Skip to content
Confir.
Governance Frameworks

Reporting EU AI Act Compliance to the Board

Guide3 August 2026· 14 min read

Report EU AI Act status to your board: exposure by risk tier, the high-risk inventory, top risks, incidents, budget, and a one-page board dashboard template.

Your compliance lead has the registers, the classifications, and the remediation backlog. Your board has none of it — yet under company law it carries ultimate accountability for that regulatory exposure. The board report is the bridge: the upward artefact that lets directors demonstrate they understood and supervised the organisation's EU AI Act exposure, on a cadence a regulator or court would recognise as oversight.

This page gives you the report's structure, a cadence, and a one-page board dashboard you can populate. It is not a committee charter and not an operating model — the board does not run compliance, it supervises it and signs off on risk appetite, budget, and ownership. Scope: how to communicate Regulation (EU) 2024/1689 status upward, for a deployer or provider that already has the machinery in place.


Why the Board Needs an EU AI Act Report at All

The Regulation places its obligations on the organisation as provider or deployer, not on the board as a named body, so no Article requires a board report by name. Two facts make one effectively unavoidable.

First, directors carry a duty of oversight under company law. A documented, regular board report is the practical evidence that oversight happened — the thing a regulator or court asks for if exposure later crystallises.

Second, the financial exposure is board-scale. Under Article 99(3), breaches of the Article 5 prohibited-practices rules carry fines up to €35 million or 7% of total worldwide annual turnover, whichever is higher; under Article 99(4), most other obligation breaches — including provider and deployer high-risk duties — carry up to €15 million or 3%; under Article 99(5), supplying incorrect or misleading information to authorities carries up to €7.5 million or 1%. A penalty calculated on group turnover is not an operational line item; it is a board-level risk. And the board does not maintain the register or run remediation — the AI governance committee and the compliance owner do that. The board receives the report, interrogates it, and sets risk appetite, budget, and ownership.


What the Board Actually Needs to Know (Five Reporting Lenses)

A board report fails when it reproduces operational detail. Reduce the programme to five lenses, each carrying a single headline metric and a red/amber/green (RAG) status.

  • Regulatory exposure by risk tier — counts in prohibited (Article 5), high-risk (Article 6 with Annex III), limited-risk transparency (Article 50), and minimal-risk.
  • The high-risk inventory and its deadlines — which systems are in scope, and readiness against each fixed date.
  • Top residual risks and remediation status — the handful that could trigger penalties, harm, or a stalled launch, each with an owner and target date.
  • Incidents and reporting obligations — serious-incident exposure and readiness to meet provider reporting duties under Article 73.
  • Budget, resourcing, and ownership — what compliance costs, where the gaps are, and who is accountable.

One number and one colour per lens — the front page reads in two minutes.


Reporting Regulatory Exposure by Risk Tier and Deadline

Translate the classification work into a board-legible picture: count and name the systems per tier, not the register itself.

Prohibited uses (Article 5) are a zero-tolerance line — the count must be zero and stay zero, including the workplace and education emotion-recognition ban under Article 5(1)(f) and the biometric categorisation inferring sensitive attributes ban under Article 5(1)(g). These prohibitions have applied since 2 February 2025, so any system that drifts into them is already non-compliant.

High-risk Annex III systems carry the heaviest obligation stack. Map each to its Annex III area so the board sees where harm and scrutiny concentrate — employment (point 4(a) recruitment, point 4(b) in-employment), creditworthiness (point 5(b)), biometrics (point 1) — which tells directors where to focus questions.

State deadlines as fixed calendar dates management can be held to. In statute, the Annex III obligations under Article 6(2) apply from 2 August 2026.

Flag the Digital Omnibus as a planning caveat, not a granted reprieve. A provisional agreement of 6–7 May 2026 would defer the Annex III obligations to 2 December 2027, but it still requires European Parliament plenary, Council adoption, and Official Journal publication before it becomes law. Until then the statute reads 2 August 2026, and the board should plan and report against that date. Not everything is deferred: the Article 5 prohibitions, the Article 4 AI-literacy obligation (in force since 2 February 2025), and the GPAI obligations are already live — do not mistake the Omnibus for a blanket pause.


Reporting Top Risks, Remediation, and Incidents

Surface the top three to five residual risks, not the register. Each gets a plain-language impact statement, an owner, a remediation milestone, and a RAG status — a board that sees thirty risks reads none of them.

Tie each risk to a specific obligation so directors see what "done" means — for a high-risk system, the risk-management system, technical documentation, human oversight, and post-market monitoring duties, each a deliverable with a date.

Report incident readiness separately. Providers of high-risk systems must report serious incidents to the relevant market surveillance authority under Article 73; the board needs that pathway rehearsed, not improvised under pressure. A line reading "zero open serious incidents; reporting workflow tested" is itself a control the board can minute.

