Last month the EU pushed back the high-risk obligations of its AI Act. Standalone systems moved to December 2027, systems embedded in regulated products to August 2028. Even those are less fixed dates than outer limits — the Commission can pull them forward once it confirms the standards are ready.
When the news landed, a lot of organisations exhaled. A date they had circled on the calendar slid back by more than a year. That's a fair reaction.
But look at why it slid, and the relief gets harder to hold on to.
Start with the reason for the delay
The main stated cause was that the harmonised technical standards needed for conformity assessment aren't ready yet. If you set a deadline without settling what conformity is to be demonstrated against, companies end up chasing a benchmark that doesn't exist. Regulators acknowledged that bind and gave more time.
Writing standards is hard work, and harder still when the thing you're writing them for won't hold still. The decision itself isn't the problem here.
What the delay does make clear is this: the deadline moved. The question didn't.
"What will you show as evidence?" is not a question regulation invented. Regulation set a date for answering it, and moving the date doesn't dissolve the question. If anything, the fact that regulators themselves haven't settled on an answer is an official confirmation that the question is harder than it looks.
When there's no standard, one of two things happens
One is what you've just seen: postponement. But not every provision can be postponed. The transparency obligations in the same Act took effect in August as planned, and there something else happened.
The what was settled and the how was empty, so each provider started implementing its own reading of it. And in announcing those implementations, they set out the limits alongside them. Some markings can disappear if a file is converted or re-saved. Some can attach to text a person actually wrote. Heavy editing can leave a marking undetectable.
The guidance is in much the same position. That no single technique satisfies everything the law asks for, so layer several — that is roughly where the available advice tops out. When you can't prescribe a method, you recommend a combination.
The two provisions look like opposites, but the cause is the same. Law defines what has to be achieved; how it gets achieved is chosen later, from whatever exists at the time. When there's nothing yet to choose from, you either postpone or let everyone try their own way.
This isn't only a European story
Korea's AI Framework Act is passing through a similar place. Duties for high-impact AI, impact assessment, transparency obligations — all written into law. Who confirms the results of any of it sits outside the framework for now. The structure where operators assess themselves and record themselves was established first; the layer that checks those records was left for later.
Different jurisdictions, different texts, and the same space empty in both.
What the law required, and what the law assumed
Step back a little and a distinction appears.
There are things the law requires explicitly. Keep records. Retain them for a period. Explain on request. These are written down, and whether you've breached them is reasonably clear.
But for those requirements to mean anything, something not written down has to be true first. That the record will later be accepted as trustworthy. Telling someone to keep a record assumes the record will one day carry weight in a dispute. Otherwise there'd be no reason to keep it.
No provision guarantees that assumption. The law says keep it, and never asks whose hands it stays in.
Practitioners are already circling this
What's interesting is that the industry conversation, not the regulatory text, has already arrived at the spot.
Two requirements keep surfacing in recent guidance. One is that audit infrastructure should be maintained independently of the operational systems it examines — segregation of duties. The other is that reconstructing a chain of responsibility after dozens of intermediate decisions across multiple agents is uncertain both technically and legally — the attribution problem.
Neither is a new insight. Segregation of duties is old news in accounting and security. You separate the person who spends the money from the person who keeps the books, the team that runs the system from the team that reviews its logs. Why separate them? Because when one side does both, the record loses its force as a record. Not because anyone is dishonest, but because there's no longer a way to confirm the honesty.
That old principle hasn't reached agent decision records yet.
Why is this the exception?
An agent decides something and acts. Where does the record of that go? Usually into the systems of whoever operates the agent. The party that acted also keeps the account of what it did.
Day to day, this causes no trouble at all. The trouble starts with a dispute. The other side is asked to accept that record as the basis of the discussion, and the party that has been keeping it is the party on the other side of the dispute. However detailed and accurate the record is, nobody is standing in a position to confirm it.
The usual response is to record more thoroughly. More fields, finer timestamps, longer retention. The instinct is right, but it operates on a different layer. Thoroughness raises the quality of a record; it doesn't change where the record sits.
Reconstructing after the fact is structurally late
The attribution problem comes from the same place.
Tracing a chain back through dozens of intermediate decisions ends up a question of interpretation, however complete the material is. Which step was decisive, where the scope was exceeded — someone reading the record has to judge that. And whoever produces the record usually has an interest in how the judgement comes out.
So what's needed isn't a better record made afterwards. It's a boundary that was already fixed outside, at the moment the decision was made.
If what was agreed to sits somewhere out of the parties' reach before execution begins, there's that much less to reconstruct later. The part that doesn't need reconstructing is already settled.
The two layers don't replace each other
To head off a misreading: this isn't an argument for replacing internal records.
Internal systems know what actually happened in the finest detail. That detail can't be reproduced from outside, and there's no reason to try. What's needed on the outside isn't detail but position — that what was agreed to, and how far its boundary ran, is held somewhere separate from the parties.
Internal and external don't stand in for one another. They exist independently, and they overlap when a dispute arrives. It's at the overlap that the argument finally ends.
What's left while we wait
Regulation will produce a standard eventually. Whether that standard centres on internal documentation or extends to external confirmation, nobody knows yet.
But waiting for a standard and knowing what's still outstanding are two different activities. The time the deadline gave back is a reprieve, and it's also room to think this through before regulation decides for you.
There's one route worth thinking about. Leave the records you've been told to keep exactly where they are — your own systems know that job best, and there's no reason to change it. Just take what was agreed to and how far it extended, and leave one copy of that outside the parties as well, before execution starts. The contents don't have to travel. When, and within what boundary, is enough.
It sounds grander than it is. We already do this. When a promise matters, we put it in writing, and sometimes we leave that writing with a third party rather than with either side. Not to expose what's in it, but to fix in advance where to return to when the accounts diverge.
Requirements to keep records are more than plentiful by now. But nobody has yet required anyone to say who confirms them. That doesn't make the question go away. It's more likely to become the fundamental one.
Top comments (0)