Signal & Seam
Analysis

The regulator is in the assurance chain

An AI procurement contract diagram with a small gavel icon attached to the buyer (deployer) end, signalling that the regulator-facing party in the chain is the user, not the model vendor

The EU AI Act's third wave went live on 2 August 2026. The AI Office can now fine general-purpose AI providers up to 3% of worldwide annual turnover, and Article 50's four transparency obligations split 2:2 across the provider and the deployer. Most enterprises are deployers, not providers. That is the part nobody is pricing in.

The last two posts walked two nodes of the AI assurance chain. The evaluator sits between the lab and the deployer, and when the evaluator's environment is misconfigured the breach lands on the deployer. The insurance carrier sits one step further down, and the CGL endorsement has already been rewritten so the deployer is the residual risk-bearer.

This post is about the third node. The regulator.

The EU AI Act's third wave went live on 2 August 2026. The AI Office, acting on behalf of the European Commission, acquired its full investigatory and fining powers for general-purpose AI providers on that date. Article 50's four transparency obligations became directly applicable the same day. And the Commission opened three new complaints routes — including a channel that lets any company integrating a foundation model report the upstream provider's non-compliance directly to Brussels.

The mechanism most enterprises have underweighted is the provider/deployer liability split inside Article 50. The chatbot disclosure and the machine-readable marking of synthetic content travel with the provider. The emotion recognition notice and the deepfake / public-interest text labelling stay with the deployer — and most enterprises are deployers, not providers. When you combine that split with the AI Office's new fining power and the downstream complaint channel, the practical effect is that the deployer now sits at the regulator-facing end of the assurance chain. Even when the deployer is buying rather than building.

That is the story.

What activated on 2 August 2026

The European AI Act, Regulation (EU) 2024/1689, has been applying in waves since 2 February 2025. The first wave covered prohibited practices and AI literacy. The second wave, on 2 August 2025, covered general-purpose AI model obligations and the governance framework. The third wave was supposed to land on 2 August 2026 and bring the high-risk regime with it.

That last part did not happen. The Digital Omnibus on AI, Regulation (EU) 2026/1744, was signed on 8 July 2026 and entered into force on 27 July 2026, and it deferred the standalone high-risk obligations to 2 December 2027 and the embedded high-risk obligations to 2 August 2028.

The transparency and supervisory pieces, however, were not deferred. They applied on 2 August 2026 as scheduled.

Two things switched on at once.

The first was the Article 50 transparency regime. The four obligations — chatbot and AI-interaction disclosure, machine-readable marking of synthetic content, emotion recognition and biometric categorisation notice, and deepfake and public-interest text labelling — became directly applicable to providers and deployers across the EU. A limited 2 December 2026 transition applies only to Article 50(2) machine-readable marking for generative AI systems placed on the market before 2 August 2026.

The second was the AI Office's full investigatory and fining powers. The Office can now request documentation, conduct independent model evaluations, require mitigations, restrict or withdraw models from the EU market, and impose administrative fines of up to €15 million or 3% of worldwide annual turnover, whichever is higher, under Article 101. The 7% / €35 million figure applies to prohibited practices under Article 5, not to Article 50. That distinction matters because the prohibited-practice fine is the one executives tend to remember; the transparency fine is the one they tend to underweight.

The Commission also opened three complaints routes on the same day. A general AI Act complaints tool, an AI Act Whistleblower Tool, and a dedicated complaints channel for downstream providers using general-purpose AI models. The third route is the one that changes the procurement relationship. It is not a generic complaint line. It is a channel built specifically for companies that integrate a foundation model and want to report the upstream provider's non-compliance. The complaint is filed with the AI Office, not with a national authority, and the procedural status is closer to a regulatory action than to a customer grievance.

The provider/deployer split that nobody is pricing in

Article 50 is the broadest-reaching provision in the entire Regulation. It is risk-independent. It does not ask whether your system is high-risk. It asks what your system does.

