Note · AI Act

The EU AI Act is in force. What it requires, in plain terms.

(Urs), September 2026. Every fact in this note is dated and sourced at the end.

Rewording an email, summarising a file, preparing a meeting with an artificial-intelligence assistant: these actions fall under a European regulation adopted in 2024 and amended this summer by a second text. Both are legal texts, long and technical. This note sets out the essentials, for anyone who uses these tools at work, whatever their position.

The law classifies uses, not companies

The regulation does not classify companies by sector. It classifies uses according to the risk they pose to people's rights and safety, in four levels — and, for products already subject to European safety regulation, such as medical devices, vehicles or lifts, the artificial intelligence that serves as a safety component of the product follows that product's regime. A bank is not "high-risk"; its credit-scoring tool is, and its writing assistant is not. The same goes for a pharmaceutical company: its CV-screening tool falls under the high-risk regime, its software embedded in a medical device falls under the regulated-products regime, its meeting summariser falls under no particular regime. General-purpose AI models — the ones behind consumer assistants — are subject to obligations of their own, in force since 2 August 2025, which fall on their providers and not on the organisations that use them.

Prohibited uses: manipulating people without their knowledge, scoring citizens on their behaviour — in force since 2 February 2025. This summer's text adds the production of intimate images of a person without their consent, applicable from 2 December 2026.

High-risk uses: artificial intelligence that contributes to a decision that is decisive for a person — granting or refusing credit, screening job applications, admitting a student, identifying someone biometrically, operating critical infrastructure. This is the most demanding regime, and it is the one this summer's text postponed.

Uses subject to transparency: when you interact with a machine, you must be told; when content has been produced by a machine, it must be identifiable as such. These rules apply since 2 August 2026, with an allowance until 2 December 2026 for content marking by systems already in service.

And all other uses — assisted writing, meeting summaries, text correction. For these, the regulation imposes almost no specific obligation. It imposes one, general obligation: organisations must ensure that the people who use these systems have a sufficient understanding of them — what they do, what they do not do, their limits. This obligation has applied since 2 February 2025. It concerns the executive assistant as much as the chief executive.

What changed this summer

The 2024 timetable set the application of the high-risk regime for 2 August 2026. An amending text, the Digital Omnibus, was proposed by the Commission on 19 November 2025, negotiated to a political agreement on 7 May 2026, voted by the European Parliament on 16 June, adopted by the Council on 29 June, signed on 8 July, published in the Official Journal on 24 July, and entered into force on 27 July 2026. It bears the number 2026/1744.

The high-risk regime will therefore apply on 2 December 2027 for stand-alone systems — credit, recruitment, education, biometrics, infrastructure — and on 2 August 2028 for artificial intelligence embedded in products already regulated elsewhere, such as medical devices.

The reason for the postponement deserves to be known. The technical standards that are to define how conformity is demonstrated were not ready, and the national supervisory authorities had not been designated in every member state. These standards are being drafted at European level; as of summer 2026, none had yet been published in the Official Journal, and their availability is expected between late 2026 and early 2027. The postponement stems from the absence of instruments of application, not from a revision of the requirements. No obligation has been removed from the high-risk regime; all of them will apply, sixteen months later than planned.

What the high-risk regime requires, in three questions

The high-risk obligations run to dozens of articles. Three of them — Articles 12, 14 and 19 — form the core, and each comes down to a question a business manager can ask without any technical expertise.

Can we retrieve what the system did? The regulation requires high-risk systems to automatically record the events of their operation, throughout their lifetime — a log kept as it happens, not a reconstruction after the fact.

Could a person intervene? The regulation requires effective human oversight: people able to understand the system, to override its outputs and to interrupt its use.

Was the record kept? The regulation requires these logs to be retained for a period appropriate to the system's use, and for at least six months — an obligation that falls on the system's provider as well as on the organisation using it, with financial institutions keeping the logs under their own sector regulation. The organisation deploying such a system must also inform workers' representatives and the affected employees before putting it into service, and inform the people who are subject to an assisted decision.

Why sixteen months is not a delay

A credit or recruitment decision taken today with the help of an artificial-intelligence system may be contested in 2028, under a regulation that will by then be fully applicable. The question asked will be: how was this decision made? If the log was not kept in 2026, it will not exist in 2028. An automatic record of events cannot be reconstructed after the fact; that is precisely what distinguishes it from a written account.

The postponement therefore grants the time to put in place what will already have to be running on the date of application. Large organisations most often have legal departments to gauge this. Small and medium-sized businesses use the same tools and take the same decisions, with fewer means to notice.

What the law does not say

Three things are commonly attributed to the regulation that are not in it.

The origin of the model. The regulation classifies uses; it says nothing about a model's nationality, nor about where it was trained. An American, Chinese or French model is subject to the same rules for the same use.

