← All field notes
EU AI Act · 8 minute read

By Securelay Research

The EU AI Act is now an operating question.

The EU AI Act became broadly applicable on 2 August 2026. That does not make every AI system high-risk, and it does not put every obligation on the same date. It does mean that governance teams need a current classification and an operating record tied to real systems—not a slide deck frozen in 2024.

EU AI Act timeline and the operating records needed across an AI workflow.
Original Securelay editorial diagram based on the European Commission’s official AI Act application timeline, updated 3 August 2026.
Primary source European Commission AI Act — application timelinePrimary source Regulation (EU) 2024/1689 — official EUR-Lex text

Read the timeline before making a claim

The Commission’s current timeline says the Act entered into force on 1 August 2024 and became broadly applicable on 2 August 2026. Prohibited practices and AI-literacy duties began earlier, and general-purpose AI obligations applied from August 2025. Following the 2026 AI Omnibus, specific high-risk transition dates extend into December 2027 and August 2028. Teams should classify the system, their role, and the relevant date before describing readiness.

Turn classification into an operating record

For each AI system, record the intended purpose, provider and deployer roles, affected people, data sources, model or service version, human-oversight point, logging path, incident owner, and the evidence retained. Connect this record to change management: a new data source, model, tool permission, or deployment context can change the assessment.

Put controls where data and decisions move

Policy documents cannot stop a prompt, retrieval result, or tool response from carrying unnecessary personal data. On connected routes, Securelay can transform configured sensitive values before a configured model provider receives them, evaluate permitted rehydration, and preserve value-free evidence of the decision. These controls can support a wider governance program; they do not classify an AI system or perform a conformity assessment.

Ask one testable question

Choose one consequential AI workflow and ask: can the team reconstruct what data entered it, under what purpose and authority, which provider received it, what human oversight applied, and what evidence remains? Any answer that depends on memory or a spreadsheet should become an engineering backlog item.

Put the control on the data path.Discuss an architecture review