
  • The Mid-Retrofit Sprinter: You’ve recognized your gaps and are actively in a 90-day sprint. Your engineering teams are doing the heavy lifting to rebuild logging systems so they capture complex reasoning chains, willingly accepting minor technical trade-offs to get it right. 
  • The Structural Compounder: Your classifications are locked, risk lifecycles update quarterly, and override mechanisms are tested bi-annually. You sailed through early examinations with zero material findings, and you're already participating in global working groups to shape future rules. The timeline shift doesn't matter to you—the asset is already built.

Move 2 - Isolate the hidden gaps 

Once you know your archetype, the next step is identifying the invisible friction points holding you back from maturity. Across organizations, the distance usually comes down to three structural gaps:

The foundational gap: systems that recommend vs. act

Legacy governance frameworks were designed for AI that suggests a choice for a human to execute. But for modern agentic systems that execute tasks autonomously, that old accountability chain doesn’t hold. 

Articles 9 through 15 of the AI Act are the regulatory expression of this exact architectural shift. If your framework was built before you started deploying autonomous agents, you are solving for the wrong problem.

The capability gap: the real performance cost 

Building compliant infrastructure isn't free, and retrofitting it after the fact is even more expensive. Intercepting and documenting a live AI agent's complex reasoning chain and tool calls requires robust architecture. That infrastructure cost needs to be named, owned, and budgeted up front, rather than discovered during an audit.

The intelligence gap: the unwritten rules 

The most valuable compliance knowledge can't be found by reading the public regulatory text. It lives in the minds of practitioners who have already sat across the table from supervisory authorities. They know exactly what examiners reach for first, which documentation failures are fatal, and which standard preparations turn out to be completely irrelevant.

Move 3 -  Move forward

No matter where you sit on the maturity curve today, the goal is to bridge these gaps by executing three deliberate strategic moves: 

The Reckoning (diagnosis)

If you are a Deferred Risk-Taker or an Architecture Mismatch, your first move is to face your architectural realities. Move past comfortable boardroom questions like “do we have a governance framework,” and get clear, auditable evidence on whether your logging can reconstruct an autonomous agent's decision-chain for an inspector. 

The Crossing (strategy)

If you are a Fragmented Builder or a Mid-Retrofit Sprinter, stop relying purely on abstract legal advice. Close your intelligence gap by collaborating directly with active peer communities where leaders share real-world examination insights, and get into the weeds of what the examiner actually tested.

The Advantage (return)

Once you become a Structural Compounder, governance stops being a speed bump and becomes a permanent commercial accelerator. Governance built into your platform architecture from the first deployment compounds with every use case that follows. Deployment cycles get shorter. Supervisory examinations become shorter. Competitors who delayed are now catching up to a standard you already exceed.

Conclusion: Start compounding

As an enterprise leader, the worst thing you can do right now is mistake a delayed enforcement calendar for an operational pause. Compliance is merely the floor; governance maturity is the actual building. 

Governance might sound like the thing that slows AI deployment down. In practice, for organizations that build it properly, the opposite is true. Research found that 56% of enterprises spend 6 to 18 months getting an AI project into production, with the governance process itself as the primary bottleneck. Organizations that resolve their governance architecture eliminate that cost from every deployment that follows — permanently. 

Compliance is merely the floor. Governance maturity is the actual building. 

The European Commission opens its first formal review of the Act in 2028. The organizations with real operational evidence by then — documented lifecycle reviews, tested oversight mechanisms, an examination track record — will help shape what the next cycle of rules looks like. Everyone else will be reading the guidance note that others wrote.

If you want to understand exactly what building looks like in practice, the Governance Arc is the place to start. It draws directly from Kore.ai's experience across 450+ Global 2000 deployments. It also includes the 90-day sprint template and trade-offs for Articles 9, 12, and 14, the six-question board self-assessment, and the article-level breakdown of what supervisory examinations are actually finding. 

Frequently asked questions

Q1 - Does the EU AI Act apply to my company if we are not based in Europe? 

Yes. Like GDPR, the Act enforces strict extraterritorial jurisdiction. If your enterprise is headquartered in the United States or Asia, but your AI systems, automated agents, or downstream outputs impact individuals located within the European Union, you are completely in scope.

Q2 - What are the maximum financial penalties for violating the EU AI Act?

The Act uses a three-tier penalty structure. 

  • Violations of prohibited AI practices carry fines up to €35 million or 7% of global annual turnover, whichever is higher. 
  • Breaches of high-risk AI system requirements carry fines up to €30 million or 6% of global turnover. 
  • Providing incorrect or misleading information to regulators carries fines up to €7.5 million or 1% of turnover. These figures exceed GDPR's maximum penalties.

