The deadline moved. The obligation didn’t.
High-risk AI-agent obligations are being pushed to December 2027 under the EU Digital Omnibus (agreed, pending final adoption). But transparency duties and the AI Office’s enforcement powers already apply from 2026 — and the engineering that satisfies the high-risk rules takes far longer than the extension buys you. NOCTRYS makes you provably ready early, by design, not in a last-minute scramble.
Where the timeline really stands in 2026
Read almost any 2025-era summary and you will see "high-risk obligations go live 2 August 2026." Under the EU Digital Omnibus, that is no longer accurate — and getting it wrong in a board deck is its own kind of risk. Here is the current picture:
Transparency + AI Office
Article 50 transparency duties and the AI Office’s enforcement powers apply. General-purpose AI model obligations are already in force.
High-risk (Annex III)
Obligations for Annex-III high-risk use-cases — credit, insurance, employment, essential services — postponed here under the Digital Omnibus.
High-risk (Annex I)
High-risk AI embedded in already-regulated products (Annex-I safety legislation) moves to this later date.
The honest read: the Digital Omnibus postpones the high-risk obligations — Annex-III use-cases (credit, insurance, employment, essential services) to about December 2027, and Annex-I-embedded high-risk systems to August 2028. This is agreed but pending formal adoption. What is not postponed: the Article 50 transparency duties and the AI Office’s enforcement powers, which apply from 2026.
An extension is runway, not a reprieve
The duties that land on autonomous agents — tamper-evident logging, real-time human oversight, robustness against manipulation, multi-year record-keeping — are not a document you write the week before an audit. They are an architecture. Teams that treat December 2027 as "do it later" will discover that retrofitting a believable, intervenable audit trail onto agents already in production is the hard, expensive path.
The hard part for autonomous agents was never writing a log. It is producing a log a regulator will believe — and being able to intervene in real time.
NOCTRYS is the by-design route: install it now, and every agent action is governed, overseeable, and independently provable from day one. When the obligations bite — and when your own auditors, insurers, and enterprise customers ask sooner than the regulator does — you are already compliant, not scrambling.
The high-risk duties, mapped to concrete controls
The extension changes when, not what. These are the obligations that land on the agent action layer, and the NOCTRYS control that satisfies each — still the substance whichever date applies.
| Article | What it requires | How NOCTRYS satisfies it |
|---|---|---|
| Art. 12 | Automatic logging of events over the system’s lifetime; full traceability. | Every action is hash-chained into a tamper-evident recorder, anchored on the AERE chain and cosigned by independent witnesses — so the log is not just complete, it is un-forgeable and independently verifiable. |
| Art. 14 | Effective human oversight; ability to detect anomalies and intervene. | High-risk actions are held for a named human’s cryptographic sign-off; a kill-switch freezes an agent — or the whole fleet — instantly. |
| Art. 15 | Accuracy, robustness, and resilience against manipulation. | Deterministic, fail-closed enforcement plus defenses against injection, self-modification, tool-drift, tool-shadowing, and Unicode smuggling. |
| Art. 26 | Deployer keeps automatically-generated logs for at least six months. | Persistent, tamper-evident store with SIEM export and redaction of secrets/PII. |
| Art. 50 | Transparency duties (already applying from 2026). | Every governed action is attributable and disclosed in the audit record — the transparency baseline is a byproduct of how NOCTRYS works. |
This is an engineering mapping and a plain-language reading of a moving legislative process, not legal advice; dates reflect the Digital Omnibus as agreed and pending adoption. Consult qualified counsel for your obligations.
What you can hand an examiner
- A one-command AI-Act audit report: totals, blocks by reason, integrity status, the anchored Merkle root, and article coverage.
- A public verifier so the examiner checks the record themselves — no need to trust you or us. Try it →
- OWASP Top 10 for Agentic Applications (2026): 10/10 covered. See Compliance →.
Be one of our first five design partners
Free pilot. Two-week, self-hosted integration. You keep the tamper-evident audit and the AI Act compliance report.
Request a pilot →