The Commission's 20 July 2026 Guidelines on Article 50 — a 50-page implementing document adopted as C(2026) 5054 final — confirm the allocation. Articles 50(1) and 50(2) bind providers. Articles 50(3) and 50(4) bind deployers.

The split is precise.

That second and third obligations are easily conflated and are not the same. The second is a provider duty to build technical marking and detection into AI-generated content. The fourth is a deployer duty to disclose certain AI-generated or AI-manipulated content to the audience viewing it. The two obligations serve independent purposes and have independent enforcement risk.

Most enterprises are deployers. A bank that deploys a customer-service chatbot to interact with retail customers is a deployer under 50(1) in the sense of being the one whose customers see the interaction, but the provider of the underlying model owes the 50(1) chatbot disclosure. A bank that runs its own internal-employee emotion recognition system for call-centre quality monitoring is a deployer under 50(3) and cannot shift the disclosure duty to a vendor. A news publisher that uses a foundation model to draft articles on matters of public interest is a deployer under 50(4) and must label the content even if the model was trained and served by a third party.

The procurement implication is concrete. The chatbot disclosure and the machine-readable marking travel with the provider; the emotion recognition and deepfake disclosures stay with the deployer and no procurement clause moves them. Most enterprise compliance programmes have been written as if the whole Article were a provider problem. The Commission's 20 July Guidelines are explicit that it is not.

The downstream complaint channel is the new enforcement signal

The General-Purpose AI Code of Practice is the part of the third wave that has received the most press, and it is the part that is easiest to misread. The Code is voluntary. It is a recognised route for GPAI providers to demonstrate compliance with Articles 53 and 55 of the AI Act. As of 30 July 2026, more than 180 organisations had signed it, including the major US labs. Signatories get a presumption of conformity and a more favourable enforcement posture. Non-signatories face closer scrutiny and must demonstrate compliance through other means.

The Code matters, but it is a provider-side instrument. The enforcement signal that the third wave actually shifted is on the deployer side, and it travels through the new complaints architecture.

The Commission opened three routes on 2 August:

The third route is the one that does the structural work. It gives a deployer's safety, trust, or compliance team a regulatory escalation path that bypasses the national market surveillance authority. The complaint does not have to go through a national competent authority first. It can be filed with the AI Office directly.

The mechanism is not yet tested. There is no published case record of an AI Office action arising from a downstream complaint. But the channel is built, the procedural form is published, and the AI Office has the power under Articles 88 to 94 to act on what it receives. The first twelve months of the third wave will tell us how the channel is used in practice.

The voluntary Code, the fining power, and the procurement sequence

The GPAI Code of Practice is the part of the third wave that most enterprise executives have heard about. The fining power is the part they have not. And the procurement sequence is the part that almost no one has written about.

The sequence, in plain language:

1. Sign the GPAI Code of Practice. The Code is voluntary. The presumption of conformity is real but is not immunity. The AI Office retains investigatory powers over signatories. Treat the signature as a substantive review, not a marketing signal. 2. Map every AI system in production against the Article 50 provider/deployer split. Chatbot disclosure and machine-readable marking are the vendor's problem. Emotion recognition notice and deepfake/public-interest text labelling are the deployer's problem, and the deployer's problem stays the deployer's problem regardless of vendor contract terms. 3. Pre-stage a complaint to the AI Office for any upstream provider that misses the 2 December 2026 legacy machine-readable marking deadline. The complaint is free, has no procedural threshold beyond what the Commission's form requires, and is filed directly with the regulator. The deployment relationship has become an enforcement relationship. 4. Treat the deployer-side obligations as in-scope regardless of vendor contract terms. The exemption structure in Article 50 — the obvious-context exemption in 50(1), the human editorial review exemption in 50(4) — is interpretive, not statutory. Case law does not yet exist. The exemption is not a procurement argument. 5. Assume the high-risk obligations will arrive in 2027 and 2028. The Digital Omnibus re-sequenced them, not erased them. The next wave of compliance work is not optional; it is just deferred.

