WIRE 10.09.2026Commission opens formal AI Act proceedings against two model providersECB digital euro pilot names first Belgian banksAgeas, AXA, Allianz sign joint letter on cloud exit clausesBelgium's NIS2 transposition enters force 18 October
All wire
Hosaka Seven

Tech, policy and power. For the people who have to sign off on it.

Policy

The AI Act's high-risk rules applied in August. The duties that bite fall on the buyer, not the builder.

A bank that licenses a credit-scoring model is a deployer under Article 26, and a deployer owes oversight, retained logs and a notice to the people it turns down. Article 27 assumes an assessment document that nobody has produced a template for.

A sealed crate passed across a counter, casting no shadow on the seller’s side and a shadow far larger than itself on the buyer’s.

Draft, not yet edited. Written by Marine Lefebvre, and not yet through the desk: nothing here has been checked against the sources listed at the foot of the page. Do not act on it.

The obligations attaching to the high-risk systems listed in Annex III of the AI Act applied from 2 August 2026. Five weeks have passed. Nearly all the preparation went into whether a given model is high risk, and almost none into what a firm owes once it accepts that one is.

What changed on that date is that using somebody else's model became a regulated act in its own right.

It lands badly, because the market spent two years organising itself around the provider. Providers carry the conformity assessment, the technical documentation, the CE marking. A bank that licenses a credit-scoring model from a vendor owes none of those. It owes a different set, in Article 26, which is shorter, cheaper and considerably harder to evidence after the fact.

The classification argument was the easy half

Article 6 routes a system into the regime either through Annex I, where the AI is a safety component of a product already regulated, or through Annex III, which is a list. Annex III places creditworthiness assessment and the risk pricing of life and health insurance inside it.Recruitment and worker management sit in the same annex, which is how a firm with no lending book at all ends up in this conversation through its HR platform. For a retail bank or an insurer, those are not edge cases. They are the P&L.

Article 6 also carries a derogation, and this is where a good deal of hopeful budgeting has gone. A provider may treat an Annex III system as not high risk where it performs only a narrow procedural task, improves the result of a human activity already completed, detects patterns without replacing human judgement, or is merely preparatory. Four routes out. The same article then shuts all four: the derogation is never available where the system profiles natural persons.

Credit scoring profiles natural persons. So does insurance risk pricing. The escape hatch is shut for precisely the two uses that put regulated firms in the annex to begin with, and it was shut in 2024, in the paragraph immediately after the one everyone quotes.

Four ways out of the high-risk classification, and the sentence that follows them removes all four for anyone scoring a person.

A provider who does use the derogation must still document the assessment and register the system in the EU database first. Opting out of the regime does not mean opting out of being visible in it.

Three deployer duties, and there are more than three

Article 26 has several parts. Three of them will consume the budget.

The first is human oversight. The deployer assigns it to natural persons who have the competence, the training and — the operative words — the authority to act on what they see. A named person who can stop the model. Not a committee, not a policy, not a quarterly review pack.

The second is logs. Where the deployer controls the logs a high-risk system generates, it keeps them, for a floor the Act measures in months rather than weeks.We have not printed the figure. Read it off the article before anyone writes a retention rule against it. This is the duty most likely to be quietly unmet, because retention was set years ago by someone in infrastructure on cost grounds.

The third is telling people. A deployer using a high-risk system to make or assist a decision about a natural person informs that person it did so. And before putting such a system into service in the workplace, it informs workers' representatives and the affected workers. That second one is a works council conversation, and works councils run to their own timetable, which is not the deployer's.

The same article carries more — on input data the deployer controls, on following the provider's instructions for use, on notifying the provider and the authority when a system presents a risk. Read them. They are not what this piece is about.

Article 27 assumes a document nobody has written

Article 27 requires a fundamental rights impact assessment before first use, from public bodies and from private deployers doing creditworthiness assessment and life and health insurance pricing. It is not the GDPR data protection impact assessment. The Act says it complements that assessment rather than replacing it, which means a firm that has done the DPIA has done part of the work and has not finished.

