Enterprise compliance · 9 min read
The Digital Omnibus is law. High-risk obligations begin on 2 December 2027, the transparency duties already apply, and the fourteen months in between are the useful ones. What changed, what did not, and a plan for a team building AI agents in Europe.

Prem Naraindas
Founder and CEO, Katonic AI
The dial
Only two dates moved. Everything else kept its clock.
2 Dec 2027
Annex III
2 Aug 2028
Annex I
Article 50 in force since 2 Aug 2026.
Part one
For most of this year the standard line in AI compliance conversations was “the dates are moving”. They were. On 8 July the EU adopted Regulation (EU) 2026/1744, the Digital Omnibus on AI. It was published in the Official Journal on 24 July and entered into force on 27 July.
What it moved is narrow. Obligations for stand-alone high-risk systems, the Annex III list, now apply from 2 December 2027. Obligations for high-risk systems built into regulated products, Annex I, apply from 2 August 2028. Before the Omnibus those dates were 2 August 2026 and 2 August 2027.
Everything else kept its date. Prohibited practices have applied since February 2025. General-purpose model duties have applied to model providers since August 2025. The transparency duties in Article 50 took effect on 2 August 2026, six days after the Omnibus did, exactly as scheduled.
So the clock did not stop. It was reset to a longer dial, and it has been running since.
One regulation, eight dates. Only two moved.
The dialPart two
The amendments are worth reading, because most of them help. Technical documentation is simplified for SMEs and small mid-caps (Article 11). The quality management system is now expressly proportionate to the size of the provider (Article 17).
The fundamental rights impact assessment can cross-reference a data protection impact assessment, and the AI Office will publish a questionnaire template (Article 27). A new Article 4a allows special categories of personal data to be processed where that is necessary to detect and correct bias.
What did not change matters more. The definitions of provider and deployer are the same. The list of high-risk uses is the same. The substance of the high-risk obligations is the same: risk management, data governance, technical documentation, record-keeping, transparency, human oversight, accuracy and robustness, post-market monitoring, incident reporting. The Omnibus bought time to do them. It removed none of them.
Part three
The Act does not regulate companies. It regulates AI systems, and it assigns duties by role. The two roles that matter are provider and deployer.
If your team builds an agent on a platform, gives it a purpose and runs it under your own name, you are the provider of that system and its deployer. Both sets of duties land on you. That is not a corner case. It is the ordinary case for an enterprise building its own agents.
Your model vendor is the provider of a general-purpose AI model, and the Chapter V duties sit with them. Your platform, tool and component suppliers sit under Article 25(4): they must give you, by written agreement, the information, access and assistance you need to comply. They cannot comply for you.
That is why one sentence you will hear in sales meetings cannot be true. No platform vendor can hold an EU AI Act certification, because the Act assesses systems, not toolkits. The useful question for a vendor is not “are you compliant?” It is “what evidence does your product produce for my obligations?”
Role 1
Provider
Develops the system, or has it developed, and puts it into service under its own name. Owes the Chapter III obligations and the conformity assessment.
Role 2
Deployer
Uses the system under its own authority. Owes human oversight by named people, log retention of at least six months, use in line with the instructions, information to workers and affected persons, and an impact assessment where in scope.
Role 3
General-purpose model provider
Your model vendor. Owes the Chapter V duties: technical documentation, a copyright policy, a training-content summary, and extra duties for systemic-risk models.
Role 4
Supplier of tools and platforms
Article 25(4). Owes you, by written agreement, the information, technical access and assistance you need to comply. Cannot hold a certification on your behalf.
Part four
Annex III names the areas: biometrics, safety components of critical infrastructure, education and training, employment and worker management, access to essential services including credit scoring and insurance pricing, law enforcement, migration and border control, justice and democratic processes.
Most internal agents are not on that list. A document-review agent for procurement, a support agent for staff IT questions, a drafting assistant for marketing: not high-risk. An agent that screens CVs, scores a loan applicant or triages a benefits claim: high-risk, and its clock reads 2 December 2027.
