REGULATORY INTELLIGENCE · ODA3 INSIGHTS

The EU AI Act Is an Engineering Problem—even When the Deadline Moves

The timetable changed. Operational evidence still has to work.

Governance, incident classification, response and evidence archive connected in an operational workflow
CATEGORYRegulatory Intelligence
DOCUMENT IDODA3-2026-07-INS-073
PUBLISHEDJuly 19, 2026
READING TIME5 min

The 2026 Digital Omnibus changed the EU AI Act timetable. Stand-alone high-risk requirements now apply from 2 December 2027, while product-embedded high-risk requirements move to 2 August 2028. That is meaningful relief—but it does not answer the operational question regulators, auditors and boards will eventually ask: what evidence shows that your controls actually worked? AI governance becomes real when policy can be translated into telemetry, decisions, response actions and retained evidence.

ODA3 Institute’s new Technical Report, From EU AI Act Obligations to Operational Evidence, addresses that question through the three-framework GAISSF Ecosystem.

Three different jobs

  • GAISSF™ v1.0 structures governance, control ownership and evidence expectations through 52 Foundational controls, with seven additional physical-AI controls applied only when D9 is in scope.
  • UAIF™ v1.0 structures the identity, cause, classification, harm pattern and rationale of an AI incident through layers L0–L6.
  • AI-IRF™ v1.0 structures containment, investigation, recovery and regulatory-review routing.

The frameworks are intentionally not collapsed into one compliance checklist. A governance control, an incident classification and a response decision are different artifacts. Treating them as interchangeable creates gaps precisely when an organization needs to explain what happened.

The operational chain

The report recommends one reviewable chain:

Applicability decision → control → evidence → incident record → response → regulatory decision → corrective action

This model matters because the AI Act does not operate through one date or one actor role. Prohibited practices, GPAI, transparency, stand-alone high-risk systems and product-embedded systems follow different provisions and transitions.

Article 73 is not a severity score

One of the report’s most important boundaries is that technical severity does not determine legal reportability. UAIF can structure harm, causality, context and severity. AI-IRF can initiate containment and route a potential notification. Legal review must still determine applicability, the competent authority and the relevant statutory timing case.

Start with 90 days

The implementation pathway begins with inventory, actor roles and applicability decisions; moves to controls, evidence and incident structure; and finishes with exercises that test prohibited-use discovery, transparency failure, serious-incident review and rollback.

The goal is not a badge or a broad compliance statement. It is the ability to reproduce the organization’s reasoning and evidence.

What the report does not claim

The report does not claim certification, conformity assessment, regulatory approval or guaranteed compliance. It does not assume harmonized standards are complete, treat an automated score as a legal decision, promise plug-and-play platform integration, or publish universal cost and staffing estimates without an organization-specific basis.

Read the Technical Report: ODA3-2026-07-TCR-HAI-004
Download the Executive Brief: ODA3-2026-07-EXB-HAI-004

GAISSF™, UAIF™ and AI-IRF™ are frameworks of ODA3 Institute, referenced under the GAISSF Ecosystem License (GEL) v1.0.

Tags

  • EU AI Act
  • EU AI Act operational readiness
  • AI governance
  • AI security
  • AI incident response
  • GAISSF™
  • UAIF™
  • AI-IRF™