AI Compliance

The dated obligations that actually bind in 2026 β€” EU AI Act Article 50 is live β€” and how much of it a gateway can enforce as routing policy.

EU AI Act Β· Article 50
Applies since 2 August 2026 β€” disclosure is now a feature, not a policy.

In 2026 AI compliance stopped being a policy PDF and became product behaviour. EU AI Act Article 50 has applied since 2 August 2026: if your product talks to people or generates content, disclosure and machine-readable marking are now features you ship β€” while the heavier high-risk regime slipped to 2027/2028. This page maps the dates that actually bind, what each one means for a team running models through a gateway, and how much of it is enforceable as routing policy.

The dates that bind
2026-01-01 California trio in force 2026-07-27 Digital Omnibus in force β–² you are here 2026-08-02 Article 50 transparency 2026-12-02 Legacy grace ends (Art 50(2) only) 2027-01-01 US ADMT duties begin 2027-12-02 EU high-risk (standalone) 2028-08-02 EU high-risk (embedded) past Β· now Β· ahead β€” deferred dates are the Digital Omnibus amendments
2026-01-01 shipped
California trio in force

AB 2013 training-data transparency, SB 53 frontier transparency (TFAIA), and the CPPA risk-assessment / ADMT / cyber-audit regulations all took effect.

Who: Anyone offering generative AI to Californians Β· source β†—
2026-07-27 shipped
Digital Omnibus in force

Regulation (EU) 2026/1744 amended the AI Act: standalone high-risk duties deferred to 2 Dec 2027 and embedded-product duties to 2 Aug 2028 β€” but 2 Aug 2026 was left untouched.

Who: Everyone in EU scope Β· source β†—
2026-08-02 LIVE NOW
Article 50 transparency APPLIES

Chatbots must disclose they are AI; synthetic audio/image/video/text must be machine-readable marked and detectable; deepfakes and AI-generated text on matters of public interest must be labelled. AI Office and national enforcement powers switch on the same day.

Who: Any product that chats or generates content Β· source β†—
2026-12-02 next up
Legacy grace ends (Art 50(2) only)

Systems already on the market before 2 Aug 2026 get until this date for the marking-and-detection duty ONLY. Chatbot disclosure and deepfake labelling had no grace period at all.

Who: Pre-existing generative systems Β· source β†—
2027-01-01 ahead
US ADMT duties begin

Colorado SB26-189 developer documentation duties begin, and California CPPA ADMT requirements for significant decisions apply.

Who: Automated decisions in hiring, lending, housing, healthcare Β· source β†—
2027-12-02 ahead
EU high-risk (standalone)

Chapter III obligations for Annex III standalone high-risk systems apply β€” deferred ~16 months by the Digital Omnibus.

Who: High-risk system providers/deployers Β· source β†—
2028-08-02 ahead
EU high-risk (embedded)

Annex I embedded-product high-risk obligations apply.

