NewsEU AI ActAI RegulationAI-Native

This Week in Agents: The EU AI Act's August Deadline, Decoded

N
Published by NativelyDrafted, reviewed, and edited by the team
· 7 min
most of it moved. here’s what didn’t.

Everyone in European compliance had August 2 circled. Then the EU passed the Digital Omnibus, formally adopted on June 29, and moved most of the finish line: the hard technical requirements for high-risk AI systems, including Article 12’s logging mandate, shifted to December 2027. What actually lands on August 2 is narrower: chatbot disclosure rules, deepfake labeling, and the Commission’s new power to fine the companies building the models. It’s not nothing. It’s just not what most of the coverage says it is.

What actually happens on August 2, 2026?

Two categories of obligation go live. First, Article 50’s transparency requirements. Providers of AI chatbots and virtual assistants must design systems to inform users they are speaking with an AI, unless it is obvious from context. Anyone deploying a system that generates deepfakes must ensure that content is disclosed as artificially generated. And anyone publishing AI-written text “with the purpose of informing the public on matters of public interest” must label it as AI-generated, unless a human reviewed and took editorial responsibility for it (EU AI Act, Art. 50, 2024). There is one narrow carve-out from the Omnibus: AI systems already on the market before August 2 get until December 2, 2026 to implement machine-readable content marking. New launches do not get that grace period.

Second, and more consequentially for large AI companies: the European Commission’s enforcement powers for general-purpose AI model providers activate. The GPAI obligations (transparency documentation, copyright summaries, systemic risk assessments for frontier models) have been in force since August 2, 2025. What changes on August 2, 2026 is that the Commission can now actually impose fines. Violations of GPAI obligations: up to €15 million or 3% of worldwide annual turnover, whichever is higher (EU AI Act, Art. 101).

That timing matters given what happened last week. The voluntary Code of Practice for GPAI providers had a signatory deadline of July 22, 2026. Non-participation is technically fine (the Code is voluntary), but it creates a cleaner line of scrutiny now that fines are possible. Any GPAI provider who skipped the Code and then faces an investigation in September has made their own position harder.

EU AI Act: revised timeline after Digital Omnibus (Council, June 29, 2026)

Feb 2025
Prohibited practices
Social scoring, RTBID, manipulation
Aug 2025
GPAI obligations
Training docs, copyright, systemic risk
Aug 2026
Transparency + enforcement
Art. 50 disclosures · GPAI fines live
Dec 2026
Content marking
Machine-readable AI labels (Art. 50(2))
Dec 2027
High-risk AI (Annex III)
Art. 12 logging · Art. 14 oversight
deferred
Aug 2028
Regulated products
Annex I AI: medical devices, vehicles
deferred

What the Digital Omnibus deferred, and why it still matters

The Omnibus was provisionally agreed on May 7 by the Council and Parliament and formally adopted on June 29. The headline change: high-risk AI system obligations for stand-alone Annex III systems (AI used in hiring and recruitment, credit scoring, biometric identification, law enforcement support, educational assessment, and border control) move from August 2, 2026 to December 2, 2027. That’s a 16-month extension (Council of the EU, 2026). For AI embedded in regulated Annex I products, that is medical devices, cars, aircraft, safety components, the date shifts further, to August 2, 2028.

Article 12 logging requirements, the ones everybody was citing for August 2, are part of Chapter III, Section 2 of the Act (Articles 9–17). They cover risk management, data governance, technical documentation, and human oversight, in addition to record-keeping. All of it moved.

The Omnibus also tightened one thing: two new prohibitions enter Article 5 in December 2026. AI-generated non-consensual intimate imagery and child sexual abuse material are now explicitly banned. Not everything slowed down.

Sixteen months of additional runway is not sixteen months of license to ignore the architecture question. It’s sixteen months to build it right, so you’re not retrofitting compliance onto a system that was never designed for it.

What Article 12 logging actually requires (for December 2027)

It’s worth understanding what Article 12 demands, because it describes something you should want regardless of when the regulator shows up.

For high-risk AI systems, Article 12 requires automatic event logging throughout the system’s operational lifetime. Not a manual audit trail, not a spreadsheet someone fills in after the fact: the system must generate these records itself. Logs must be tamper-evident and retained for at least six months (twenty-four months for biometric identification and law enforcement systems). They must capture enough to enable full traceability: inputs received, outputs produced, and the decision path followed (EU AI Act, Art. 12). Article 13 adds a documentation layer: deployers must be given the means to collect and interpret those logs, in effect requiring the system to ship with a guide to its own audit trail.