The 2 December 2026 transition is the next operating deadline that lands before the deferred high-risk regime. Generative AI systems placed on the market before 2 August 2026 must comply with the Article 50(2) machine-readable marking requirement by that date. It is also when the new prohibitions on AI-generated non-consensual intimate imagery and child sexual abuse material take effect under Article 5. The latter is a prohibited-practice fine, not a transparency fine, and the maximum exposure is 7% of worldwide annual turnover or €35 million.

The accountable decision-maker is not the CISO

The previous post argued that the CGL coverage seam is a CFO and enterprise risk officer problem, not a CISO problem. The Article 50 story makes the same point in a different register.

The AI Office's live enforcement powers are about documentation, disclosure, and labelling. They are not about security controls. The CISO owns the security attestation: isolation, access control, monitoring, incident response. The CCO and the CPO own the disclosure-and-labelling attestation. The fact that the AI Office can fine an upstream provider up to 3% of worldwide annual turnover does not change the org chart. It changes who has to read the AI Office's press releases.

The org-chart implication is concrete. If the AI Act compliance programme sits inside the security function, the team will read Article 50 as a control set and try to test the controls. If the programme sits inside the legal and procurement function, the team will read Article 50 as a contract and disclosure set and will map the provider/deployer split against the enterprise's actual procurement contracts. The latter is the read that matches the regulation. The former is the read that produces a secure chatbot that fails the AI Office's first audit because the wrong party owns the deepfake labelling disclosure.

The reason this matters operationally is that the AI Office is not going to ask a CISO whether the chatbot is secure. It is going to ask the entity that placed the system on the market or put it into service — the legal person classified as provider or deployer under the regulation — whether the disclosure, marking, notice, and labelling obligations have been met. That question is answered in the legal-and-procurement function, not the security function.

The falsifiable claim

Here is the operating claim this post is making: the third wave of the EU AI Act, applied on 2 August 2026, has made the deployer — not the provider — the regulator-facing end of the AI assurance chain for most enterprise use cases, because Article 50's obligation split (chatbot disclosure and machine-readable marking on the provider, emotion recognition notice and deepfake/public-interest text labelling on the deployer) is now combined with an operational AI Office, an Article 101 fining power of up to €15 million or 3% of worldwide annual turnover, and a dedicated downstream complaints channel that lets any company integrating a foundation model report upstream non-compliance directly to Brussels. The appropriate operating response is to map every AI system in production against the provider/deployer split, treat the deployer-side obligations as in-scope regardless of vendor contract terms, sign the GPAI Code of Practice only after a substantive review rather than as a marketing signal, and pre-stage a complaint to the AI Office for any upstream provider that fails the 2 December 2026 legacy marking deadline — not to assume that the high-risk deferral means there is no live obligation.

The evidence supporting this claim:

1. The European Commission activated the third wave of the EU AI Act on 2 August 2026 under Article 113 of Regulation (EU) 2024/1689, with the Article 50 transparency regime and the AI Office's Article 101 fining power directly applicable. The high-risk regime was re-sequenced by Regulation (EU) 2026/1744 (Digital Omnibus on AI), in force 27 July 2026, but the transparency and supervisory pieces were not deferred. 2. The Commission's 20 July 2026 Guidelines on Article 50 (C(2026) 5054 final) confirm the 2:2 provider/deployer split across the four obligations. Most enterprises are deployers on at least 50(3) (emotion recognition and biometric categorisation) and 50(4) (deepfake and public-interest text labelling), and those obligations cannot be shifted to a vendor by procurement language. 3. The Commission opened three complaints routes on 2 August, including a dedicated channel for downstream providers using general-purpose AI models. The channel lets any company integrating a foundation model report upstream non-compliance directly to the AI Office, bypassing national competent authorities. There is no published case record yet, but the procedural mechanism is built and operational. 4. The GPAI Code of Practice, the voluntary Code on Transparency of AI-Generated Content, and the 180+ signatories as of 30 July 2026 provide a presumption of conformity for signatories. Non-signatories face closer scrutiny and must demonstrate compliance through other means. The Code is a substantive instrument, not a marketing one, and signing without implementation is an enforcement liability. 5. The 2 December 2026 transition is the next operating deadline, applying to Article 50(2) machine-readable marking for generative AI systems placed on the market before 2 August 2026, and to the new Article 5 prohibitions on AI-generated non-consensual intimate imagery and CSAM.

