Skip to main content
Six Mistakes Teams Make Preparing for the EU AI Act's Expert BodiesEU AI Act & GPAI
5 min readFor AI Governance Leaders

Six Mistakes Teams Make Preparing for the EU AI Act's Expert Bodies

The European Commission has just appointed 60 independent AI experts to the Scientific Panel and 174 stakeholders to the Advisory Forum. These groups will significantly influence how the EU AI Act is enforced, how General-Purpose AI Models are classified, and what "systemic risk" means in practice. Yet, many teams are ignoring these bodies while they focus on documenting high-risk systems.

That's a mistake. The Scientific Panel's recommendations will directly affect market surveillance and risk evaluation methods. The Advisory Forum will address standardization and implementation challenges. If you're waiting for final guidance before taking action, you're already behind.

Why These Mistakes Keep Happening

The EU AI Act introduces a governance structure that doesn't align with existing compliance frameworks. There are hard deadlines, like the 2 August 2026 transparency obligations under the Code of Practice, and soft guidance, as the Code itself is voluntary. Meanwhile, the expert bodies' outputs will shape enforcement before most teams have even classified their systems.

Confusion arises from three sources. First, the Act's risk-based structure means different obligations activate at different times for different systems. Second, the Digital Omnibus amendments pushed some high-risk deadlines from August 2026 to potentially December 2027, creating a false sense of security. Third, teams confuse "voluntary" instruments like the Code of Practice with "optional" compliance, they're not the same.

Let's explore what goes wrong and how to fix it.

Mistake 1: Treating the Scientific Panel as a Research Committee

Why it happens: The name "Scientific Panel" sounds academic. Teams assume these experts will publish white papers and hold conferences while real enforcement happens elsewhere.

The consequence: You miss that this panel's core mandate includes alerting the AI Office to systemic risks and advising on General-Purpose AI Model classification. If your model gets flagged, you're not getting a research recommendation, you're getting regulatory scrutiny.

The fix: Map your General-Purpose AI Models against the panel's expertise: capability evaluation, risk assessment, technical mitigations, misuse risks, provider cybersecurity, and compute measurement. If your system touches any of these areas, document your current risk controls now. The panel serves renewable two-year terms, so they'll see patterns across providers.

Mistake 2: Ignoring the Code of Practice Because It's "Voluntary"

Why it happens: The Code of Practice on marking and labeling AI-generated content is explicitly voluntary. Teams read "voluntary" and deprioritize it against hard regulatory requirements.

The consequence: The Code outlines steps for meeting transparency obligations that become mandatory on 2 August 2026. If you're deploying generative AI that produces deepfakes or text on public interest matters, you need machine-readable marking and user-facing labels. "Voluntary" means you can choose how to comply, it doesn't exempt you from the underlying obligations.

The fix: Treat the Code as your implementation blueprint. It was drafted by six independent experts with input from over 180 stakeholders. If you skip it, you'll need to develop your own marking and labeling approach and justify how it meets the Act's transparency requirements. The Code offers a safe harbor, use it.

Mistake 3: Assuming the Advisory Forum Won't Affect Your Timeline

Why it happens: With 174 members from civil society, academia, industry, SMEs, and startups, the Advisory Forum looks like a stakeholder engagement exercise, not an enforcement mechanism.

The consequence: The Forum advises the Commission and the AI Board on standardization and implementation challenges. If your industry raises compliance issues in Forum discussions, that feedback could shape how requirements are interpreted or enforced. The Forum includes permanent members like ENISA and the Fundamental Rights Agency, organizations with direct oversight roles.

The fix: Monitor Forum outputs through your trade association or directly if you're large enough. When the Forum identifies implementation challenges in your sector, document how you're addressing them. If standardization gaps emerge, engage early rather than waiting for final technical standards.

Mistake 4: Conflating High-Risk Postponement with General-Purpose AI Relief

Why it happens: The Digital Omnibus amendments pushed high-risk compliance deadlines from August 2026 to potentially December 2027. Teams hear "postponement" and assume all near-term pressure is off.

The consequence: The Omnibus left the 2 August 2026 timeline for General-Purpose AI Models intact. If you're a foundation model provider, your obligations haven't moved. The Scientific Panel's work on systemic risk assessment and classification methodologies directly targets your systems, and enforcement begins in less than 18 months from the date the Code of Practice was published.

The fix: Separate your compliance roadmap by system type. High-risk systems may have breathing room (if the Omnibus is formally adopted). General-Purpose AI Models do not. The Scientific Panel's expertise in capability evaluation and risk assessment wasn't assembled to wait until 2027.

Mistake 5: Waiting for Commission Guidelines Before Acting

Why it happens: The Code of Practice will be "accompanied by Commission guidelines clarifying the scope of the obligations." Teams want clarity before investing in marking and labeling infrastructure.

The consequence: Guidelines clarify edge cases, they don't replace the core obligation. If you're generating deepfakes or publishing AI-manipulated text on public interest matters, the requirement to mark and label is already clear. Waiting for guidelines means you're starting implementation in mid-2026 for an August deadline.

The fix: Implement the Code's two-part structure now: machine-readable marking for providers, user-facing labels for deployers. Flag genuinely ambiguous scenarios (what counts as "public interest"? when is human review sufficient?) and document your interpretation. When guidelines arrive, you'll have a baseline to adjust, not a system to build from scratch.

Mistake 6: Underestimating the Panel's Influence on Market Surveillance

Why it happens: Market surveillance sounds like a post-deployment concern. Teams focus on getting systems documented and classified before worrying about ongoing oversight.

The consequence: The Scientific Panel explicitly supports market surveillance activities. They'll advise on what gets audited, how risks are assessed in the field, and which technical mitigations count as adequate. If your risk controls don't align with the panel's evolving understanding of General-Purpose AI Model risks, you'll face enforcement actions even if you met the initial requirements.

The fix: Build continuous monitoring into your AI Management System now, not after your first market surveillance inquiry. Track the panel's public outputs on risk methodologies and evaluation criteria. If your mitigation approach diverges from emerging panel guidance, document why your controls are equivalent or superior.

Prevention Checklist

  • Classify all General-Purpose AI Models by the panel's expertise domains (capability evaluation, misuse risks, cybersecurity)
  • Implement machine-readable marking for AI-generated content before mid-2026
  • Separate compliance timelines: high-risk systems (potentially 2027+) vs. General-Purpose AI Models (August 2026)
  • Document current risk controls for any system that could trigger systemic risk alerts
  • Establish monitoring for Scientific Panel and Advisory Forum outputs relevant to your sector
  • Map transparency obligations (deepfakes, chatbots, public interest text) to the Code of Practice's two-part structure
  • Flag ambiguous scenarios in marking/labeling and document your interpretation before guidelines arrive
  • Build continuous risk monitoring that can adapt to evolving panel guidance on evaluation methodologies

The Scientific Panel and Advisory Forum aren't theoretical constructs, they're operational bodies with direct influence on how the EU AI Act gets enforced. Treat them that way.

You Might Also Like