The Act provides for the AI Office to make a questionnaire available. Whether it exists in a form a second-line function can use, we could not establish. The duty applies either way. A firm in scope that has not done the assessment is in breach now, and the remedy is not a project — it is a document, written by people who will have to defend its reasoning.

What is not in the text

The Act does not say who inside the firm owns any of this. No named function, no management body sign-off, no equivalent of the DORA provision that puts the ICT risk framework on the board and leaves it there. The oversight duty attaches to the deployer as a legal person and then stops. It therefore lands wherever the organisation chart last left an ambiguity, which is usually between the model risk function and whoever bought the software.

Nor does it define, with any precision anyone would rely on, the change that pulls a legacy system out of grandfathering and into full compliance. Systems already on the market before the application date get transitional relief until they are significantly modified. What counts as significant is the sort of question a supervisor answers, not a text.

The presumption of conformity route, meanwhile, depends on harmonised standards. How much of that set has been delivered we would want confirmed before asserting. What can be said is that no firm we know of has been able to plan against a complete one.

One caveat on the date, stated plainly

A Commission proposal to defer parts of the high-risk timetable has been live for some time. We could not establish from this desk what became of it, and this piece describes the regulation as adopted in July 2024 rather than as it may since have been amended. If the deferral passed, the deadline moved. The duties did not.

The first supervisory question in this area will not be about a model. It will be a request for the name of the person exercising oversight, and their training record, and the date they were given the authority to switch the thing off.

Primary The document itself. Claims in this piece rest only on these.

  1. Regulation (EU) 2024/1689 (Artificial Intelligence Act)Official Journal of the European Union2024-07-12The instrument this piece rests on. Articles 6, 26 and 27 and Annex III are named because the argument needs locations; the sub-paragraph numbering inside 26 and 27, and the Annex III point numbers for creditworthiness and insurance pricing, are described rather than printed. An editor should read them off the consolidated text before this runs.
  2. Placeholder: the application date for Annex III high-risk obligations2 August 2026 is the date the whole piece hangs on. It is widely stated and we believe it correct. Verify against the final provisions before publication; if it has moved, the lead moves with it.
  3. Placeholder: the log retention floor in the deployer obligationsWe describe the retention period as a floor measured in months rather than printing a figure, because we are not confident enough of the number to put it in front of this audience. Replace the hedge with the figure once the article is open.
  4. Placeholder: status of the Commission's digital omnibus proposal as it affects the high-risk timetableWe could not establish from this desk whether the proposal to defer parts of the high-risk regime has been adopted, amended or abandoned. The piece says so in the body and describes the text as adopted in 2024. This is the single largest verification risk in the article.
  5. Placeholder: whether the AI Office has published the fundamental rights assessment questionnaireThe Act provides for a template. Whether it exists in usable form on the date of publication, we could not confirm. The sentence is written so that it survives either answer, but check it.
  6. Placeholder: harmonised standards delivered by CEN-CENELEC for the high-risk requirementsThe claim that the standards underpinning the presumption of conformity are incomplete is stated cautiously for that reason. Confirm the current list before this line runs.

Reporting Attributed, not relied on. Where the reporting is the fact, it says so.

  1. Placeholder: Brussels reporting on the August application date and supervisory readinessPolitico EuropeWould be attributed if used. No claim in this piece rests on it.

Lead Pointed us at the story. Nothing here is cited as authority.

  1. Placeholder: law firm and vendor readiness alerts on deployer obligationsPointed us at how little of the published material addresses deployers rather than providers. Not cited, not relied on.

Marine Lefebvre

Policy correspondent

Marine is one of Hosaka Seven's AI correspondents: a model with a defined beat and a defined voice, not a person. Drafts are edited and verified by Ussama Dahnin, who is accountable for what is published.