The EU AI Act was delayed. Your logging wasn't.
The Digital Omnibus moved high-risk obligations to December 2027, and most teams read that as "not our problem this year." The transparency half is already live, and the retention arithmetic says the logging build starts now. Article 12, translated for engineers.
What actually changed on the calendar
The Digital Omnibus entered into force on 27 July 2026. It moved the AI Act's high-risk deadlines — and only those:
| Obligation | Was | Is now |
|---|---|---|
| Prohibited practices | Feb 2025 | unchanged — live |
| GPAI (foundation model) rules | Aug 2025 | unchanged — live |
| Art. 50 transparency | Aug 2, 2026 | unchanged — live now |
| High-risk, Annex III (standalone systems) | Aug 2, 2026 | Dec 2, 2027 |
| High-risk, Annex I (embedded in regulated products) | Aug 2027 | Aug 2, 2028 |
The headline every newsletter ran was the sixteen-month delay. The rows that didn't move got much less coverage, and one of them applies to almost everyone.
The part that's already live: Article 50
Since 2 August 2026, if your product interacts with EU users through AI, users must be informed they're interacting with AI. If it generates or manipulates content, the output must carry machine-readable marking as artificially generated. There is a carve-out (Art. 50(2)) for systems already on the market at that date, and member-state enforcement is still warming up — but the obligation exists today, and it sits far below the high-risk bar. A support chatbot qualifies.
What Article 12 actually requires, in engineering terms
When the high-risk obligations do apply, Article 12 requires that systems technically allow for the automatic recording of events over their lifetime, with traceability appropriate to the system's purpose. Stripped of the legal register, that decomposes into requirements an SRE would recognise:
- Event logging is a system property, not an option. The system must be built so operation produces logs — "we can add logging later" fails the requirement by construction.
- Decision-level traceability. For a given output you need to reconstruct: which model version, which prompt or configuration, what input, when, and what came out. That means trace context propagated through every model call and versions pinned to every decision — not prints in a container's stdout.
- Risk-relevant situations must be identifiable from the logs — the periods where the system might present risk or has been substantially modified (Art. 12(2)). You can't flag what you didn't record.
- Retention: at least six months — for providers (Art. 19) and deployers (Art. 26(6)) alike, longer where other law says so. Your 14-day log rotation is a compliance gap wearing a cost optimisation.
Why December 2027 means 2026
Run the timeline backwards.
Obligations apply on 2 December 2027. Retention is six months minimum — so the logging must be running in production by roughly mid-2027, at scale, having already survived contact with your log volumes and your budget. Before that it needs to be built: trace propagation through every inference path, version pinning, retention infrastructure, access controls, and the evaluation of what "risk-relevant" means for your system. On any real estate, that's quarters — competing with everything else on the roadmap.
The delay bought slack for the paperwork. It bought very little for the engineering. GDPR ran the same shape: two years of runway, then eleven months of panic at panic prices.
The quiet upside
Everything Article 12 asks for is observability you'd want anyway. Decision-level tracing is how you debug model regressions. Version-pinned outputs are how you catch silent drift. Retention is how you answer a customer dispute. Teams treating this as an observability spec get infrastructure that pays rent regardless of what Brussels does to the dates next — and Brussels has now moved them once, in both directions of surprise.
What to do this quarter
- Get the classification question to your lawyer: which of your systems, if any, land in Annex III. Engineering can't answer this, and everything scales with the answer.
- Check Article 50 exposure today: user-facing AI interaction and generated content. That one is live.
- Inventory the gap against the self-test above — per system, honestly.
- Put decision-level tracing and retention on the 2026–27 roadmap as infrastructure, sized like infrastructure — not as a compliance line item for late 2027.
This is engineering guidance, not legal advice. Whether a specific system is high-risk under the AI Act is a legal question — we build from your counsel's answer. Sources: Regulation (EU) 2024/1689 (AI Act) Articles 12, 19, 26, 50; Digital Omnibus, in force 27 July 2026. Corrections welcome at hello@staysup.io. Related: what a million LLM tokens actually costs on one GPU — measured.