Stays Up

The EU AI Act was delayed. Your logging wasn't.

The Digital Omnibus moved high-risk obligations to December 2027, and most teams read that as "not our problem this year." The transparency half is already live, and the retention arithmetic says the logging build starts now. Article 12, translated for engineers.

What actually changed on the calendar

The Digital Omnibus entered into force on 27 July 2026. It moved the AI Act's high-risk deadlines — and only those:

ObligationWasIs now
Prohibited practicesFeb 2025unchanged — live
GPAI (foundation model) rulesAug 2025unchanged — live
Art. 50 transparencyAug 2, 2026unchanged — live now
High-risk, Annex III (standalone systems)Aug 2, 2026Dec 2, 2027
High-risk, Annex I (embedded in regulated products)Aug 2027Aug 2, 2028

The headline every newsletter ran was the sixteen-month delay. The rows that didn't move got much less coverage, and one of them applies to almost everyone.

The part that's already live: Article 50

Since 2 August 2026, if your product interacts with EU users through AI, users must be informed they're interacting with AI. If it generates or manipulates content, the output must carry machine-readable marking as artificially generated. There is a carve-out (Art. 50(2)) for systems already on the market at that date, and member-state enforcement is still warming up — but the obligation exists today, and it sits far below the high-risk bar. A support chatbot qualifies.

What Article 12 actually requires, in engineering terms

When the high-risk obligations do apply, Article 12 requires that systems technically allow for the automatic recording of events over their lifetime, with traceability appropriate to the system's purpose. Stripped of the legal register, that decomposes into requirements an SRE would recognise:

The self-test that compresses all of it: can you reproduce, from logs alone, why your system made one specific decision six months ago? Model version, input, output, and the path between them. If yes, Article 12 is mostly paperwork. If no, you have an engineering project, not a compliance project.

Why December 2027 means 2026

Run the timeline backwards.

Obligations apply on 2 December 2027. Retention is six months minimum — so the logging must be running in production by roughly mid-2027, at scale, having already survived contact with your log volumes and your budget. Before that it needs to be built: trace propagation through every inference path, version pinning, retention infrastructure, access controls, and the evaluation of what "risk-relevant" means for your system. On any real estate, that's quarters — competing with everything else on the roadmap.

The delay bought slack for the paperwork. It bought very little for the engineering. GDPR ran the same shape: two years of runway, then eleven months of panic at panic prices.

The quiet upside

Everything Article 12 asks for is observability you'd want anyway. Decision-level tracing is how you debug model regressions. Version-pinned outputs are how you catch silent drift. Retention is how you answer a customer dispute. Teams treating this as an observability spec get infrastructure that pays rent regardless of what Brussels does to the dates next — and Brussels has now moved them once, in both directions of surprise.

What to do this quarter

This is engineering guidance, not legal advice. Whether a specific system is high-risk under the AI Act is a legal question — we build from your counsel's answer. Sources: Regulation (EU) 2024/1689 (AI Act) Articles 12, 19, 26, 50; Digital Omnibus, in force 27 July 2026. Corrections welcome at hello@staysup.io. Related: what a million LLM tokens actually costs on one GPU — measured.