Article 6(3) also exempts systems in a listed area that only perform a narrow procedural task, improve the result of a human activity, detect patterns without replacing human assessment, or do preparatory work. The exemption comes with a duty: the provider must document the assessment. The classification decision is itself a record. Make it, date it, keep it.
If the agent does one of these, it is high-risk from 2 December 2027.
Annex IIIBiometrics: remote identification, biometric categorisation, emotion recognition where not prohibited
Critical infrastructure: safety components in energy, water, digital infrastructure, road traffic
Education and training: admission, assessment, proctoring, level placement
Employment: CV screening, candidate ranking, task allocation, performance monitoring
Essential services: credit scoring, life and health insurance pricing, benefits eligibility, emergency call triage
Law enforcement: risk assessment of individuals, evidence evaluation
Migration and borders: visa and asylum application assessment
Justice and democratic processes: assisting judicial decisions, influencing elections
Article 6(3) exemption
A system in a listed area is not high-risk if it only performs:
Document the assessment either way (Article 6(4)).
Part five
Three things are in force now for anyone running AI systems in the EU, high-risk or not.
Transparency (Article 50). People interacting with an AI system must be told so, unless it is obvious from the context. Synthetic audio, image, video and text must be marked in a machine-readable way, and deepfakes must be labelled. Systems placed on the market before 2 August 2026 have until 2 December 2026 to meet the marking requirement (Article 111(4)). New systems have no grace period.
AI literacy (Article 4, as amended). The duty is softer than in the 2024 text, but the expectation that the people operating AI systems on your behalf understand what they are using has not gone away.
Prohibited practices (Article 5). Emotion recognition in the workplace and in education, social scoring, untargeted scraping of facial images and the rest of the list have been banned since 2 February 2025. An agent builder can cross that line by accident. An HR assistant that infers mood from message tone can be an emotion-recognition system.
From 2 December 2026 the Omnibus adds two prohibitions to that list: systems that generate intimate imagery of an identifiable person without consent, and systems that generate child sexual abuse material.
In force now, high-risk or not.
Transparency
Since 2 Aug 2026
Tell people they are dealing with an AI system. Mark synthetic content in a machine-readable way. Label deepfakes. Systems on the market before August: marking by 2 Dec 2026.
AI literacy
Since 2 Feb 2025, softened July 2026
The people who operate and use AI systems on your behalf understand what they are using.
Prohibited practices
Since 2 Feb 2025
No workplace or classroom emotion recognition, no social scoring, no untargeted facial-image scraping, no manipulative or exploitative systems.
Part six
Fourteen months is enough if the work starts now and runs in the order below. Each step is anchored to the article it satisfies, so the plan doubles as the index of your evidence.
Now to December 2026: know what you have. Nothing else in the Act can be done without an inventory. Every AI system in use, with its owner, intended purpose, model and model provider, and a written Annex III classification (Article 6). Then name the people who oversee each system and give them the authority to stop it (Articles 14 and 26(2)).
January to June 2027: turn on the records. Logs for every high-risk system, kept at least six months and under your control (Articles 12, 19 and 26(6)). Version everything the system is made of, so that technical documentation is exported from the system of record rather than written from memory in November (Article 11).
July to December 2027: prove it works, and keep proving it. Risk management becomes a running process fed by evaluations rather than a document (Article 9). Testing produces results you can show (Article 15). Monitoring and incident reporting have owners (Articles 72 and 73). Providers of Annex III systems finish with conformity assessment, CE marking and registration (Articles 43 to 49).
Fourteen months, three phases.
Each step names its articleNow to Dec 2026
Know what you have
Jan to Jun 2027
Turn on the records
Jul to Dec 2027
Prove it works
Part seven
A platform cannot make you compliant. What it can do is make the evidence a by-product of building and running the agent, so that December 2027 is an export rather than a project.
