Perimattic

Compliance · EU AI Act

AI observability for EU AI Act compliance

The 2026 Digital Omnibus moved the high-risk deadlines to December 2027 and August 2028, while transparency duties still apply from August 2026. Here are the dates that matter and the records each obligation expects you to keep.

Last reviewed by the Perimattic AI Suite team

In short

What does the EU AI Act require you to monitor?

For high-risk AI systems, the Act requires automatic logging of events (Article 12), log retention by providers and deployers (Articles 19 and 26), human oversight (Article 14), a post-market monitoring system (Article 72) and reporting of serious incidents (Article 73). After the 2026 Omnibus, these apply from 2 December 2027 for Annex III systems and 2 August 2028 for Annex I products. Observability supplies the logs, metrics and incident records those duties rely on.

  • Transparency did not move

    Article 50 duties, such as telling people they are talking to an AI system, apply from 2 August 2026. Providers of systems already on the market before then have until 2 December 2026 for the Article 50(2) content-marking requirement.

  • The extra time is for building, not waiting

    Logging, monitoring and incident processes take months to design and test. Teams that start now can run them for a full cycle before the high-risk deadlines.

Hand signing a printed document with a pen

Regulation overview

What the EU AI Act requires

A risk-based law for AI systems placed on the EU market or whose output is used in the EU. Prohibited practices are banned outright. High-risk systems carry the heaviest duties: risk management, data governance, technical documentation, logging, human oversight, accuracy and robustness, and post-market monitoring. Limited-risk systems carry transparency duties, and general-purpose AI model providers have their own obligations.

Authority
European Commission (AI Office) and national market surveillance authorities in each EU member state
Legal basis
Regulation (EU) 2024/1689, as amended by the Digital Omnibus on AI, Regulation (EU) 2026/1744
Penalties
Up to €35M or 7% of worldwide annual turnover for prohibited practices; up to €15M or 3% for most other obligations; up to €7.5M or 1% for supplying incorrect information (Article 99). General-purpose AI model providers face up to €15M or 3% (Article 101).

Key dates

  1. 1 Aug 2024Applies now

    The AI Act enters into force.

  2. 2 Feb 2025Applies now

    Prohibited practices banned; AI literacy duty begins (softened by the Omnibus to supporting staff literacy).

  3. 2 Aug 2025Applies now

    Obligations for providers of general-purpose AI models apply; governance and most penalty provisions start.

  4. 27 Jul 2026Applies now

    Digital Omnibus on AI (Regulation (EU) 2026/1744) enters into force.

  5. 2 Aug 2026Applies now

    Article 50 transparency obligations apply. Fines for general-purpose AI model providers can be imposed.

  6. 2 Dec 2026Upcoming

    End of the grace period for Article 50(2) content marking on systems placed on the market before 2 August 2026.

  7. 2 Aug 2027Upcoming

    General-purpose AI models placed on the market before 2 August 2025 must comply; member state AI sandboxes due.

  8. 2 Dec 2027Upcoming

    High-risk obligations apply to stand-alone systems listed in Annex III (for example credit scoring, hiring, education).

  9. 2 Aug 2028Upcoming

    High-risk obligations apply to AI built into products covered by Annex I legislation (for example medical devices, machinery).

Sources: Gibson Dunn, Jones Walker and Usercentrics analyses of the Digital Omnibus, checked 1 October 2026. This is a summary for planning, not legal advice. Confirm dates for your system with counsel.

Requirement to evidence

Which records each EU AI Act duty expects

The articles below apply to high-risk systems unless noted. The middle column is the telemetry that supports each duty; the right column is the record you would hand to an assessor or authority.

Which records each EU AI Act duty expects
ObligationTelemetry that supports itEvidence you can produce
Art. 12 Record-keepingAutomatic, timestamped traces of each request, model version, inputs and outputs (redacted where needed)Event logs covering the system’s lifetime, searchable by request or period
Arts. 19 and 26(6) Log retentionRetention policy per project, applied to stored tracesProof that logs were kept for at least six months, or longer where other law requires
Art. 14 Human oversightAlerts on low-quality or out-of-policy outputs; reviewer actions recorded on the traceLog of what was flagged, who reviewed it and what they decided
Art. 72 Post-market monitoringQuality, drift and incident metrics on live traffic over timeMonitoring data feeding the post-market monitoring plan and its reviews
Art. 73 Serious incident reportingIncident detection with the affected traces, timeline and impact attachedIncident record ready for the authority within the reporting deadline (generally 15 days)
Art. 9 Risk managementOngoing risk signals: hallucination rate, injection attempts, error and fallback ratesMeasured inputs for each risk-management review cycle
Art. 50 Transparency (limited-risk)Trace attribute showing the AI disclosure was shown or content was markedSample-based proof that disclosures were made

Sample evidence

What an EU AI Act evidence record looks like

Each record ties one AI decision to the obligation it supports, with the data an assessor asks for. The structure is the same whether you export one request or a month of traffic.

Perimattic AI Suite supports your compliance programme. It is not legal advice and does not certify that a system complies with the EU AI Act.

{
  "record_type": "eu_ai_act.art12.event_log",
  "system": "credit-pre-screening",
  "risk_class": "high-risk (Annex III)",
  "request_id": "req_31c9…",
  "model": "<provider/model@version>",
  "human_oversight": { "flagged": true, "reviewer": "<role>", "decision": "override" },
  "retention_until": "2027-04-30"
}
Illustrative record with sample values, not customer data.

FAQ

Common questions

Short answers to common questions. They are general information, not legal advice.

When do the EU AI Act high-risk obligations apply?

After the Digital Omnibus, from 2 December 2027 for stand-alone high-risk systems listed in Annex III, and from 2 August 2028 for AI built into products covered by Annex I legislation. The original dates were 2 August 2026 and 2 August 2027.

Did the Omnibus delay the transparency rules?

No. Article 50 transparency obligations still apply from 2 August 2026. The only relief is a grace period until 2 December 2026 for the Article 50(2) content-marking duty on systems placed on the market before 2 August 2026.

Is a customer service chatbot high-risk under the EU AI Act?

Usually not. A chatbot that answers questions is normally a limited-risk system with Article 50 transparency duties: people must be told they are interacting with AI. It can become high-risk if it is used for a purpose listed in Annex III, such as deciding access to credit or essential services.

How long must logs be kept under the EU AI Act?

Providers and deployers of high-risk systems must keep automatically generated logs for a period appropriate to the system’s purpose, and for at least six months, unless other EU or national law sets a different period (Articles 19 and 26(6)).

What fines apply to general-purpose AI model providers?

Up to €15 million or 3% of worldwide annual turnover, whichever is higher, under Article 101. The Commission can impose these fines from 2 August 2026.

Does Perimattic AI Suite make a system EU AI Act compliant?

No tool can do that on its own. Compliance depends on your risk management, documentation, data governance and organisational processes. Perimattic AI Suite supplies the logging, monitoring and incident records those processes need. The compliance hub shows how it supports the other frameworks too.