A few days ago an article in UC Today lit up enterprise IT Slack channels across Europe. The premise was surgical: under Article 5(1)(f) of the EU AI Act, inferring emotions from employees in the workplace has been illegal since February 2025, and yet contact center vendors are still selling “voice mood detection” modules, HR platforms are still scoring candidates on “facial expression engagement,” and collaboration suites are still rating remote workers on sentiment.
The vendors keep selling. The IT departments keep deploying. The legal teams have no idea they are, technically, running contraband software that carries a fine of up to 7% of global turnover.
The contact center story is just the most visible edge of a much larger problem, and that larger problem is what this article is actually about.
The operational playbook for EU AI compliance. Free, open source, reviewed by lawyers, available on:
A regulation that does not care about your roadmap
The EU AI Act is not a white paper. It is not a proposal. It is in force, it has teeth, and the penalty architecture is already on the books: up to €35 million or 7% of global turnover for prohibited practices, €15 million or 3% for high-risk system violations, €7.5 million or 1% for filing incorrect information.
The prohibitions under Article 5 have been enforceable since 2 February 2025. The AI literacy obligation of Article 4 is live. And the heavy operational layer, the one that covers “high-risk” AI systems under Annex III, becomes legally binding on 2 August 2026.
The European Commission’s Digital Omnibus proposal, adopted by the Parliament on 26 March 2026 and by the Council on 13 March 2026, would shift the high-risk deadline to December 2027. As of April 2026 the Omnibus is still in trilogue, with political agreement expected at the 28 April 2026 meeting and publication in the Official Journal targeted for July 2026. Until that publication, 2 August 2026 remains the law. Any planning that assumes otherwise is assuming a political outcome that has not happened yet.
The “high-risk” label is, honestly, misleading. It sounds like it belongs to self-driving cars or autonomous weapons. Under Annex III, it also covers the most ordinary tools in your HR and operations stack: AI systems used to screen CVs, to monitor employee productivity, to evaluate creditworthiness, to dispatch emergency services, to infer race or political opinions through biometric categorisation. If you use an AI tool to rank job applicants or to measure how long a remote worker is active on a keyboard, you are the deployer of a high-risk AI system in the eyes of the regulator.
The part where we say the quiet thing out loud
Yes, there is a real tension between regulation and innovation, and we are not going to pretend otherwise. A badly calibrated rule can freeze an entire category of experimentation. A rigid compliance process can kill the productivity gains that made the investment worth it in the first place. We are grounded in innovation, and we think that context always matters. Disruption, by definition, happens at the edges of what existing frameworks anticipated, and any agency that tells you otherwise is either lying or not actually innovating.
But there is no debate on the other side of the ledger. Legality and compliance are not optional, and we have never advised a client to “break the rules” because they are inconvenient. The interesting questions are downstream of that: how do you design an operating model that respects the law without turning every AI initiative into a six-month committee exercise? How do you move fast inside a perimeter instead of pretending the perimeter is not there? That is the useful work, and it is the work this article is really about.
The “emotion recognition is illegal” headline is a good entry point because it is concrete. But the actual governance problem is not that vendors are selling one prohibited feature. The governance problem is that most European enterprises cannot answer a very simple question: what AI is actually running on our network, and who decided to put it there?
Our view on how to build narrative and governance at the same time is collected in the Strategic Storytelling framework we use with clients.
The 83% statistic that should end every AI strategy meeting
In April 2026, Vision Compliance released a readiness report built on enterprise assessments across eight industries. Two numbers stood out:
- 78% of assessed organisations have not taken meaningful steps toward EU AI Act compliance.
- 83% have no formal inventory of the AI systems they use or deploy.
The second number is the one that matters. An enterprise without an AI inventory has no epistemic basis for any compliance claim it might make. When the supervisory authority sends a letter asking whether the organisation uses any systems that fall under Article 5 prohibitions or Annex III high-risk categories, the honest answer is “we do not know.” And “we do not know” is not a defence, it is an aggravating factor.
