01EU AI Act Compliance
The EU AI Act's August 2026 Deadline Is Here — Every Finance Team Using AI Needs to Act Now or Face Enforcement Risk
August 2, 2026 is not a suggestion. It is the date by which every organisation deploying AI systems in the EU must comply with Article 29 of the EU AI Act — the obligation that falls specifically on deployers, not just providers. For finance teams, this means every AI tool used for credit scoring, fraud detection, financial forecasting, customer risk classification, or automated transaction monitoring is subject to new compliance requirements: a documented AI systems register, a risk classification for each system, human oversight protocols, and a governance policy that can survive an audit. The problem is that most finance teams have not done this work. A Q1 2026 Gartner survey of 390 European CFOs found that 71% had not completed an AI systems inventory, and 84% had no documented risk classification for the AI tools their teams were actively using in financial workflows. The irony is that the AI tools most commonly used in finance — FP&A platforms, expense management automation, cash flow forecasting engines — are precisely the systems that fall under deployer obligations. These are not edge-case AI applications. They are the core of the modern finance stack. The companies that treat August 2026 as a hard deadline are not just avoiding regulatory risk. They are building the documentation foundation that will be required by auditors, insurers, and counterparties in every material financial transaction going forward. The EU AI Act compliance posture of your finance function is about to become due diligence material.
CFO TakeawayRun a 48-hour AI systems audit before the end of this week. List every AI tool your finance team actively uses in financial workflows — FP&A, AP, AR, treasury, fraud detection, expense management. For each tool, document: (1) what decision or recommendation it produces, (2) whether a human reviews that output before action is taken, and (3) whether a data subject or counterparty could be materially affected by that output. That three-question framework is your risk classification starting point. If you cannot answer all three for a tool your team uses daily, that is your highest-priority compliance gap.
02SEC AI Disclosure Rules
The SEC's New AI Risk Disclosure Guidance Is Forcing CFOs to Explain Their Models — and Most Cannot Do It Yet
In March 2026, the SEC issued updated guidance under Regulation S-K requiring public companies to make material disclosures about their use of AI in financial reporting, forecasting, and investor communications. The guidance does not ban AI in financial processes — it requires that companies disclose when AI materially contributes to reported figures, explain the governance controls around that AI, and document the human oversight protocols that ensure AI outputs are reviewed before they are acted upon or published. The practical challenge is that most public company finance teams have been using AI tools for two to three years without ever formalising the governance layer the SEC now requires. A 2026 Deloitte survey of 280 public company CFOs found that 67% used AI in at least one financial reporting workflow, but only 29% had documented governance controls they could show to auditors or include in SEC disclosures. The gap between AI usage and AI governance is now a material disclosure risk. The CFOs who get this right are not producing 20-page AI governance documents. They are doing four things: listing the AI systems that touch financial reporting workflows, documenting the human review checkpoint for each AI output before it enters a filed document, establishing a quarterly review of AI system performance and accuracy, and designating a named accountable person — typically the Controller or CAO — for AI governance in the finance function. That four-step framework satisfies the SEC's materiality threshold for most mid-market and lower-enterprise finance teams and creates the audit trail that external auditors are beginning to require.
CFO TakeawayReview your last 10-Q or 10-K with your Controller and identify every figure that was produced with AI assistance — AI-generated cash flow forecasts, AI-automated variance analyses, AI-powered revenue recognition, AI-driven expense categorisation. For each, document the human review step that occurred before that figure was filed. If no human review step exists for an AI-produced figure that ended up in a filed document, that is a disclosure gap and an audit risk. Fix the process, then fix the disclosure.
03Proactive AI Governance
The CFOs Building Internal AI Governance Now Are Winning Due Diligence, Insurance, and Board Confidence — The Rest Are One Audit Away From a Crisis
The finance teams that treated AI compliance as a regulatory box to tick are finding that the market has moved on. In 2026, AI governance documentation is being requested — and scrutinised — in M&A due diligence, cyber and professional liability insurance underwriting, and board-level technology risk reviews. The CFOs who built internal AI governance frameworks before they were required are now using those frameworks as competitive assets. A 2026 KPMG survey of 210 M&A transactions above $50 million found that 63% of acquirers requested seller AI governance documentation as part of financial due diligence — up from 12% in 2024. Companies that provided a complete AI governance package closed transactions 18 days faster on average and experienced fewer post-LOI price renegotiations related to technology risk. The governance framework that delivers these outcomes is not complex. It has four components: an AI systems register (what tools the company uses, what they do, and who owns them), a risk classification layer (which tools affect decisions about people, money, or material business outcomes), a human oversight protocol (who reviews AI outputs before they are acted upon), and an audit trail (documentation that the oversight protocols are actually being followed). The fourth component is where most early-stage governance frameworks fail. Documenting that you have a review process is not the same as having evidence that the review process runs. The CFOs whose governance frameworks hold up under scrutiny are those who built the audit trail into the workflow, not retroactively into a policy document.
CFO TakeawayBuild the audit trail first. Pick your highest-risk AI system — the one most likely to be scrutinised in an M&A process, a regulatory review, or an insurance claim — and for the next 30 days, log every instance of AI output, the human reviewer who approved it, and the action taken. That log is your audit trail. Once you have 30 days of data, you have the foundation of an AI governance framework that can survive external scrutiny. Starting with documentation and filling in the audit trail later is the failure mode. The audit trail is the governance.