Q3 - How do I know if my AI system counts as high-risk? 

The classification depends on how the tool is used, not which tool it is. An AI system becomes high-risk when it is used to influence decisions that affect people's rights, financial outcomes, employment, healthcare, or access to services. The same tool may be low risk in one use case and high risk in another depending on how it is deployed. If you have not done a formal classification exercise, assume you have high-risk systems until you confirm otherwise.

Q4 - We already have an AI governance policy. Does that satisfy the Act? 

The question is not whether a policy exists, but whether it works under real operational conditions. The Act's obligations under Article 9 (continuous risk management), Article 12 (reasoning-chain logging), and Article 14 (tested human oversight) go significantly further than a policy document. 

Q5 - Did the 2026 Digital Omnibus update delay all compliance obligations? 

No. While the Digital Omnibus extended the enforcement timeline for Annex III high-risk systems to December 2027, other deadlines remain active. For instance, transparency rules for general-purpose AI and customer-facing chatbots go into full effect by August 2026.

Q6 - What specific logging details are mandatory for agentic AI under Article 12? 

Article 12 requires automated event logging throughout the entire operational lifecycle of a high-risk AI system. Your systems must explicitly capture exact data inputs, confidence thresholds, anomalies, and specific moments of human intervention, allowing a regulator to retroactively trace and audit the system. 

Q7 - What does “human oversight” actually mean under Article 14? 

It means more than having an override button. Article 14 requires a mechanism that has been genuinely tested under realistic, live conditions, with documented evidence of each exercise. Regulators ask to see records of the last three times the mechanism was exercised in practice. 

Read EU AI Act
Book a demo
Share
Link copied
authors
Gaurav Bhandari
Gaurav Bhandari
Content Management
Forrester logo at display.
Kore.ai named a leader in the Forrester Wave™ Cognitive Search Platforms, Q4 2025
Access Report
Gartner logo in display.
Kore.ai named a leader in the Gartner® Magic Quadrant™ for Conversational AI Platforms, 2025
Access Report
Stay in touch with the pace of the AI industry with the latest resources from Kore.ai

Get updates when new insights, blogs, and other resources are published, directly in your inbox.

Subscribe
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Recent Blogs

View all
Build governed AI agents: Introducing Arch AI
AI engineering
July 21, 2026
Build governed AI agents: Introducing Arch AI
Democratizing the frontier: Why enterprises don’t need to build their own AI model
July 17, 2026
Democratizing the frontier: Why enterprises don’t need to build their own AI model
How to ensure AI agents comply with industry regulations
AI governance
July 10, 2026
How to ensure AI agents comply with industry regulations
Accelerate time-to-value from AI

Find out how Kore.ai can help

Talk to an expert
Start using { Artemis } today

Meet our new Agent Platform

MEET {ARTEMIS}
Background Image 4
Background Image 9
You are now leaving Kore.ai’s website.

‍

Kore.ai does not endorse, has not verified, and is not responsible for, any content, views, products, services, or policies of any third-party websites, or for any verification or updates of such websites. Third-party websites may also include "forward-looking statements" which are inherently subject to risks and uncertainties, some of which cannot be predicted or quantified. Actual results could differ materially from those indicated in such forward-looking statements.



Click ‘Continue’ to acknowledge the above and leave Kore.ai’s website. If you don’t want to leave Kore.ai’s website, simply click ‘Back’.

CONTINUEGO BACK
Agentic AI applications for the enterprise
English
Spanish
Spanish
Spanish
Spanish
Pre-Built Applications
BankingHealthcareRetailRecruitingHRIT
Kore.ai agent platform
Platform OverviewAI for ServiceAI for WorkAgent Marketplace
Industries
Healthcare (Payer)Healthcare (Provider)
company
About Kore.aiLeadershipCustomer StoriesPartnersAnalyst RecognitionNewsroom
resources
DocumentationBlogWhitepapersWebinarsAI Research ReportsAI GlossaryVideosGenerative AI 101Responsive AI frameworkCXO Toolkit
GET INVOLVED
EventsSupportAcademyCommunityCareers

Let’s work together

Get answers and a customized quote for your projects

Submit RFP
Follow us on
Review Kore.AI on G2
© 2026 Kore.ai Inc. All trademarks are property of their respective owners.
Trust CenterPrivacy PolicyTerms of ServiceAcceptable Use PolicyCookie PolicyIntellectual Property Rights
|
×