5-minute executive briefing · The Decision Layer™
Regulatory Radar · Week 4Executive update

What moved, and what it obliges you to do.

The month's regulatory, supervisory, and policy movement, filtered to what changes an obligation, a date, or an expectation. Developments that change none of the three are left out.
PublishedTue 25 August 2026
Read time5 minutes
CycleWeek 4 of 4
Clock as at25 August 2026
01 · Clock update

Carried forward from the Issue 01 dashboard and recalculated to the publication date. Shaded rows are live or fall inside one hundred days.

DateObligation / milestoneRemainingChange
2 Aug 2026Article 50 transparency obligationsLiveIn force
2 Aug 2026Commission enforcement powers for GPAI obligationsLiveIn force
2 Dec 2026Article 50(2) marking / detection transition for pre-2 Aug systems ends99 daysNew
2 Dec 2026New Article 5 prohibitions apply99 daysNew
2 Dec 2027Annex III standalone high-risk requirements464 daysDeferred
2 Aug 2028Annex I high-risk requirements for regulated products708 daysDeferred

August has separated the calendar into three categories: obligations already enforceable, a narrow transition ending in 99 days, and high-risk requirements that have moved materially outward. The delivery plan should now reflect those distinctions.

02 · Three developments

One · The high-risk deferral is settled. Rebaseline, do not pause.

What moved Regulation (EU) 2026/1744 entered into force on 27 July. Annex III high-risk requirements now apply from 2 December 2027, while Annex I high-risk systems embedded in regulated products move to 2 August 2028. The same Regulation also reframed Article 4: providers and deployers must take measures to support AI literacy rather than guarantee a specific level for each individual.
What it obliges you to do Rebaseline the programme, classifications, control build and funding. Do not treat the deferral as permission to stop inventory, ownership or evidence work. For AI literacy, revisit policies written against the previous wording and retain a defensible rationale for the measures taken by role and context.
Supervisory implication A programme still carrying the old dates is stale. A programme that has stopped because the dates moved is equally difficult to defend. The useful question is whether the extra time is being converted into a more defensible operating position.
02 · Three developments, continued

Two · Article 50 is live. The grandfathering is narrow.

What moved Article 50 transparency obligations began applying on 2 August 2026. Providers must address direct AI interaction and, where applicable, machine-readable marking of generated or manipulated content. Deployers have disclosure duties for specified uses including emotion recognition, biometric categorisation, deepfakes and certain AI-generated public-interest text. The 2 December grace applies only to Article 50(2) for qualifying systems already placed on the market before 2 August.
What it obliges you to do Stop running one generic transparency workstream. Identify which live systems trigger interaction disclosure, content marking, deepfake disclosure, emotion-recognition or biometric-categorisation duties, and which legacy systems genuinely qualify for the limited transition. Where the voluntary Transparency Code is not used, retain evidence of the alternative measures relied upon.
Supervisory implication The question has changed from “Are we preparing for Article 50?” to “Which systems are already subject to it, and can we demonstrate compliance today?”

Three · Frontier AI has entered the financial supervisory conversation.

What moved On 31 July, the EBA, EIOPA and ESMA called for a cross-sectoral, risk-based and consistent supervisory approach to ICT risks from frontier AI models. The statement emphasises prevention, detection and management, links the issue to existing governance and DORA oversight, and encourages financial entities and competent authorities to use it as a basis for supervisory dialogue.
What it obliges you to do For EU financial entities, map where frontier models enter critical or important processes, including through suppliers. Identify the cyber scenarios that change because of frontier capability, correlated dependencies, detection requirements, ownership, fallback and the resilience testing that covers them.
Supervisory implication This does not create a new DORA article. It changes the expected conversation around existing obligations. “DORA is implemented” is not a complete answer if the ICT-risk framework has not considered how frontier models change attack speed, dependency or concentration.
03 · Inside one hundred days
DateBecomes bindingFunction affected
2 Dec 2026Article 50(2) marking / detection transition ends for qualifying pre-2-Aug systemsProduct, engineering, legal, AI governance
2 Dec 2026New Article 5 prohibitions applyLegal, trust & safety, product, AI governance

The next hard date is 99 days away. That is still inside the current planning cycle. Unresolved scope, ownership or funding decisions will increasingly determine whether delivery is possible on time.

04 · One question for the chair

Which AI obligations are already live, which become binding before year-end, and where are we still relying on a programme date rather than an accountable owner and funded delivery plan?

05 · Sources

Regulation (EU) 2026/1744, Official Journal of the European Union, 24 July 2026, in force 27 July 2026; Regulation (EU) 2024/1689 as amended; European Commission, Guidelines on Article 50 transparency obligations, 20 July 2026; EU AI Act Service Desk, implementation timeline and enforcement FAQs, current at 23 August 2026; EBA, EIOPA and ESMA, Joint Statement on ICT risks from frontier AI models, 31 July 2026. Day counts calculated to 25 August 2026.

Next in the cycle

Board AI Risk Intelligence, Issue 02, Tuesday 1 September. Decision Signals, Tuesday 8 September.