Everything published, newest first.
Every analysis, guide and reference from the desk, dated. Pieces are revised in place when the underlying text changes, and the revision is noted on the page. Older pieces written before the Digital Omnibus carry a note saying what moved.
- EU AI Act Article 49: registration in the EU database, and the one entry a deployer makesArticle 49 holds four different registrations. Three belong to the provider. Only one belongs to a deployer, and most private companies do not have it.
- AI already on the market on 9 December 2026: which product liability regime applies?Directive 2024/2853 applies to products placed on the market after 9 December 2026. For AI software that keeps changing, the date each version counts from.
- The first European supervisory answer on frontier AI came through DORAEurope's three financial supervisors put frontier AI risk on the operational resilience rail rather than the AI Act rail. What the statement asks for.
- For most high-risk AI, the Act asks the provider to assess itselfArticle 43 sends Annex III points 2 to 8 to internal control under Annex VI, a procedure which does not provide for the involvement of a notified body.
- The Article 50 instruments are finished. The high-risk ones are not.Read at source on 28 August 2026: the Article 50 code and guidelines are final, while the high-risk classification and incident guidance are still drafts.
- The Commission's own article pages are not the amended AI Act textThe Commission's AI Act Service Desk serves pre-Omnibus article text under a notice most readers miss. What to trust, page by page, and the traps it creates.
- Sixteen extra months. What a deployer should actually do with them.The Omnibus moved Annex III to 2 December 2027. Standing the programme down costs more than it saves, because the strongest evidence can only be built forward.
- 2 December 2026: the EU AI Act deadlines the Omnibus did not move.The Omnibus moved the high-risk deadlines to 2027 and 2028. Three obligations still land in the first nine days of December 2026. What they are and who they reach.
- The Digital Omnibus is now in force. What actually changed for AI deployers.The Digital Omnibus on AI entered into force 27 July 2026. Annex III moves to December 2027. Here is exactly what changed for deployers and what did not.
- South Korea AI regulation 2026: an operators guide.South Korea's AI Basic Act took effect 22 January 2026. This guide explains high-impact AI obligations, MSIT enforcement, penalty levels, and the comparison to the EU AI Act.
- India AI regulation 2026: complete operators guide.India AI regulation 2026 for operators: the DPDPA, IT Rules, MeitY advisories, the IndiaAI Mission, RBI FREE-AI work, and how India compares to the EU AI Act.
- Switzerland AI regulation 2026: an operators guide.Switzerland AI regulation 2026: no horizontal AI Act, revFADP Article 21, FINMA guidance, Council of Europe accession, and the comparison to the EU AI Act.
- EU AI Act Article 26: the final three-week deployer checklist before August 2, 2026.The July 2026 three week countdown to the EU AI Act high-risk deadline, kept as a record. Superseded: the Digital Omnibus entered into force 27 July 2026 and Annex III now applies from 2 December 2027.
- AI regulation penalties by jurisdiction: a 2026 comparison tracker.A living comparison of maximum AI regulatory penalties across the EU, US, UK, China, Korea, Japan, Brazil, Canada, and Singapore, updated as rules change.
- Australia AI regulation 2026: operators guide.Australia AI regulation 2026 for operators: the Voluntary AI Safety Standard, proposed mandatory guardrails, Privacy Act reform, ASIC and APRA guidance for AI.
- EU AI Act Article 3: key definitions for providers and deployers.EU AI Act Article 3 definitions explained: provider, deployer, operator, GPAI model, systemic risk. Which category you fall into determines every obligation you carry.
- Does my professional liability or E&O policy exclude AI mistakes?Most professional indemnity, E&O, and cyber policies do not clearly cover AI mistakes, and exclusions are being added at 2026 renewals. What to check in your policy, plus the affirmative AI coverage trend (Counterpart, Coalition).
- EU AI Act Article 25. When a deployer or distributor becomes the provider.Article 25 of Regulation (EU) 2024/1689 explains when a deployer or distributor becomes a provider. Covers substantial modification, rebranding, contractual duties, and liability allocation across the AI value chain.
- EU AI Act Article 4. AI literacy obligations that have been in force since February 2025 and apply to every deployer.Article 4 of Regulation (EU) 2024/1689 requires deployers to ensure AI literacy for all staff using AI. Already in force since February 2025. A complete guide to what the obligation requires.
- EU AI Act Article 99. Penalties, fine tiers, and what deployers actually face.Article 99 of Regulation (EU) 2024/1689 explained for deployers: three fine tiers, how amounts are set, SME proportionality under Art 99(6), and the link to Art 101 GPAI fines.
