Blog

min read

The Audit Window: What the EU AI Act's Deferral Actually Bought You

By

Dor Sarig

and

September 9, 2026

min read

EU AI Act compliance for AI agents starts with a complete, continuously updated inventory, because both the transparency duties that became enforceable on 2 August 2026 and the high-risk obligations now due 2 December 2027 attach to individual systems you must first know exist. The deferral of the high-risk wave is a sixteen-month window to build an evidence pipeline that survives your release cycle, and organizations whose agent estates double every few months cannot start that work in 2027.

On 2 August 2026, the EU AI Act stopped being a future problem. Transparency obligations under Article 50 now carry fines of up to €15 million or 3% of worldwide annual turnover, and the European Commission can enforce directly against general-purpose model providers. Yet most of the compliance advice reaching security leaders' inboxes this month gets the moment wrong in both directions: it misses that the high-risk obligations moved to December 2027, and it treats that deferral as breathing room when it is actually an audit window.

The audit window is the period between now and 2 December 2027, in which regulators are already enforcing the transparency layer while expecting organizations to build the evidence base the high-risk wave will demand. What you do inside that window determines whether December 2027 is a milestone or a crisis.

What does the EU AI Act actually require from 2 August 2026?

From 2 August 2026, the EU AI Act requires providers and deployers to meet the Article 50 transparency obligations, and it gives regulators the power to fine violations up to €15 million or 3% of worldwide annual turnover, whichever is higher (Cooley, Aug 2026). Four duties are now live:

  • Interaction disclosure. Providers of AI systems that interact with people must make clear that the user is dealing with AI, no later than the first interaction, unless it is obvious from context.
  • Synthetic content marking. Providers of generative systems must embed machine-readable markings in AI-generated audio, image, video, and text, and offer detection mechanisms. Systems already on the market have until 2 December 2026 to comply.
  • Biometric and emotion recognition notice. Deployers of emotion recognition or biometric categorization systems must inform the people exposed to them.
  • Deepfake and public-interest content disclosure. Deployers must disclose that content is artificially generated or manipulated, including AI-written text published on matters of public interest, unless it went through human editorial review.

The same date activated the Commission's enforcement powers over general-purpose AI model providers. GPAI obligations have applied since 2 August 2025; as of 2 August 2026 the AI Office can impose fines for violations under Article 101, at the same €15 million or 3% ceiling (kla.digital, Aug 2026). Models placed on the market before 2 August 2025 have until 2 August 2027 to reach conformity.

What moved is the high-risk regime. The Digital Omnibus, voted through the European Parliament on 16 June 2026 and published in July, deferred obligations for standalone high-risk systems under Annex III from 2 August 2026 to 2 December 2027, pushed high-risk AI embedded in Annex I regulated products to 2 August 2028, and moved the member-state regulatory sandbox deadline to 2 August 2027 (Gibson Dunn, 2026). Deferred, in every case. Cancelled, in none.

The Act regulates a moving target. Your compliance process assumes a still one.

Point-in-time compliance is the practice of producing conformity evidence once, at assessment time, and treating it as valid until the next audit. The model works for systems that hold still: a payment application changes on a quarterly release train, and last quarter's assessment describes roughly the system running today.

AI agents do not hold still. Gartner predicts that by 2028 an average global Fortune 500 enterprise will have more than 150,000 agents in use, up from fewer than 15 in 2025, and only 13% of organizations believe they have the right AI agent governance in place (Gartner, Apr 2026). A new skill, a new MCP server, a revised system prompt, or an upgraded model version changes what an agent can read, do, and leak.
Each of those changes lands weekly, and each one can invalidate the conformity story you wrote last month.

Practitioners already know this. In a Hacker News thread on operationalizing the Act, one engineer put it plainly: "The hard part is proving you actually did all four, consistently, across every agent interaction, in a way a regulator can independently verify. Documentation gets stale the moment you deploy" (Hacker News, Mar 2026). The Cloud Security Alliance reports that 40% of enterprise AI systems resist clear risk-tier classification (CSA, 2026), which means the paperwork problem starts before the first control is even selected.

The window exists so you can replace point-in-time compliance with something that survives contact with your release cycle. Three problems stand between most organizations and that state.

Shadow AI is now a regulatory finding

Article 50 duties attach per system. Every customer-facing chatbot, every generative feature quietly embedded by a product team, every departmental agent spun up outside procurement now carries its own disclosure obligation and its own fine exposure. Yet more than half of organizations lack a systematic AI inventory (CSA, 2026).

You cannot disclose an interaction you do not know exists.

Before August, an unknown chatbot was a security gap. Now it is a regulatory finding with a number attached. Shadow AI discovery, which security teams have treated as hygiene, became the first compliance control of the Act's live phase.

You cannot classify what you have not inventoried

The high-risk regime turns on classification: does this system fall under an Annex III use case, and what is its actual purpose, data access, and tool reach? Classification requires knowing what each agent reads, which tools it can call, and where its outputs land. At an estate of 100+ agents that change weekly, classification by spreadsheet and interview collapses. The organizations that treat December 2027 as far away are the ones that will attempt this exercise, for the first time, on an estate several times larger than the one they run today.

