{"schema_version":"3.2.0","engine_version":"2.5.7","iso_timestamp":"2026-10-10T14:01:53.364497+00:00","track_key":"eu-ai-act","track_name":"EU AI Act & Algorithmic Governance","short_title":"EU AI Act","risk_posture":"HIGH","headline":"Digital Omnibus Establishes Annex III Application for December 2027 as 2 December 2026 Synthetic Media Window Matures","primary_liability_driver":"Imminent expiration of the 2 December 2026 machine-readable marking transition under Article 50(2) for pre-August 2026 generative AI systems exposes providers to administrative fines up to €15,000,000 or 3% of worldwide turnover under Article 99(4), while prohibited AI practices under Article 5 trigger penalties up to €35,000,000 or 7% under Article 99(3).","executive_summary":"Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744 (Digital Omnibus on AI, in force 27 July 2026), governs artificial intelligence systems across the EU. Statutory prohibitions under Article 5—encompassing workplace emotion recognition under Article 5(1)(f) and biometric categorization inferring sensitive attributes under Article 5(1)(g)—have been active since 2 February 2025. Crucially, the Digital Omnibus inserted new prohibitions: Article 5(1)(ba) on AI systems generating non-consensual sexually explicit deepfakes and Article 5(1)(bb) on child sexual abuse material, both enforceable from 2 December 2026 subject to Article 5(1a)-(1b) scope limits (including lawful security research, testing, and legitimate procedural defences), backed by Article 99(3) fines up to €35,000,000 or 7% of worldwide turnover. Operative milestones set out in amended Article 113 establish that standalone Annex III High-Risk AI Systems will apply on 2 December 2027 (exactly 418 calendar days from 10 October 2026), while Annex I embedded AI systems apply on 2 August 2028.\n\nAn immediate statutory milestone occurs on 2 December 2026 under Article 50(2): providers of generative AI systems placed on the market before 2 August 2026 must ensure outputs are marked in a machine-readable format and detectable as artificially generated (systems placed on the market after 2 August 2026 must comply immediately). Concurrently, deployer duties under Article 50(4) (deepfake and public text disclosures) and provider duties under Article 50(1) (conversational disclosure) have been fully applicable since 2 August 2026. In parallel, general-purpose AI (GPAI) model providers must deliver technical documentation to downstream integrators under Article 53. Enterprises deploying third-party models must secure contractual warranties from foundation model vendors while preparing technical files for candidate Annex III high-risk applications ahead of the December 2027 deadline.","milestones":[{"status":"ENACTED / IN FORCE","citation":"Regulation (EU) 2024/1689, Article 5(1)(f) & (g)","gate":"2025-02-02","link":"https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27","impact":"Statutory prohibitions on unacceptable-risk systems, including workplace emotion recognition (Art. 5(1)(f)) and biometric categorization inferring sensitive traits (Art. 5(1)(g)); non-compliance triggers Article 99(3) fines."},{"status":"ADOPTED (COMMENCING 2026-12-02)","citation":"Regulation (EU) 2024/1689 as amended by Reg (EU) 2026/1744, Article 5(1)(ba) & (bb)","gate":"2026-12-02","link":"https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27","impact":"Statutory prohibition on AI systems generating non-consensual sexually explicit content and CSAM, subject to defined Article 5(1a)-(1b) scope exceptions; non-compliance triggers Article 99(3) fines up to €35M or 7% global turnover."},{"status":"ENACTED / IN FORCE","citation":"Regulation (EU) 2024/1689, Article 50(1) & (4)","gate":"2026-08-02","link":"https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27","impact":"Direct transparency duties in force since 2 August 2026: provider disclosure when natural persons interact with conversational AI (Art. 50(1)) and deployer labeling of deepfakes and public informational text (Art. 50(4))."},{"status":"ADOPTED (COMMENCING 2026-12-02)","citation":"Regulation (EU) 2024/1689 as amended by Reg (EU) 2026/1744, Article 50(2) & Article 111","gate":"2026-12-02","link":"https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27","impact":"End of grace period for providers of generative AI systems placed on the market prior to 2 August 2026 to implement machine-readable marking and watermarking under Article 50(2)."