GLACIS·EU AI Act series·General Counsel·EU timeline checked August 2026

EU AI Act for General Counsel.

A walkthrough of the Regulation for legal teams: Article 2 territorial scope, vendor and deployer liability allocation, post-market obligations under Articles 26 and 72, and how the AI Omnibus dates affect procurement clauses and compliance calendars.

Talk to us Series hub →
General Counsel Deputy GC Privacy counsel Regulatory affairs
Article 2
Extraterritoriality: output used in the EU
Articles 25, 26
Provider/deployer liability allocation, vendor reps and warranties
Articles 72, 73, 99
Post-market obligations and the penalty structure (€35M / 7%)
26 Aug 2026
Status reviewed; confirm current national authority and enforcement records for each jurisdiction
Status reviewed 26 August 2026

After a provisional agreement in May 2026, the AI Omnibus was adopted as Regulation (EU) 2026/1744 and entered into force on 27 July 2026. Relevant Annex III high-risk obligations apply from 2 December 2027; relevant Annex I product-embedded obligations apply from 2 August 2028. Procurement and vendor clauses should use the enacted dates while preserving change-in-law language and a provision-specific compliance calendar.

Member states remain at different implementation stages. Germany’s Bundestag adopted KI-MIG on 11 June 2026, but this page does not independently establish promulgation or entry into force; Belgium has designated BIPT; Italy’s law 132/2025 is in force with AgID and ACN named; and the Netherlands’ public consultation on its proposed Implementation Act ran from 20 April through 1 June 2026. These status notes do not alter the directly applicable duties or replace a jurisdiction-specific check.

The Commission maintains a live register of GPAI Code of Practice signatories; xAI is listed for the Safety and Security chapter only. In procurement, record the provider’s current signatory status and claimed compliance route, but do not treat signature or non-signature as proof that a particular model or deployment complies.

By Joe Braidwood·14 min read·EU timeline checked August 26, 2026

Executive summary

The Regulation creates obligations on system behavior, not just on data handling. Article 2 can extend scope to non-EU providers and deployers where the conditions in the Article are met. Under Article 3 and the provider-allocation provisions, materially modifying a third-party AI system or placing it on the market under another name can change the responsible role. The proposed AI Liability Directive was withdrawn on 6 October 2025 and is not enacted EU burden-shifting law.

Penalty ceilings under Article 99 are €35M or 7% of global turnover for prohibited practices, €15M or 3% for other non-compliance, and €7.5M or 1% for incorrect information to authorities. Enforcement competence and application dates depend on the provision, actor, system class, and transition rule. Article 73 sets serious-incident reporting duties for in-scope high-risk systems; counsel should confirm when those duties apply to the specific system.

The legal-defense posture rests on contemporaneous, scoped evidence: risk-management records, technical documentation, applicable logs, oversight records, and incident files. This guide maps the Act onto General Counsel responsibilities using Regulation (EU) 2026/1744, the AI Omnibus now in force, and explains where Glacis records may contribute without constituting a compliance determination.

In this guide

Why the Act creates new legal exposure

The EU AI Act represents a fundamental shift in how organizations must approach AI deployment. For General Counsel, three aspects create particularly significant legal exposure:

Behavioural obligations, not just data rules

GDPR focused on how organizations handle data. The AI Act focuses on how AI systems behave and make decisions. This means legal liability now extends to algorithmic outputs, model accuracy, bias in automated decisions, and the effectiveness of human oversight mechanisms. These are areas where legal teams historically had limited visibility.

Expanded definition of “provider”

Under Article 3, organizations that substantially modify AI systems or put their name on AI products may become “providers,” assuming full compliance obligations including conformity assessment. A company that integrates a third-party AI model into a high-risk use case (employment screening, credit decisions) may inherit provider-level liability regardless of who built the underlying model.

