Skip to main content

regulation.eu_2024_1689

On 2 August 2026 the regulation stops being a calendar and starts carrying fines

That is the day the Article 50 transparency obligations start to apply and the penalty regime switches on. The high-risk obligations were pushed back to December 2027, and that has led a lot of people to read it as a reprieve. It is not: the evidence the regulation will ask for then accumulates from today.

Next date of application

Article 50 transparency and the penalty regime, across the whole European Union and therefore in Spain.

calendar.amended

The calendar changed in June 2026, and almost no page reflects it

The Digital Omnibus on AI was formally adopted — European Parliament on 16 June 2026, Council on 29 June — and entered into force that same July. If you are reading material dated before that, it is probably giving you the old calendar.

What was in fact postponed

  • Annex III high risk — biometrics, critical infrastructure, education, employment, law enforcement, migration — moves from 2 August 2026 to 2 December 2027
  • Annex I high risk, the kind embedded in products already covered by sectoral legislation, moves to 2 August 2028
  • Generative systems already on the market have until 2 December 2026 to comply with the marking required by Article 50(2)

What did not move

  • The Article 50 transparency obligations apply from 2 August 2026
  • The penalty regime switches on that same date: the supervision and fining machinery stops being theoretical
  • Prohibited practices and the AI literacy obligation have been in application since 2 February 2025
  • The obligations for general-purpose models apply from 2 August 2025

The dates and references on this page were verified against the European Commission's official calendar on 21 July 2026. If you are reading this much later, check them again.

regulation.timeline

The full calendar, as it now stands

Eight dates. Three already apply, one is just around the corner and the rest mark out the work of the next two years.

  1. in application

    Entry into force

    Regulation (EU) 2024/1689 enters into force. The staggered calendar of application starts to run.

  2. in application

    Prohibited practices and AI literacy

    The general provisions, the definitions, the AI literacy obligation and the list of prohibited practices apply.

    • Social scoring, subliminal manipulation and exploitation of vulnerabilities
    • Your staff must have a sufficient level of AI competence for the systems they operate
  3. in application

    General-purpose models and governance

    The obligations for general-purpose AI models apply and the governance structures are established. Member States designate their competent authorities.

  4. imminent

    Transparency and the penalty regime

    Most of the regulation applies. The Article 50 transparency obligations become enforceable and market surveillance authorities can impose penalties.

    • Anyone interacting with an AI system has to know they are talking to a machine
    • Generated or manipulated content is marked in a machine-readable format
    • Anyone deploying emotion recognition or biometric categorisation must inform the people exposed to it
    • Fines stop being a threat on paper
  5. upcoming

    New prohibitions and the end of the grace period

    The prohibitions on nudification applications and abuse material come in, and the window that generative systems already on the market had to comply with the marking required by Article 50(2) expires.

  6. upcoming

    Regulatory sandboxes

    Every Member State must have at least one AI regulatory sandbox up and running.

  7. upcoming

    Annex III high risk

    The obligations for standalone high-risk systems apply. This is where Articles 12, 13, 14 and 15 come in, and where the evidence you have been accumulating decides whether you make it or not.

    • Record-keeping, transparency, human oversight and robustness
    • Risk management system and technical documentation
    • The original date was August 2026; the Digital Omnibus moved it here
  8. upcoming

    Annex I high risk

    The obligations apply for high-risk systems that are safety components of products already covered by sectoral Union legislation.

evidence.retrospective

A postponement is not a licence to do nothing

That is the comfortable reading of the Omnibus, and it is an expensive one. There is a technical reason why waiting until 2027 does not work, and it has nothing to do with diligence: it has to do with how Article 12 is drafted.

Record-keeping is a retrospective obligation. When December 2027 arrives, the authority will not ask whether you have a logging system installed: it will ask for the records covering the period. And those cannot be generated after the fact. An agent that starts emitting telemetry in November 2027 reaches the date with three weeks of history; the one that started today, with two years.

Evidence accumulates, it is not manufactured

No vendor can hand you traces for a period in which you were not instrumented. It is the one requirement in the regulation that money cannot solve at the last minute.