The disconfirming indicator to watch: if the AI Office does not open any formal investigation under Articles 88 to 94 within the first twelve months of the third wave (i.e., by 2 August 2027), and if the downstream complaints channel produces no published AI Office action, then the practical effect of the enforcement shift is more procedural than operational, and enterprises have more residual time to align their AI Act programmes than the current filings suggest. A second disconfirming indicator: if a major national market surveillance authority — Germany's federal AI authority, France's CNIL-adjacent AI office, Italy's AgID — issues guidance that narrows the deployer-side obligations to in-scope systems only and excludes general-purpose AI integrations, the post's claim about deployer exposure would be substantially overstated. The structural severity of this story depends on whether the AI Office uses the new fining power publicly in the next twelve months and whether the downstream complaint channel produces a published action. If neither happens, the post overweights the deployment-side exposure; if both happen, the post underweights it.

What I think

The assurance chain has a regulator now.

The previous two posts argued that the evaluator is a supply-chain node and that the CGL policy form is a supply-chain node. Both arguments are upstream of the regulator node. They describe the operational and contractual layers of the chain. The regulator is the node that turns the operational and contractual layers into legal exposure. An environment misconfiguration that lets an evaluator's model breach a real organization is now also a complaint that can be filed with the AI Office. A hallucinated output that is excluded from the CGL and not covered by the cyber policy is now also a transparency violation that can be reported under Article 50(3) or 50(4) by the deployer who suffered the loss.

The Digital Omnibus re-sequenced the high-risk timeline. The most common reading of the re-sequencing is that the AI Act is now soft. That reading is wrong. The high-risk regime is deferred, but the transparency and supervisory regime is not. The 2 December 2026 transition is the next live deadline, and the prohibition on AI-generated non-consensual intimate imagery and CSAM carries a 7% / €35 million maximum exposure.

The enterprises that will absorb the regulatory exposure are the ones that treated Article 50 as a provider problem and let the procurement contract absorb the deployer-side obligations. The enterprises that will not are the ones that have already mapped their AI systems against the provider/deployer split, signed the GPAI Code of Practice after a substantive review, and pre-staged the downstream complaint for any vendor that misses the December marking deadline — not because the CISO found a control gap, but because the CCO and CPO found a legal exposure.

The regulator is in the assurance chain. The next twelve months will tell us how the AI Office uses the new powers.

Source trail

Primary

Secondary

Topic-selection trail

---

Model disclosure

This post was drafted with MiniMax-M3 through Ollama Cloud. The model's parameter size is not stated in a model card I could verify, so I will not assert it as fact; its scale is undisclosed. Running through Ollama Cloud rather than locally gave the synthesis access to a wide context window over twelve sources — the Commission's 31 July press release, the 20 July Article 50 Guidelines, the GPAI Code of Practice signatory page, both binding regulations, and seven reputable law-firm and regulatory-analysis alerts — which helped sustain the provider/deployer split as the structural argument and preserve the falsifiable-claim shape across both the substantive sections and the source trail. A plausible limitation visible in the resulting article: the downstream complaints channel is presented as a structural shift in the procurement-to-enforcement relationship, but the channel is brand new and has no published AI Office action arising from it, so the prediction that the channel will be operationally significant is interpretive rather than empirically grounded. A second tradeoff is that the cloud runtime, while helpful for breadth across legal and policy sources, does not have access to the live SERFF filing window, the national market surveillance authorities' forthcoming guidance, or the AI Office's complaint-processing procedures, so the disconfirming indicators rest on a twelve-month clock that the article itself acknowledges may not be the right window if the AI Office moves on enforcement slowly. The prose also reflects MiniMax-M3's tendency toward structured, role-by-role analysis, which serves the provider/deployer framing but may make the regulatory-mechanism passages read more like a compliance brief than an editorial argument about who absorbs the bite.