The withdrawn AI Liability Directive proposal

The Commission’s 2022 proposal for an AI Liability Directive included evidence-disclosure and rebuttable-presumption mechanisms. The Commission withdrew procedure 2022/0303(COD) on 6 October 2025. It is therefore historical context, not current EU law. Existing national liability and procedural law, the revised Product Liability Directive where applicable, and sector-specific regimes still require jurisdiction-specific analysis.

Key General Counsel responsibilities under the Act

Liability assessment and risk allocation

General Counsel must map AI systems across the organization and classify them according to the Act’s risk taxonomy. For each high-risk system, liability must be clearly allocated between internal teams, vendors, and partners. Key questions include:

  • Who bears liability for model performance and accuracy?
  • How is responsibility allocated when multiple parties contribute to a system?
  • What insurance coverage exists for AI-specific liability?
  • Are indemnification provisions adequate for regulatory penalties?

Contractual obligations

Vendor agreements require immediate review. Contracts with AI providers must address:

  • Clear allocation of provider vs. deployer obligations
  • Representations regarding risk classification and conformity status
  • Audit rights for compliance verification
  • Incident notification aligned with Article 73 (generally no later than 15 days, with shorter deadlines in specified cases)
  • Indemnification for regulatory penalties from vendor non-compliance
  • Data governance warranties per Article 10
  • Documentation delivery for downstream compliance

Customer terms must be updated to include appropriate AI disclosures, particularly for systems requiring transparency under Article 50 (chatbots, emotion recognition, deepfakes).

Regulatory-engagement strategy

The AI Act establishes national competent authorities in each member state, coordinated by the EU AI Office. General Counsel should develop relationships with relevant authorities before enforcement actions arise. Consider:

  • Identifying which member state authorities have jurisdiction
  • Monitoring regulatory guidance and codes of practice
  • Participating in regulatory sandboxes where available
  • Preparing for potential market surveillance activities

Evidence-preservation requirements

Article 12 requires high-risk AI systems to support automatic event logging appropriate to intended purpose, including events relevant to risk identification and post-market monitoring. Legal and technical teams should consider:

  • Logging systems capture decision-relevant data
  • Retention periods meet regulatory requirements
  • Legal hold procedures extend to AI system logs
  • Chain of custody protocols exist for algorithmic evidence

Documentation and disclosure obligations

Article 11 mandates comprehensive technical documentation before high-risk systems enter the market. Article 13 requires transparency for users. General Counsel oversight ensures documentation is legally sound and disclosures don’t create unintended liability exposure.

Questions General Counsel should be asking the organization

AI Inventory and Classification

“Do we have a complete inventory of AI systems, and has each been classified under the EU AI Act risk categories? Who made those classification decisions, and is the rationale documented?”

Vendor Compliance

“For AI systems we procure, have we verified our vendors’ conformity status? Do our contracts clearly allocate EU AI Act obligations, and do we have audit rights?”

Evidence Generation

“If a regulator requested evidence that our risk management system operates effectively, what would we produce? Is that evidence timestamped and tamper-evident, or would we be reconstructing from scattered logs?”

Human Oversight

“Can we demonstrate that humans actually review and can override AI decisions? Is there an audit trail of human interventions, or just a policy saying oversight exists?”

Incident Response

“Do we have a protocol for classifying and reporting AI-related incidents within the applicable Article 73 deadline, including accelerated cases? Has legal reviewed what constitutes a reportable incident and the correct authority route?”

Board Awareness

“Has the board been briefed on AI-related legal exposure? Are AI risks included in enterprise risk management, and is the board receiving regular updates?”

Red flags indicating legal and compliance gaps

No AI System Inventory

If the organization cannot produce and maintain an appropriately scoped inventory of relevant AI systems, classification, role analysis, and oversight are materially impaired.

“We’re Just Using Vendor Tools”

Belief that vendor-provided AI absolves organizational liability. Deployers have independent obligations; integration into high-risk use cases may trigger provider-level duties.