Who: Regulated products with AI inside Β· source β†—
Article 50, as engineering work β€” four duties; only one has a grace period
ArticleThe dutyWhat you actually buildGrace?
Art 50(1)Tell people it is AIA persistent, unmissable disclosure in any chat surface β€” not buried in ToS. Applies from 2 Aug 2026 with no grace period.none
Art 50(2)Mark synthetic output machine-readablyEmbed provenance in generated media/text (e.g. C2PA-style manifests, watermarks) so it is detectable downstream. This is the one duty with a legacy grace period β€” to 2 Dec 2026 β€” for systems on the market before 2 Aug 2026.to 2 Dec 2026
Art 50(3)Notify emotion-recognition / biometric categorisationExplicit notice to exposed individuals before processing.none
Art 50(4)Label deepfakes and public-interest AI textVisible labelling on deepfakes and on AI-generated text published on matters of public interest. No grace period.none
Compliance as routing policy β€” what a gateway can enforce, and what this one does today
The useful insight for a router: most of this is enforceable at the routing layer. Residency, retention and provider allow-lists are request parameters, not paperwork β€” with a defined failure mode when no compliant provider can serve the request. Here's the honest status of each in this gateway.
ControlWhat it doesRequest shapeStatus here
Zero data retentionForce endpoints that do not store prompts or completions.provider.zdr: trueroadmap
OpenRouter documents this shape; our gateway does not enforce it yet β€” the honest status.
No training on your dataExclude providers that retain or train on inputs.provider.data_collection: "deny"roadmap
Needs a per-provider retention flag in the catalog.
Data residencyKeep processing in-region (e.g. EU-only).eu.openrouter.ai / region-pinned endpointsroadmap
Provider-side capability; would become a routing constraint.
Provider pinning + fail-closedPin approved providers and ERROR rather than silently falling back to a non-compliant one.only / order + allow_fallbacks: falsepartial today
Our gateway already scopes providers via X-Switchboard-Providers; fail-closed (no fallback outside the allowed set) follows from it.
AI disclosure stampingStamp responses as AI-generated to help satisfy Art 50(1).response header / disclosure fieldroadmap
A natural gateway feature: one flag, applied to every routed response.
Frameworks & standards
EN 18286:2026
2026-07-31
CEN-CENELEC JTC 21

First European standard published in support of the AI Act β€” a sector-neutral quality-management system aimed squarely at the Article 17 QMS duty.

⚠ OJEU citation β€” which is what actually confers the Article 40 presumption of conformity β€” had not happened yet as of publication.
ISO/IEC 42001
β€”
ISO/IEC

Broader organisational AI-governance management system. EN 18286 Annex D maps across to ISO/IEC 42001 Annex A controls.

⚠ Complementary, not a drop-in substitute: an existing 42001 programme is reusable input for EN 18286, not automatic conformity.
NIST AI RMF 1.0
2026-04-07
NIST

Under revision as part of the White House AI Action Plan; a concept note for a Critical Infrastructure profile landed 7 Apr 2026. COSAiS overlays and the Cyber AI Profile (IR 8596) remain drafts.

⚠ US buyers still ask for RMF mapping, so evidence stays useful across the revision.
Code of Practice on Transparency of AI-generated Content
2026-06-10
EU AI Office

Final code assessed adequate by the Commission and AI Board. Section 1 = provider marking/detection (Art 50(2)); Section 2 = deployer deepfake/text labelling (Art 50(4)). ~190 organisations signed by 31 Jul 2026.

⚠ Signing is the cheapest defensible route; not signing means proving equivalence to each market surveillance authority.
Enforcement
Penalty ceilings
Prohibited practices (Art 5)up to €35M or 7% of worldwide annual turnover
GPAI obligations & most other breachesup to €15M or 3%
Supplying incorrect informationup to €7.5M or 1%
Enforcement powers of the AI Office and national competent authorities apply from 2 August 2026 β€” covering prohibited practices, GPAI provider obligations and Article 50 transparency, including model evaluations, requests for information and corrective measures.
πŸ‡ΊπŸ‡Έ The US picture

The US pattern inverted in 2026: Colorado retreated from a duty-of-care model (SB24-205) to ADMT disclosure under SB26-189 with obligations from 1 Jan 2027, while California's training-data (AB 2013) and frontier-transparency (SB 53) laws went live 1 Jan 2026. Executive Order 14365 then put state AI laws under federal challenge, so treat US state rules as configuration, not hard-coded assumptions.

βš– Engineering guidance, not legal advice. Dates and figures are cited to primary sources and were verified on 2026-08-18; the Digital Omnibus amendments are recent and US state rules are under active federal challenge, so re-check before relying on any of it.
Primary sources β€” every date above traces to one of these
Sign in to continue

LLM Switchboard is private β€” sign in with Authlee to access the control room.

Sign in with Authlee
← Back to home