The EU is the anchor regime for AI governance — the regime that, for most international firms, ends up setting the ceiling. Three instruments matter, and they work on different clocks.
The AI Act: live obligations and deferred deadlines
The EU AI Act remains the world’s most comprehensive AI statute, but its timeline moved significantly in the past year. Obligations on providers of general-purpose AI models (the foundation models behind most adviser-facing tools) took effect on 2 August 2025, supported by the voluntary General-Purpose AI Code of Practice, with Commission enforcement powers following from August 2026 [1].
The high-risk obligations — originally due 2 August 2026 — were deferred by the “Digital Omnibus on AI”, provisionally agreed by EU legislators on 7 May 2026: standalone high-risk systems under Annex III (which includes creditworthiness assessment and certain insurance pricing uses) now attach from December 2027, and AI embedded in regulated products under Annex I from August 2028.
Crucially, the Article 50 transparency obligations — telling people when they are interacting with an AI system, and disclosing AI-generated content — were not deferred and apply from 2 August 2026. The prohibited-practices list has been in force since February 2025, and deployers at every risk level carry an AI-literacy duty.
For a typical advisory or professional firm using AI for research, drafting, meeting notes and client communications, most tools will not be “high-risk” under the Act at all — the transparency obligations, the prohibitions and the literacy duty are the parts most likely to touch day-to-day work.
GDPR: the rule that travels
GDPR applies in full to any processing of EU-resident client data — and its reach does not stop at the EU border. A firm established in Dubai or Singapore advising a client resident in France is very likely within GDPR’s extraterritorial reach, and feeding that client’s data into an AI tool is processing like any other: it needs a lawful basis, a processor agreement, and a lawful transfer mechanism if the data leaves the EEA. The EU–US Data Privacy Framework still stands but is under sustained legal challenge; prudent firms keep standard contractual clauses and transfer impact assessments in place rather than relying on the adequacy decision alone.
DORA: AI vendors are ICT third parties
DORA, in application since January 2025, treats AI vendors as ICT third-party service providers: they belong in your register of information, your contracts and your exit planning like any other critical supplier [2]. The European supervisory authorities designated their first critical ICT third-party providers in late 2025 — dominated by the cloud platforms on which most AI tooling runs. If the same underlying provider sits behind your transcription tool, your report writer and your CRM’s AI features, one upstream incident hits all three.
What this means in practice
The controls the EU regime demands are the same converged core described in the overview: inventory, named owner, human review of client-facing output, vendor due diligence, and records — plus two EU-specific disciplines: disclosure (AI-generated content and AI interactions, from August 2026) and transfer hygiene (where client data goes, under what mechanism).
Because the EU regime is usually the strictest that plausibly applies, it is the natural baseline for a cross-border firm — build to it once, and treat other regimes as delta checks. That argument, and the one-page jurisdiction matrix that goes with it, is set out in the companion piece on AI governance for cross-border financial advisers.
This article is for informational purposes only and does not constitute regulated financial advice, legal advice, or a compliance opinion. Consult a qualified compliance professional for advice specific to your firm.
Sources
[1] European Commission, ‘Timeline — Implementation of the EU AI Act’, accessed July 2026. Available at: https://ai-act-service-desk.ec.europa.eu/en/ai-act/timeline/timeline-implementation-eu-ai-act
[2] EIOPA, ‘Digital Operational Resilience Act (DORA)’, accessed July 2026. Available at: https://www.eiopa.europa.eu/digital-operational-resilience-act-dora_en