},{"status":"ADOPTED (COMMENCING 2027-12-02)","citation":"Regulation (EU) 2024/1689 as amended by Reg (EU) 2026/1744, Article 113(b) & Annex III","gate":"2027-12-02","link":"https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27","impact":"Full statutory application for standalone Annex III high-risk AI systems (HR/employment, credit scoring, biometrics, critical infrastructure), mandating Articles 9-15 technical documentation, QMS, and EU database registration."},{"status":"SCHEDULED HORIZON","citation":"Regulation (EU) 2024/1689 as amended by Reg (EU) 2026/1744, Article 113(c) & Annex I Section A","gate":"2028-08-02","link":"https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27","impact":"Operational application of high-risk requirements for AI systems embedded as safety components in products covered by Union harmonisation legislation listed in Annex I Section A (e.g., MDR medical devices, machinery, civil aviation)."}],"actions":[{"priority":"CRITICAL","requirement_type":"LEGAL REQUIREMENT","title":"Audit generative AI systems where company acts as provider to ensure machine-readable metadata marking complies with Article 50(2) before 2 December 2026.","owner":"Chief Information Security Officer","gate":"2026-12-02","anchor":"Regulation (EU) 2024/1689, Article 50(2)"},{"priority":"HIGH","requirement_type":"LEGAL REQUIREMENT","title":"Maintain active user-facing disclosures across all deployed conversational agents and customer-facing interfaces pursuant to Article 50(1) and 50(4).","owner":"Chief Compliance Officer","gate":"IMMEDIATE / ACTIVE","anchor":"Regulation (EU) 2024/1689, Article 50(1) & (4)"},{"priority":"HIGH","requirement_type":"RECOMMENDED CONTROL","title":"Review enterprise GPAI vendor contracts to ensure provision of Article 53 technical documentation and copyright compliance representations.","owner":"General Counsel","gate":"2027-01-15","anchor":"Regulation (EU) 2024/1689, Article 53"},{"priority":"HIGH","requirement_type":"RECOMMENDED CONTROL","title":"Conduct enterprise classification of internal HR, recruitment, and scoring algorithms against Annex III criteria to scope Article 9-15 technical compliance.","owner":"Head of Enterprise Risk","gate":"2027-03-31","anchor":"Regulation (EU) 2024/1689, Article 6(2) & Annex III"}],"budget":{"range":"€420,000 - €780,000","methodology":"Illustrative enterprise scenario: assumes deployment of 4 generative AI interfaces, 2 candidate Annex III high-risk algorithms, external conformity advisory, and synthetic media watermarking integration.","breakdown":[{"item":"Synthetic content machine-readable watermarking engineering","amount":"€180,000"},{"item":"GPAI downstream vendor licensing & Article 53 legal review","amount":"€135,000"},{"item":"Candidate Annex III high-risk AI classification & technical files","amount":"€150,000"},{"item":"Algorithmic bias audit & data governance validation (Article 10)","amount":"€95,000"},{"item":"EU AI Office regulatory compliance contingency","amount":"€60,000"}],"total_calculated":"€620,000"},"board_decisions":["DECISION: Mandate technical verification of Article 50(2) watermarking across all internally developed generative models prior to 2 December 2026, closed upon validation of synthetic media detector compatibility.","DECISION: Authorize foundation model contract review budget (modeled at €135,000) under Article 53 downstream documentation standards, closed upon receipt of compliant technical files.","DECISION: Establish Enterprise Algorithmic Governance Committee to oversee Annex III high-risk system classifications, closed upon charter approval."],"liability_vector":"Administrative fines under Article 99(4) (up to €15,000,000 or 3% of worldwide turnover) for transparency non-compliance under Article 50, alongside potential Article 99(3) fines (up to €35,000,000 or 7% of turnover) for prohibited practices under Article 5.","affected_population":"Providers and deployers of AI systems generating synthetic media, enterprises deploying conversational agents, downstream integrators of GPAI models, and entities operating candidate Annex III high-risk AI systems in the EU.","telemetry_hash":"57bd99786026f135847a76a82ae615e0ab37b5f050bf6fadaafafa3369e2fac2","formatted_timestamp":"2026-10-10_1401 UTC"}