Logiciel Solutions Contact Us
Success Stories Tech News Investors Contact Us
whitepaper

AI Governance Under Regulation.

The Annex III high-risk deadline moved from August 2026 to December 2027, and most organisations read that as sixteen months of breathing room. It is not. Transparency duties under Article 50 became applicable in August 2026 and bind you now, prohibitions have been live since February 2025, and the conformity file a regulator eventually asks for is built from records of how the system has been run. You cannot generate operating history in the final quarter.

In depth

Sixteen More Months Of Deadline Is Not Sixteen More Months Of Slack.

01

The delay moved one deadline and left four in place.

Annex III high-risk obligations now apply from 2 December 2027 and Annex I products from 2 August 2028, but Article 5 prohibitions have bound you since February 2025, general-purpose model duties since August 2025, and Article 50 transparency since August 2026. Read the calendar as four live obligations and one deferred one, not as a single date that moved.

In shortnot as a single date that moved
02

Conformity is proved with records, not with intentions.

The technical documentation an authority expects is assembled from data governance records, event logs, post-market monitoring and human oversight decisions, all of which describe how a system has actually been operated over time. A team that starts in mid-2027 will arrive with a file documenting three months of operation against a system that has been live for years.

In shortA team that starts in mid-2027 will arrive with a fi…
03

A policy document is not evidence.

Most organisations that believe they are governing AI have written a position, circulated it, and stopped, which produces something to show a customer but nothing to show a regulator. The distinction that matters is whether your evidence is generated as a by-product of running the system or has to be assembled by hand when somebody asks for it.

In shortThe distinction that matters is whether your evidenc…
The detail

Three Regimes That Already Bind You, Whatever The AI Act Does.

The AI Act is the loudest instrument but rarely the first one to bite. These three reach your AI systems today, through contracts, sector supervision and existing data law.

Zone · 01

ISO/IEC 42001

The certifiable AI management system, and increasingly the thing enterprise customers ask for in procurement rather than waiting for a regulator. It is a management standard, so it asks who owns each system, how decisions are recorded and how the whole thing is reviewed, which is the same evidence an AI Act conformity file needs.

Zone · 02

NIST AI RMF

The de facto expectation in US federal and enterprise contracting, organised around govern, map, measure and manage. It is voluntary and unenforceable on its own, which is exactly why it appears in contracts instead, where it becomes a commitment you can be held to commercially rather than by a supervisory authority.

Zone · 03

Sectoral supervision

Financial services, healthcare and critical infrastructure regulators already have powers over the decisions your AI systems influence, through existing operational resilience and data protection law. They do not need AI-specific rules to ask how a decision was reached, and GDPR Article 22 has covered automated decisions for years.

By the numbers

The figures that make it a board-level conversation.

2 Dec 2027
revised deadline for Annex III high-risk obligations, moved from 2 August 2026
2 Aug 2026
Article 50 transparency duties became applicable and were not delayed
63%
of organisations had no AI governance policy in place at all
Inside the report

What you'll take away.

01

Step 1 - Sort your systems by role, not by technology

Provider, deployer and importer carry different duties, and most organisations are more than one at once. Fine-tune a model past a threshold and you become a provider.

02

Step 2 - Turn on the records that accrue over time

Event logging, data provenance at ingestion and post-market monitoring as a time series. These are worth little on day one and everything in two years, so start them now.

03

Step 3 - Meet the transparency duty that is already live

Article 50 binds chatbots, generated content and emotion recognition today. Disclosure and machine-readable marking are cheap to add now and awkward to retrofit later.

04

Step 4 - Generate the evidence, do not assemble it

Make model cards, oversight records and monitoring output fall out of the pipeline automatically. Hand-written artefacts go stale between the writing and the audit.

Questions

Frequently asked.

Does the Digital Omnibus delay mean we can pause our AI Act work?

No. It moved Annex III high-risk obligations to 2 December 2027 and Annex I to 2 August 2028, but left prohibitions, general-purpose model duties and Article 50 transparency exactly where they were. Three of those are already in force, so pausing means missing live obligations while you wait for a deferred one.

We are a deployer, not a provider, so how much of this applies?

Less, but not none, and the line is easier to cross than most teams expect. Deployers carry human oversight, input data and monitoring duties. Put your own name on a bought system, or fine-tune one past a substantial modification threshold, and you take on provider obligations for it.

Is an ISO/IEC 42001 certificate enough to satisfy the AI Act?

It is not a conformity presumption, but it is the most useful thing you can hold. The management system it certifies produces the ownership records, review cadence and documentation discipline that a conformity file draws on, so certified organisations start from evidence rather than from nothing.

What should we actually start this quarter?

The things that only have value once they have been running: event log retention, data provenance captured at ingestion rather than reconstructed later, post-market monitoring as a time series, and oversight records that capture where a human disagreed with the system.

How does this differ from your engineering reference on the same topic?

This paper covers the duties and the evidence that satisfies them. AI Governance: An Engineering Reference is the control catalogue that produces that evidence, with numbered controls and the artefact that proves each one. Read this for what is required, that one for what to build.

Who is this report for?

CISOs, general counsel and heads of risk who have to answer what happens if an authority or a customer's auditor asks this quarter. It assumes you already know the AI Act exists and now need the dates, the roles and the evidence list.

Get the whitepaper

Have it emailed to you.

Drop your details and we'll send AI Governance Under Regulation straight to your inbox - no spam, unsubscribe anytime.

Download whitepaper
Next step

Evidence you can hand over is built years before it is asked for.

Talk through what your systems would need to produce if a supervisory authority asked this quarter. A working session with our engineering leads, not a sales pitch. SECTION 7 - FAQ - 5 to 8 questions

Talk to our engineers