The Deadline Moved. The Evidence Problem Didn't.
The EU AI Act's high-risk deadline slipped eighteen months. If that changed your plan, your plan was never about evidence.
Securing the Agentic Era. Article 4
We published this in April with a countdown in the title. One hundred and fourteen days to August 2, 2026, when the EU AI Act’s high-risk obligations were due to bite.
Then the clock moved. The Digital Omnibus on AI deferred stand-alone high-risk obligations to December 2, 2027, and high-risk AI embedded in regulated products to August 2, 2028. Parliament adopted it in June. It is done.
Five hundred and five days now, if you want a new number.
I would rather you did not take one. The countdown was always the weakest part of this argument, and the deferral is the proof. Every organization that was racing toward August just got eighteen months back. Not one of them is closer to answering the question a regulator will actually ask.
Because the question never had a date on it.
What the EU AI Act Actually Requires
The regulation establishes a tiered risk framework. Unacceptable-risk systems are banned outright. High-risk systems. The category most enterprises are building toward. Face the most demanding requirements: conformity assessments, technical documentation, human oversight mechanisms, accuracy and robustness standards, and continuous monitoring with logging obligations.
The logging requirements are worth dwelling on. High-risk AI systems must be designed to automatically log events throughout their operational lifetime. The logs must be kept for a defined period. They must be available to national authorities on request.
This is not a GDPR-style “we have a privacy policy” compliance posture. This is operational infrastructure. The evidence has to exist, has to be accurate, and has to be retrievable. At the moment an auditor asks, not six weeks later after a manual collection exercise.
Most enterprise AI deployments are not built this way. They were built to work. The audit trail was an afterthought, if it exists at all.
The Evidence Gap
When I talk to CISOs and CTOs preparing for EU AI Act compliance, the conversation follows a predictable pattern.
Step one: the AI inventory. Most organizations know they need one. Many have started building it. Few have finished, because the inventory problem is harder than it looks. AI is embedded in SaaS tools, in developer workflows, in third-party vendors, in models deployed by business units that never told IT. A spreadsheet is not an inventory. An inventory is a living, auditable record that captures every AI system, its purpose, its risk classification, and its governance status.
Step two: risk classification. This is where most compliance programs stall. The EU AI Act’s definition of “high-risk” is specific but requires judgment to apply. Most legal teams can classify the obvious cases. The edge cases. An AI agent that assists with hiring decisions, an AI system that scores customer creditworthiness indirectly. Require technical and legal expertise working together, and documented rationale for every decision.
Step three: audit trails. This is the infrastructure problem. For high-risk systems, you need to prove that your human oversight controls ran, that your accuracy thresholds were maintained, that your system behaved consistently with its conformity assessment. That proof has to come from logs. Automated, tamper-resistant, and structured for retrieval. Most enterprise AI deployments generate logs. Almost none generate audit-ready evidence.
Step four: vendor due diligence. You are responsible for the AI systems in your stack, including the ones you didn’t build. Your foundation model provider, your AI platform vendor, your SaaS tools with embedded AI. All of them are part of your compliance posture. The regulation requires documented third-party assessments. “We use a reputable vendor” is not sufficient.
Why This Is an Infrastructure Problem, Not a Legal Problem
The temptation is to treat EU AI Act compliance as a legal exercise: update the policies, add the disclosures, file the documentation, and move on. That approach will fail for the same reason that every other compliance-as-paperwork approach eventually fails. It does not survive contact with an actual audit.
Regulators under the EU AI Act have the authority to request system documentation, audit logs, and evidence of ongoing monitoring. If your compliance posture is built on policies and periodic assessments rather than automated evidence collection, you will not be able to produce what is asked for, on the timeline that is required, at the level of detail that is expected.
The organizations that are going to be ready are the ones that treated this as an infrastructure problem from the start. They built the governance layer into their AI deployments. Automated logging, policy enforcement at the system level, continuous monitoring with evidence collection baked in. Rather than trying to reconstruct it after the fact.
This is what Reign is built to do: policy-as-code enforcement, automated audit trails, and regulatory evidence collection across every AI tool in your stack. Not as a compliance bolt-on, but as operational infrastructure. The evidence is generated automatically because the governance layer runs continuously. When an auditor asks, the answer is ready.
