The deadline moved. The obligation didn’t.
High-risk AI-agent obligations move to 2 December 2027 under the EU Digital Omnibus, now law as Regulation (EU) 2026/1744. But transparency duties and the AI Office’s enforcement powers already apply from 2026, and the engineering that satisfies the high-risk rules takes far longer than the extension buys you. NOCTRYS makes you provably ready early, by design, not in a last-minute scramble.
Where the timeline really stands in 2026
Read almost any 2025-era summary and you will see "high-risk obligations go live 2 August 2026." Under the EU Digital Omnibus, now law, that is no longer accurate, and getting it wrong in a board deck is its own kind of risk. Here is the current picture:
Transparency + AI Office
Article 50 transparency duties and the AI Office’s enforcement powers apply. General-purpose AI model obligations are already in force.
High-risk (Annex III)
Obligations for Annex-III high-risk use cases (credit, insurance, employment, essential services) apply from this date under the Digital Omnibus, Regulation (EU) 2026/1744.
High-risk (Annex I)
High-risk AI embedded in already-regulated products (Annex-I safety legislation) moves to this later date.
The honest read: the Digital Omnibus postpones the high-risk obligations, and the deferral is now law: published in the Official Journal on 24 July 2026 as Regulation (EU) 2026/1744, in force from 27 July 2026. Annex-III use cases (credit, insurance, employment, essential services) move to 2 December 2027, and Annex-I-embedded high-risk systems to 2 August 2028. What is not postponed: the Article 50 transparency duties and the AI Office’s enforcement powers, which apply from 2 August 2026.
An extension is runway, not a reprieve
The duties that land on autonomous agents (tamper-evident logging, real-time human oversight, robustness against manipulation, multi-year record-keeping) are not a document you write the week before an audit. They are an architecture. Teams that treat December 2027 as "do it later" will discover that retrofitting a believable, intervenable audit trail onto agents already in production is the hard, expensive path.
The hard part for autonomous agents was never writing a log. It is producing a log a regulator will believe, and being able to intervene in real time.
NOCTRYS is the by-design route: install it now, and every agent action is governed, overseeable, and independently provable from day one. When the obligations bite, and when your own auditors, insurers, and enterprise customers ask sooner than the regulator does, you are already compliant instead of scrambling.
The high-risk duties, mapped to concrete controls
The extension changes when, not what. These are the obligations that land on the agent action layer, and the NOCTRYS control that satisfies each. The substance stays the same whichever date applies.
| Article | What it requires | How NOCTRYS satisfies it |
|---|---|---|
| Art. 12 | Automatic logging of events over the system’s lifetime; full traceability. | Every action is hash-chained into a tamper-evident recorder, anchored on the AERE chain and cosigned by independent witnesses, so the log is not just complete but unforgeable and independently verifiable. |
| Art. 14 | Effective human oversight; ability to detect anomalies and intervene. | High-risk actions are held for a named human’s cryptographic sign-off; a kill-switch freezes an agent, or the whole fleet, instantly. |
| Art. 15 | Accuracy, robustness, and resilience against manipulation. | Deterministic, fail-closed enforcement plus defenses against injection, self-modification, tool-drift, tool-shadowing, and Unicode smuggling. |
| Art. 26 | Deployer keeps automatically generated logs for at least six months. | Persistent, tamper-evident store with SIEM export and redaction of secrets/PII. |
| Art. 50 | Transparency duties (already applying from 2026). | Every governed action is attributable and disclosed in the audit record; the transparency baseline is a byproduct of how NOCTRYS works. |
This is an engineering mapping and a plain-language reading of the law, not legal advice; dates reflect the Digital Omnibus as published in the Official Journal (Regulation (EU) 2026/1744). Consult qualified counsel for your obligations.
What you can hand an examiner
- A one-command AI-Act audit report: totals, blocks by reason, integrity status, the anchored Merkle root, and article coverage.
- A public verifier so the examiner checks the record themselves, with no need to trust you or us. Try it →
- OWASP Top 10 for Agentic Applications (2026): 10/10 covered. See Compliance →.
Be one of our first five design partners
Free pilot. A two-week, self-hosted integration. You keep the tamper-evident audit and the AI Act compliance report.
Request a pilot →