Create one inventory of AI systems, embedded AI features and employee-selected tools—including agents acting across email, files and business applications
AI GOVERNANCE UPDATE · AUGUST 2026
The AI deadline moved. Your AI risk did not.
On 27 July 2026, the European Commission announced that the AI Omnibus had entered into force, extending the application dates for major high-risk AI rules. That is extra implementation time—not permission to postpone control. UAE organisations are already using AI to draft, decide, screen, analyse and act. The management question is no longer whether AI exists inside the company, but whether anyone can explain where it is used, what it can access, who checks its output and what happens when it is wrong.
FREE INTERACTIVE CHECKLIST
Is your organisation AI ready?
Answer 24 practical governance questions, receive an immediate readiness percentage and download your completed assessment.
WHEN THIS HELPS
Situations we can help you resolve.
- ✓Employees use public AI tools with company, customer or personal information
- ✓An AI agent can send messages, change records, approve work or trigger transactions
- ✓Recruitment, safety, credit, education or other consequential decisions use AI-supported screening
- ✓A vendor says its product is ‘AI powered’ but provides little information about data, monitoring or human oversight
- ✓The company serves European customers or operations and needs to assess possible EU AI Act exposure
- ✓Management wants AI productivity without creating an unowned compliance and operational risk
PRACTICAL DECISION SEQUENCE
Work through the question in a useful order.
Use this sequence to clarify the requirement and organise the next decision. Confirm standard-specific interpretations with the authorised standard and an independent certification body.
Record the intended purpose, owner, affected people, information used, external connections and decisions influenced by each use case
Classify business, safety, privacy, security, bias, legal and reputational impact before deciding the level of control
Define where a competent person must review, challenge or authorise an AI output—especially before a material decision or external action
Limit data and system access to what the use case needs; control credentials, confidential information, personal data and agent permissions
Keep proportionate evidence of approval, testing, monitoring, incidents, complaints, changes and corrective action
Assess AI suppliers for transparency, data handling, security, change notification, performance limitations and exit arrangements
Map the controls already available through quality and information-security systems, then assess whether ISO/IEC 42001 provides the right AI management framework
BUSINESS OUTCOMES
Designed to improve the way the system works.
DIRECT ANSWERS
Questions about this resource.
What changed in the EU AI Act timeline?+
The European Commission says the AI Omnibus entered into force on 27 July 2026. Its published timeline moves rules for certain Annex III high-risk AI systems to 2 December 2027 and rules for high-risk AI embedded in regulated products to 2 August 2028. Other AI Act provisions have different dates, so organisations should check the current official timeline.
Does the EU AI Act apply to every UAE company using AI?+
No. Applicability depends on the organisation's role, the AI system, market, users and territorial connection. A UAE company offering or using AI in connection with the EU may need a specific legal assessment. This article is management-system guidance, not legal advice.
Is ISO/IEC 42001 the same as EU AI Act compliance?+
No. ISO/IEC 42001 is a voluntary AI management-system standard for organisations that develop, provide or use AI. It can help structure governance, risks, responsibilities, monitoring and improvement, but implementing or certifying the standard does not by itself prove compliance with every applicable law.
Why are AI agents a different management concern?+
An agent may do more than generate text: it can interact with systems and act on a user's behalf. NIST's 2026 AI Agent Standards Initiative highlights security, identity, authorisation and interoperability as important conditions for trusted adoption.
Can LETA issue ISO/IEC 42001 certification?+
No. LETA provides management-system consultancy and implementation support. An independent certification body conducts any certification audit and makes the certificate decision.
PRIMARY SOURCES
Check the current information at source.
Reviewed by LETA Advisory on 18 August 2026. Standards and transition arrangements can change; confirm the edition and audit timetable applicable to your organisation.START WITH CLARITY
Tell us what triggered the requirement.
A tender, customer request, operational issue or audit date is enough to start the conversation.