The inventory takes longer than you think

Before you can govern, you have to know which agents exist, who maintains them and what data they reach. In a large organisation that conversation runs for months, and it does not depend on technology.

By August 2026 the penalty regime is already live

The postponement affects high risk, not transparency and not the power to impose penalties. Anyone reading the Omnibus as "this was for 2027" is skipping the part that already applies.

risk.classification

The four risk classes

The regulation does not treat every system alike. The class determines which obligations land on you, which is why it is the first thing to settle for each agent in the inventory.

  1. prohibited

    Prohibited practices

    Uses banned across the Union since February 2025. There is no compliance regime available: they simply cannot be deployed.

  2. high

    High risk

    Where the bulk of the obligations live: record-keeping, transparency, human oversight, robustness and technical documentation.

  3. limited

    Limited risk

    Article 50 transparency obligations. This is where most conversational assistants and content generators land.

  4. minimal

    Minimal risk

    No specific obligations beyond the general ones. Even so, it is worth keeping them inventoried: the classification can change when the use changes.

In Regentic.AI the risk class is declared per agent and recorded alongside its purpose, its data categories and its oversight mechanism. It is an assisted, declared classification, not an automatic legal determination — and that is written inside the product too.

compliance.article_mapping

The articles, and which data the evidence for each one comes from

This is the part that separates a governance tool from a spreadsheet with tick boxes. The status of each article is not set by a person: it is derived from what is in the telemetry.

Coverage per agent

  • Art. 12

    Record-keeping

    High-risk systems must automatically record events throughout their lifecycle, with enough traceability to reconstruct how they operated.

    where the status comes from

    From whether traces for the agent exist in the telemetry table. Not from a declaration: from there being spans.

    • covered
    • pending
  • Art. 13

    Transparency and information

    The system must come with enough information for whoever deploys it to understand what it does, what it is for and with what limitations.

    where the status comes from

    From the agent's declared purpose and its technical declaration in the registry. If only one of the two is there, the article stays partial.

    • covered
    • partial
    • pending
  • Art. 14

    Human oversight

    The system must be capable of being overseen by people while in use, with measures that allow them to intervene or stop it.

    where the status comes from

    From the oversight mechanism declared for that agent: who watches it and how they can intervene.

    • covered
    • pending
  • Art. 15

    Accuracy, robustness and cybersecurity

    The system must reach an appropriate level of accuracy and robustness, and maintain it consistently throughout its lifecycle.

    where the status comes from

    From whether there are quality evaluations over the agent's executions. With telemetry but no evaluations, the article stays partial.

    • covered
    • partial
    • pending

Each article ends up covered, partial or pending, and from there comes a weighted coverage figure per agent and across the estate. It exports to CSV and to PDF, with its legal disclaimer, ready to attach to an audit.

article.50

What actually applies on 2 August: Article 50

It is not high risk. It is transparency, and it reaches many more systems than people think, because it does not depend on the risk classification but on the type of interaction.

  • A system that interacts with people has to be designed so that they know they are dealing with an AI
  • Synthetic content — text, image, audio, video — is marked in a machine-readable and detectable format
  • Anyone deploying emotion recognition or biometric categorisation informs the people exposed to it
  • Deepfakes and certain generated content are identified as such

Where Regentic.AI helps and where it does not

Content marking and the notice to the user are implemented inside your agent: the platform does not do that for you, and be wary of anyone who says otherwise. What Regentic.AI brings is the part before and the part after — knowing which agents you have and which of them interact with people, having their purpose declared, and being able to show with traces what each one did and when. You cannot meet Article 50 on a system whose existence you had not recorded.

enforcement.penalties

What is at stake from that date on

These get mixed up often, so it is worth separating them: the top band is for prohibited practices, not for a transparency failure.

Prohibited practices

up to €35M or 7% of total worldwide annual turnover

whichever is higher

The highest band in the regulation, reserved for the uses banned under Article 5.

Breach of obligations

up to €15M or 3% of total worldwide annual turnover

whichever is higher

Applicable to the obligations of providers and deployers, including the Article 50 transparency ones.

