EU AI Act

The deadline moved. The obligation didn’t.

High-risk AI-agent obligations are being pushed to December 2027 under the EU Digital Omnibus (agreed, pending final adoption). But transparency duties and the AI Office’s enforcement powers already apply from 2026 — and the engineering that satisfies the high-risk rules takes far longer than the extension buys you. NOCTRYS makes you provably ready early, by design, not in a last-minute scramble.

Art. 12 loggingArt. 14 oversightArt. 15 robustnessArt. 26 retentionup to €15M / 3%
The corrected clock

Where the timeline really stands in 2026

Read almost any 2025-era summary and you will see "high-risk obligations go live 2 August 2026." Under the EU Digital Omnibus, that is no longer accurate — and getting it wrong in a board deck is its own kind of risk. Here is the current picture:

From 2026Applies now

Transparency + AI Office

Article 50 transparency duties and the AI Office’s enforcement powers apply. General-purpose AI model obligations are already in force.

~December 2027Agreed · pending adoption

High-risk (Annex III)

Obligations for Annex-III high-risk use-cases — credit, insurance, employment, essential services — postponed here under the Digital Omnibus.

August 2028Agreed · pending adoption

High-risk (Annex I)

High-risk AI embedded in already-regulated products (Annex-I safety legislation) moves to this later date.

The honest read: the Digital Omnibus postpones the high-risk obligations — Annex-III use-cases (credit, insurance, employment, essential services) to about December 2027, and Annex-I-embedded high-risk systems to August 2028. This is agreed but pending formal adoption. What is not postponed: the Article 50 transparency duties and the AI Office’s enforcement powers, which apply from 2026.

Why "later" is not "relax"

An extension is runway, not a reprieve

The duties that land on autonomous agents — tamper-evident logging, real-time human oversight, robustness against manipulation, multi-year record-keeping — are not a document you write the week before an audit. They are an architecture. Teams that treat December 2027 as "do it later" will discover that retrofitting a believable, intervenable audit trail onto agents already in production is the hard, expensive path.

The hard part for autonomous agents was never writing a log. It is producing a log a regulator will believe — and being able to intervene in real time.
The NOCTRYS thesis

NOCTRYS is the by-design route: install it now, and every agent action is governed, overseeable, and independently provable from day one. When the obligations bite — and when your own auditors, insurers, and enterprise customers ask sooner than the regulator does — you are already compliant, not scrambling.

Article-by-article

The high-risk duties, mapped to concrete controls

The extension changes when, not what. These are the obligations that land on the agent action layer, and the NOCTRYS control that satisfies each — still the substance whichever date applies.

ArticleWhat it requiresHow NOCTRYS satisfies it
Art. 12Automatic logging of events over the system’s lifetime; full traceability.Every action is hash-chained into a tamper-evident recorder, anchored on the AERE chain and cosigned by independent witnesses — so the log is not just complete, it is un-forgeable and independently verifiable.
Art. 14Effective human oversight; ability to detect anomalies and intervene.High-risk actions are held for a named human’s cryptographic sign-off; a kill-switch freezes an agent — or the whole fleet — instantly.
Art. 15Accuracy, robustness, and resilience against manipulation.Deterministic, fail-closed enforcement plus defenses against injection, self-modification, tool-drift, tool-shadowing, and Unicode smuggling.
Art. 26Deployer keeps automatically-generated logs for at least six months.Persistent, tamper-evident store with SIEM export and redaction of secrets/PII.
Art. 50Transparency duties (already applying from 2026).Every governed action is attributable and disclosed in the audit record — the transparency baseline is a byproduct of how NOCTRYS works.

This is an engineering mapping and a plain-language reading of a moving legislative process, not legal advice; dates reflect the Digital Omnibus as agreed and pending adoption. Consult qualified counsel for your obligations.

Audit-ready output

What you can hand an examiner

  • A one-command AI-Act audit report: totals, blocks by reason, integrity status, the anchored Merkle root, and article coverage.
  • A public verifier so the examiner checks the record themselves — no need to trust you or us. Try it →
  • OWASP Top 10 for Agentic Applications (2026): 10/10 covered. See Compliance →.

Be one of our first five design partners

Free pilot. Two-week, self-hosted integration. You keep the tamper-evident audit and the AI Act compliance report.

Request a pilot →