DISPATCHES · Summit Cognitive

← All dispatches

RegulationAssurance NotesJuly 27, 20264 min read

The compliance date is a systems deadline

A legal obligation that begins next month cannot be met next month if the required evidence, controls, and reporting paths were never built into the deployed system.

A compliance date appears on a calendar, so organizations treat it as a legal milestone. Counsel interprets the rule. A program office drafts policies. Training is scheduled. The date arrives, the documents are approved, and the organization declares readiness. But obligations concerning evidence, monitoring, incident response, and human oversight are not created by the policy’s signature. They are capabilities the system must already possess.

The European Commission’s current guidance for general-purpose AI model providers states that relevant obligations entered into application in August 2025 and that Commission enforcement powers apply from 2 August 2026. It also identifies documents providers may need to submit through EU SEND, including notifications, reassessment requests, incident reports, and safety and security materials.

The date is close enough to expose a general truth. An institution cannot submit reliable incident information if it did not preserve it. It cannot show which model version was deployed if versions were overwritten. It cannot demonstrate monitoring if the metric began yesterday. Legal readiness is constrained by the oldest evidence the technical system can produce.

Some controls cannot be backfilled

Policies can often be written retrospectively. Operational history cannot. A provider may reconstruct parts of an evaluation from retained artifacts, but it cannot recreate unlogged tool calls, discarded model states, unknown downstream deployments, or decisions made under a policy version that no longer exists. The closer the deadline, the more tempting the reconstruction; the weaker its evidentiary value.

Monitoring requires a baseline. Incident detection requires definitions and escalation paths. Human oversight requires interfaces, authority, staffing, and time. Corrective action requires a way to identify affected systems and people. Each capability has dependencies that cross engineering, operations, legal, procurement, and support. Calling the work ‘compliance’ can obscure the product changes it actually demands.

The law may begin on a date. The evidence it requires must begin earlier.

This does not mean every regulatory expectation is technically fixed in advance. Guidance evolves, implementation details remain contested, and proportionality matters. The engineering response is not to predict every clause. It is to create adaptable primitives: versioned inventories, traceable changes, durable evaluation records, incident correlation, ownership, and exportable evidence.

Those capabilities let an organization answer new questions without pretending it anticipated them. They also reduce dependence on one compliance interpretation. A structured record can support a regulator, auditor, customer, insurer, or internal review, each with different disclosure needs, while a narrative assembled for one deadline rarely travels well.

Readiness belongs to the value chain

The Commission’s AI Act overview distributes responsibilities across providers, deployers, importers, distributors, and market-surveillance authorities. A system can therefore be ready in one organization and unready in the chain. The model provider may publish documentation that the deployer cannot connect to a local decision. The deployer may detect harm that the provider cannot correlate to a model state.

Contracts should identify the evidence each party must produce, the format and timing of exchange, and the response to material changes. Interfaces need stable identifiers for model and system versions. Procurement needs rights to receive updated documentation and incident notices. Operations needs contacts who can act, not only addresses that satisfy a clause.

Substantial modification is a particularly important boundary. Changing an intended purpose, retraining, adding autonomous tools, or altering a decision threshold may change obligations or roles. The institution needs a change-control process that asks regulatory questions before deployment, not an annual inventory that discovers the new system months later.

Readiness also includes the ability to stop. If a serious risk emerges, can the organization identify affected deployments, suspend a version, preserve evidence, notify partners, and maintain essential service through a safer alternative? A policy promising corrective action is empty when the architecture cannot isolate the component or reverse its effects.

The deadline should produce a test

Organizations should rehearse compliance as an operational exercise. Select a deployed system. Ask for its current classification, responsible parties, model and policy versions, latest evaluations, monitoring evidence, known incidents, affected downstream uses, and corrective-action path. Time the answers. Missing facts and slow handoffs reveal readiness more honestly than a completed checklist.

The Commission’s General-Purpose AI Code of Practice offers documentation forms and safety practices as one voluntary route for providers to demonstrate compliance. Whether an organization signs the code or uses another adequate means, the proof must still arise from actual practice. A blank form is guidance; a populated form with reproducible evidence is a capability.

Boards should ask what cannot be made true by the deadline. Which systems lack historical telemetry? Which vendor terms do not provide necessary evidence? Which high-consequence workflows lack staffed oversight? Which incident fields cannot be populated? These are not reasons to manufacture certainty. They are reasons to reduce scope, add controls, or delay use until the institution can carry the obligation.

Evidence retention must also be settled before volume rises. Keeping everything creates privacy, security, and cost risks; deleting too early destroys accountability. A readiness program should define what each obligation requires, who may access the retained material, how disclosures are redacted, and which event suspends ordinary deletion. Retention is part of the control, not an archive setting.

A regulatory date can focus attention, but the objective is not a moment of ceremonial compliance. It is the ability to remain compliant as models, uses, guidance, and evidence change. Build the inventory, reporting path, change control, and proof before the calendar requires them. When enforcement begins, the institution should be operating the answer, not drafting it.

— Dispatches · Summit Cognitive

Continue from here

Turn the argument into a practice.

Get new dispatches, assess how your organization handles consequential decisions, or explore Summit Cognitive.