- The EU AI Act for deployers. A complete operator orientation.The complete operator guide to EU AI Act deployer obligations. Art 4 literacy, Art 5 prohibitions, Art 6 classification, Art 9-15 high-risk requirements, Art 26 duties, Art 27 FRIA, Art 50 transparency, enforcement and penalties.
- Who is liable when an AI agent makes a mistake?When an AI agent makes a mistake, liability falls on the business that deployed it, not the model provider. The EU liability chain under the AI Act and the revised Product Liability Directive, real cases, and the evidence that reduces exposure.
- EU AI Act Article 86: the right to explanation of individual decision-making, a deployer guideArticle 86 of the EU AI Act gives affected persons a right to obtain explanations of decisions made on the basis of high-risk AI. What deployers must explain, when the right applies, and how it relates to GDPR Article 22.
- South Africa AI regulation 2026: operators guide.How South African AI rules sit alongside EU AI Act deployer duties. POPIA enforcement, the National AI Policy Framework, and SARB guidance read from a European operator perspective.
- EU AI Act Article 72: post-market monitoring obligations for high-risk AI deployersArticle 72 of the EU AI Act requires post-market monitoring systems for high-risk AI. What deployers must implement, what providers must maintain, and how the two obligations interact.
- EU AI Act national supervisors in 2026. BaFin, AFM, ACPR and what each one is actually building.How Germany's BaFin, the Netherlands' AFM and DNB, and France's ACPR are building EU AI Act enforcement capacity in 2026. Practical obligations for financial services deployers across the EU.
- Serious incident reporting under Article 73. What deployers must do.What EU AI Act Article 73 requires of deployers when a high-risk AI system causes a serious incident. Who reports, to which authority, within what timeframe, and what documentation is required.
- EU AI Act Article 15. Accuracy, robustness and cybersecurity requirements for high-risk AI.Article 15 of Regulation (EU) 2024/1689 requires high-risk AI systems to meet accuracy, robustness, and cybersecurity standards. A deployer-focused reading of every obligation.
- EU AI Act Article 43. The conformity assessment procedures that govern whether a high-risk AI system can legally reach the market.Article 43 of Regulation (EU) 2024/1689 governs conformity assessment for high-risk AI. This guide explains both tracks, notified body requirements, and deployer verification duties.
- EU AI Act Article 6. The classification decision that determines whether high-risk obligations apply.Article 6 of Regulation (EU) 2024/1689 determines which AI systems are high-risk. This guide explains both classification tracks and the Article 6(3) exception.
- EU AI Act Article 11. The technical documentation obligation that underpins every high-risk AI deployment.What Article 11 of Regulation (EU) 2024/1689 requires, what Annex IV specifies, and what deployers should expect from providers before Annex III applies on 2 December 2027.
- EU AI Act Annex III. The eight categories that determine whether your AI deployment is high-risk.Annex III of Regulation (EU) 2024/1689 lists eight high-risk AI categories across critical sectors. This guide maps each category to specific use cases and to the obligations that apply from 2 December 2027.
- EU AI Act Article 16. Ten obligations providers must meet before a high-risk AI system reaches any deployer.Article 16 of Regulation (EU) 2024/1689 sets out ten obligations for providers of high-risk AI systems. This guide explains each obligation and what deployers must verify before putting a high-risk system into service.
- EU AI Act Article 12. The logging requirement that underpins every compliance defence and every insurance claim.Article 12 of Regulation (EU) 2024/1689 mandates automatic logging for high-risk AI. This guide explains what deployers must retain, for how long, and why the log record is also insurance evidence.
- The EU AI Act's eight prohibited practices: what operators need to know.Article 5 of EU Regulation 2024/1689 lists eight prohibited AI practices that have been in force since February 2025. A deployer's guide to each prohibition and its scope.
- EU AI Act Article 10: What Deployers Must Understand About Data Governance for High-Risk AIArticle 10 of Regulation (EU) 2024/1689 sets binding data governance standards for high-risk AI. What deployers must understand and document before Annex III applies on 2 December 2027.
- EU AI Act Chapter V. What deployers building on GPAI models actually face.How the EU AI Act's general-purpose AI model provisions in Articles 51 to 56 affect deployers who build products on foundation models, and when a deployer becomes a GPAI provider.
- EU AI Act Article 17. Technical documentation and what deployers must demand from providers.Article 17 of Regulation (EU) 2024/1689 compels providers to produce technical documentation before deployment. This guide explains what deployers must require and how to evaluate adequacy.
- EU AI Act Article 26. Every deployer obligation, read in sequence.A complete reading of Article 26 of Regulation (EU) 2024/1689. Every deployer duty, from instructions compliance to FRIA to incident notification, mapped to practical action. Annex III now applies from 2 December 2027.
