The AI Act Does Not Have One Clock
Europe’s landmark AI law can reach companies far beyond Europe—and it is arriving in stages. Its deadlines are not dates to memorize but conclusions to prove.
On 2 December 2026, Europe will make two legally different moves on artificial intelligence under the same date. One clock will stop. Another will start.
For readers outside Brussels, the AI Act is the European Union’s binding, risk-based rulebook for AI. It prohibits certain practices, regulates high-risk systems and general-purpose models, and imposes transparency duties on specified AI interactions and outputs. Its reach is not confined to European companies: in defined circumstances, the Act applies to providers outside the EU that put systems on the European market, and to providers or deployers abroad when output from their systems is used in the Union. But the law does not switch on all at once. Different rules attach to different actors, systems, uses, and events.
That is why “the AI Act is live” is both true and dangerously incomplete.
On 2 December, a narrow grace period ends for providers of certain synthetic-content systems placed on the EU market before 2 August 2026. Those systems must then meet Article 50(2)’s machine-readable marking and detectability rule. On the same day, two Article 5 prohibitions take effect concerning AI systems intended, capable, or used to produce non-consensual intimate material or child sexual abuse material. The first route looks backward to system identity and market placement. The second looks to intended purpose, reproducible capability, safeguards, actual use, consent, and legal right. Earlier placement does not immunize the system.
A deadline spreadsheet can make those events look alike. They are not. One points mainly to product, engineering, and compliance. The other demands trust-and-safety, abuse-prevention, legal, and deployment evidence. Combine them, and a company can assign the wrong owners, ask the wrong questions, and preserve the wrong proof.
This is the article’s governing point: a date is not the unit of compliance. The fact pattern is. Legal analysis identifies which facts control; intelligence discipline reconstructs them, tests uncertainty, and preserves the evidence needed to defend the route. The calendar comes last.
The deadline is the answer, not the question
Deadline charts are useful because they compress. They are dangerous because they hide the assumptions that produced them.
Start one level below the calendar. Establish the system’s identity and the actors around it. Under the Act, a provider generally develops or markets a system under its name; a deployer uses one under its authority. Manufacturers, importers, distributors, and downstream modifiers can matter too. Map who controls what, what the system was designed to do, what it can do, how it is actually used, and in which context.
Those facts select the classification route, any exception or product-law dependency, and the temporal event that matters. Only then can an organization identify the required or prohibited conduct, the evidence capable of supporting that conclusion, the authority entitled to review it, and the guidance, standard, benchmark, or conformity route affecting implementation.
Across four dates sit five selected legal clocks—not an exhaustive timeline. Under the current consolidated Act, Article 50’s transparency duties generally began to apply on 2 August 2026, subject to the narrow Article 50(2) transition and the applicable enforcement route. On 2 December 2026, that transition ends and the two new Article 5 prohibitions begin under separate tests. Specified Chapter III duties then reach use-case high-risk systems classified through Article 6(2) and Annex III on 2 December 2027, and product-related high-risk systems classified through Article 6(1) and Annex I on 2 August 2028.
The dates orient the work; they do not define its unit. One system can carry several duties, dates, owners, proof routes, and reviewers. Placement history may select one transition; purpose, capability, safeguards, use, integration, or later design change may select another rule. A compliance calendar is therefore a derived product. It should be built only after the underlying facts have selected the duty and route.
The clearest proof is the day on which two unrelated legal grammars collide.
One day, two legal architectures
On 2 December 2026, one clock expires and another begins. The date is shared. Almost nothing else is.
The expiring clock is about a narrow transparency transition. Article 111(4) gave providers of qualifying systems that generate synthetic audio, images, video, or text—and were placed on the market before 2 August 2026—four additional months to comply with Article 50(2). By 2 December, covered outputs must be marked in a machine-readable format and detectable as artificially generated or manipulated. The relevant proof is historical and technical: provider identity, EU placement, type, model, version, modality, and marking performance. The transition reaches Article 50(2) only. It did not postpone direct-interaction notice or deployer duties concerning emotion recognition, biometric categorization, deepfakes, or certain public-interest text.
