EU AI Act · Updated for the Digital Omnibus, Reg. (EU) 2026/1744

The AI Act's transparency obligations still land 2 August 2026. High-risk just moved to 2 December 2027.

Most AI Act consultants can tell you where you're exposed. We tell you — and then build the self-hosted, EU-sovereign fix ourselves. Advise and build, same team, no handoff.

For regulated organizations: financial services, insurance, healthcare, HR-tech, public sector, and Mittelstand with IP worth protecting.


One deadline moved. The one six days out did not.

The EU AI Act (Regulation (EU) 2024/1689) entered into force on 1 August 2024 and has been phasing in ever since. On 24 July 2026 the EU published the Digital Omnibus on AI (Regulation (EU) 2026/1744), in force from 27 July 2026. It defers the substantive obligations for high-risk AI systems: Annex III standalone systems move from 2 August 2026 to 2 December 2027, and Annex I embedded systems — medical devices, machinery, toys — to 2 August 2028.

What the Omnibus did not defer is Article 50. The transparency obligations still apply from 2 August 2026. If you run a system that interacts with people, generates or manipulates content, or performs emotion recognition or biometric categorisation, you owe disclosure: telling people they are dealing with an AI system, marking synthetic content in machine-readable form, and labelling deepfakes and emotion recognition. One narrow easement, and it cuts both ways: providers have until 2 December 2026 to meet the Article 50(2) machine-readable marking requirement on systems already placed on the market. Anything newly placed on the market from 2 August has no grace period at all. Ship a new product this autumn and you are exposed on day one, while an incumbent has four months.

Two other things were already live and did not move. The Article 5 prohibited practices have applied since 2 February 2025. Obligations on general-purpose AI model providers have applied since 2 August 2025. The Omnibus reopens neither.

The high-risk scope itself is unchanged, only its timing. You are in scope if you deploy a high-risk AI system in your operations, even if you didn't build it, and coverage is extraterritorial: non-EU organizations are included if the system's output is used in the EU. “High-risk” is a defined list, not a guess — it includes AI used in employment and HR decisions, biometric identification, critical infrastructure, education and exam scoring, access to essential services like credit or insurance, law enforcement, migration, and the justice system.

€35M / 7%
Prohibited practices (Art. 5) — enforceable since February 2025
€15M / 3%
Transparency breaches (Art. 50, via Art. 99(4)(g)) — enforceable 2 August 2026
€7.5M / 1%
Incorrect or misleading information to authorities

Read the middle figure carefully. Article 99(4) is a single tier covering both the high-risk operator obligations and Article 50 transparency. With high-risk deferred, your live 2026 trigger for that tier is Article 50 — not Annex III. The ceiling is the same number; the thing that reaches it has changed. Any page still presenting a high-risk penalty exposure dated 2 August 2026 is working from a pre-Omnibus brief. SMEs and startups: each ceiling is capped at the lower of the fixed sum or the percentage.

The honest read: your 2 August exposure is transparency, and it is six days out. Your high-risk exposure did not disappear, it moved — and what moved is the obligation date, not the build lead-time. Conformity assessment, technical documentation, data-governance evidence and post-market monitoring on a system already running in production is a multi-quarter engineering programme, not a documentation exercise. Organizations that start in mid-2027 will be buying emergency remediation at emergency prices.

And the exposure that has nothing to do with the Omnibus did not move at all. If your organization processes EU personal data through a US-hosted LLM, a SaaS tool with AI features bolted on, or a US-parented cloud, your GDPR international-transfer and CLOUD Act exposure is live today, enforced today, and untouched by anything the EU published this month.


What you get

A fixed-scope, one-to-two-week audit that tells you exactly where you stand — before a regulator, a customer, or an auditor asks.

The five deliverables

  1. Data-flow map Every place your organization's AI and LLM usage sends data outside the EU — direct API calls to US-hosted models, SaaS tools with AI features bolted on, anything routing through a US-parented cloud even when the servers sit in Frankfurt.
  2. CLOUD Act exposure assessment What US jurisdiction over your data actually means in practice, and precisely where it collides with GDPR's international-transfer rules.
  3. AI Act risk classification, system by system Prohibited, high-risk, limited-risk, or minimal-risk — for each AI system you actually run, with the reasoning shown so your legal and compliance teams can defend the classification, not just cite it.
  4. Regulatory overlap map Where AI Act obligations stack with GDPR, DORA (financial services), and NIS2 (critical infrastructure) — the compound exposure a single-framework audit misses, and the thing that actually drives penalty size when it's missed.
  5. Prioritized remediation roadmap What has to change before 2 August 2026 for transparency, what belongs on the longer road to 2 December 2027 for high-risk, and a realistic cost and effort estimate for each item — a plan you can execute, not a report that ends in “consult further”.
Duration
1–2 weeks, fixed scope
Payment
50% on signature, 50% on delivery
Included
One clarification call
Price & scope
westoverlabs.eu →

Fixed scope, frozen up front — genuine unknowns become a short written change order, never silent scope creep. The binding price and full scope live on the rate card at westoverlabs.eu.


