Executive summary
The deadline moved; the need for operational evidence did not. CISOs should use the additional high-risk implementation window to establish inventory, classification, transparency controls, role-specific GPAI documentation, incident readiness and evidence governance.
Corrected regulatory position
| Obligation | Current position | Operational consequence |
|---|---|---|
| Article 5 prohibited practices | Applied from 2 February 2025; new Omnibus prohibitions have their own timetable. | Maintain active prohibition screening and a cessation or escalation process. |
| GPAI provider duties under Articles 53–55 | Core obligations applied from 2 August 2025; enforcement and penalty provisions follow the Act’s staged timetable. | Confirm whether the organization is a GPAI provider, downstream provider, importer or deployer before assigning controls. |
| Article 50 transparency | Separate transparency obligations remain on the 2026 track, subject to the amended text, exceptions and transitional provisions. | Implement and test applicable human-interaction notices, synthetic-content marking and emotion or biometric notices. |
| Annex III high-risk systems | Stand-alone high-risk rules delayed to 2 December 2027. | Continue classification, documentation, human-oversight and evidence work. |
| Annex I product-embedded systems | Delayed to 2 August 2028. | Coordinate AI controls with the applicable product-safety conformity regime. |
Penalty language
Article 99(4) places listed provider, deployer, notified-body and Article 50 transparency non-compliance in the tier of up to €15 million or 3% of worldwide annual turnover, subject to the Regulation’s detailed calculation rules. Article 5 violations occupy the higher Article 99(3) tier of up to €35 million or 7%. GPAI-provider penalties are addressed separately by Article 101. Confirm the actor, violated provision and applicable enterprise calculation before publishing a monetary exposure.
Revised 14-week CISO action plan
| Weeks | Focus | Evidence output |
|---|---|---|
| 1–2 | Establish accountable ownership; inventory AI systems, models and material third-party dependencies. | Approved AI register, ownership map and scope assumptions. |
| 3–4 | Classify actor role and system category; screen for Article 5 prohibitions and Article 50 triggers. | Classification matrix, legal-review queue and prohibition decisions. |
| 5–6 | Map applicable controls across GAISSF governance, UAIF incident classification and AI-IRF response architecture. | Control crosswalk with owners and evidence requirements. |
| 7–8 | Implement or validate human-interaction notices, synthetic-content marking and other applicable transparency controls. | Design records, test results and exception rationale. |
| 9–10 | Build GPAI documentation only where the organization’s role triggers the relevant duties; request upstream evidence where dependent on providers. | Role-specific documentation package and supplier requests. |
| 11–12 | Exercise AI-incident triage and Article 73’s tiered reporting logic. | Tabletop record, escalation tree and evidence-preservation log. |
| 13–14 | Conduct a readiness review, document gaps and approve a dated remediation plan. | Readiness report, management sign-off and corrective-action plan. |
Technical priorities
- Maintain a continuously updated AI system and model inventory.
- Capture the legal actor role and risk classification for every material system.
- Implement transparency mechanisms that can be demonstrated and tested, not merely described.
- Preserve model, prompt, data, decision, override and incident evidence proportionate to system risk.
- Treat watermarking and C2PA as implementation options where suitable, not as universally mandated technologies.
- Test Article 73 notification decision logic. Reporting is immediate after the relevant causal-link assessment, with outer limits that vary by incident type—generally 15 days, with specified 2-day and 10-day cases.
Readiness checklist
| Requirement | Status |
|---|---|
| AI systems and models inventoried with accountable owners | ☐ |
| Actor roles and system categories documented | ☐ |
| Article 5 prohibited-practice screening operational | ☐ |
| Applicable Article 50 transparency controls implemented and tested | ☐ |
| Role-specific GPAI documentation or supplier evidence available | ☐ |
| AI incident triage, evidence preservation and escalation exercised | ☐ |
| High-risk implementation roadmap aligned to the revised timetable | ☐ |
Notably absent
- This article does not assert that an inventory, crosswalk or readiness review demonstrates legal compliance.
- It does not assume every organization using a GPAI model is a GPAI provider.
- It does not prescribe a single watermarking technology or guarantee that C2PA satisfies Article 50 in every context.
- It does not predict enforcement priorities or inspection behaviour without published evidence.
The bottom line
Replace the obsolete countdown with a continuous-evidence programme. The additional time should produce traceable classification decisions, tested transparency mechanisms, role-specific documentation, exercised incident response and a remediation plan tied to the operative legal timetable.
Source provenance: Originally published by ODA3 Institute on 27 April 2026. This corrected edition preserves the historical publication date while replacing obsolete or internally inconsistent regulatory instructions.
Authoritative references
- Council of the European Union — final adoption of the Digital Omnibus on AI, 29 June 2026
- Regulation (EU) 2024/1689 — Artificial Intelligence Act
Research and practitioner guidance only. This article is not legal advice, certification, regulatory approval or a representation of compliance.