The clock that begins that day is about prohibited conduct. New Article 5 rules address non-consensual intimate material and child sexual abuse material. For a provider, the test asks whether producing the material is intended—or is a reasonably foreseeable and reproducible result of the system’s design, training, architecture, capabilities, or user-facing functions without significant technical modification—and whether reasonable and adequate safeguards reliably prevent the result and correct observed or reported misuse. For a deployer, the question is actual purpose: did it use the system to produce or manipulate the prohibited material? The intimate-material route also turns on an identifiable person, realistic depiction, covered subject matter, and consent; the child-protection route preserves a “without right” defense under applicable national law.
These are not two versions of one deadline. A pre-August system may qualify for the marking transition and still face Article 5 on 2 December. Market history selects the first route. It does not excuse the second.
The difference is easiest to see by asking the same five questions of each rule.
Who is regulated?
Article 50(2) transition: The provider.
Article 5 prohibitions: Providers and deployers, under different legal tests.
What triggers the rule?
Article 50(2) transition: A qualifying system that generates synthetic audio, images, video, or text was placed on the EU market before 2 August 2026.
Article 5 prohibitions: For providers, intended purpose or reasonably foreseeable and reproducible capability, assessed with safeguards; for deployers, actual prohibited purpose.
What must the actor do?
Article 50(2) transition: Bring the system’s marking and detectability into compliance by 2 December 2026.
Article 5 prohibitions: Do not place, put into service, or use a system in circumstances prohibited by Article 5.
What evidence matters?
Article 50(2) transition: Provider identity; EU placement; system type, model, and version; covered output modality; linkage to the current system; and marking and detectability testing.
Article 5 prohibitions: Product positioning; capability and reproducibility testing; misuse and circumvention analysis; safeguards and corrections; deployment purpose; and applicable consent or legal-right evidence.
What does earlier market placement change?
Article 50(2) transition: It may qualify the system for the four-month transition.
Article 5 prohibitions: It provides no general grandfathering defense.
The operational split is immediate. The first route belongs chiefly to product, engineering, and compliance teams that can prove identity, European placement, and marking performance. The second requires trust-and-safety, abuse-prevention, legal, and deployment teams to reconstruct purpose, capability, safeguards, misuse, consent, and corrective action. Put both under one calendar row and the legal distinction disappears precisely where the work begins.
Analytic judgment — high confidence. A master-date plan that does not separately model actors, triggers, conduct, and proof will misroute at least some work. That judgment rests on enacted differences, not a prediction about enforcement intensity. Mature obligation-level programs may already make the separation; a material amendment or contrary authoritative interpretation would weaken the judgment.
The December collision exposes a deeper problem: “legacy” is not one question. A system, its outputs, and its later design each carry their own time.
A system can be old while its output is new
An image generator launched in 2025 can create a covered output in 2026. The product’s age does not age the output. The AI Act asks at least three different time questions.
When did the system enter the EU market or first go into service? For Article 50(2), Article 111(4) asks whether a covered synthetic-content system was placed on the market before 2 August 2026; only qualifying providers received that transition. High-risk legacy treatment differs: Article 111(2) covers a high-risk system placed on the market or put into service before the Chapter III date for its classification route. Placement proof needs more than a press release. It needs a provider, an EU transaction or first use, and a type, model, and version. The current Act draws both boundaries.
When was the output generated, published, or first shown? That time belongs to the item, not merely to the system. The Commission’s non-binding Article 50 guidance says covered outputs made before 2 August 2026 need no retroactive mark or label. But public-interest text generated earlier and published on or after that date requires disclosure, while direct-interaction notice is due at first interaction. A system’s launch date does not travel with its output.
Did the system later change in a legally consequential way? Under Article 111(2), a pre-existing high-risk system loses general legacy treatment when its design changes significantly. Recital 39 ties the grace period to the first unit of the same type and model and an unchanged design. Article 25 addresses a related but distinct event: a substantial modification or changed intended purpose can make another operator the provider. A familiar product name can conceal a different architecture, capability, or intended purpose. The record must show the change, not merely the brand.
The 2027–2028 split follows the route. Article 6(2) and Annex III classify specified high-risk systems by use case and reach their Chapter III date on 2 December 2027. Article 6(1) and Annex I depend on regulated-product and third-party conformity-assessment conditions and follow on 2 August 2028. Legacy status then depends on the first unit, type/model, placement or first service, and later design.
Call the resulting record the system’s legal biography—analytical shorthand, not the Regulation’s term. Inventories and change-control logs are ordinary governance. What changed is the legal work they now perform. They can select an application date, preserve or end transition treatment, reallocate provider responsibility, and route a system toward a different compliance burden.
