The revised timeline: what moved, and what did not
The Act never arrived all at once, and the Omnibus changed only part of it. Knowing which deadline is which is the difference between having runway and missing a duty that is already live.
The Act entered into force, August 2024. The text became law across the EU, starting a staged set of deadlines rather than a single switch.
General purpose model duties applied, 2 August 2025. Obligations landed on providers of general purpose AI models, covering transparency and documentation.
Transparency and enforcement, 2 August 2026, live. Article 50 transparency duties began, the Commission gained its enforcement toolkit for general purpose models, and the penalty framework became operative.
Watermarking grace period ends, 2 December 2026. Generative systems already on the market before August 2026 got four extra months on the machine-readable marking duty. New systems had no such grace.
Annex III high-risk systems, 2 December 2027, deferred. Stand-alone high-risk uses, including recruitment screening, credit scoring, education and access to essential services. Moved from August 2026.
Annex I embedded AI, 2 August 2028, deferred. AI built into products already covered by EU product legislation. Moved from August 2027.
The Digital Omnibus received final Council approval on 29 June 2026. The deferral is unconditional: it replaced the originally proposed conditional trigger with fixed dates.
Live since 2 August 2026: three things landed on schedule
These reach far more organisations than the high-risk rules ever would, and they are enforceable today.
Article 50 transparency. People have to be told when they are dealing with an AI system rather than a person, at the latest on first interaction. Synthetic audio, image, video and text has to be marked in a machine-readable way. Deepfakes have to be disclosed. This is the duty that reaches ordinary businesses, and it got a fraction of the attention the high-risk rules did.
Enforcement powers for general purpose models. The obligations on general purpose model providers have applied since August 2025, but the Commission could not act on them. It can now request information, require access to models, and compel changes. If you fine-tune or white-label a model and place it on the EU market, it is worth checking whether that makes you a provider.
The penalty framework. Breaches of the transparency and general purpose duties sit in the tier reaching 15 million euros or 3% of total worldwide annual turnover, whichever is higher. National authorities can act on provisions already in force, and a documentation request is usually the opening move.
Arriving December 2027: four obligations that land on agent activity
These were expected in August 2026 and now apply from 2 December 2027 for stand-alone high-risk systems. They are the ones that change how an agent estate has to be built and operated, rather than how it is documented, which is why the lead time matters.
- Automatic record keeping. High risk systems will be expected to log events across their lifetime so activity can be traced back. For an agent estate that means a record of what each agent did, not a sample and not a summary, kept long enough to still be there when someone asks.
- Human oversight. People need to be able to understand, intervene in and stop the system. For agents acting at machine speed, oversight after the fact is not oversight. It has to be possible to interrupt an action while it is happening.
- Traceability. Reconstructing how an outcome was reached. When one agent invokes another, which invokes a third, the chain itself becomes part of the answer, and most estates cannot produce it today.
- Deployers carry duties too. Organisations using a high risk system have obligations of their own, including keeping logs and assigning human oversight to people who can act. Buying an agent platform from a vendor does not move those off your side of the line.
Where estates fall short: the controls usually exist on paper and not in the call path
Logs exist, but not as evidence. Most teams have application logs. Few have a record that spans every agent in the business, ties an action to the person or policy that authorised it, and can be shown to be unaltered.
Oversight is a review meeting. Sign off at design time is common. Being able to hold a specific high-risk action until a named person approves it, on the call, is rare.
Nobody has the full inventory. You cannot disclose, govern or evidence anything about an agent you did not know existed. Estates that grew through separate teams and low code tools usually have more running than anyone has written down.
What KPATH gives you: evidence and controls, in the call path
KPATH sits between your agents and the services they reach. Because every call goes through it, the record and the intervention point are properties of the architecture rather than something each team has to remember to build.
A record of every agent action. Each call is recorded with the agent that made it, the authority it acted under, and the time. The record is tamper-evident, so an alteration is detectable rather than invisible, and it is built for long retention.
Human approval at the moment of action. Actions carrying higher risk can be held until a person decides. The approval and the decision both land in the same record, rather than being reconstructed from memory later.
The chain, end to end. When agents invoke other agents, KPATH tracks which one called which. That is what lets you answer how an outcome was reached, and stop the whole chain of work that followed from a single request.
An inventory you did not have to compile. Monitor mode enforces no policy while it builds a picture of the agents and services already running, including the ones nobody registered.
Where to start: four things worth doing with the extra time
None of these require a purchase, and the first two do not require a vendor at all. They are in this order because each one depends on the one above it.
- Find out what you are running. Every other step depends on this one. An inventory of the agents making calls, and of the systems they reach, tells you which are customer-facing and therefore in scope for transparency today, and which plausibly sit in a high risk use for 2027.
- Check your customer-facing agents disclose. This is live now, not in 2027. Any agent a person interacts with has to make clear it is an AI system. Support bots and voice agents are the usual gaps, and they are often the ones a team forgot it had deployed.
- Try to evidence one action. Pick an agent action from last month and produce who authorised it, what it reached, and proof the record has not changed. The distance between what you can produce and what will be asked for is the real size of the work.
- Put a person in the path of the risky actions. Oversight has to be exercisable. That means a named human able to hold a specific action, not a committee reviewing a dashboard next quarter. This has a long lead time, which is what the extra months are for.
This page is not legal advice. Whether a particular system of yours is high risk under the Act, and what that requires, is a question for your legal and risk teams.
Related: finding the agents nobody registered, or the KPATH platform.
Start with what you can evidence today.
A free 30-minute conversation about your agent estate and the records it produces.