Data Governance · Updated July 20, 2026
The deadline moved. The work didn't.
By the MortarIQ Founder · 7 minute read · Not legal advice
In June 2026, the EU gave high-risk AI systems a reprieve: the Digital Omnibus deferred the AI Act's Annex III obligations, including the Article 10 data governance requirements, from August 2, 2026 to December 2, 2027. If your compliance plan just exhaled, this post is for you, because the deferral changed the enforcement calendar and nothing else. The data feeding your production AI systems is exactly as governed, or ungoverned, as it was before the vote.
Here is the argument this post makes: data governance for AI was never really about a regulator's date. Production AI fails on data before it fails on models. The teams treating governance as a readiness practice, measured and maintained like uptime, ship AI that works and sail through whatever questionnaire arrives, from Brussels or from their biggest customer. The teams treating it as a compliance sprint now have sixteen extra months to not start.
What actually changed in June 2026
Three facts, because precision matters more than urgency theater. First: the Annex III high-risk obligations, Article 10 included, now apply from December 2, 2027. Second: high-risk AI embedded in regulated products under Annex I moved to August 2028. Third: August 2, 2026 still happens. Transparency rules under Article 50 start to apply, and enforcement begins at national and EU level for general-purpose AI models, prohibitions, transparency, and AI literacy. The Act did not pause; one lane of it did.
Why the urgency survives the deferral
Strip the regulation away entirely and ask what is left. Your AI systems, the ones in production right now, read from your data estate on every request. Whether their answers are right, safe, and explainable depends on properties of that estate that most teams have never measured:
Documentation. When 80 percent of columns have no description, nobody can say what the model is actually reading, and every incident investigation starts from zero.
Exposure. Unmasked personal data in tables that feed pipelines is a live privacy incident waiting for a retrieval query, deadline or no deadline. In one demo estate we scan, five of six PII columns, including emails, names, and IP addresses, sit unprotected in AI-adjacent tables.
Freshness. Half the training tables not updated in a year means the model is confidently describing a business that no longer exists.
Bias and gaps.“We never looked” is not a neutral answer. It is the answer that turns into headlines when a production system treats one group of customers differently.
None of these wait for December 2027. They are why AI projects stall today: industry surveys keep finding that a majority of data leaders say their data is not AI-ready, and stalled AI projects overwhelmingly blame data, not models. And the market is enforcing governance faster than the regulators are: the procurement questionnaire from your next enterprise customer already asks Article 10's questions, with a shorter deadline than Brussels ever set.
What good governance requires (with or without a regulator)
Article 10 remains the clearest public articulation of the bar, and it is worth keeping as your checklist precisely because it resolves to measurable properties of the estate, not paperwork:
1. Documented data practices. Design choices, where the data came from and how it was collected, how it was prepared (labelling, cleaning, enrichment), and whether it is available, sufficient, and suitable for the purpose.
2. Examined data. Checked for biases that could affect health, safety, or fundamental rights, and for gaps and shortcomings, with measures taken to address what you find.
3. Fit-for-purpose data. Relevant, sufficiently representative, as error-free as possible, and complete for the intended use, including the specific geographic, behavioural, or functional setting the system runs in.
Every one of those resolves to a property of your actual data estate. You cannot claim documented practices when the columns are undescribed. You cannot claim examination when nobody knows which tables hold personal data or whether it is masked. The evidence has to come from the estate itself, which is also what makes this measurable today.
What to do this quarter
First: find out where you stand. Inventory which AI systems touch which schemas, then measure those schemas. A readiness scan takes about a minute per schema with read-only credentials and scores what governance actually depends on: documentation coverage, classification, PII masking, freshness, identifiers. You will know your worst gaps by Friday.
Then: close the gaps that matter, in order.Mask the PII first; exposure is the gap that hurts you soonest. Document the columns that feed models, starting with the tables your AI actually reads. Add classification tags. Assign owners and track the work, because “we fixed it once” is not a governance practice; a running program is.
Ongoing: keep the evidence current. Data drifts. New columns appear, masking policies get dropped in migrations, documentation rots. Re-scan on a schedule and watch the deltas, so what was true at the audit stays true in production. Teams that run governance this way will meet December 2027 without a sprint, because they will have stopped treating it as a date at all.
And to be precise about the boundary, because precision is the whole point here: a scan produces readiness to produce evidence, never a certification. Parts of any governance obligation are about process and judgment, and some properties of data cannot be measured from metadata at all. A tool that claims to make you compliant in one click is describing a tool that should worry you. What a scan does is turn the data-shaped parts of the obligation into numbers you can act on and show.
Production AI fails on data first. Find out where.
Score your estate's AI readiness in about a minute, read-only, starts free.
Get your readiness scoreFrequently asked questions
Was the EU AI Act's August 2026 high-risk deadline delayed?
Yes. Under the Digital Omnibus amendments, given final approval by the Council of the EU on June 29, 2026, the obligations for high-risk AI systems under Annex III, including Article 10 data governance, were deferred from August 2, 2026 to December 2, 2027. High-risk AI embedded in regulated products under Annex I moved from August 2027 to August 2028. August 2, 2026 still matters: Article 50 transparency rules start to apply, and enforcement begins at national and EU level for general-purpose AI models, prohibitions, transparency rules, and AI literacy.
What does Article 10 of the EU AI Act require?
Article 10 requires that training, validation, and testing data for high-risk AI systems be subject to documented data governance practices: design choices, data origin and collection, preparation operations like labelling and cleaning, an assessment of availability and suitability, and examination for possible biases and data gaps. The data must be relevant, sufficiently representative, as error-free as possible, and complete in view of the intended purpose.
Why does AI data governance matter before any regulatory deadline?
Because production AI systems fail on data before they fail on models. Undocumented columns, unmasked personal data, stale tables, and unexamined bias produce wrong answers, privacy exposure, and stalled projects today, regardless of when a regulator starts checking. Industry surveys consistently find a majority of organizations say their data is not AI-ready, and most stalled AI projects cite data problems as the cause. Enterprise buyers also increasingly require documented data governance in procurement, independent of any law.
Does the EU AI Act apply to companies outside the EU?
Yes, it has extraterritorial reach. It applies to providers placing AI systems on the EU market or putting them into service in the EU regardless of where the provider is established, and to providers and deployers outside the EU when the system's output is used in the EU.
This article is general information about Regulation (EU) 2024/1689 as amended by the June 2026 Digital Omnibus, not legal advice. Whether a specific system is high-risk, and what compliance requires for it, is a question for qualified counsel.