Once time separates the records, the next question becomes unavoidable: what can the evidence actually prove?
A mark is not a truth machine
In the public debate, provenance is often asked to do too much. In this bounded Article 50 setting, content evidence can support a specific claim: that covered AI-generated or manipulated output carries a machine-readable mark, can be detected as artificial, or bears the required disclosure. The Commission’s non-binding guidance expressly stops short of requiring providers to preserve a complete provenance chain.
A mark or disclosure, standing alone, proves neither truth, authenticity, legality, authorship, consent, authorization, nor the absence of later modification. A label can tell a reader something important about how content was generated or presented. It cannot tell the reader whether the underlying claim is true or the depicted person consented. Article 50 is not a universal chain-of-custody or content-authentication regime.
Even the narrower technical task resists a universal solution. The performance-based standard calls for methods that are effective, interoperable, robust, and reliable as far as technically feasible, taking account of content type, cost, and the state of the art. The final Article 50 Code and the Commission’s three modality studies support layered, modality-specific approaches. They identify no method or common benchmark that guarantees performance across text, audio, images, and video.
System lineage does a different job. It asks who the provider is and how related undertakings divide responsibility; what the system was intended to do; which type, model, and version was placed on the market or put into service; which classification route applies; how the system was integrated; and whether a later change carries legal consequence. This article uses “regulatory provenance” as shorthand for that system lineage, not as a statutory term. The record can defend a transition, classification, application date, or authority route for the system behind the output.
The AI Act creates no unified law or doctrine of provenance. The connection is evidentiary: content evidence supports a proposition about the output; system lineage supports the legal route behind it. The two records can connect through identity and responsibility, but neither substitutes for the other.
That distinction is where legal analysis meets intelligence practice: define the proposition, identify the record capable of proving it, and refuse to let a convenient proxy answer a different question.
Voluntary does not mean irrelevant
The Article 50 Code does not change the law. It changes the shape of the conversation about evidence.
The Commission’s Code and adequacy record describe adherence as voluntary and relevant—but not conclusive—evidence of compliance. The Code can help providers and deployers implement Articles 50(2), (4), and (5), but the obligation comes from the Regulation. Recital 41 gives these codes limited legal effect and no presumption of conformity. The Code is no statutory safe harbor, no Article 40-style presumption, and no promise of a favorable enforcement result. Adequate alternative measures remain lawful.
Administratively, however, the paths diverge. The Commission’s non-binding guidance treats the adequate Code as the only Union-wide recognized practical framework. A signatory can map each applicable commitment to marking or disclosure methods, performance tests, technical documentation, detection and access arrangements, and update governance. An organization using alternatives must present the same substantive case in a bespoke bundle: a measure-by-measure map to Article 50, proof that its methods meet the applicable performance or disclosure rule, and an explanation of divergences or gaps.
That is not a formal burden shift, and administrative legibility is not legal superiority. But familiarity can matter without becoming law. With the Code, an authority begins with a known structure and tests implementation. With an alternative, it may first have to understand the structure before it can test adequacy.
Analytic judgment — medium confidence. Alternative routes are likely to generate greater evidentiary friction and more granular questions. The inference rests on the guidance’s express expectation of more detailed information, requests, and access where authorities know less about bespoke measures. The limitation is decisive: there is no mature public enforcement record. The judgment implies nothing about suspicion, sanctions, or outcome, and would weaken if mature practice shows equal or lower friction for well-documented alternatives.
The next question is who is entitled to ask for that evidence.
The facts also choose the regulator
Many readers outside Europe will assume that “the Commission” enforces the AI Act. Sometimes. Not always.
Amended Article 75 gives the AI Office exclusive supervision and enforcement in two defined lanes. One covers certain systems built on general-purpose AI models when the model and system are developed by the same provider or undertaking, subject to product and sectoral exclusions. The other covers systems that constitute or are integrated into a designated very large online platform or search engine. Competence generally attaches to providers and reaches deployers only when they are also the provider or belong to the same undertaking. For covered high-risk systems requiring third-party conformity assessment, the Office also owns the assessment and testing route.
Outside those lanes, national market-surveillance authorities remain central. Product integration can route a product-law authority; financial use can route a financial supervisor; specified law-enforcement, border-management, and justice systems can route specially designated authorities. The European Data Protection Supervisor is competent for Union institutions, bodies, offices, and agencies, subject to the Court of Justice’s judicial-capacity exception.