The neutrality of its answers. Hosting a model on servers located in France settles the question of where your data goes. It changes nothing about what the model has learned or how it answers. In June 2026, France's Directorate General of the Treasury tested for three weeks, with about a hundred staff, an internal assistant built on Qwen, the model of the Chinese group Alibaba; the tool ran offline, with no identified risk of data leakage. It was switched off on 23 June after senior officials raised alerts about answers deemed slanted regarding China, and replaced with a model from Mistral AI. The deployment was beyond reproach under the regulation. It was withdrawn for a reason the regulation does not cover: the content of the answers. Conversely, since 11 August 2026, Mistral AI offers on its own European infrastructure a Chinese model, GLM-5.2, served unmodified: the data stays in Europe, the model remains what it is.

Open source. The regulation lightens certain obligations for those who publish a model under a free licence, with its parameters accessible and without monetising it — essentially documentation obligations, and provided the model does not present systemic risk. These reliefs concern the party publishing the model. They never concern the party using it: a CV-screening tool built on a free model falls under the high-risk regime exactly as it would if built on a proprietary model.

The regulation says when an organisation must be able to prove what its system did. It verifies nothing on its behalf — neither the accuracy of an answer, nor the reliability of a source, nor the slant of a model. That is the concrete meaning of the sufficient-understanding obligation mentioned above: knowing that a tool can be wrong in the same way, wherever it runs.

What we make of it

At (Urs), Evidence was designed to answer these three questions before they are asked. Every claim in an AI-assisted document is verified against its sources. Every analysis is archived and replayable identically, years later. Every case the system cannot settle is referred to a person, with the reason for the referral recorded. Retrieving, intervening, keeping the record are properties of the construction, measurable at every run.

The regulation is not simple. It is understandable, and the questions it asks are the right ones. One cannot govern what one does not understand, and one cannot prove what one has not kept.

This is the (Urs) wager: retrieving, intervening and keeping the record are not compliance options but properties of the construction. Explore the infrastructure →

Sources. Regulation (EU) 2024/1689 of 13 June 2024 (the "AI Act"): Article 6 (classification of high-risk systems: Annex I, safety components of regulated products; Annex III, listed uses), Chapter V (general-purpose AI models, provider obligations applicable since 2 August 2025), Article 4 (AI literacy, applicable since 2 February 2025), Article 5 (prohibited practices, applicable since 2 February 2025), Article 12 (automatic recording of events), Article 14 (human oversight), Article 19 (retention of logs by providers, minimum six months), Article 26 §6 and §7 (retention by deployers, minimum six months; information of workers’ representatives and employees), Article 50 (transparency, applicable since 2 August 2026), Annexes I and III. — Regulation (EU) 2026/1744 (the "Digital Omnibus on AI"): Commission proposal of 19 November 2025; political agreement of 7 May 2026; European Parliament vote of 16 June 2026; Council adoption of 29 June 2026; signature of 8 July 2026; publication in the Official Journal of 24 July 2026; entry into force on 27 July 2026. Postponement of the high-risk regime to 2 December 2027 (Annex III) and 2 August 2028 (Annex I); new prohibition in Article 5 applicable from 2 December 2026; Article 50 unchanged. — Regulation (EU) 2024/1689, Article 2 §12 (exclusion of systems under free licence, except high-risk, prohibited practices and transparency) and Article 53 §2 (reliefs for general-purpose models published under free licence, except systemic risk). — Harmonised standards: CEN-CENELEC Joint Technical Committee 21 (established 1 June 2021, over 300 experts, over 20 countries); status as of June 2026 per the public tracker of deliverables (EN 18286 at formal vote; prEN 18228, 18229-1 and 18282 at enquiry; availability targeted Q4 2026; amended standardisation request running to 28 February 2027; no standard cited in the Official Journal); European Commission, "Understanding the standardisation of the AI Act". — Directorate General of the Treasury: Le Figaro (26 June 2026), Le Monde, AFP, L’Usine Digitale (29 June 2026) — HéphAIstos experiment on Qwen (Alibaba) with about a hundred staff from early June, stopped on 23 June 2026, offline operation, replaced by Mistral AI. — Mistral AI, hosting of GLM-5.2 (Z.ai) on European infrastructure, announcement of 11 August 2026 (VentureBeat, Journal du Net). — Consolidated texts consulted: European Commission AI Act Service Desk (Article 26); artificialintelligenceact.eu (Articles 19 and 26). — Concordant legal analyses: DLA Piper (30 June 2026), Gibson Dunn (27 May 2026), Cloud Security Alliance (1 August 2026), Winston Taylor (2026), AI Act Blog NL (13 June 2026), Sakara Digital (August 2026).