Show trend, not just snapshot — whether residual risk is rising or falling quarter over quarter tells the board whether the programme is working. Connect any overdue remediation to the Article 99 penalty exposure, so amber and red items earn executive attention rather than sliding.


The One-Page Board Dashboard (Template)

The centrepiece is a single table the board can absorb in two minutes — one row per reporting lens, one number and one colour per row, with supporting evidence held in the register that feeds it.

Reporting lensHeadline metricRAGOwnerNext milestone
Prohibited-use exposure (Art 5)0 systemsGreenCompliance OwnerQuarterly re-scan
High-risk systems in scope (Art 6 / Annex III)2 systems, 70% readyAmberCompliance OwnerTech file complete 30 Sep 2026
Limited-risk transparency (Art 50)1 system, disclosedGreenProduct LeadAnnual review
Top residual riskRecruitment bias testing incompleteAmberHead of PeopleRemediated 31 Aug 2026
Open serious-incident exposure (Art 73)0 open; workflow testedGreenCompliance OwnerAnnual rehearsal
Penalty exposure ceiling (Art 99)€15M / 3% turnover tierAmberCFOStanding
Programme budget vs spend€240k approved, 55% spentGreenCFOQ3 review
AI literacy coverage (Art 4)80% of in-scope staffAmberHead of People100% by 31 Jul 2026

Because the dashboard is generated from the use-case register and classification data, it stays current without manual re-keying. The worked example below populates this same template for a named company.


Reporting Cadence: How Often, to Whom, in What Form

Use a layered cadence rather than a single annual set-piece.

  • Quarterly: a standing report to the board, or to its audit or risk committee, using the dashboard above. Stable structure, same metrics each time, so the board reads trend.
  • Annually: a deep-dive on risk appetite and budget, where the board sets direction for the year rather than just receiving status.
  • Event-driven: an escalation when a concrete trigger fires, between the standing reports.

Define the reporting line clearly. The AI governance committee or compliance owner prepares the report; the accountable executive presents it; the board or its committee receives and minutes it. The minute matters as much as the report — a documented trail of board oversight is the evidence that directors discharged their supervisory duty if a regulator later asks.

Tie escalation triggers to events, not calendar drift: a role-flip to provider under Article 25 (a name added, a substantial modification, or an intended-purpose change to high-risk), a newly classified high-risk system, or a serious incident reportable under Article 73.


The Accountability and Liability Case: Why the Board Should Care

Make the directors' self-interest explicit. Penalties under Article 99 are calculated on total worldwide annual turnover, which makes non-compliance a material financial and reputational risk sitting squarely in the board's oversight remit.

State the proportionality point accurately, because boards get it wrong. Under Article 99(6), administrative fines for SMEs and start-ups are capped at the lower of the percentage or the fixed amount — the lower, not the higher. A real relief, but a modest one, and overstating it understates the exposure.

Be precise about who is liable. The organisation, not the board personally, is the addressee of the Regulation's obligations; the board's exposure runs through its governance and oversight duties under company law. That is exactly why the reporting trail is the control that matters — a board that can show it asked the right questions on the right cadence is in a defensible position; one that cannot is not.

Connect to the wider cost of inaction beyond the headline fine: stalled product launches, blocked EU market access, and remediation under time pressure at multiples of the planned cost. The report itself is a risk-management control.


Tying the Report to the AI Governance Committee and Owner

Keep the division of labour clean. The governance committee and the compliance owner produce the data and run remediation; the board consumes the report and sets direction. Do not duplicate the committee's internal RACI or decision rights in the board pack — this report is the upward artefact, not the committee's operating manual.

Map the data lineage so each board metric traces to an operational source:

use-case register → Article 6 classification → risk and remediation tracking → board dashboard.

When a director questions a dashboard figure, that chain is the answer. Have the same owner present consistently quarter over quarter; familiarity builds board confidence. For the machinery that produces this data, see the governance operating model and the compliance-owner guide linked below — this page addresses only the reporting layer above it.


Worked Example: Board Reporting at Halden Mobility (a ~600-person company)

Halden Mobility is a fictional ~600-person mobility and logistics scale-up. It deploys two AI systems that matter for the EU AI Act — a recruitment-screening tool that ranks driver and warehouse applicants, and a creditworthiness model that sets financing terms for fleet-leasing customers — plus a customer-support chatbot.

Exposure. Both AI systems are high-risk Annex III deployments: recruitment screening under Article 6 / Annex III point 4(a) and creditworthiness assessment under point 5(b). The chatbot is limited-risk and triggers Article 50 transparency — customers must be told they are interacting with an AI system. There are no prohibited-use systems.