This is a governance failure, not a technology failure. It happens because corporate procurement treats AI features as checkbox items in SaaS contracts rather than as distinct systems that need to be classified, logged and reviewed. It happens because embedded AI (the “sentiment analysis” add-on, the “smart summary” beta, the “intelligent routing” module) gets rolled out by product teams without any structured handoff to legal or security. It happens because most CISOs were hired to protect networks, not to classify probabilistic models against a risk taxonomy written in Brussels.
The Shadow AI accelerator, and what Samsung really taught us
The inventory problem is compounded by Shadow AI. Gartner estimates that by 2026, 80% of employees will use generative AI for work without company approval. They are not doing this to be reckless. They are doing it because a free consumer tool with no procurement lag beats a corporate SaaS that takes three months to approve.
When a company bans AI without offering a sanctioned alternative, adoption does not stop. It just moves outside the observable perimeter. Data Processing Agreements disappear. Audit trails disappear. Data Loss Prevention rules stop applying, because the traffic is no longer flowing through the corporate network in a way that DLP can inspect. A managed risk becomes an unmanaged crisis.
The 2023 Samsung case is usually cited as a cautionary tale about generative AI leaking source code. That framing misses the point. The actual lesson is about what happens when a large organisation fails to provide a safe, fast, internal path to tools its employees need to do their jobs. If there is no approved path, people will build their own, and they will not check whether the terms of service of a consumer chatbot permit paste of proprietary code (they usually do not).
If you want a neutral baseline number to bring to the board before making the case, our Digital Maturity Assessment Scorecard is open source and runs entirely in the browser.
The GPAI inheritance problem
There is another layer of exposure that deserves its own attention: General Purpose AI (GPAI).
If an enterprise builds on top of foundation models (GPT-4, Claude, Gemini, Llama) or deploys an application that embeds them, it is not only responsible for its own deployment. It also inherits parts of the compliance posture of the upstream model provider. Under Articles 53 to 55 of the AI Act, GPAI providers must maintain technical documentation, publish a summary of training data, implement a copyright policy, and, for models trained above the 10^25 FLOPs threshold (the “systemic risk” tier), perform adversarial red-teaming and report serious incidents to the AI Office. The geopolitics behind that compute threshold, and who actually controls the hardware behind it, is another story I have been tracking.
A deployer relying on a GPAI model whose provider cannot produce the required documentation is, in practical terms, deploying on a foundation of sand. And most standard vendor questionnaires do not catch this, because they were designed for a SOC 2 / ISO 27001 world. “Are you SOC 2 Type II certified?” is a valid question. It is also irrelevant to Article 53. The questions that matter now are different: Does the system infer emotion from biometric signals? Is customer data used to fine-tune or train base models? Can you produce the Annex XI technical file on request? Are you aligned with the GPAI Code of Practice published in July 2025?
Why PDF policies will not save anyone this time
The instinctive corporate response to a new regulation is to draft a 40-page policy, circulate it by email, and declare the matter handled. It worked, more or less, for earlier waves of compliance.
It will not work for the AI Act.
The reason is structural. The AI Act is not only a disclosure regime, it is an operational one. Article 26 requires continuous human oversight for high-risk deployments. Article 12 requires automated logging retained for at least six months. Article 27 requires a Fundamental Rights Impact Assessment (FRIA) before putting certain high-risk systems into use. Article 73 requires notification of serious incidents within strict windows (15 days in general, shorter for certain categories).
None of this can be satisfied with a PDF. A regulator auditing a high-risk deployment will not ask to see a policy, they will ask to see logs, versioned impact assessments, and evidence of actual human review in the loop. According to the Vision Compliance report, 61% of enterprises currently have no process for generating the technical documentation required for high-risk AI systems. That is a compliance cliff, and the brakes are not installed yet.