Other regimes do not disappear. Data-protection, consumer-protection, and fundamental-rights powers can overlap, and cross-border cases can require coordination or joint action. A single fact pattern may therefore have more than one reviewer.
The same variables that choose the date—classification, provider relationships, model and system development, product integration, sector, institutional status, and exclusions—also route the authority. The Code determines none of this. An EU-level organizational chart cannot resolve every national or sectoral overlap.
The law is live. The machinery is uneven.
The AI Act’s implementation infrastructure is neither imaginary nor complete. The Commission issued Article 50 guidance, found the final Code adequate, and began enforcement on 2 August. The AI Board, AI Office, European Data Protection Supervisor, national and sectoral supervisors, and conformity-assessment structures operate. CEN-CENELEC has also published EN 18286, a quality-management standard designed to translate legal requirements into verifiable processes. Those facts defeat the claim that Europe is waiting to invent an enforcement system.
But “ready” conceals three different questions. Legal operability asks whether the enacted duty, date, and competence route apply. Compliance translation asks whether guidance, codes, standards, benchmarks, and technical methods convert the duty into repeatable controls. Review capacity asks whether authorities, laboratories, notified bodies, sectoral assessors, and coordinating institutions can evaluate the evidence consistently and at scale. The latter two can mature unevenly without suspending the first.
The public record at the 8 August review cutoff shows that separation. Article 6 classification guidance remained draft after consultation. EN 18286 had been published, but CEN-CENELEC still expected a later Official Journal reference; Article 40’s presumption depends on that reference. JTC 21’s broader standards work continued. The Commission’s public roster of national contact points remained incomplete, and database visibility could not capture all sectoral conformity capacity. Enforcement had begun, but its first week could not supply a mature public practice record. Those are limits on implementation and public visibility—not proof that authorities or assessment bodies do not exist.
An intelligence assessment must hold the contrary evidence at the same time. Europe has enacted law, operative institutions, final Article 50 guidance, an adequate Code, a published standard, and sectoral infrastructure. That defeats a failure thesis. It does not erase uneven translation, public routing, or review capacity.
Analytic judgment — medium confidence. Mixed support maturity is likely to raise translation costs, reduce predictability about acceptable evidence, generate more detailed or repeated information requests, constrain some assessment channels, and complicate coordination. The assessment rests on the amendment’s account of delayed standards, governance, and conformity frameworks and on the current uneven record. It does not alter any duty or application date. The judgment should weaken as final classification guidance arrives, standards gain Official Journal references, public routing becomes clearer, and early review practice converges.
The lawyer’s error would be to treat unfinished machinery as a suspension clause. The analyst’s error would be to treat a live statute as proof that every implementation layer is mature.
Build the case file before the countdown
An executive does not need another universal countdown. The useful instrument is a system-and-obligation matrix: one row for each potentially applicable duty, so one system can carry several dates, owners, proof routes, and reviewers without collapsing into one “go-live” entry.
Establish identity and control. Record the system, type, model, version, provider, other actors, and their relationships. Capture intended purpose, actual use, capability, safeguards, and affected context. Map the classification route, any exception, and any product-law dependency.
Preserve the facts that route time. Link placement or putting-into-service evidence to the specific system and version. Where output duties matter, retain generation, publication, and first-exposure evidence. Document later design changes and distinguish the legal framework under which each change matters.
Build the obligation record. State the conduct rule and transition treatment, selected compliance method and supporting tests, accountable owner, reviewing authority, and sectoral overlap. Add update triggers for guidance, standards, benchmarks, or conformity dependencies that may change implementation or proof.
The matrix is a governance instrument, not a universal statutory form. It does not turn every field into a recordkeeping mandate or replace required technical documentation, registrations, conformity materials, or sector-specific records. It connects the facts needed to classify and route an obligation with the records its governing provision and operator role actually require.
Good records do not guarantee a favorable enforcement outcome. They do something more modest and more useful: reduce avoidable ambiguity, expose missing evidence while it can still be collected, and preserve the organization’s ability to explain why it chose a particular route.
Facts choose the clock. Records defend the route. Institutions shape the friction. The calendar still matters—but it should be the last thing the analysis produces, not the first thing the organization believes.




