The Decision Layer Compass™ · Week 4 Regulatory Radar

Seventy-one days to a deadline the old timeline cannot show.

The Omnibus deferred the headline and kept the enforcement. The next hard EU date is 2 December, seventy-one days out, and any pre-Omnibus timeline still shows the old one.

PublishedTue 22 September 2026
Read time6 minutes
CycleWeek 4 of 4
FollowsBoard Case Study, 15 September
01 · The clock

Day counts are from the stated publication date, 22 September. Rows shaded gold are live or inside six months. Every date is anchored to primary legal or regulator material, not a secondary timeline.

DateObligationDays
2 Feb 2025Prohibited practices and AI literacy. Article 4 rewritten 27 July 2026 from a duty to ensure literacy to one of supporting its development, with no guaranteed outcome.In force
2 Aug 2025General-purpose AI model obligations, AI Office, AI Board, national competent authorities, penalties regime.In force
2 Aug 2026Article 50 transparency obligations began applying. National market-surveillance authorities lead enforcement; the AI Office has competence in defined system, model and platform cases.Enforced
2 Dec 2026Marking of AI-generated content. End of the four-month transitional period for systems placed on the market before 2 August 2026. Systems placed on the market on or after 2 August received no Article 50(2) grace period.71
2 Dec 2026New Article 5 prohibitions on non-consensual intimate imagery and CSAM. Transitional period ends; top penalty tier attaches.71
2 Aug 2027Member States must have an operational national AI sandbox. Deferred one year.314
2 Dec 2027Annex III standalone high-risk systems. Deferred sixteen months.436
28 Jan 2028Notified body designation deadline.493
2 Aug 2028Annex I high-risk embedded in regulated products. Deferred one year.680
2 Aug 2030Legacy high-risk systems used by public authorities must comply.1,410
The Omnibus was redistribution, not deregulation

Operators received deferred deadlines and lighter documentation. The AI Office also received direct oversight of defined AI systems built on general-purpose models by the same provider and AI integrated into designated very large online platforms or search engines, with powers to compel information, conduct inspections and seal premises, books and records. Periodic penalty payments may reach 5% of average daily income or worldwide annual turnover in the preceding financial year per day. The practical effect is redistribution: selected deadlines moved, while enforcement capacity expanded.

02 · What moved since Issue 02
DateDevelopment
18 Sep 2026EBA finalised its Guidelines on third-party risk for non-ICT services. They align the non-ICT framework more closely with DORA, focus on arrangements supporting critical or important functions and include a two-year transition. The text is final but awaits official-language translations and is not yet applicable.
After 12 SepEU Data Act Article 3(1) now captures connected products and related services placed on the market after 12 September 2026. The trigger is after that date, not from the start of 12 September.
11 Sep 2026Cyber Resilience Act reporting went live. Manufacturers must report actively exploited vulnerabilities and severe incidents: early warning within 24 hours, full notification within 72 hours, then a final report within 14 days after a corrective or mitigating measure is available for a vulnerability, or within one month for a severe incident. Eleven days old at publication.
15 Aug 2026Netherlands NIS2 transposition entered into force. Austria's enacted NISG 2026 takes effect on 1 October. The Commission's 8 July referral of France, Ireland and Spain remains the relevant unresolved enforcement marker for this edition.
31 Jul 2026EBA, EIOPA and ESMA called for consistent, risk-based supervision of ICT risk from frontier AI models and said ongoing and planned DORA oversight of critical ICT third-party providers will address that risk.
8 Jul 2026Commission referred Ireland, Spain, France and the Netherlands to the CJEU for failure to notify full NIS2 transposition, requesting lump-sum and daily financial penalties. The Dutch law subsequently entered into force on 15 August.
03 · Beyond the AI Act
RegimePosition verified 19 September 2026
UKNo general government AI bill has been introduced in the current session as at the verification cut-off. AI-related private members' bills are active, including the Artificial Superintelligence Bill, introduced in the Commons on 8 September. SI 2026/425, in force 12 May, requires the Information Commissioner to prepare a statutory code on personal data, AI and automated decision-making; the ICO says that code is still being developed. FCA AI Live Testing cohort two runs through year-end, with evaluation in Q1 2027.
StandardsEN 18286:2026 was published on 22 July as the first European standard supporting the AI Act, but Commission assessment for Official Journal citation is still ongoing. It therefore carries no AI Act presumption of conformity yet. Three further drafts have reached the Enquiry stage: AI risk management, AI cybersecurity and the logging part of the trustworthiness framework. ISO/IEC 42001 certification is accredited in the UK through UKAS, first granted to BSI on 15 January 2026; ISO/IEC 42006:2025 sets requirements for the bodies providing that certification.
United StatesExecutive Order 14365 of 11 December 2025 remains the federal policy anchor on state AI laws and funding alignment. Colorado is the correction: SB 24-205 did not simply become operative on 30 June under a court stay. SB 26-189 was signed on 14 May, repealing and reenacting the framework around automated decision-making technology; key developer duties begin 1 January 2027. California SB 53, Texas TRAIGA and Illinois HB 3773 remain in force. FTC enforcement against deceptive AI claims continues, including claims made to small-business purchasers.
Financial servicesDORA's 2026 EU-level Register of Information cycle reached the 31 March submission deadline for competent authorities; firms' filing dates are set earlier at national level. In the US, SR 26-2 of 17 April 2026 superseded SR 11-7 and excludes generative and agentic AI models from this model-risk guidance. The same guidance says broader risk-management and governance practices should determine controls for tools outside its scope. This is a supervisory-framework scope change, not an exemption from risk governance or law.
Post-quantumThe NCSC roadmap sets a first milestone by 2028: complete discovery and assessment, define migration goals and build an initial plan. Highest-priority migration activities should be completed by 2031, with full migration targeted for 2035. Treat 2028 as a planning horizon, not a day-count deadline.
04 · Corrections and stale sources
Three sources your team may be working from are wrong