Practically: if your AI agent takes consequential actions in an Annex III domain (screening job applications, making credit recommendations, supporting law enforcement, processing biometric data), it is a high-risk AI system. December 2027 is the compliance date. The architecture question, can you produce a tamper-evident log of every decision that agent made, and why, is a question about how the system was built, not about when the regulator arrives.

An agent that cannot explain what it did in sequence is also an agent you cannot trust operationally, independent of any regulation. The two things are not separate. See how to set clear limits for an AI agent for the autonomy-tier model, which maps directly onto the bounded-scope requirements the Act had in mind when defining high-risk classification.

The ISO 42001 question, and what it actually gives you

Alongside the regulatory clock, there is a procurement clock. ISO 42001, the AI management system standard published in December 2023, is becoming a vendor due-diligence checkbox in enterprise procurement: IT, legal, and compliance teams are asking for it before signing contracts with AI vendors, much the way ISO 27001 became the default evidence bar for cloud security a decade ago.

Worth knowing before anyone sells you a certification: ISO 42001 is not a harmonized EU standard, and certification does not provide legal presumption of conformity with the EU AI Act (ISO/IEC 42001:2023). It certifies an organization’s AI management system: the governance processes, risk management procedures, and oversight structures, not the AI product itself. The EU AI Act regulates the product; ISO 42001 certifies the organization. These are different objects under different legal frameworks. You can hold the certificate and still fail a conformity assessment, which would be an uncomfortable thing to discover in a procurement meeting.

What ISO 42001 does give you is a defensible governance posture and a structured way to satisfy the operational overlap with the AI Act’s organizational requirements (risk management, data governance, human oversight). Deloitte’s January 2026 survey of more than 3,000 business and IT leaders found that 74% of organizations expect to be using AI agents at least moderately by 2027, but only 21% have mature governance in place to manage agentic AI risk (Deloitte State of AI in the Enterprise, 2026). The governance gap is real. ISO 42001 is a reasonable starting point for closing it. Just don’t confuse “starting point” with “compliance.”

What this means if you build or deploy AI agents

The immediate list is short. If the AI systems you deploy interact with people in the EU, they need to identify themselves as AI. If you generate deepfakes (most deployments don’t, but some do), those need disclosure labels. If your product is a GPAI model, the Code of Practice window has closed and enforcement powers just went live.

The December 2027 list is longer. If any of the AI systems you run touch employment, credit, biometrics, law enforcement, or critical infrastructure, they are high-risk under Annex III, and the architecture of your logging layer is a compliance deliverable with a fixed deadline. The 16 months of runway the Omnibus just granted are most valuable if you use them to build the logging, oversight, and documentation correctly from the start, not to defer the conversation.

The structural argument is the same one running under what an AI-native organization actually is: the human checkpoint on consequential decisions isn’t a compliance feature layered on top of an agent. It’s what makes the agent worth trusting in the first place. The regulation is catching up to the design principle, not the other way around.

Sources

  1. 1.Council of the EU: Digital Omnibus: Council and Parliament agree to simplify and streamline AI rules (May 7, 2026; formally adopted June 29, 2026): Annex III high-risk AI deferred Aug 2026 → Dec 2, 2027; Annex I to Aug 2, 2028
  2. 2.EU AI Act: Article 12: Record-Keeping. Requires automatic event logging, tamper-evident, 6-month minimum retention (24 months biometric/LE); applies to high-risk AI systems (deferred to Dec 2, 2027 for Annex III by Digital Omnibus)
  3. 3.EU AI Act: Article 50: Transparency obligations for providers and deployers of certain AI systems (chatbot disclosure, deepfake labeling, AI-generated public-interest text labeling); applicable August 2, 2026
  4. 4.EU AI Act: Article 99 & 101: Penalties: Tier 1 (prohibited practices): €35M or 7% turnover; Tier 2 (Art. 50 violations, other operator obligations): €15M or 3%; GPAI enforcement (Art. 101): €15M or 3%, Commission powers active August 2, 2026
  5. 5.Deloitte: State of AI in the Enterprise 2026 (Jan 2026, 3,000+ leaders): 74% of organizations plan to use AI agents moderately by 2027; only 21% have mature governance
  6. 6.ISO/IEC 42001:2023: AI Management Systems: voluntary, certifiable standard; not a harmonized EU standard and does not provide presumption of conformity with the EU AI Act

See competitive intelligence running.Win the deals you're losing, run end to end and stopped for your approval before anything is sent, published, or spent. Live in days, and the system stays in your account.

How competitive intelligence works →