What to do in the next ninety days
If you are reading this and your EU AI Act program is still primarily a legal workstream, here is a practical framework for the next three months.
Days 1 to 30: Inventory and classify. Complete your AI system inventory. Every system, every vendor, every embedded use. Classify each against the EU AI Act risk tiers with documented rationale. Identify your high-risk systems. These are your compliance priority.
Days 31 to 60: Assess your evidence posture. For each high-risk system, audit your current logging and monitoring. What evidence do you have today that your controls ran? What would you need to produce for an auditor? The gap between what you have and what you need is your remediation list.
Days 61 to 90: Build or deploy the evidence infrastructure. Close the gap. This means automated audit logging, policy enforcement monitoring, and a retrieval mechanism that lets you produce evidence on demand. For most organizations, building this in-house is not realistic in 90 days. The question is which platform provides it.
Days 91 and beyond: run a mock audit. Have someone outside your compliance team request the evidence your highest-risk systems would need to produce. Identify what’s missing. Fix it.
What actually moved, and what did not
Precision matters here, because most of the commentary has been sloppy about it.
Moved. Stand-alone high-risk systems under Annex III, the category that covers AI in employment, credit, healthcare, critical infrastructure, law enforcement, and education, now apply from December 2, 2027. High-risk AI embedded in regulated products under Annex I moves to August 2, 2028. National regulatory sandboxes move to August 2, 2027.
Did not move. The Article 50 transparency obligations still apply from August 2, 2026. That is eighteen days from now. If you interact with people through an AI system, you still have to tell them, on the original schedule.
Got tighter. The grace period for synthetic-content transparency was cut from six months to three, landing December 2, 2026. And a new prohibition on AI-generated non-consensual intimate imagery and CSAM arrives this December.
So the EU AI Act was delayed is not true. Parts of it were deferred, one part was accelerated, and a new prohibition was added. An organization that heard delay and slowed down has already made its first error.
And the penalties did not move. Breach the high-risk obligations and it is up to EUR 15 million or 3% of worldwide turnover, whichever is higher. The EUR 35 million and 7% figure that gets quoted in most coverage is the prohibited-practices tier under Article 5. Different obligation, different tier. If your risk register has 7% next to your high-risk AI systems, someone copied the wrong number.
Why the deferral should not change what you build
Here is the test. If an eighteen-month extension changed your roadmap, your roadmap was a compliance project. Compliance projects produce documents on a deadline, and the document is finished when the deadline passes.
An evidence capability is not a project. It is a property of how your systems run. It does not have a completion date, because it is not producing an artifact for an examiner. It is producing an artifact continuously, as a byproduct of the work, and the examiner is simply one of several people who might eventually ask to see it. The board is another. A customer running vendor due diligence on you is a third.
If you build the second thing, December 2027 is not a deadline. It is a Tuesday on which you happen to already be ready.
If you build the first thing, you now have five hundred and five days to do a thing that takes ninety, which means you will start in month fourteen, which means you will be exactly where you were in April.
The organizations that used the last three months well did not slow down. They noticed that nothing about what an auditor asks for had changed at all.
Automated audit trails, policy-as-code enforcement, and regulatory evidence collection. Article-by-article automation map for high-risk AI obligations.
Paul Goldman is CEO of iTmethods and architect of Reign and Forge. AI governed. Outcomes assured. He writes about AI governance, enterprise AI infrastructure, and what regulated industries need to build safely in the agentic era.
Previously in this series: The AI-Native Stack · Self-Hosted Agents · The Platform Engineering Pivot
Paul Goldman
CEO, iTmethods
Creator of Reign and Forge. The platform and operational substrate for AI governance in regulated industries. Previously published "MCP Is Exploding. Your Governance Isn’t Ready."
Continue the AI Governance series
Previous
Chamath Just Said What Every Enterprise CISO Already Knows
Why data sovereignty, AI cost control, and attorney-client privilege demand governed infrastructure
Next
Reign and Forge for AI Agents: Governed by Design
Or share your thoughts here
Your comment will appear on this page. The best insights may be shared in the LinkedIn discussion.
Get Paul’s next article before it publishes
Join 500+ security leaders