Everyone in European compliance had August 2 circled. Then the EU passed the Digital Omnibus, formally adopted on June 29, and moved most of the finish line: the hard technical requirements for high-risk AI systems, including Article 12’s logging mandate, shifted to December 2027. What actually lands on August 2 is narrower: chatbot disclosure rules, deepfake labeling, and the Commission’s new power to fine the companies building the models. It’s not nothing. It’s just not what most of the coverage says it is.
Two categories of obligation go live. First, Article 50’s transparency requirements. Providers of AI chatbots and virtual assistants must design systems to inform users they are speaking with an AI, unless it is obvious from context. Anyone deploying a system that generates deepfakes must ensure that content is disclosed as artificially generated. And anyone publishing AI-written text “with the purpose of informing the public on matters of public interest” must label it as AI-generated, unless a human reviewed and took editorial responsibility for it (EU AI Act, Art. 50, 2024). There is one narrow carve-out from the Omnibus: AI systems already on the market before August 2 get until December 2, 2026 to implement machine-readable content marking. New launches do not get that grace period.
Second, and more consequentially for large AI companies: the European Commission’s enforcement powers for general-purpose AI model providers activate. The GPAI obligations (transparency documentation, copyright summaries, systemic risk assessments for frontier models) have been in force since August 2, 2025. What changes on August 2, 2026 is that the Commission can now actually impose fines. Violations of GPAI obligations: up to €15 million or 3% of worldwide annual turnover, whichever is higher (EU AI Act, Art. 101).
That timing matters given what happened last week. The voluntary Code of Practice for GPAI providers had a signatory deadline of July 22, 2026. Non-participation is technically fine (the Code is voluntary), but it creates a cleaner line of scrutiny now that fines are possible. Any GPAI provider who skipped the Code and then faces an investigation in September has made their own position harder.
EU AI Act: revised timeline after Digital Omnibus (Council, June 29, 2026)
The Omnibus was provisionally agreed on May 7 by the Council and Parliament and formally adopted on June 29. The headline change: high-risk AI system obligations for stand-alone Annex III systems (AI used in hiring and recruitment, credit scoring, biometric identification, law enforcement support, educational assessment, and border control) move from August 2, 2026 to December 2, 2027. That’s a 16-month extension (Council of the EU, 2026). For AI embedded in regulated Annex I products, that is medical devices, cars, aircraft, safety components, the date shifts further, to August 2, 2028.
Article 12 logging requirements, the ones everybody was citing for August 2, are part of Chapter III, Section 2 of the Act (Articles 9–17). They cover risk management, data governance, technical documentation, and human oversight, in addition to record-keeping. All of it moved.
The Omnibus also tightened one thing: two new prohibitions enter Article 5 in December 2026. AI-generated non-consensual intimate imagery and child sexual abuse material are now explicitly banned. Not everything slowed down.
Sixteen months of additional runway is not sixteen months of license to ignore the architecture question. It’s sixteen months to build it right, so you’re not retrofitting compliance onto a system that was never designed for it.
It’s worth understanding what Article 12 demands, because it describes something you should want regardless of when the regulator shows up.
For high-risk AI systems, Article 12 requires automatic event logging throughout the system’s operational lifetime. Not a manual audit trail, not a spreadsheet someone fills in after the fact: the system must generate these records itself. Logs must be tamper-evident and retained for at least six months (twenty-four months for biometric identification and law enforcement systems). They must capture enough to enable full traceability: inputs received, outputs produced, and the decision path followed (EU AI Act, Art. 12). Article 13 adds a documentation layer: deployers must be given the means to collect and interpret those logs, in effect requiring the system to ship with a guide to its own audit trail.
Practically: if your AI agent takes consequential actions in an Annex III domain (screening job applications, making credit recommendations, supporting law enforcement, processing biometric data), it is a high-risk AI system. December 2027 is the compliance date. The architecture question, can you produce a tamper-evident log of every decision that agent made, and why, is a question about how the system was built, not about when the regulator arrives.
An agent that cannot explain what it did in sequence is also an agent you cannot trust operationally, independent of any regulation. The two things are not separate. See how to set clear limits for an AI agent for the autonomy-tier model, which maps directly onto the bounded-scope requirements the Act had in mind when defining high-risk classification.
Alongside the regulatory clock, there is a procurement clock. ISO 42001, the AI management system standard published in December 2023, is becoming a vendor due-diligence checkbox in enterprise procurement: IT, legal, and compliance teams are asking for it before signing contracts with AI vendors, much the way ISO 27001 became the default evidence bar for cloud security a decade ago.
Worth knowing before anyone sells you a certification: ISO 42001 is not a harmonized EU standard, and certification does not provide legal presumption of conformity with the EU AI Act (ISO/IEC 42001:2023). It certifies an organization’s AI management system: the governance processes, risk management procedures, and oversight structures, not the AI product itself. The EU AI Act regulates the product; ISO 42001 certifies the organization. These are different objects under different legal frameworks. You can hold the certificate and still fail a conformity assessment, which would be an uncomfortable thing to discover in a procurement meeting.
What ISO 42001 does give you is a defensible governance posture and a structured way to satisfy the operational overlap with the AI Act’s organizational requirements (risk management, data governance, human oversight). Deloitte’s January 2026 survey of more than 3,000 business and IT leaders found that 74% of organizations expect to be using AI agents at least moderately by 2027, but only 21% have mature governance in place to manage agentic AI risk (Deloitte State of AI in the Enterprise, 2026). The governance gap is real. ISO 42001 is a reasonable starting point for closing it. Just don’t confuse “starting point” with “compliance.”
The immediate list is short. If the AI systems you deploy interact with people in the EU, they need to identify themselves as AI. If you generate deepfakes (most deployments don’t, but some do), those need disclosure labels. If your product is a GPAI model, the Code of Practice window has closed and enforcement powers just went live.
The December 2027 list is longer. If any of the AI systems you run touch employment, credit, biometrics, law enforcement, or critical infrastructure, they are high-risk under Annex III, and the architecture of your logging layer is a compliance deliverable with a fixed deadline. The 16 months of runway the Omnibus just granted are most valuable if you use them to build the logging, oversight, and documentation correctly from the start, not to defer the conversation.
The structural argument is the same one running under what an AI-native organization actually is: the human checkpoint on consequential decisions isn’t a compliance feature layered on top of an agent. It’s what makes the agent worth trusting in the first place. The regulation is catching up to the design principle, not the other way around.
See competitive intelligence running.Win the deals you're losing, run end to end and stopped for your approval before anything is sent, published, or spent. Live in days, and the system stays in your account.