EU AI Act · Staged Enforcement

The first enforcement wave arrives this August.The deadline moved. Your preparation window shouldn't.

The EU AI Act Omnibus revision extended the high-risk enforcement deadline to December 2, 2027. That is not a pause. Transparency obligations and the AI Office's fining powers go live on August 2, 2026, new prohibitions follow in December 2026, and the extension is a 16-month window to build governance infrastructure that will last.

VERDIX structures your pre-production governance to satisfy Article 9 requirements before the deadline arrives, and to withstand the obligations that are already here.

00 — The Timeline

Enforcement is staged. Preparation shouldn't be.

Date

February 2, 2025

Prohibited practices ban in force. Penalties up to €35M or 7% of global turnover.

August 2, 2026

Article 50 transparency obligations apply. The AI Office gains full fining powers over general-purpose AI providers.

December 2, 2026

New prohibitions on non-consensual intimate imagery and CSAM generation. Machine-readable marking of AI-generated content required for systems already on the market.

December 2, 2027

High-risk obligations for Annex III systems: risk management, technical documentation, human oversight, conformity.

August 2, 2028

High-risk obligations for AI embedded in Annex I regulated products.

Only the last two rows moved. Everything above them is live or arriving within months.

01 — The Regulation

From optional to mandatory. The shift is already underway.

The EU AI Act makes structured AI governance a legal requirement for high-risk AI systems. Organisations deploying AI in regulated contexts, including HR, credit, healthcare and critical infrastructure, must demonstrate documented risk management, data governance, technical documentation, and human oversight.

Most European enterprises are not yet structured to satisfy these requirements. The governance infrastructure they would need doesn't exist in their organisations. VERDIX builds it.

01

Risk management system

Article 9 requires a documented risk management process for every high-risk AI system — not a one-time assessment but an ongoing lifecycle.

02

Technical documentation

Article 11 requires technical documentation prepared before market placement. This documentation must be available to regulators on request.

03

Human oversight

Article 14 requires that high-risk AI systems are designed and governed with meaningful human oversight. Documented, not assumed.

02 — Capability Mapping

How VERDIX satisfies each requirement.

EU AI Act Requirement

Article 9 — Risk management system

VERDIX structures a risk management lifecycle for every AI initiative, with documented assessment, mitigation, and residual risk sign-off before production.

Article 10 — Data and data governance

Evidence category for data quality, provenance, and governance is mandatory in the VERDIX evidence package for all high-risk initiatives.

Article 11 — Technical documentation

The AI Asset Package generated at production handover constitutes the technical documentation required under Article 11.

Article 12 — Record-keeping

Every VERDIX governance decision is timestamped, attributed, and stored as an immutable audit record. Record-keeping is automatic.

Article 13 — Transparency and information

Council review includes a transparency assessment. Stakeholder communication requirements are documented in the evidence package.

Article 14 — Human oversight

The federated council governance model ensures human oversight is formally documented for every high-risk AI initiative.

03 — The Window

The timeline moved. Most organisations haven't adjusted their preparation accordingly.

The EU AI Act Omnibus revision extended the high-risk enforcement deadline from August 2026 to December 2027. For many organisations, this prompted relief, followed by inaction.

That is the wrong response, twice over. First, the extension only covers high-risk obligations. Transparency duties and the AI Office's fining powers arrive in August 2026, and new prohibitions in December 2026, on the original penalty scale. Second, the extension doesn't reduce the scope of what's required. It increases the time available to build governance infrastructure properly, rather than rushing a compliance exercise. Organisations that use this window well will have a structured, auditable governance programme by December 2027. Organisations that don't face the same scramble, with less sympathy from regulators.

Use the window. Don't use it to wait.

Further reading: The EU AI Act Omnibus 2026 — what changed and what it means →
04 — EU-Native

Incorporated where the regulation lives.

Using a US-incorporated AI governance platform to satisfy EU AI Act requirements creates a structural tension: your compliance documentation is held by an entity subject to US law, not EU law.

VERDIX is incorporated in the Netherlands, operated under EU law, and stores all governance data in EU infrastructure. Your AI governance record is subject to the same jurisdiction as the regulation it satisfies.

For regulated European organisations, in financial services, healthcare and critical infrastructure, this is not a marginal advantage. It's a requirement.

Learn about our EU data sovereignty tiers →
05 — Standards

One process. Multiple frameworks.

The VERDIX governance lifecycle is designed to satisfy EU AI Act requirements and ISO/IEC 42001 simultaneously. Running VERDIX is not a separate compliance project — it is the governance programme that compliance follows from.

EU AI Act — Article 9 Risk ManagementEU AI Act — Article 10 Data GovernanceEU AI Act — Article 11 Technical DocumentationEU AI Act — Article 12 Record-keepingGDPR alignmentEU AI Act ReadyISO/IEC 42001 Ready

December 2027 is closer than it looks when you're building from scratch. And August is already here.

Use the preparation window the Omnibus gave you. Deploy VERDIX now and have a structured, auditable AI governance programme in place well before high-risk enforcement begins, and a defensible position for the obligations that arrive this year.