The FRIA, in particular, is often confused with the GDPR DPIA. They are not the same instrument. A DPIA evaluates data protection risks. A FRIA evaluates impact on EU Charter fundamental rights: human dignity (Article 1), non-discrimination (Article 21), effective remedy (Article 47), freedom of expression (Article 11), privacy (Articles 7 to 8), workers’ rights (Articles 27 to 31), rights of the child (Article 24), rights of persons with disabilities (Article 26). It is a different exercise with a different output, and in many cases both are required.
From theory to operational guardrails: what we actually built
This is the specific problem that drove us to build the diShine AI Compliance Toolkit.
We started roughly ten months ago on a client engagement where the legal team was blocking every AI initiative and the engineering team was frustrated by vague directives. We wrote the first version for that project, used it again on a later engagement, kept updating it, and eventually decided that every mid-sized European enterprise was facing a version of the same problem. So we open-sourced it on GitHub a month ago, and it is now published as a full operational site with an integrated wiki at compliance.dishine.it.
The framework is organised into four phases that mirror the sequence any honest compliance program has to follow.
Phase 1: assess and contain
You cannot govern what you cannot measure. The framework starts with a browser-based Shadow AI Risk Calculator that scores an organisation across four dimensions (organisational awareness, technical controls, data governance, incident history) and maps the result to a risk band with a concrete remediation roadmap. It runs entirely client-side. No data leaves the browser, which is deliberate: no one should have to create a new data privacy risk in order to quantify an existing one.
Alongside the calculator, an Acceptable AI Use Policy template classifies corporate data (Public, Internal, Confidential, Restricted) and maps each class to the AI tiers that may process it. This is the part that directly addresses Shadow AI. Instead of banning tools, it tells employees exactly which tools they are allowed to use for which data.
Phase 2: audit and procure
If an upstream vendor is selling prohibited features, the enterprise needs to know before the regulator does. The toolkit includes a 25-point AI Vendor Audit Checklist that goes well beyond standard procurement forms. It forces vendors to answer specific questions about model training data provenance, GDPR Article 22 implications, and EU AI Act GPAI obligations. A vendor that cannot pass the checklist does not get a deployment slot.
Phase 3: architect and deploy
Not every AI use case requires the same level of lockdown. A tool that drafts internal marketing copy is not equivalent to a tool that screens CVs. The Enterprise AI Deployment Decision Matrix routes workloads to the appropriate tier: Tier 1 (Consumer APIs, high risk, prohibited for internal data), Tier 2 (Enterprise API Agreements, medium risk, standard productivity), Tier 3 (Private Cloud / VPC deployment, low risk, sensitive data), Tier 4 (Self-hosted open-source models, zero external risk, required for highly classified IP or strict regulatory contexts).
Phase 4: monitor and respond
For the high-risk systems that fall under the August 2026 obligations, the toolkit ships the exact templates required by the law: a DPIA template specialised for AI (addressing algorithmic opacity and bias), a standalone FRIA template implementing Article 27, a GPAI Model Governance Checklist for Articles 53 to 55, and an AI Incident Response Playbook that maps the forensic response lifecycle to the 15-day AI Act reporting window and the 72-hour GDPR window. Specific tactics for prompt injection, model inversion and algorithmic bias discovery are documented in line with the ENISA AI Threat Landscape.
The framework also includes sector-specific addenda (financial services, technology, healthcare and life sciences, human resources, beauty and cosmetics), an ISO/IEC 42001:2023 alignment guide with a twelve-month roadmap toward an Artificial Intelligence Management System, a Conformity Assessment Pathway guide distinguishing internal control from notified-body assessment, and an AI Liability and Product Safety guide covering the three-pillar framework (AI Act, AI Liability Directive, revised Product Liability Directive 2024/2853 with its 9 December 2026 transposition deadline).
One more thing about innovation and rules
At the risk of restating the obvious: the AI Act is not a perfect regulation. Some of its definitions are fuzzy. Some of its thresholds will age badly. The 10^25 FLOPs line for systemic risk is already being overtaken by architectural efficiency gains that the text did not fully anticipate. The interaction with GDPR, the Product Liability Directive, NIS2, DORA and the Cyber Resilience Act creates overlaps that will take years to reconcile in case law.
