Field notes Governance

The grace period is over.

July 2026  ·  7 min read

Three things happened this month that closed the door on "we'll deal with the EU AI Act later."

From 2 August 2026, the European Commission can issue fines for general-purpose AI violations that reach back to August 2025. The 2026 EU AI Act Readiness Report from Vision Compliance puts the share of organisations that have taken no meaningful compliance steps at 78%, with the enforcement date now weeks away. And two frontier models, Anthropic’s Fable 5 and Mythos 5, were pulled offline for eighteen days by a US Commerce Department export-control order — a reminder that the model underneath your workflow is not a fixed asset you own.

None of these is a labelling problem. They are the same problem, seen three ways: governance you cannot produce on demand is governance you do not have. We have written about the shape of that discipline before — in Vibes don't comply and Your AI governance architecture is your Art.50 strategy. This piece is about what changes now that the calendar has run out.

"But didn't the deadline just move?"

It is the first thing a well-briefed reader will say, and it is half right. In November 2025 the Commission proposed the Digital Omnibus; by mid-2026 it was agreed and heading for the Official Journal. It defers the high-risk obligations — the Annex III regime, CE marking, the conformity machinery — from August 2026 to December 2027. If your exposure is a high-risk system, you have genuinely been handed sixteen months.

Here is the half that gets lost. The Omnibus does not touch the general-purpose AI regime. The GPAI obligations have applied since August 2025, and the GPAI enforcement and penalty powers still switch on, as scheduled, on 2 August 2026. Article 50 transparency lands on the same date. The deferral moved the part of the Act that fewest organisations are directly on the hook for, and left standing the part that catches nearly every deployer. "The deadline moved" is the sentence that will get people caught — because the deadline that applies to them didn't.

The Omnibus is not relief. It is a narrowing. What remains due on 2 August is the part most organisations were relying on it to excuse.

"Retroactive" is the word that matters

Most coverage treats 2 August as a starting gun — the day the obligations switch on. Read the enforcement provisions and a harder fact emerges: the general-purpose AI obligations have applied since August 2025. What arrives in August 2026 is not the duty. It is the Commission's power to penalise the duty, backdated across the year you have already lived through.

That inverts the usual deadline psychology. You cannot sprint the last three weeks and be ready, because readiness is being assessed against a record that already exists or already doesn't. The logs were kept or they weren't. The risk process ran or it didn't. Improvising under deadline produces a policy document dated last week, which is precisely the artefact an auditor reads as an admission.

The deadline was never the test. The record was — and the record is written continuously, not the week before.

78% is not a readiness problem. It's an orientation problem.

It is tempting to read the 78% figure as procrastination. It isn't. Most of those organisations have been busy — shipping AI features, wiring models into workflows, reporting hours saved. They optimised the fast part of the loop and starved the slow part. This is the failure mode we called vibes-driven AI: a fast loop with stale orientation. It feels decisive right up until someone with authority asks a question you cannot answer from a system of record.

The teams that are ready did not move slower. They moved with a closed loop — observe, orient, decide, act — where every phase leaves evidence. The gap between the ready 22% and the unready 78% is not effort or budget. It is whether orientation was treated as work or treated as overhead.

The model you rely on can vanish by government order

The export-control episode is the one most organisations will wave away as somebody else's problem. It is the most instructive of the three. A model that thousands of workflows depended on was unavailable for the better part of a month, not because of an outage, but because of a policy decision made by a government, over the heads of everyone downstream.

If your answer to "which model is in this workflow, what version, and what happens the day it is pulled" is a shrug, you do not have a resilient system. You have a dependency you have not written down. Provenance — knowing exactly what is running, where, and under whose control — is not a compliance nicety bolted on for Article 50. It is operational continuity. When the model layer moves, and it now moves for regulatory and geopolitical reasons as well as commercial ones, the organisations that can answer the provenance question keep working. The rest wait.

What "ready" actually means now

Ready is not a binder. It is four properties of the systems people actually use, and each one maps to an article of the Act rather than a slide:

You know what model is running. Version, provider, region, and the fallback if it disappears — queryable, not remembered. This is provenance, and it is the difference between a three-week outage and a three-hour one.

Decisions live in a system of record. Not a chat thread. What was proposed, who decided, on what evidence — the Article 12 logging obligation, met because the tools enforce it, not because someone remembered to write it down.

Every change is reversible. A documented rollback before commit. The Act assumes you can intervene when a system misbehaves; you cannot intervene in something you cannot reverse.

Nothing ships that cannot be monitored. If a change cannot be observed in production, it does not exist for the purposes of the record — and it does not exist for the purposes of the auditor either. This is Article 72, post-market monitoring, expressed as an engineering default.

These are not AI-safety practices in the abstract sense. They are operating practices. An organisation that runs them is not scrambling in the last three weeks, because it has been ready every week. That is the whole point of a closed loop: readiness stops being an event and becomes a property.

What this piece doesn't claim

A closed loop is not legal advice on the Act, and it is not a guarantee of compliance — that depends on your specific systems, your risk classification, and counsel who has read your architecture. What we are claiming is narrower. If your organisation already runs a governed loop — provenance you can query, decisions in a system of record, reversibility before commit, nothing shipped that cannot be monitored — then 2 August is not a cliff. It is a Tuesday. You were already keeping the record the Commission is about to ask for.

If any of this raises questions — about how the general-purpose obligations reach a workflow you are running, about what "provenance" has to mean in practice, or about closing a loop that is currently open — that is the conversation we are built for.

The deadline was never the test. The loop was.

All field notes

  • OpenAI
  • Anthropic
  • Google Gemini
  • Meta
  • Mistral AI
  • xAI
  • DeepSeek
  • Cohere
  • Qwen
  • Ollama
  • Hugging Face
  • NVIDIA

the model layer we work across · routing, evaluation and fallback Marks are the property of their owners, shown to describe our own stack. No endorsement, sponsorship or partnership implied.

Tell us what you are accountable for.

The useful first conversation is usually about the thing that worries you, not about our capabilities. If it turns out we are the wrong firm for it, we will say so.

One reply from a person who has read what you sent.