Documentation Exists Only as Policies

Policies describing what should happen without records that help explain actual operation. The evidence a regulator may request depends on the provision, role, system and inquiry; no single operational record is universally sufficient.

No AI-Specific Contract Language

Vendor and customer contracts that don’t address AI-specific obligations, liability allocation, or compliance representations.

Human Oversight is Theoretical

Claims of human-in-the-loop processes without audit trails showing humans actually review decisions or documentation of override capabilities.

IT Owns AI Governance Alone

AI governance treated as a technical function without legal, compliance, and business unit involvement. This siloed approach misses liability implications.

Personal-liability considerations

While the EU AI Act primarily imposes organizational penalties, General Counsel should be aware of pathways to personal liability:

Member State Implementation

Individual member states may implement the AI Act in ways that create personal liability for directors or officers. Monitor transposition legislation in key jurisdictions where the organization operates.

Civil Litigation

When AI systems cause harm, affected parties may pursue civil claims under applicable national and EU law. The withdrawn AI Liability Directive proposal does not create a current burden-shifting rule; exposure and evidentiary standards depend on the cause of action, jurisdiction, and facts.

Fiduciary Duties

Depending on the jurisdiction, organization, and materiality, existing oversight duties may require a board to address material AI risk. Whether a failure breaches a fiduciary duty requires jurisdiction- and fact-specific legal analysis.

Regulatory Action Against Individuals

The EU AI Act primarily assigns obligations and penalties to operators. Any individual liability or regulator action depends on applicable national law, the person’s role, the conduct, and the facts; do not infer it from the AI Act alone.

The Colorado intersection: SB 26-189 and ADMT transparency

US organizations subject to the EU AI Act often track Colorado as the leading US state regime. That regime changed materially in May 2026. The 2024 Colorado AI Act (SB 24-205) was repealed and replaced before it ever took effect by SB 26-189, titled “Automated Decision-Making Technology,” signed by Governor Polis on May 14, 2026. Substantive compliance commences January 1, 2027; the duties are not yet enforceable. The earlier “June 30, 2026” effective date is no longer operative.

From high-risk AI systems to covered ADMT

SB 26-189 drops the “high-risk artificial intelligence system” category and the reasonable-care framework around it. It instead regulates covered automated decision-making technology (ADMT), defined as technology that processes personal data to generate outputs (predictions, recommendations, classifications, rankings, scores) used to materially influence a consequential decision in domains such as education, employment, housing, financial or lending services, insurance, health-care services, and essential government services. “Materially influence” replaces SB 24-205’s “substantial factor” with a non-de-minimis-factor test; incidental or clerical uses are excluded. The Colorado Attorney General must adopt clarifying rules by January 1, 2027.

What the new regime requires. What it dropped.

The replacement is a narrower transparency-and-disclosure framework. Deployer duties are: clear-and-conspicuous pre-use notice before a covered ADMT materially influences a consequential decision; plain-language disclosure within 30 days of an adverse outcome describing the ADMT’s role and the consumer’s rights; data-correction access on request; and meaningful human review on request, to the extent commercially reasonable. Developers must supply deployers with documentation on intended uses, known limitations, and instructions for monitoring and human review, with records retained at least three years.

Several SB 24-205 obligations did not survive: the duty of reasonable care to prevent algorithmic discrimination is gone (discrimination is now handled under existing Colorado anti-discrimination law); mandatory risk-management programs and annual impact assessments are eliminated; the NIST AI RMF / ISO 42001 rebuttable-presumption safe harbor was removed with no comparable replacement; there is no size-based (fewer-than-50-employee) exemption; and the standalone “you are interacting with an AI system” chatbot disclosure does not survive. Only the consequential-decision pre-use notice remains. Enforcement is exclusively by the Colorado Attorney General, with a 60-day notice-and-cure period (sunsetting January 1, 2030) and no private right of action.