Some secondary AI Act timelines still render pre-Omnibus dates. Do not run an operational compliance plan from an undated secondary timeline. Use Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744, plus the Commission's current implementation pages.

MDCG 2025-6 still points medical-device AI programmes at 2 August 2027. Regulation (EU) 2026/1744 moved the Annex I high-risk date to 2 August 2028, and the June 2025 guidance has not been reissued. The stale date is conservative, but it can still distort sequencing, contracts and assurance planning.

ISO/IEC 42006 is dated 2025, not 2026. It was published on 7 July 2025. At least one aggregator lists it as a 2026 standard.

Two corrections to our own record. Issue 01 described the marking grace period as cut from six months to three; it is four, and Issue 02 carried the correction. Issue 01 also treated the 2 February 2025 AI-literacy duty as settled. Article 4 was amended on 27 July 2026 from outcome-oriented wording to a duty to take measures supporting the development of AI literacy. The control expectation changed, so the board brief should change with it.

05 · Position movement

Against the Board Case Study of 15 September.

Content marking readinessNew entry at 83
Vendor-borne model exposure89, held
Agent permission sprawl87 to 85, down 2
Shadow AI and employee-built agents82, held
Model supply concentration78, held
AI decision confidence index47 to 48, up 1

Confidence recovers a point for the first time this cycle. Nothing improved operationally. The dates are now established and sourced, and a known deadline is a cheaper position to hold than an uncertain one.

06 · What did not move

The classification rule and the third-party register are unchanged since Issue 01. Four editions, one worked case study, still no owner. They close this cycle as they opened it.

Sources

Verification cut-off: 19 September 2026. Regulation (EU) 2026/1744 and the AI Act consolidated text; European Commission AI Act, Article 50 and standardisation pages. Cyber Resilience Act reporting, European Commission, 11 September 2026. Regulation (EU) 2023/2854, Article 50. EBA third-party-risk Guidelines, 18 September 2026; EBA/EIOPA/ESMA frontier-AI statement, 31 July 2026. Netherlands Cyberbeveiligingswet and Austria NISG 2026; Commission NIS2 infringement package, 8 July 2026. SI 2026/425 and ICO code pipeline; UK Parliament, Artificial Superintelligence Bill. EN 18286:2026; ISO/IEC 42006:2025; UKAS. Colorado SB 26-189; FTC AI enforcement. Federal Reserve SR 26-2, 17 April 2026. NCSC PQC roadmap. MDCG 2025-6. Position scores are editorial positions for this cycle and are not a firm-level assessment.

Next in the cycle

Issue 03, 6 October 2026. The cycle then repeats: Decision Signals, Board Case Study, Regulatory Radar.

Maman Ibrahim. F-ISRM · F-IoCR · CISSP · CISA · CRISC
The Decision Layer Compass™ · The Decision Layer
© 2026 DiamondSoul · All rights reserved. Reproduction prohibited without permission.