You're already deploying high-risk AI. Here's what to show a regulator.
TL;DR. Most organisations using off-the-shelf AI are deployers under the EU AI Act, and many are deployers of high-risk systems without having classified them as such. The high-risk obligations were deferred to 2 December 2027, which has been widely read as breathing room. It is not. The Article 50 transparency obligations apply from 2 August 2026, AI literacy and the prohibitions have been enforceable since February 2025, and NIS2 and DORA are already in force. The practical question is not whether you are compliant on paper. It is what you can put in front of someone who asks you to show your work.
There is a good question going around at the moment, and it deserves a real answer:
If a regulator walked into your building tomorrow and asked to see evidence of human oversight of your AI systems, what would you show them?
It is a fair question, and most organisations cannot answer it. What follows is an attempt to answer it concretely rather than to restate it.
The deadline that moved is not the one arriving
The Digital Omnibus deferred the high-risk obligations for standalone Annex III systems from August 2026 to 2 December 2027, and for AI embedded in regulated products under Annex I to 2 August 2028. That deferral was real and it was significant.
It also caused a widespread and expensive misreading: that nothing bites until late 2027.
Here is what is actually enforceable, today:
| Obligation | Applies from |
|---|---|
| Prohibited practices (Art. 5) | 2 February 2025, in force |
| AI literacy for staff working with AI (Art. 4) | 2 February 2025, in force |
| GPAI obligations, models placed on the market after the date | 2 August 2025, in force |
| Transparency obligations, including deployer transparency (Art. 50) | 2 August 2026 |
| Provider marking of synthetic content (Art. 50(2)) | 2 December 2026 |
| GPAI models already on the market before Aug 2025 | 2 August 2027 |
| High-risk, standalone Annex III systems | 2 December 2027 |
| NIS2, Swedish Cybersecurity Act (cybersäkerhetslagen) | 15 January 2026, in force |
| DORA | In force since January 2025 |
If your organisation operates in financial services or in a NIS2 sector, the AI Act timeline is close to irrelevant to your near-term exposure. You are already inside two regimes that are being supervised now.
Why you are probably a deployer already
Under the Act, an organisation that uses an AI system it did not build is a deployer. If your staff use an AI assistant in the course of their work, you are a deployer. Deployer status is not something you opt into by launching an AI programme. It attaches to use.
Whether a given system is high-risk is where most self-assessments go wrong, because the answer is not a property of the tool. It depends on the role the system plays in a decision inside your organisation. The same CV-screening tool can be high-risk in one company and not in another, depending on whether its output meaningfully shapes the outcome for a person or is one reference point among several that a human weighs.
This is why "we only use standard products" is not a finding. It is an assumption. The Annex III categories worth checking first are employment and worker management, access to essential private and public services including creditworthiness, education, and law enforcement.
What the Act actually requires, stated precisely
This is where a lot of vendor material, including some written by people who should know better, overstates the law. It is worth being exact, because a compliance claim you cannot support is itself a risk.
Article 12 requires that high-risk systems technically permit the automatic recording of events over the system's lifetime, so that operation is traceable. For deployers, Article 26 requires keeping the logs that are under your control, for at least six months unless other law says otherwise. Article 12 does not, in itself, require you to write down each decision and the reasoning behind it.
Article 14 requires that high-risk systems be designed so that a natural person can effectively oversee them, and requires deployers to assign oversight to people with the competence, training and authority to do it. It addresses interpreting output, resisting automation bias, and the ability to intervene, override or reverse. It does not, in itself, mandate a written rationale for every decision.
So the honest position is this: the Act does not tell you to keep a decision record. It tells you to be able to demonstrate that oversight happened and that your system's operation is traceable. When a supervisory authority, an auditor, or an affected individual asks you to show that, a contemporaneous record of what was decided, by whom, and on what basis is what makes the answer possible. Everything else is reconstruction after the fact, which is slow, inconsistent, and unconvincing precisely when it matters.
That distinction, between what the law compels and what actually lets you answer, is the whole of practical AI governance.
What to do in the next two weeks
Twelve-month governance roadmaps are useful for boards and useless on a Tuesday. Four things are worth doing now:
- List where AI touches a decision about a person. Hiring, credit, access to services, performance management, benefits. Not a tooling inventory, a decision inventory. Most organisations have never written this down.
- For each one, name the human. Who can override it, do they know they can, and do they have the standing to do so. If nobody can be named, the oversight requirement is already unmet.
- Check your Article 50 position before 2 August. Where people interact with AI, or where AI generates or manipulates content presented as genuine, they generally need to be told. That obligation arrives in a fortnight and it is not deferred.
- Start recording decisions from today, not from when your programme is ready. Evidence cannot be backdated honestly. The record you wish you had in 2027 is the one you begin keeping now.
Questions we get asked
Are we high-risk if we only use commercial AI tools? Possibly. High-risk status follows the use, not the vendor. A general-purpose tool used to screen candidates can place you in an Annex III category, while the same tool used to draft internal copy does not.
The deadline moved to December 2027. Can we wait? Not safely. The Article 50 transparency obligations apply from 2 August 2026, the prohibitions and AI literacy duties have been enforceable since February 2025, and the Swedish Cybersecurity Act implementing NIS2 has been in force since 15 January 2026, with DORA in force since January 2025.
Does the AI Act require us to keep a decision log? No, not in those terms. Article 12 concerns automatic event logging and traceability, and Article 26 requires deployers to retain logs under their control for at least six months. A decision record is not mandated by name. It is, in practice, how organisations become able to demonstrate the oversight that Article 14 does require.
What counts as evidence of human oversight? There is no prescribed format. In practice it means being able to show, after the fact, that a competent person could and did exercise judgment: what the system recommended, what the human decided, when, and on what basis.
We are a Swedish company. Which regime hits us first? For most, the Cybersecurity Act implementing NIS2 (in force 15 January 2026) or DORA, both well before the AI Act's high-risk obligations in December 2027. Note also that supervision moved to the National Cyber Security Centre at FRA on 1 July 2026.
The answer to the question
If a regulator asked you today, the answer should not be a policy document written last quarter. It should be a dated, structured record of the decisions themselves.
That is what we build. IRP Compliance runs a free structured assessment against the EU AI Act, NIS2 and DORA, and produces a permanent evidence record of what you decided and why, with your fine exposure and a prioritised action plan. It takes about twenty minutes. There is no charge for the assessment or the record, and no sales call attached to it.
If you want the board-ready PDF report as well, that is 299 EUR. If you only want to know where you stand and to start keeping the record, that costs nothing and you can begin today.
Intent Record AB builds IRP Compliance, which turns the decisions an organisation already makes into audit-ready evidence for the EU AI Act, NIS2 and DORA. The protocol is MIT-licensed and available at github.com/S0tman/irp-capture.
Sources: EU AI Act implementation timeline, European Commission guidelines on high-risk classification, Gibson Dunn on the Omnibus agreement. This article is general information, not legal advice.