Reasonable people can disagree about where the balance should sit. We have opinions about it, some of them in the “this should be tighter” direction and some in the “this should be lighter” direction. What we are not going to do is advise anyone to ignore the law because parts of it are imperfect. The €35 million fines are not calibrated to punish companies that try, in good faith, to comply and make a paperwork error. They are calibrated to punish companies that deploy AI recklessly, with no inventory, no vendor audit, no human oversight and no documentation, and then act surprised when a regulator asks questions.
Compliance, done properly, is not the opposite of innovation. It is the operating system on top of which innovation becomes a repeatable capability rather than a legal gamble. An organisation with a current AI inventory, a deployment matrix, audited vendors and a trained workforce can evaluate and adopt a new AI capability in days. An organisation running on shadow IT and PDF policies will spend months in committee and eventually deploy something that quietly exposes it to a fine larger than the productivity gain could ever justify.
A short homework list before August
If you stopped reading five paragraphs ago and came back to the end, here is the operational minimum:
- Stand up an AI inventory. Everything. Embedded features, standalone tools, API integrations, internal experiments. You cannot comply with what you cannot see.
- Run the Shadow AI Risk Calculator as a baseline. Keep the result.
- Audit your top ten AI vendors against the 25-point checklist. Start with contact center, HR, CRM, collaboration, and analytics. That is where emotion recognition and biometric categorisation tend to hide.
- Classify every active deployment against Article 5 (prohibited), Annex III (high-risk), Article 50 (transparency) and the minimal-risk default. Document the reasoning.
- For every high-risk deployment, schedule a DPIA and, where applicable, a FRIA. Do not confuse the two.
- Publish an Acceptable AI Use Policy that employees can actually follow. Tell them what they can do, not only what they cannot.
- Deliver the Article 4 AI literacy obligation in a documented, role-based way. It is already in force.
All of the templates, calculators and guides referenced above are free and open source at compliance.dishine.it. The source repository is on GitHub, with an integrated wiki for the deeper regulatory material. Pull requests welcome.
The August 2026 deadline is approaching whether the Digital Omnibus shifts it or not. It is a good moment to find out exactly what is running on the network.
About the author
This article was written by Kevin Escoda and the diShine team, a creative tech agency based in Milan working on digital strategy, performance marketing, AI adoption and MarTech architecture. The Enterprise AI Compliance Toolkit referenced here is one of the projects we open-source when we think something should exist and does not yet.
The Enterprise AI Compliance Toolkit sits alongside our other open-source work; Prismo, FlowAudit, diShine Converter, and the Cookie Audit scanner. Fork any of them, improve them, tell us what broke.
References
- UC Today. “EU AI Act Shock: Emotion Recognition Is Now Illegal at Work. So Why Is Your Vendor Still Selling It?” April 2026. https://www.uctoday.com/workplace-management/eu-ai-act-shock-emotion-recognition-is-now-illegal-at-work-so-why-is-your-vendor-still-selling-it/
- European Commission. “AI Act — Shaping Europe’s digital future.” https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai
- European Parliament and Council of the EU. “Digital Omnibus on AI Regulation” — adopted texts of 13 March 2026 (Council) and 26 March 2026 (Parliament), pending trilogue conclusion.
- WisFarmer / EIN Presswire. “Vision Compliance Releases 2026 EU AI Act Readiness Report, Finds 78% of Enterprises Unprepared for Obligations.” 1 April 2026. https://www.wisfarmer.com/press-release/story/49888/vision-compliance-releases-2026-eu-ai-act-readiness-report-finds-78-of-enterprises-unprepared-for-obligations/
- MEXC News. “Vision Compliance Releases 2026 EU AI Act Readiness Report.” 1 April 2026. https://www.mexc.com/news/997514
- diShine AI Compliance Framework. https://compliance.dishine.it/
- Additional reading on the cybersecurity layer of this problem: AI for threat detection and vulnerability assessment e Open Source Intelligence for public-sector use cases.