Evidence has to survive your release cycle

The high-risk obligations arriving in December 2027 include record-keeping under Article 12 and accuracy, robustness, and cybersecurity requirements under Article 15. Both assume you can show a regulator how the system behaved, and that it withstands adversarial use, on an ongoing basis. A penetration test passed in August proves nothing about the October release. Worse, controls bolted on without verification create what one practitioner called a false paper trail: "I've seen teams bolt on compliance checks as middleware that silently degrades to 'allow' on timeout. That's worse than no check at all" (Hacker News, Mar 2026).

Regression-aware evidence is the alternative: every attack objective and every control re-tested against every release, with the results logged, versioned, and comparable over time. That is a testing architecture, and building it takes months. This is why the window matters. Frameworks already exist to structure the work, from NIST AI RMF and ISO 42001 to our own open SAIL 2.0 framework, which catalogs 91 agentic risks across the AI lifecycle and maps each one to the EU AI Act at the article level: Article 17 for AI policy, Articles 9 and 15 for insecure posture, Article 15(5) for runtime controls.

What to do with the audit window

Security owns this work whether it wants to or not. Legal interprets the Act and GRC files the reports, but the artifacts a regulator can independently verify come from security tooling, and 96% of CISOs now hold AI governance in their scope (Dark Reading, Jul 2026).

The sequence is unglamorous and effective. Inventory every AI system, agent, model, MCP server, and skill, including the ones nobody registered, and capture the result as an AI Bill of Materials. An AI Bill of Materials (AIBOM) is a machine-readable record of every AI asset in an environment and the connections between them, and it is the foundation every later compliance step builds on. Classify each system against the Act's tiers using its real purpose and data access, and record the reasoning; SAIL 2.0's EU AI Act filter turns its 91-risk catalog into a compliance checklist written in the regulation's own article language, which is a working starting point for that mapping. Put Article 50 disclosures in place for anything customer-facing now, since that obligation is live and fined. Make adversarial testing continuous rather than annual, so each release generates fresh evidence instead of invalidating old evidence. Log agent behavior at runtime, because interaction records are both your Article 12 trail and your incident forensics. Then automate the reporting, so the December 2027 submission is an export aligned to EU AI Act controls rather than a project.

Sixteen months is enough time to build this once. It is not enough time to build it twice.

FAQs

Did the EU AI Act high-risk deadline move to 2027?

Yes. The Digital Omnibus, approved by the European Parliament on 16 June 2026, deferred the obligations for standalone high-risk AI systems under Annex III from 2 August 2026 to 2 December 2027. The high-risk AI embedded in Annex I-regulated products was moved from 2 August 2027 to 2 August 2028. The deferral changed the dates, and nothing else: the classification duties, technical requirements, and conformity assessments still apply, and the transparency obligations that took effect on 2 August 2026 were unaffected.

What are the Article 50 transparency obligations?

Article 50 requires providers of interactive AI systems to disclose that users are dealing with AI, providers of generative systems to embed machine-readable markings in synthetic content and offer detection mechanisms, deployers of emotion recognition or biometric categorization to inform exposed individuals, and deployers to disclose deepfakes and AI-generated text on matters of public interest. These duties became enforceable on 2 August 2026. Generative systems already on the market have until 2 December 2026 to meet the marking requirements.

What fines apply under the EU AI Act in 2026?

Violations of the Article 50 transparency obligations carry fines of up to €15 million or 3% of worldwide annual turnover, whichever is higher. The same ceiling applies to fines that the European Commission can now impose on general-purpose AI model providers under Article 101, a power that took effect on 2 August 2026. Prohibited-practice violations, enforceable since February 2025, carry higher penalties of up to €35 million or 7% of turnover.

Does the EU AI Act apply to AI agents?

Yes. The Act regulates AI systems by function and risk, and agents qualify wherever they interact with people, generate content, or perform an Annex III use case such as employment screening, credit scoring, or essential-services access. Agents raise the compliance bar in practice: they change with every new tool, skill, or prompt revision; they act under delegated permissions; and they multiply faster than manual inventories can keep track of. An agent's classification can shift as its capabilities do, which is why classification must be continuous.

How do you prove EU AI Act compliance for AI systems that change weekly?

By replacing one-time assessments with a standing evidence pipeline: a live inventory that detects new and changed systems, risk classification that re-evaluates when capabilities change, adversarial testing that re-runs against every release with versioned results, and runtime logging that records what each system actually did. The output is evidence that a regulator can verify independently of your documentation, which is the standard implied by the Act's record-keeping and robustness articles for high-risk systems.

What is an AI Bill of Materials (AIBOM)?

An AI Bill of Materials (AIBOM) is a machine-readable inventory of every AI asset in an organization: models, agents, prompts, MCP servers, skills, datasets, and the connections between them. It plays the role for AI systems that an SBOM plays for software supply chains. Under the EU AI Act, an AIBOM is the practical foundation for compliance, because the Act's transparency duties and high-risk classifications attach to individual systems, and an organization can only classify, disclose, and monitor the systems its inventory captures.

Subscribe and get the latest security updates

Back to blog

MAYBE YOU WILL FIND THIS INTERSTING AS WELL

Valid, But Never Issued: Session Spoofing and SSRF in Grafana MCP

By

Ariel Fogel

and

September 2, 2026

Research
A WIF Of Fresh Access: How a GitHub Issue on Gemini-CLI Led to GCP Project Compromise

By

Dan Lisichkin

and

August 18, 2026

Research
Lose Control Flow: Unauthenticated Tool Execution in Dolt MCP

By

Ariel Fogel

and

August 13, 2026

Research