On top of that comes the cost that does not appear in the regulation: stopping a deployment in production because you cannot demonstrate how it behaved.

jurisdiction.es

How it lands in Spain

The regulation is directly applicable across the whole Union, so 2 August does not wait for any national parliament to finish its process. What does depend on Spain is who supervises and under what procedure they impose penalties.

AESIA as market surveillance authority

The Spanish Agency for the Supervision of Artificial Intelligence was created by Real Decreto 729/2023 (Royal Decree 729/2023), is based in A Coruña and was the first national authority of its kind in the European Union.

Supervision split across sectors

AESIA is not the only competent body: the Bank of Spain supervises matters relating to the financial system, the Spanish Data Protection Agency those touching personal data, and the General Council of the Judiciary those relating to the justice system.

Organic law going through parliament

On 26 May 2026 the Spanish Council of Ministers approved the draft organic law on the good use and governance of AI, which designates authorities and sets the national penalty regime. As of 21 July 2026 it is still in passage and has not entered into force.

And in Catalan, and in English

If you work with the Catalan administration or under an international parent company, compliance documentation ends up being requested in more than one language. The reports come out of the same data.

onboarding.evidence

What happens from the first day you connect an agent

There is no six-month compliance project before you see anything. The evidence starts accumulating with the first execution that comes in.

  1. 01

    Day one — the agent enters the inventory

    It is registered with its service name, its declared risk class, its purpose and its oversight mechanism. The declarative part of Articles 13 and 14 is already covered.

  2. 02

    First execution — record-keeping begins

    Every trace that arrives is Article 12 evidence, with its timestamp. From here on the clock runs in your favour instead of against you.

  3. 03

    First evaluations — Article 15 comes in

    Once executions are scored across the five quality dimensions, the accuracy and robustness article stops being partial and starts having backing.

  4. 04

    When somebody asks — the report already exists

    Daily, biweekly or monthly, versioned and sealed with the fingerprint of the dataset, with its EU AI Act section and its legal disclaimer. There is nothing to prepare: there is something to download.

That is what we mean by compliance from day zero: not that a product declares you compliant — nobody can do that — but that from the very first execution you are generating the evidence the regulation is going to ask you for.

What this page is not

It is not legal advice. Regentic.AI does not certify conformity and does not replace the assessment your legal advisers have to make, and each agent's risk classification is declared and assisted, not an automatic determination. What the platform does is speed the work up and hold it together with real data: gather the evidence, keep it traceable and leave it exportable. The decision on whether your system complies remains yours and your advisers'.

faq.compliance

Frequently asked questions

If high risk was postponed to December 2027, why start now?

Because Article 12 asks for records covering a period, and records cannot be generated after the fact. When the date arrives, the question will not be whether you have the tool installed but what history you can show. On top of that, Article 50 transparency and the penalty regime apply from August 2026, with no postponement.

Is my internal chatbot high risk?

Probably not, and that is exactly the biggest mistake we see: a lot of people assume high risk by default and freeze. High risk is defined by Annex III by use case — biometrics, critical infrastructure, education, employment, law enforcement, migration. An internal assistant is usually limited risk, with transparency obligations. That said, the classification depends on the specific use and is a decision to document, not to guess at.

Does Regentic.AI certify my compliance?

No, and nobody can. What it does is derive from real data what evidence exists for each obligation and where the gaps are, and leave it exportable for your advisers or for an audit. Conformity is determined by your organisation and whoever advises you legally.

Does it work for agents you did not build?

Yes, and that is the normal case. Any agent that emits telemetry is in, whether through OpenTelemetry, through the API REST or through MCP. Coverage per article is calculated the same way whoever built it.

Does it block an agent that breaches a rule?

No. The platform observes, evaluates, audits and leaves evidence; it does not sit in the execution path. If your requirement is admission control that prevents actions in real time, we do not cover that today, and we would rather tell you now than later.

What if my organisation is not in the European Union?

The regulation reaches anyone who places AI systems on the Union market or whose outputs are used within it, wherever they are established. The useful question is not where your head office is, but where the people affected by what your agent does are.

See your exposure with your own agents

The fastest route is to look at it over your real estate: which agents there are, how they would be classified and what evidence exists today for each article. Out of that comes a list of gaps, which is what is actually needed.