Why self-hosted and EU-sovereign is the compliance advantage, not just an architecture preference.

A large share of these obligations — the high-risk ones now due in 2027, and the transparency and record-keeping ones due next week — are really about two things: control and provability. Data governance. Audit trails. Human oversight. Knowing, specifically, where inference runs and where your data goes.

Self-hosted / EU-sovereign

Provable

On a self-hosted or EU-sovereign deployment, you can attest to all of that directly. Your data never leaves your control. Full logs exist. There is no third-country transfer to explain, because there is no third-country transfer.

US-hosted LLM API

Harder to attest

CLOUD Act exposure means you can't fully guarantee where your data goes once the request leaves your network, which sits awkwardly next to the data-governance and data-transfer obligations you're trying to satisfy in the first place. You can still use a US-hosted model responsibly, but you're closing a compliance gap with a policy document instead of an architectural fact.

That's the practical reason “sovereign AI” matters here, not as a buzzword, but as the infrastructure choice that turns an obligation into something you can prove, instead of something you assert.

It is also the half of your exposure the Omnibus did not touch. CLOUD Act jurisdiction, the Schrems II line of case law, and GDPR's international-transfer rules run on their own timetable, are enforcement-active today, and have no deferral coming. Whatever the AI Act's high-risk calendar says, this part was already due.


Why Westover Labs, and not a compliance firm.

Most AI Act consultants come from a legal or GRC background. They're genuinely good at the first half of the job: telling you what's wrong and what the regulation requires. What they generally can't do is the second half — actually standing up the self-hosted or EU-sovereign infrastructure that resolves the exposure.

James Westover spent years as a Staff engineer at Uber (navigation and geospatial systems) and at HERE. He now runs Westover Labs' own production infrastructure day to day: a self-hosted, multi-agent AI platform with zero-egress architecture, full infrastructure-as-code, and two shipping consumer apps with paying subscribers where privacy is the actual product, not a compliance checkbox.

This audit is written and delivered by the person who would build your remediation — not handed off to someone else afterward. That means the recommendations you get are ones that are actually buildable, realistically priced, and sequenced the way real engineering work gets sequenced, not the way a slide deck gets sequenced.

“Advise and build, same person, no handoff.”


What regulated buyers ask first.

The high-risk deadline just moved to December 2027. Do we still need this now?
Yes, for two reasons. Article 50's transparency obligations were not deferred and apply from 2 August 2026, so if you run a chatbot, generate or manipulate content, or do emotion recognition, you have a live obligation in days — and breaches sit at the same EUR 15M / 3% ceiling as the high-risk obligations do. Separately, your GDPR transfer and CLOUD Act exposure never depended on the AI Act timetable at all. The deferral changes the sequencing of your high-risk work, not whether it is needed - and it moved the obligation date, not the build lead-time. Conformity assessment, technical documentation, data-governance evidence and post-market monitoring on a production system is a multi-quarter engineering programme. Whoever starts in mid-2027 will be buying emergency remediation at emergency prices.
We already had a GDPR or AI Act audit from a law firm. Why would we need this too?
This audit doesn't replace legal advice, it completes it. Most legal/GRC audits stop at “here's what's wrong and what the law requires.” This one adds the engineering layer: a data-flow map, a system-by-system risk classification, and a remediation plan you can actually hand to an engineering team and execute — plus, if you want it, the team to build that remediation.
Do we need to be “high-risk” under the AI Act for this to be worth doing?
No. Part of the audit's job is determining your classification in the first place — many organizations assume they're minimal-risk and are wrong, or assume they're high-risk and are over-scoping their response. Either way, you want the answer in writing with the reasoning shown, not a guess.
What if the audit finds we need to move off a US-hosted LLM provider entirely?
Then that's what the roadmap says, with a realistic cost and effort estimate attached. It won't always be the answer — sometimes the fix is narrower (routing sensitive workloads differently, tightening data governance, adding logging) than a full migration. The audit tells you which one you actually need, not the maximal answer by default.
How long does the audit take, and what does it cost?
One to two weeks, fixed scope, fixed price. The binding price is on the rate card at westoverlabs.eu. Fifty percent on signature, fifty percent on delivery, one clarification call included.
What happens after the audit?
The audit is the door-opener, not a sales trap. If it surfaces a build need — a self-hosted deployment, an EU-sovereign inference layer, ongoing technical implementation — that's a natural next engagement, scoped and quoted separately. Never assumed, never bundled in without your sign-off.

One deadline moved. The other is six days out. Find out which one you're actually facing.

A fixed-scope audit, one to two weeks, delivered by the person who'd build the fix.

Deutsche Version Rate Card Westover Labs UG · Berlin