The date most EU AI Act compliance work was planned around, 2 August 2026, arrived without the obligations everyone had prepared for. Six days earlier, Regulation (EU) 2026/1744 - the digital omnibus on AI, published in the Official Journal on 24 July 2026 and in force from 27 July - moved the application date for stand-alone high-risk systems under Article 6(2) and Annex III to 2 December 2027, and for AI acting as a safety component of a regulated product to 2 August 2028. The stated reason was that the harmonised standards were not ready. Article 26, which carries the duties that land on deployers, sits inside exactly the block that moved.

What arrived on time was Article 50, alongside an Article 4 that had already applied since 2 February 2025 and that the omnibus rewrote six days before. Neither of them asks whether your AI is high-risk. The work those two articles create is an asset inventory and a log retention policy, two artefacts your NIS2 and ISO 27001 evidence packs already half contain. Nobody has to classify a model to produce either one.

Almost every infrastructure team is a deployer rather than a provider: you use AI systems under your own authority in a professional capacity, but you did not develop one and put your name on it. That makes the obligation set narrower than most compliance vendors imply, and considerably larger than nothing.

AI Act deployer obligations, and the article that turns you into a provider

Article 25(1) converts a deployer into a provider, with the full Chapter III obligation set attached, in three situations: you put your own name or trademark on a high-risk system already on the market, you make a substantial modification to a high-risk system that stays high-risk, or you change the intended purpose of an AI system, including a general-purpose one, so that it becomes high-risk. The third case catches platform teams without anyone touching a model: wiring a general-purpose assistant into a decision Annex III lists is a purpose change, and the paperwork that follows is not the paperwork you scoped. That conversion runs on the same deferred clock, so it is a design constraint on what you wire up in 2027 rather than an obligation today.

The headline penalty number belongs to somebody else. Article 99 puts prohibited practices under Article 5 at up to EUR 35 million or 7% of worldwide annual turnover. Breaches of the operator obligations, which is where Article 26 and Article 50 live, cap at EUR 15 million or 3%, and misleading an authority at EUR 7.5 million or 1%. Article 99(6) then reverses the formula for SMEs and start-ups, capping the fine at whichever of the two figures is lower rather than higher.

The AI system inventory is the artefact everything else rests on

An IAPP analysis published on 6 May 2026 listed five things deployers cannot produce when asked: an AI system register, a written rationale for how each system was classified, human oversight documented as something other than an org chart, a retention policy covering specific AI systems, and a defined escalation or suspension threshold for incidents. Every one of those five is a thing an infrastructure team builds, and four are impossible without the first. An AI system register is written against a machine inventory, and Sencai builds that second list by reading the accounts back, across eleven cloud providers and the on-premise hardware a host agent reaches, so it is dated by the run rather than by whoever last edited it.

Shadow AI is where the register goes wrong, and it has a price. IBM's Cost of a Data Breach Report 2025 found that one in five studied organisations reported a breach involving AI nobody had sanctioned, and where shadow AI involvement was high those breaches ran about USD 670,000 above the global average of USD 4.44 million. The statutory link is direct: Article 50 requires you to disclose that a person is dealing with an AI system, and you cannot disclose a system you do not know is running.

AI Act logging requirements put a six-month floor on two different parties

Article 26(6) requires deployers to keep the automatically generated logs of a high-risk AI system that are under their control for a period appropriate to its intended purpose, and at least six months, unless Union or national law provides otherwise. Article 19 places the mirror duty on providers with the same six-month floor, so the number appears twice in the Act, on two parties who will each assume the other is holding the record.

Article 12(3), written about biometric identification, is the most useful paragraph in the Act for anyone designing a log format. It names the start and end date and time of each period of use, the reference database checked, the input data that produced a match, and the identity of the people who verified the result. Read as a specification rather than as a rule about biometrics, it describes what a defensible log line contains: when, against what, on what input, and on whose authority.

The same audit trail answers NIS2 and ISO 27001

None of this is new evidence work if you are already inside NIS2. The directive required transposition by 17 October 2024 and runs a three-stage clock on significant incidents: an early warning within 24 hours, a fuller notification within 72, a final report within a month. Meeting that clock is a reconstruction exercise, which is a log problem. ISO/IEC 27001:2022 has carried the matching controls since publication: Annex A 8.15 on producing, storing and protecting logs, 8.16 on monitoring for anomalous behaviour. ISO/IEC 42001:2023, the AI management system standard published on 18 December 2023, is not yet a harmonised European standard, so certifying against it buys you a credible answer to a customer and no presumption of conformity with the Act.

That overlap is the argument for logging an AI-assisted action like any other change, instead of standing up a second AI governance record that goes stale by quarter two. Sencai takes it literally: a remediation a model proposed and a person approved is filed beside a firewall rule someone edited by hand, and updates and deletes are refused by the storage layer instead of discouraged by policy. Read Article 26(6) against that design and its point sharpens. Six months of logs are six months of evidence only if retention is a property of the store; a record an operator can quietly edit in month four has a retention policy the way a propped-open door has a lock.

The supplier questionnaire arrives long before the regulator does

Your customers are in scope too, and their compliance programme reaches you as a document request months before any regulator does. The questions are consistent: which model providers process our data, when they are engaged, under what retention, and what stops usage running away. Three of the four are answerable from a document written once and published, which is how we answer them. The fourth resists that, because a truthful answer needs a number, not a paragraph: ours is a per-person budget with a fixed upper bound, the only form a customer can check against an invoice. A sub-processor list names companies; your DPA and your own classification rationale decide whether naming them is enough.

What to build first, and what can wait until 2027

Start with the register: Article 50 binds today, and everything later depends on knowing what you run. Machine-readable marking of synthetic output from generative systems already on the market before 2 August 2026 has a grace period closing on 2 December 2026, and the labelling duties for deepfakes and for AI-generated text on matters of public interest fall on the deployer, not on the vendor who sold you the model. Then set retention: six months is a floor for high-risk systems, not a target, and it will collide with a data protection rule you have already written.

Article 4 costs the least of the three. The omnibus softened it from ensuring a sufficient level of AI literacy to taking measures that support its development, with express text that no specific level in any individual has to be guaranteed, so a dated attendance record for a one-hour session is the cheapest compliant artefact in the whole Act. Do that work through 2027 and 2 December arrives with the register written and the retention rule already applied to the systems it names, instead of being drafted in the same month those systems come into scope. The register still goes first.