Building the quarterly report. The compliance owner maps the two high-risk systems to the 2 August 2026 statutory deadline (the Digital Omnibus 2 December 2027 deferral noted as a caveat). Populated into the template above, Halden's dashboard reads: prohibited-use exposure 0 (green); two high-risk systems ~70% ready (amber, files complete 30 Sep 2026); the chatbot disclosed under Article 50 (green); top residual risk a recruitment bias-testing gap (amber, closed 31 Aug 2026); zero open serious incidents, workflow tested (green); penalty exposure at the €15M / 3% tier (amber); budget €300k approved, 60% spent (green); and AI literacy at 78% of in-scope staff (amber, 100% by 31 Jul 2026).

The decision it drove. Reading two ambers on readiness and literacy, Halden's audit committee approved an additional €60k to close the recruitment bias-testing gap before 2 August 2026 and confirmed the Chief Operating Officer as the accountable executive who presents each quarter. That minuted decision is the report's purpose: oversight that produced a documented action, not just a status update.


How Confir helps

The board dashboard in this guide is only as current as the data behind it. Confir builds that data layer: a use-case register, an Article 6 classification per system, and risk and remediation tracking — the operational sources each board metric traces back to. From that register it generates the exposure-by-tier counts, the high-risk inventory mapped to its deadlines, and the open-risk and incident lines that populate a one-page board view, so the quarterly pack assembles itself rather than being re-keyed.

The classification and obligation logic is deterministic and rule-based — no model inference, no hallucination — so the same inputs always produce the same output, the property a board and an auditor need from the numbers they sign off.


Frequently asked questions

Does the EU AI Act require us to report compliance to our board?

The Regulation places its obligations on the organisation as a provider or deployer, not on the board as a named body, so it does not mandate a board report by article. But directors carry an oversight duty under company law, and penalties under Article 99 are calculated on total worldwide annual turnover, making this a material risk the board must be able to show it supervised. A documented, regular board report is the practical evidence that oversight happened.

What should an EU AI Act board report actually contain?

Keep it to five lenses: regulatory exposure by risk tier (prohibited, high-risk, limited-risk, minimal), the high-risk inventory and its deadlines, the top residual risks with owners and remediation status, incident readiness and any live serious incidents under Article 73, and budget, resourcing, and ownership. Each lens should reduce to one headline metric and a red/amber/green status, with the detail held in the underlying register rather than the board pack.

How often should we report EU AI Act status to the board?

A layered cadence works best: a standing quarterly report to the board or its risk/audit committee, an annual deep-dive covering risk appetite and budget, and event-driven escalation for serious incidents, a newly classified high-risk system, or a role-flip to provider under Article 25. Keep the standing report's structure stable so the board tracks the same metrics over time and can read the trend, not just the snapshot.

What does a one-page board dashboard for the EU AI Act look like?

It is a single table the board can read in two minutes, with rows for each reporting lens — prohibited-use exposure, high-risk systems and readiness to deadline, transparency obligations, top residual risk, open incident exposure, penalty ceiling, budget, and literacy coverage — and columns for headline metric, RAG status, owner, and next milestone date. One number and one colour per row; supporting evidence stays in an appendix or the use-case register that feeds the dashboard.

Are the August 2026 deadlines in our board report still correct after the Digital Omnibus?

Report against the statute. The high-risk Annex III obligations under Article 6(2) read as applying from 2 August 2026. A Digital Omnibus provisional agreement of 6–7 May 2026 would defer them to 2 December 2027, but it still needs European Parliament plenary, Council adoption, and OJ publication before it becomes law. Until then, plan and report against 2 August 2026 and flag the proposed change as a caveat, not a granted reprieve. Note that Article 5 prohibitions, Article 4 literacy, and GPAI obligations are already in force regardless.

What is the board's actual liability under the EU AI Act?

The Regulation's fines are addressed to the organisation, not to directors personally: under Article 99 they reach €35 million or 7% of total worldwide annual turnover for prohibited practices, €15 million or 3% for most other breaches, and €7.5 million or 1% for incorrect information. For SMEs and start-ups, Article 99(6) caps each fine at the lower of the two. The board's exposure is through its governance and oversight duties — which is exactly why a documented reporting trail matters.

How is the board report different from the AI governance committee's work?

The committee and the compliance owner produce the data and run remediation; the board consumes the report, sets risk appetite, and approves budget and ownership. The board report is the upward artefact — a summary the directors can act on — not the committee's internal charter, RACI, or decision rights. The dashboard's metrics should each trace back to an operational source: the use-case register, the Article 6 classification, and the risk and remediation tracking that the committee maintains.


Manage your EU AI Act compliance in one place

Confir automates risk classification, technical documentation, and audit trails for any company. No consultants. No 6-month projects. 14-day free trial.

Start free trial →