Ask your team which EU AI Act article your production model triggers.
Most cannot answer. Since 2 August 2026, somebody can ask officially.
What landed on that date
The AI Office and national authorities took on supervision and enforcement.
Their powers are concrete:
- Send a formal request for information.
- Run their own evaluation of your model.
- Demand access to a general-purpose model.
- Interview staff and inspect provider premises.
- Order a provider to restrict a model's public availability. None of that starts in a courtroom.
Five artefacts, and when to build them
Evidence, not intent. That means:
- A register with a named owner per model, including third-party APIs and bundled vendor features.
- Data lineage per dataset. Source, licence, and whether personal data sits inside it.
- Model cards and version history, so you can say which version decided what, and when.
- Input and output logs for anything touching a person's job, credit, health or education.
- A human review path that somebody actually staffs. Build it into the pipeline. Reconstructing it after an incident does not work.
Teams already running consent tooling from Seers hold half of this. Disclosure evidence and data maps overlap heavily with AI documentation.
One deadline moved. One did not.
Annex III high-risk duties now apply from 2 December 2027. High-risk AI inside regulated products gets until 2 August 2028.
That is real breathing room.
GDPR did not move. Articles 13 and 14 already require you to tell people how automated processing works on their data.
Why the business cares
A register with owners, versions and logs answers a customer security questionnaire in a day.
Without one it takes a month. Enterprise deals stall on that gap more often than on price.
The comparison of AI governance and AI compliance is worth reading before your next release.
Seers AI Governance scans a live site and maps each system it finds to the articles that system triggers.
Top comments (0)