Implications for EU AI Act compliance

For organizations operating under both regimes, the same evidence foundation does double duty. SB 26-189 leans on pre-use notice, post-adverse-outcome disclosure, developer documentation, and at-least-three-year recordkeeping. That is exactly the kind of contemporaneous, retained record the EU AI Act’s logging requirements (Article 12) and post-market monitoring obligations (Article 72) already contemplate. Following NIST AI RMF or ISO 42001 is no longer a codified Colorado defense, but remains sound practice and maps cleanly to EU technical-documentation expectations.

Evidence standards for regulatory defense

When regulators investigate or litigation arises, evidence quality determines outcomes. General Counsel must understand what constitutes defensible evidence under AI regulations:

Contemporaneous Documentation

Contemporaneous records can reduce reliance on after-the-fact reconstruction. A timestamped event can show what a configured system recorded at a moment in time; it does not alone establish the completeness or effectiveness of the surrounding control environment.

Tamper-Evident Records

Integrity measures can make later modification detectable. Cryptographic signatures are one optional design choice, not an Article 12 mandate, and their evidentiary value depends on key custody, field selection, integration coverage and verification procedures.

Mapping to Regulatory Requirements

Evidence must clearly correspond to specific regulatory obligations. General documentation about “AI governance” is less valuable than evidence specifically demonstrating Article 9 risk management, Article 10 data governance, or Article 14 human oversight.

The “Proof Gap” Problem

Many organizations have a “proof gap” between controls described on paper and inspectable evidence from operation. Policy documents record intent; scoped operational records can make selected claims from configured control paths easier to verify. Neither artifact alone proves that a control was well designed, effective, or legally sufficient.

Working with other stakeholders

Chief Information Security Officer (CISO)

Coordinate on: logging infrastructure, data security for AI systems, cybersecurity requirements under Article 15, incident detection and response, vulnerability management for AI-specific threats.

Chief Compliance Officer (CCO)

Coordinate on: compliance program design, regulatory mapping, training and awareness, audit schedules, remediation tracking, policy development.

Business Unit Leaders

Coordinate on: AI use case identification, risk classification input, operational implementation of controls, human oversight execution, incident escalation protocols.

Data Protection Officer (DPO)

Coordinate on: GDPR/AI Act intersection, data governance under Article 10, privacy impact assessments, cross-border data considerations, subject access requests involving AI.

Board reporting on AI risk

General Counsel should ensure the board receives regular, substantive reporting on AI-related legal exposure:

Recommended Board Reporting Elements

  • AI System Inventory: Number and classification of AI systems, changes since last report
  • Compliance Status: Progress against regulatory deadlines, gap analysis, remediation timelines
  • Incident Summary: AI-related incidents, near-misses, regulatory inquiries
  • Regulatory Developments: New guidance, enforcement actions in the industry, legislative updates
  • Risk Quantification: Estimated exposure, insurance coverage, liability reserves
  • Resource Needs: Budget, personnel, and technology requirements for compliance

Litigation-readiness checklist

AI Litigation Readiness

How GLACIS provides defensible evidence

GLACIS addresses the core challenge General Counsel face: producing evidence that AI controls actually operate, not just documentation that they should.

Cryptographic Attestation

GLACIS signs selected operational fields so later changes can be detected by a verifier. This can support integrity and chain-of-custody analysis, but does not establish completeness, control effectiveness or legal compliance.

Regulatory Mapping

Evidence fields can be mapped to selected EU AI Act, NIST AI RMF and ISO 42001 concepts to support review. A mapping is not a conformity assessment or demonstration of compliance.

Continuous Monitoring

Rather than relying only on point-in-time review, GLACIS can preserve ongoing signed reports of selected covered control outcomes. Verification checks supported signatures and covered-field integrity; effectiveness and coverage require separate testing and evidence.

Review-Ready Evidence Packages

Teams can assemble selected signed records with policies, testing, coverage notes, and source evidence for board, regulatory, or litigation review. Glacis does not currently promise an automated report export.

Frequently asked questions

What are the key dates General Counsel should track?

