Updated · 1 July 2026

On 29 June 2026, the Council of the EU gave final adoption to the Digital Omnibus. Annex III high-risk obligations — including Article 12 logging and Article 9 risk management — are now fixed at 2 December 2027. Article 50 transparency obligations remain live from 2 August 2026. The analysis below has been updated to reflect settled law.

EU AI Act / Enforcement Deadline

EU AI Act August 2026: What Actually Changes, and What Was Delayed to 2027

Published 29 June 2026 · Updated 12 July 2026 · KairoNull · 6 min read
--
days remaining
2 December 2027
Annex III · Article 12 · Article 9 · fixed by Digital Omnibus

Following the Digital Omnibus, Annex III high-risk obligations are fixed at 2 December 2027. That is -- days from now. Regulated financial institutions deploying high-risk AI systems need more than a compliance plan by then. They need a tamper-evident audit trail that can answer a regulator on demand — and the time to build it is not 2027.

What the Digital Omnibus Changed

On 29 June 2026, the Council of the EU gave final adoption to the Digital Omnibus package, deferring Annex III Chapter III obligations — including Article 12 logging and Article 9 risk management — to 2 December 2027 for standalone Annex III systems. This is now settled law, not a proposal. Article 50 transparency obligations are unaffected and remain live from 2 August 2026.

Annex III covers high-risk AI applications in financial services: credit scoring, insurance underwriting, algorithmic systems that materially influence decisions affecting individuals or organisations, and AI used in employment and access to essential services. From 2 December 2027, national competent authorities can open investigations, request audit logs, and issue penalties for non-compliance under Article 12 and Article 9. The maximum penalty for a provider of a non-compliant high-risk AI system is 3% of global annual turnover or €15 million, whichever is higher (Art. 99(4)).

Article 12: The Logging Obligation

Article 12 requires that high-risk AI systems technically allow for the automatic recording of events throughout operational lifetime. Three words carry the compliance weight: automatic, lifetime, and technically.

The Six-Month Gap Problem

Article 19 requires automatically generated logs to be retained for a minimum of six months. Organisations that start logging on August 2 will have no audit trail for decisions made before that date.

If a complaint or regulatory investigation covers a decision made in June or July 2026, there will be no records to produce. That absence is itself a compliance failure. Organisations that started logging in February have a complete six-month trail from day one of enforcement.

What Must Be in Place Before 2 December 2027

Why Starting Now Still Matters

The Annex III deadline moved from August 2026 to December 2027. The audit trail requirement did not. Article 12 requires logging to capture the system's operational lifetime, not just the period after enforcement begins. Organisations that start logging in late 2027 will have no records for decisions made in 2025 or 2026 — the period when AI adoption accelerated most rapidly in financial services.

Regulators investigating a 2026 credit decision in 2028 will ask for the audit trail. Organisations that built it will produce it. Organisations that waited will have nothing to show. The delay in enforcement date does not create a delay in the need for evidence.

KairoNull provides cryptographic evidence infrastructure for AI decisions in regulated financial institutions. SHA-256 hash-chained, RFC3161-timestamped records of every AI decision event, built to meet the authentication, integrity, and chain-of-custody standards applied to digital evidence. Deployment takes days, not months.

See how KairoNull deploys →