That is how we built Katonic. Agent definitions, instructions and model choices are versioned, with prior versions kept. Promotion to production goes through a reviewer who is not the proposer. Tool actions that need a person do not run until one approves, and one approval covers one action with the exact arguments shown.
Every turn, tool call and model call is traced and can be exported over OpenTelemetry to a store you control, for as long as you decide. Guardrails run on input, output and tool arguments, with PII redaction built on Presidio. Evaluation runs keep per-sample results and human annotations. Every answer carries its citations and document provenance.
It runs in your Kubernetes cluster: on-premises, private cloud or fully air-gapped. Interaction data never leaves it. In connected mode the only outbound traffic is licence validation and release-catalogue sync with Katonic’s operations hub. Air-gapped mode removes even that.
Katonic develops no models of its own and, like every platform vendor, holds no EU AI Act certification, because none exists for a platform. We are certified to ISO/IEC 27001:2022. The obligations under the Act are yours. The evidence for them should come out of the platform you build on.
Five obligation families, and what the platform produces for each.
Record-keeping and traceability
Articles 12, 19, 26(6)
Traces of every agent turn, tool call and model call. Conversation exports. Append-only audit ledger. OpenTelemetry export to your own store.
Human oversight
Articles 14, 26(2)
Reviewer-gated promotion, where the proposer cannot approve. Fail-closed tool approvals, one approval per action with the exact arguments.
Data governance
Article 10
Guardrail profiles on input, output and tool arguments. Presidio-based PII redaction. Citations and document provenance on every answer.
Technical documentation and transparency
Articles 11, 13
Versioned agent definitions, instructions and model choices with prior versions retained. Exports of definitions, versions and evaluation reports.
Risk management, robustness and monitoring
Articles 9, 15, 72
Evaluation datasets, runs with per-sample results, comparison, schedules and human annotation. Injection detection and content-safety rails. Guardrail statistics.
Did the Digital Omnibus delay the EU AI Act?
Only the high-risk dates. Regulation (EU) 2026/1744, in force since 27 July 2026, moves the obligations for stand-alone high-risk systems (Annex III) to 2 December 2027 and for high-risk systems inside regulated products (Annex I) to 2 August 2028. Prohibited practices (since February 2025), general-purpose model duties (since August 2025) and the Article 50 transparency duties (since 2 August 2026) kept their dates.
Is Katonic EU AI Act compliant or certified?
No platform vendor can be. The Act assesses AI systems, and its obligations fall on the provider and the deployer of each system, which for an agent you build and run is you. Katonic is certified to ISO/IEC 27001:2022 and develops no models of its own. The platform is the control and evidence layer for your obligations: versioned agent definitions, reviewer-gated promotion, fail-closed tool approvals, guardrail profiles with PII redaction, traces of every turn exportable over OpenTelemetry, and evaluation records.
If we build an agent on a platform, who is the provider?
If you develop the agent, or have it developed, and put it into service under your own name, you are its provider and its deployer. Your model vendor is the provider of a general-purpose AI model and carries the Chapter V duties. Your platform and tool suppliers sit under Article 25(4): they owe you, by written agreement, the information, technical access and assistance you need to comply.
Close
The clock did not stop. It restarted with a longer dial, and fourteen months is exactly enough time to build the records once, inside the system that produces them, instead of reconstructing them under a deadline. Start with the inventory. Everything else hangs off it.
December 2027 should be an export, not a project.
Read the amending regulation on EUR-Lex: Regulation (EU) 2026/1744. This article is general information about the EU AI Act, not legal advice. Dates were checked against EUR-Lex on the day of publication.

Prem Naraindas
Founder and CEO, Katonic AI
Prem founded Katonic to put enterprise AI to work on infrastructure the enterprise owns. He spends his weeks with the customers, partners and regulators who have to make AI answer for itself, and writes about what that takes.
About Katonic →§ Related articles
Talk to us about your inventory, your roles under the Act and the evidence you will need in December 2027. We will walk through it with you, on infrastructure you own.