February 2, 2025: prohibited-practice and AI-literacy provisions began applying. August 2, 2025: GPAI model obligations began applying. July 27, 2026: the AI Omnibus entered into force. December 2, 2027: relevant Annex III high-risk obligations apply. August 2, 2028: relevant Annex I product-embedded obligations apply. In the US, Colorado’s SB 26-189 reaches substantive compliance on January 1, 2027.

How should we handle AI systems from US-based vendors?

EU AI Act scope follows Article 2’s operator, market, use, and output-use tests, not a general “affected EU resident” test. Review where the provider and deployer are established, whether a system is placed on the EU market or put into service or used in the EU, and whether output from a third-country operator is used in the EU. Contracts should allocate the EU-specific support and evidence required for the applicable roles.

What’s the relationship between GDPR and AI Act enforcement?

The regimes have different scopes and can both apply where an AI system processes personal data and their respective triggers are met. Authorities may coordinate, but enforcement and penalty interaction depend on the distinct infringements, facts, competent authorities, and applicable non-duplication principles.

Should we engage with regulatory sandboxes?

Regulatory sandboxes (Article 57-62) offer valuable benefits: regulatory guidance during development, potential for modified obligations, and relationship-building with authorities. For organizations developing novel AI applications, sandbox participation can reduce compliance uncertainty. However, sandbox benefits don’t exempt you from core obligations, and sandbox interactions create records that may be discoverable.

How do we handle existing AI systems that may not comply?

Conduct an immediate gap analysis. For systems that cannot achieve compliance by applicable deadlines, options include: (1) modification to meet requirements, (2) re-classification to a lower risk category if legitimately appropriate, (3) geographic restriction to exclude EU markets, or (4) decommissioning. Document the analysis and decision rationale. Regulators will scrutinize “re-classification” decisions carefully.

What privilege considerations apply to AI compliance work?

Structure AI audits and assessments carefully to preserve privilege where appropriate. Legal-directed compliance assessments may qualify for attorney-client privilege or work product protection. However, operational compliance documentation (logs, attestations, routine monitoring) generally won’t be privileged. Consult with outside counsel on privilege strategies before commencing major AI compliance initiatives.

References

  1. European Union. “Regulation (EU) 2024/1689 of the European Parliament and of the Council.” Official Journal of the European Union, July 12, 2024. EUR-Lex 32024R1689
  2. European Parliament Legislative Observatory. “AI Liability Directive, procedure 2022/0303(COD).” Proposal withdrawn 6 October 2025. europarl.europa.eu
  3. Colorado General Assembly. “SB 26-189: Automated Decision-Making Technology” (repealing and reenacting the 2024 Colorado AI Act, SB 24-205). Signed May 14, 2026. leg.colorado.gov
  4. European Commission. “Questions and Answers: Artificial Intelligence Act.” March 13, 2024. europa.eu
  5. ISO/IEC. “ISO/IEC 42001:2023 Information Technology — Artificial Intelligence — Management System.” December 2023. iso.org

Defensible evidence

Close the proof gap before a competent authority asks.

GLACIS can preserve signed records for selected policy, control and action events before an inquiry begins. Those records may support a broader Article 12 evidence set, but they do not replace Article 11 technical documentation or establish compliance, coverage or control effectiveness.

Talk to us See an evidence pack →

Related guides

EU AI Act series hubArticles, penalty structure, GLACIS coverage map.
Full compliance guideRisk categories, Articles 9–15 in detail, GPAI, conformity assessment, Omnibus status.
EU AI Act vs HIPAASide-by-side crosswalk for healthcare and life-sciences operators with US obligations.
Colorado SB 26-189 (ADMT)The repeal-and-replace ADMT transparency regime; AG-enforced, compliance from January 1, 2027.
For CCOsArticles 9, 11, 17, 26 framed for the compliance lead.
The proof gap (whitepaper)Why compliance documentation alone is insufficient.