Skip to main content
    Regulatory alignment · EU AI Act

    Three tracks. One governance posture.

    The AI Omnibus, Regulation (EU) 2026/1744, in force 27 July 2026, leaves three implementation tracks running at different speeds. Each one demands the same underlying evidence: classification, risk management, documentation, oversight, and continuous monitoring.

    Obligations and evidenceThe timelineAll frameworks

    No compliance claim. iTmethods makes no compliance, certification or accreditation claim under the EU AI Act or any other framework named on this page. We are not certified against, accredited for, or approved under any of them. Alignment is not compliance. The determination belongs to your own risk function, and nothing here transfers it to us.

    Obligations and evidence

    Every high-risk obligation lands on the same evidence layer.

    The obligations differ by track. What they ask you to produce differs a good deal less.

    Classification

    Which of your systems are high risk, on what basis, and who decided. The answer changes as use cases move, so it is a record rather than a one-time assessment.

    Could you defend your classification?

    Documentation and oversight

    Technical documentation, human oversight and record keeping. Three obligations that all resolve to the same question: what happened, and can you show it.

    Show it from where?

    Monitoring after deployment

    The obligation does not end at go-live. Post-market monitoring is continuous, and evidence assembled afterwards is the weakest kind.

    What is watching yours today?

    Reign maps each high-risk obligation to a capability and an evidence stream. Where an obligation to hold a regulatory status sits with your institution it stays there, and what Reign carries is the operating record those obligations are assessed against.

    The timeline

    The deadline moved. The work did not.

    The AI Omnibus, Regulation (EU) 2026/1744, in force 27 July 2026, extends the date. It does not reduce what has to exist by that date.

    Annex III high-risk — employment, credit scoring, education, essential services — moves from 2 August 2026 to 2 December 2027. Annex I high-risk, which covers AI embedded in regulated products including medical devices, moves from 2 August 2027 to 2 August 2028. Prohibited practices and AI literacy have applied since February 2025 and GPAI obligations since August 2025; neither moved.

    What did not move, and is enforceable now. The bulk of the Article 50 transparency obligations have applied since 2 August 2026. Systems already on the market before that date have until 2 December 2026 to meet the synthetic-content marking requirement. Neither of those is covered by the extension, and both are live while the high-risk deadlines sit in 2027 and 2028. If any part of this timeline is doing work for you today, it is this part.

    Institutions building the governance posture now will have more of the evidence already in place. Whether that amounts to readiness is their risk function’s determination. Institutions that wait face the same workload on a shorter clock, and the parts that take longest are the parts that cannot be bought at the end.

    Reign is aligned to the EU AI Act. It is not certified against it, no product can be, and no product makes an institution compliant with it. No authority responsible for it endorses, approves or recommends Reign or iTmethods.

    Next step

    Start on the evidence, not the deadline.

    We will look at which obligations your current estate could already answer, and which have nothing behind them yet.