AI governance is one of five capabilities RAVENTRYX operates, and the one most clients arrive through. The Article 50 transparency obligation on AI-generated content is live from 2 August 2026; that date did not move. The Digital Omnibus provisional agreement of 7 May 2026 deferred standalone Annex III high-risk conformity to 2 December 2027 and AI embedded in regulated products to 2 August 2028, but the deferral binds only once it is published in the Official Journal. Until that publication lands, the original dates remain the legally active position, and a conformity framework takes twelve or more months to build. The credible reading is headroom, not reprieve.
The exposure that most US organizations miss sits in Article 26. If you buy and configure a third-party high-risk AI system, you are a deployer, and the deployer obligations bind you regardless of the provider’s conformity status: human oversight, six-month log retention, fifteen-day serious incident reporting, worker notification in employment contexts, and a fundamental-rights impact assessment in credit, insurance, and public-sector use. Provider conformity does not transfer these to the provider. A company that runs someone else’s AI in production has obligations it never signed up for and often does not know already apply.
This page is the regulatory depth behind the capability. The engagement model that turns this exposure into a defensible, audit-ready position is set out in our full AI governance engagement model.