EU AI Act: Article 50 transparency live 2 August 2026  ·  Annex III high-risk now fixed at 2 December 2027

N° 0026 · Regulatory Deadline · Updated 29 June 2026

The clock stopped moving.

On 29 June 2026 the Council gave final adoption to the Digital Omnibus. Annex III high-risk obligations, including Article 12 logging and Article 9 risk management, are now fixed at 2 December 2027. Article 50 transparency obligations and enforcement powers remain live from 2 August 2026. What does your evidence look like?

--Days
--Hours
--Minutes
--Seconds

Article 50 transparency  ·  enforcement powers active

Annex III high-risk · Article 12 logging · Article 9 risk management 2 December 2027
CONFIRMED · NOT PROPOSED Council final adoption · 29 June 2026

Enforcement is active. Prohibited AI practice restrictions have been active since February 2025. GPAI model obligations since August 2025. On 2 August 2026, Article 50 transparency obligations and the AI Office's enforcement powers activate. Annex III high-risk obligations, Article 12 logging and Article 9 risk management among them, are now fixed at 2 December 2027 following the Council's final adoption on 29 June 2026. That's runway to build the evidence layer properly, not a reason to wait until Q3 2027 to start.

Active and imminent obligations: regulated financial institutions

Active now
GPAI Model Documentation

Providers and deployers must maintain technical documentation of training, testing, and capabilities. Applicable since 2 August 2025.

KairoNull: captures model identity, version, and parameters at every decision event
Since Aug 2025
Dec 2027
Article 12 Mandatory Logging

High-risk AI systems must automatically log events throughout their operational lifetime to ensure traceability of output. Now fixed at 2 December 2027 for standalone high-risk (Annex III) systems, following the Council's final adoption of the Digital Omnibus on 29 June 2026.

KairoNull: SHA-256 hash-chained ledger captures every event at the point of generation
2 Dec 2027
Dec 2027
Article 9 Risk Management Documentation

Deployers of high-risk AI must establish, implement, document, and maintain a risk management system throughout the AI lifecycle. Now fixed at 2 December 2027 for standalone high-risk (Annex III) systems, following the Council's final adoption of the Digital Omnibus on 29 June 2026.

KairoNull: policy-traced invariant evaluation creates continuous documented risk management
2 Dec 2027
-- days
Article 50 Transparency Obligations

AI systems interacting with humans and generating synthetic content must disclose their AI nature. Violations under Art. 99(4): up to €15M or 3% of global annual turnover.

KairoNull: contemporaneous capture produces the disclosure documentation record at the moment of generation
2 Aug 2026
Dec 2027
Annex III High-Risk System Full Compliance

Full obligations for credit scoring, employment decisions, and insurance risk assessment systems. Fixed by Council's final adoption of the Digital Omnibus, 29 June 2026.

KairoNull: builds the evidence record now so December 2027 is a confirmation, not a scramble
2 Dec 2027
Active now
FCA Consumer Duty and SM&CR

FCA-regulated firms must evidence who owns AI-enabled processes, what controls apply, and how performance is monitored.

KairoNull: produces the evidence pack the FCA expects to see, on demand
Active
Active now
GDPR Article 22 Automated Decision-Making

Organisations making automated decisions with legal effects must document the logic, significance, and envisaged consequences.

KairoNull: every record includes the governing policy, rationale, and outcome
Active

Quick risk assessment: regulated financial services

What does your AI system primarily do?

2 December 2027 is a fixed date now, not a political guess.

Most compliance programs will start planning in Q3 2027, when the runway is gone. Build the evidence layer now, while you have room, so December 2027 is a confirmation, not a scramble.

KairoNull deploys in minutes. No architectural changes. No model lock-in.

Book an evidence briefing →