- EU AI Act Article 9. The risk management system that every high-risk AI deployment depends on.Article 9 of Regulation (EU) 2024/1689 requires a risk management system for all high-risk AI. What deployers must understand, verify and document before Annex III applies on 2 December 2027.
- The Digital Omnibus on AI explained. The April 2026 record, superseded.The April 2026 provision-by-provision reference on the proposed AI Act deferral, kept as a record. The Omnibus is now law: in force 27 July 2026, Annex III from 2 December 2027, Annex I from 2 August 2028.
- EU AI Act Article 50. The transparency and labelling obligations every deployer must implement by 2 August 2026.Article 50 of Regulation (EU) 2024/1689 sets four distinct disclosure duties. This guide reads each in sequence. Article 50 has applied since 2 August 2026.
- EU AI Act Member State Implementation Tracker. Where each of the 27 stands.Which national authority supervises the EU AI Act in each of the 27 Member States, re-verified at national sources on 17 August 2026. Annex III now applies from 2 December 2027.
- 100 days to August 2. The EU AI Act operator checklist for deployers who are not ready.Written in April 2026, when 2 August 2026 was the operator deadline, and kept as a record. Annex III now applies from 2 December 2027.
- AI policy exclusions in 2026. What your existing coverage actually excludes.How AI policy exclusions work in 2026: carrier endorsements, the silent and affirmative distinction, and the renewal questions to ask.
- The Double Exposure. EU AI Act and the Revised Product Liability Directive in 2026.The EU AI Act and the revised Product Liability Directive create a double exposure for AI deployers in 2026. The dates, the rebuttable presumption, the operator file.
- The 90-day FRIA countdown. A deployer checklist for EU AI Act Article 27.A deployer checklist, template structure and supervisor notification guide for Article 27, written for the original 2 August 2026 date. The FRIA now falls due with Annex III on 2 December 2027.
- EU AI Act Article 27. The Fundamental Rights Impact Assessment every deployer must file.A 2026 guide to the Fundamental Rights Impact Assessment under Article 27 of the EU AI Act. Who must file, what it contains, and how to maintain it.
- EU AI Act Article 14. The human oversight design requirement explained.What Article 14 of the EU AI Act requires deployers to build, staff and document for high-risk AI systems. Annex III now applies from 2 December 2027.
- EU AI Act enforcement. Who is watching and what they can do to you.How the EU AI Act enforcement architecture works: the AI Office, national market surveillance authorities, and the penalty tiers that have applied since 2 August 2026.
- EIOPA's AI governance opinion and what it means for EU AI Act alignment.EIOPA's Opinion on AI governance and risk management of 6 August 2025, mapped to EU AI Act obligations under Articles 9, 14, 17 and 26 of Regulation (EU) 2024/1689.
- EU AI Act Article 13. Transparency requirements for high-risk AI providers and deployers.Article 13 of Regulation (EU) 2024/1689 requires high-risk AI systems to be transparent. This guide sets out what providers must supply and what deployers must pass on.
- AI liability chains. How EU law splits responsibility between provider and deployer.When an AI agent causes harm, who is liable: the model provider, the integrator, or the deployer? A structured reading of EU law's multi-party liability framework.
- The revised Product Liability Directive and AI software exposure.Directive 2024/2853 makes AI software a product subject to strict liability. A European operator's guide to the exposure that lands in December 2026.
- EU AI Act operator obligations. A 2026 compliance guide.A practical 2026 guide to the EU AI Act operator obligations: Article 26 duties, human oversight, logging, incident reporting, and the deadlines every deployer must meet.
- The operator provisions of Regulation 2024/1689, read in plain sequence.A walk through Article 26 and its neighbours in the order a deployer meets them, revised for the Digital Omnibus.
- When AI agents make mistakes. Who is liable under EU law.A clear reading of AI agent liability under the Revised Product Liability Directive, the EU AI Act, and national case law beginning to shape deployer responsibility.
- Three gaps between today's AI stack and tomorrow's underwriting requirements.Verification, governance, standards: the three artefacts that make autonomous agent risk readable to an underwriter.
- How to document AI agent risk management for compliance.A practical nine-document framework for AI agent risk management documentation under the EU AI Act: Article 9, Article 12, Article 26, and ISO 42001 in one file.
Every entry is dated. Every claim has a source.
The archive is kept as a working record. Entries are revised in place rather than republished, each revision is stamped with a date, and material corrections are logged on the corrections page. Readers who need an earlier wording can write to the editors.