ISO consultancy division of LETA International (FZE)☎ +971 58 596 8708WhatsApp
LETAADVISORYDiscuss your scope

AI GOVERNANCE UPDATE · AUGUST 2026

The AI deadline moved. Your AI risk did not.

On 27 July 2026, the European Commission announced that the AI Omnibus had entered into force, extending the application dates for major high-risk AI rules. That is extra implementation time—not permission to postpone control. UAE organisations are already using AI to draft, decide, screen, analyse and act. The management question is no longer whether AI exists inside the company, but whether anyone can explain where it is used, what it can access, who checks its output and what happens when it is wrong.

FREE INTERACTIVE CHECKLIST

Is your organisation AI ready?

Answer 24 practical governance questions, receive an immediate readiness percentage and download your completed assessment.

Check your AI readiness24 questions · instant result →

WHEN THIS HELPS

Situations we can help you resolve.

  • Employees use public AI tools with company, customer or personal information
  • An AI agent can send messages, change records, approve work or trigger transactions
  • Recruitment, safety, credit, education or other consequential decisions use AI-supported screening
  • A vendor says its product is ‘AI powered’ but provides little information about data, monitoring or human oversight
  • The company serves European customers or operations and needs to assess possible EU AI Act exposure
  • Management wants AI productivity without creating an unowned compliance and operational risk

PRACTICAL DECISION SEQUENCE

Work through the question in a useful order.

Use this sequence to clarify the requirement and organise the next decision. Confirm standard-specific interpretations with the authorised standard and an independent certification body.

01

Create one inventory of AI systems, embedded AI features and employee-selected tools—including agents acting across email, files and business applications

02

Record the intended purpose, owner, affected people, information used, external connections and decisions influenced by each use case

03

Classify business, safety, privacy, security, bias, legal and reputational impact before deciding the level of control

04

Define where a competent person must review, challenge or authorise an AI output—especially before a material decision or external action

05

Limit data and system access to what the use case needs; control credentials, confidential information, personal data and agent permissions

06

Keep proportionate evidence of approval, testing, monitoring, incidents, complaints, changes and corrective action

07

Assess AI suppliers for transparency, data handling, security, change notification, performance limitations and exit arrangements

08

Map the controls already available through quality and information-security systems, then assess whether ISO/IEC 42001 provides the right AI management framework

BUSINESS OUTCOMES

Designed to improve the way the system works.

Visible AI use instead of shadow AINamed ownership and human oversightSafer agent permissionsEvidence for customers and regulatorsInnovation with a repeatable control system

DIRECT ANSWERS

Questions about this resource.

What changed in the EU AI Act timeline?+

The European Commission says the AI Omnibus entered into force on 27 July 2026. Its published timeline moves rules for certain Annex III high-risk AI systems to 2 December 2027 and rules for high-risk AI embedded in regulated products to 2 August 2028. Other AI Act provisions have different dates, so organisations should check the current official timeline.

Does the EU AI Act apply to every UAE company using AI?+

No. Applicability depends on the organisation's role, the AI system, market, users and territorial connection. A UAE company offering or using AI in connection with the EU may need a specific legal assessment. This article is management-system guidance, not legal advice.

Is ISO/IEC 42001 the same as EU AI Act compliance?+

No. ISO/IEC 42001 is a voluntary AI management-system standard for organisations that develop, provide or use AI. It can help structure governance, risks, responsibilities, monitoring and improvement, but implementing or certifying the standard does not by itself prove compliance with every applicable law.

Why are AI agents a different management concern?+

An agent may do more than generate text: it can interact with systems and act on a user's behalf. NIST's 2026 AI Agent Standards Initiative highlights security, identity, authorisation and interoperability as important conditions for trusted adoption.

Can LETA issue ISO/IEC 42001 certification?+

No. LETA provides management-system consultancy and implementation support. An independent certification body conducts any certification audit and makes the certificate decision.

PRIMARY SOURCES

Check the current information at source.

European Commission: AI Omnibus enters into force — 27 July 2026European Commission: navigating the AI ActISO: ISO/IEC 42001 AI management systemsNIST: AI Agent Standards InitiativeUAE Government: UAE position on AI policy
Reviewed by LETA Advisory on 18 August 2026. Standards and transition arrangements can change; confirm the edition and audit timetable applicable to your organisation.

START WITH CLARITY

Tell us what triggered the requirement.

A tender, customer request, operational issue or audit date is enough to start the conversation.

Request your next step