We’re evolving. Mercer is now part of the new, expanded Marsh brand

From strategic compass to supervisory reality: The EU AI Act enters its next phase 

In our previous article "EU AI Act can strengthen organisations and HR", published on 23 June 2026, we laid out why the EU AI Act is not just a compliance obligation but a strategic compass and also noted that concrete next steps would follow. The regulatory environment has since moved quickly. This follow-up delivers on that promise.

Three signals that change the equation

Since then, three significant developments have reshaped the EU AI Act landscape, raising both the urgency and the strategic stakes for every large organisation operating in Europe.

On 7 May 2026, the European Parliament and Council reached political agreement on the EU AI Omnibus, a targeted simplification package that adjusts key deadlines under the original AI Act. The most significant change: the compliance deadline for high-risk AI systems listed under Annex III, which includes employment-related AI (recruiting, performance evaluation, task allocation), credit scoring, and biometric systems, has been extended from 2 August 2026 to 2 December 2027. That is a roughly 16-month extension.
  • Important:
    This extension is a ceiling, not a floor. Harmonised standards could be confirmed 6–12 months earlier, triggering mandatory compliance before December 2027. Rolling preparation, not last-minute compliance remains the only defensible posture.

Other provisions remain unchanged: the prohibitions on emotion recognition in workplaces, social scoring, and biometric mass surveillance were already applied from 2 February 2025. General Purpose AI (GPAI) model obligations and Article 50 transparency requirements are fully in force from 2 August 2026. Fines for non-compliance now reach up to €15 million or 3% of global turnover.

The Omnibus bought time for the hardest requirements. It did not buy time for the foundational work, inventory, classification, governance, on which those requirements depend. 

On 7 July 2026, ECB Supervisory Chair Claudia Buch sent a formal letter to the CEOs of all 110 Significant Institutions supervised under the Single Supervisory Mechanism (SSM). The message was unambiguous: AI-enabled cyber threats have become a structural risk to the European financial system.
This is a long-term, structural change in the threat landscape.
Claudia Buch

ECB Supervisory Chair, July 2026

The backdrop: the European Systemic Risk Board (ESRB) had just escalated its systemic cyber risk assessment to "severe", citing Frontier AI Models capable of dramatically compressing the time needed to develop cyber exploits. What once took weeks can now take minutes. The ECB's letter required all 110 banks to submit comprehensive action plans by 31 October 2026.

The letter required banks to address:

  • Accelerated vulnerability management, assuming AI-assisted attackers
  • Enhanced monitoring and detection capabilities, potentially using AI defensively
  • Third-party and supply chain risk management (96% of European banks have already experienced breaches via third parties)
  • Board-level governance under the existing DORA framework
  • Legacy infrastructure modernisation and internet-facing systems protection

Although the ECB letter sits within the DORA framework rather than the AI Act itself, it should not be read as an extension of the AI Act. The two issues are related, but distinct. The AI Act applies to the AI systems organisations develop, deploy, or use in their operations. The ECB letter, by contrast, is about the need to protect institutions against cyber threats that are increasingly enabled or accelerated by AI. The broader supervisory message is therefore not that the AI Act is being brought forward, but that regulators already expect firms to respond to AI-driven risk with greater urgency and stronger governance.

Financial Services Industry has consistently been among the first sectors to face regulatory intensification in emerging technology domains. The ECB's explicit letter to 110 banks is not an isolated event, it is the leading edge of a broader regulatory wave.

Insurance, asset management, and payments, also supervised under the AI Act's high-risk categories, face similar exposure. But CHROs and HR leaders across all sectors should take note: the regulatory logic that drives financial services compliance today regularly becomes the standard for other industries within one to two regulatory cycles.

  • The question for CHROs is not whether intensification will reach your sector. It is whether you will be ready when it does.

What this means for CHROs and decision-makers

In June we set out five priorities for AI Act readiness. Those still are valid. What has changed since is why and how fast and the ECB`s intervention adds a dimension that was not visible a month ago: organisations cannot afford to treat December 2027 as a finish line. The combination of a compressed timeline (standards could trigger earlier enforcement), active supervisory pressure (ECB/DORA now), and growing cross-sector spillover means that preparation needs to accelerate, not slow down.

For CHROs and HR leaders, this translates into five near-term priorities:

  1. Know your AI estate especially HR-related systems
    Conduct a living inventory of all AI systems, including embedded AI features in commercial platforms for e.g. recruitment, performance management, workforce planning, and compensation benchmarking. Many fall into the high-risk category under Annex III.
  2. Engage IT and legal on the classification question 
    The classification of AI systems as high-risk is not a legal technicality; it defines your compliance roadmap. HR needs to be at the table with IT, legal, and risk when these determinations are made, not informed after the fact.
  3. Audit vendor commitments
    Most HR AI sits in third-party platforms. Under the AI Act, deployers (your organisation) carry obligations regardless of vendor status. Verify that your HR technology vendors can provide the required transparency documentation, bias testing results, and human oversight mechanisms. This is a procurement and contract management issue as much as a compliance one.
  4. Build AI literacy across HR and drive it for the organisation 
    Mandatory AI literacy training for all staff who work with or deploy AI systems is an active requirement. HR is the natural owner of this agenda — and has an opportunity to lead it credibly, not just administer it.
  5. Own the people side of the governance needs
    The AI Act gives HR a formal mandate to participate in AI governance: oversight of algorithmic decisions affecting employees, workers' council consultation in relevant jurisdictions, and lifecycle accountability for people-facing AI systems. Forward-thinking CHROs will seize this mandate as a strategic expansion of HR's remit, not a compliance burden.

Maintaining the strategic frame: compliance as confidence

Our first article made the case that the EU AI Act, used well, is a strategic compass — an accelerant for overdue modernisation of HR technology, governance, and operating models. That argument has only strengthened in the months since.

Organisations that pursue rolling readiness, inventorying, classifying, testing, governing, and documenting their AI estate progressively, will enter the enforcement window with defensible evidence, mature practices, and operational confidence. Organisations that wait for a final published standard before acting will find themselves under-prepared, over-exposed, and competing for scarce implementation resources.

The organisations that move now will not just be compliant — they will be faster, more trusted, and better positioned to extract real value from AI at scale.

How Marsh can support your AI Act readiness

Marsh brings together capabilities across risk governance, people strategy, HR transformation, and regulatory advisory that are uniquely suited to helping organisations navigate the dual demands of AI Act compliance and AI-enabled growth. Our work spans both the enterprise governance layer and the HR execution layer, so neither side of the challenge is left unaddressed.

The best outcomes are achieved when strategy and risk governance are aligned. We can help clients build defensible EU AI Act readiness through:

  • EU AI Act preparedness/compliance assessment (gap analysis, evidence review, and roadmap definition)
  • AI governance and operating model implementation 
  • AI management system design and implementation (compliant with ISO 42001, the international management system standard for AI)
  • Training and awareness for business owners and control functions
  • Mapping HR AI use cases and workforce impacts
  • Redesigning work, roles, skills, and job architecture for an AI-enabled workplace
  • Aligning HR policies and employee lifecycle processes with AI-enabled decisions

Together, this covers end-to-end needs: enterprise governance and HR execution, without leaving HR alone to solve what is fundamentally a cross-functional challenge.

About the author(s)
Related solutions
Related insights