The EU is the anchor regime for AI governance: the regime that, for most international firms, ends up setting the ceiling. Three instruments matter, and they work on different clocks.
The AI Act: live obligations and deferred deadlines
The EU AI Act remains the world’s most comprehensive AI statute, but its timeline moved significantly in the past year. Obligations on providers of general-purpose AI models (the foundation models behind most adviser-facing tools) took effect on 2 August 2025, supported by the voluntary General-Purpose AI Code of Practice, with Commission enforcement powers following from August 2026 [1].
The high-risk obligations (originally due 2 August 2026) were deferred by the “Digital Omnibus on AI”, now adopted as Regulation (EU) 2026/1744 (Official Journal 24 July 2026, in force 27 July 2026): standalone high-risk systems under Annex III (which includes creditworthiness assessment and certain insurance pricing uses) attach from 2 December 2027, and AI embedded in regulated products under Annex I from 2 August 2028. These are fixed calendar dates, not a conditional pause, and for financial firms with credit-scoring or insurance-pricing AI they are a preparation window, not a cancellation.
Crucially, the Article 50 transparency obligations (telling people when they are interacting with an AI system, and disclosing AI-generated content) were not deferred and have applied since 2 August 2026, with enforcement operational: national market-surveillance authorities are running, and the Commission’s GPAI fining powers became exercisable the same day. Three practical points for a deployer firm:
- AI-drafted content for the public carries a workable safe harbour: where a human has reviewed the text and someone holds editorial responsibility, the disclosure duty on AI-generated text does not bite, which is where most professional-firm use sits. Deepfake-style content must be labelled regardless.
- Embedded chatbots must disclose they are AI in the interaction itself; that is mainly the provider’s design duty, and a deploying firm should never strip it.
- The Code of Practice on Transparency of AI-generated Content (around 190 signatories by late July 2026, including Anthropic, Google, Microsoft and OpenAI, with a dedicated deployer section) is the easy compliance pathway.
The prohibited-practices list has been in force since February 2025 (with a further prohibition on AI-generated intimate-image abuse applying 2 December 2026, the same date the machine-readable marking grace period ends), and deployers at every risk level carry an AI-literacy duty, softened by the Omnibus from an outcome to an obligation of effort: taking measures to support staff AI literacy.
For a typical advisory or professional firm using AI for research, drafting, meeting notes and client communications, most tools will not be “high-risk” under the Act at all; the transparency obligations, the prohibitions and the literacy duty are the parts most likely to touch day-to-day work.
GDPR: the rule that travels
GDPR applies in full to any processing of EU-resident client data, and its reach does not stop at the EU border. A firm established in Dubai or Singapore advising a client resident in France is very likely within GDPR’s extraterritorial reach, and feeding that client’s data into an AI tool is processing like any other: it needs a lawful basis, a processor agreement, and a lawful transfer mechanism if the data leaves the EEA. The EU–US Data Privacy Framework still stands but is under sustained legal challenge; prudent firms keep standard contractual clauses and transfer impact assessments in place rather than relying on the adequacy decision alone.
DORA: AI vendors are ICT third parties
DORA, in application since January 2025, treats AI vendors as ICT third-party service providers: they belong in your register of information, your contracts and your exit planning like any other critical supplier [2]. The European supervisory authorities designated their first critical ICT third-party providers in late 2025, dominated by the cloud platforms on which most AI tooling runs. If the same underlying provider sits behind your transcription tool, your report writer and your CRM’s AI features, one upstream incident hits all three.
What this means in practice
The controls the EU regime demands are the same converged core described in the overview: inventory, named owner, human review of client-facing output, vendor due diligence, and records, plus two EU-specific disciplines: disclosure (AI-generated content and AI interactions, from August 2026) and transfer hygiene (where client data goes, under what mechanism).
Because the EU regime is usually the strictest that plausibly applies, it is the natural baseline for a cross-border firm: build to it once, and treat other regimes as delta checks. That argument, and the one-page jurisdiction matrix that goes with it, is set out in the companion piece on AI governance for cross-border financial advisers.
This article is for informational purposes only and does not constitute regulated financial advice, legal advice, or a compliance opinion. Consult a qualified compliance professional for advice specific to your firm.
Sources
[1] European Commission, ‘Timeline — Implementation of the EU AI Act’, accessed July 2026. Available at: https://ai-act-service-desk.ec.europa.eu/en/ai-act/timeline/timeline-implementation-eu-ai-act
[2] EIOPA, ‘Digital Operational Resilience Act (DORA)’, accessed July 2026. Available at: https://www.eiopa.europa.eu/digital-operational-resilience-act-dora_en