The deadline moved. Control readiness still matters.
Organizations deploying AI in employment, credit, education, healthcare, public services or other sensitive contexts should not treat the revised timetable as permission to suspend governance work. Inventory, classification, human oversight, technical documentation, incident readiness and evidence quality remain long-lead operational capabilities.
The practical question is no longer “Can we finish in 74 days?” It is: Can we demonstrate a controlled, dated and role-specific readiness programme?
What the companion report should cover
The companion Executive Brief and Technical & Compliance Report should translate legal requirements into implementable controls and evidence expectations without claiming that a control mapping demonstrates compliance.
Risk classification
Maintain a documented inventory and classification rationale for every material AI system. Record the organization’s actor role, intended purpose, affected persons, applicable category, assumptions, legal-review status and triggers for reassessment.
Prohibited-practice screening
Screen systems against Article 5 before deployment and during material change. Distinguish an actual prohibited practice from a high-risk or transparency-regulated use case, and document the basis for lawful exceptions where relevant.
High-risk control mapping
Map applicable requirements to accountable owners, technical or procedural controls and minimum evidence artifacts. Treat the legal requirement, the control implementation and the evidence of operation as three related but distinct layers.
Cross-framework mapping
Use GDPR, ISO/IEC 42001, NIST AI RMF and other mappings to identify reusable governance capabilities. A mapping is not equivalence: state confidence, limitations and residual gaps explicitly.
Substantial-modification decisions
Assess changes using the Act’s legal definition and competent guidance. Do not use an invented universal performance threshold. Preserve the decision, evidence considered, reviewer and next review trigger.
What reviewers may need to verify
- The AI inventory and the basis for including or excluding each system.
- The organization’s actor role and classification rationale.
- How human oversight works in practice, including authority, escalation, override and retained evidence.
- Testing methods, limitations and acceptance criteria appropriate to the intended context.
- AI-incident triage, evidence preservation and Article 73 decision logic. Reporting is immediate after the relevant causal-link assessment, with outer limits that vary by incident type—generally 15 days, with specified 2-day and 10-day cases.
- The method used to assess whether a change may constitute a substantial modification.
A revised implementation pathway
| Phase | Outcome | Minimum evidence |
|---|---|---|
| 1 — Scope | Inventory systems and classify organizational roles and system categories. | Register, classification rationale and legal assumptions. |
| 2 — Design | Map applicable requirements to controls and owners. | Control matrix, design decisions and exception log. |
| 3 — Operate | Implement and test oversight, transparency and incident processes. | Test records, logs, tabletop results and corrective actions. |
| 4 — Assure | Review readiness against the current timetable and unresolved dependencies. | Review record, residual-risk acceptance and remediation plan. |
Notably absent
- No claim that ODA3, GAISSF, UAIF or AI-IRF provides certification, regulatory approval, legal compliance or a safe harbour.
- No proprietary readiness statistic or conformity-body lead-time estimate without a published source.
- No universal technical threshold for substantial modification.
- No prediction of regulator priorities, penalty size or leniency.
The bottom line
The 74-day countdown is historical. The durable objective is continuous, auditable evidence across governance, incident classification and response. GAISSF can organize governance and assurance context, UAIF can structure incident classification, and AI-IRF can support response architecture. Those relationships do not themselves demonstrate legal compliance.
Attribution: Originally published by ODA3 Institute.
Authoritative references
- Council of the European Union — final adoption of the Digital Omnibus on AI, 29 June 2026
- Regulation (EU) 2024/1689 — Artificial Intelligence Act
Research and practitioner guidance only. This article is not legal advice, certification, regulatory approval or a representation of compliance.
