Boards are asking hard questions about AI risk, and the evidence is scattered across disconnected tools. AIBound helps you generate continuous audit trails, framework-mapped evidence, and board-ready dashboards, generated automatically from your live AI inventory.
These are legal facts, not estimates. Each row names its instrument and provision. The timetable was amended by Regulation (EU) 2026/1744, in force 27 July 2026.
Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744. The 27 July 2026 entry into force is independently confirmed by White and Case, Hunton Andrews Kurth, Cooley and NicFab, 2026.
Two errors are circulating about the amendment, and both are easy to check.
The first is the scope of the deferral. What moved was Sections 1, 2 and 3 of Chapter III, the substantive requirements for high risk systems. Copy that says the AI Act was delayed, or that every high risk obligation now sits in December 2027, is wrong. Article 50 transparency became enforceable on 2 August 2026 and was not touched, and the amendment added two prohibitions from 2 December 2026, confirmed by Taylor Wessing and Spicy Advisory, 2026. There is no blanket moratorium.
The second is its mirror image. Registration in the EU database did not disappear with the deferral. The 2026 amendment kept the registration duty and reduced the information a provider has to submit, confirmed by Goodwin, 2026. Anyone who read the headline and concluded there is nothing to file has read it backwards.
No article of the AI Act requires a general internal inventory of every AI system an organisation uses. The nearest statutory mandate is registration of Annex III high risk systems under Articles 49 and 71. An inventory is how an organisation reaches defensible answers under the record-keeping, documentation and logging obligations. It is not itself a legal requirement, and saying so is more credible than implying otherwise.
A body that meets and produces nothing is a meeting. Three independent measurements say the same thing from three directions.
Screenshots, exported spreadsheets and ad hoc queries answer the first audit and fail the fifth. The work becomes a permanent second job, arriving on someone else's calendar.
Mapping means each item of evidence is attached to the control or obligation it supports, so an auditor is not asked to do that work themselves. It is a claim about how evidence is organised, not a claim about certification, and that distinction lands differently on the two frameworks named here.
A regulation. Obligations apply by law, on the dates above, to operators in the roles it defines. Evidence mapped to it supports demonstrating compliance. Whether an organisation is compliant is a legal determination, not an output a product can produce.
Document NIST AI 100-1, published 26 January 2023, still at version 1.0. NIST states it is intended for voluntary use. It carries no certification scheme and no attestation scheme, so there is nothing to be certified against. Mapping evidence to its functions is honest. Any stronger verb is not.
What comes out is a continuous audit trail rather than a quarterly reconstruction, evidence already attached to the obligation it answers, a risk posture view an executive can read without a translator, and a record of what AI the business pays for. All of it is generated from the live inventory.
EU AI Act high-risk requirements apply from 2 December 2027 for Annex III standalone systems and from 2 August 2028 for Annex I product embedded systems. Those dates replaced 2 August 2026 and 2 August 2027 when Regulation (EU) 2026/1744 entered into force on 27 July 2026. Any timetable still showing 2 August 2026 is out of date.
No. The 2026 amendment deferred only Sections 1, 2 and 3 of Chapter III, the substantive requirements for high-risk systems. Article 50 transparency became applicable and enforceable on 2 August 2026, the general purpose AI obligations have applied since August 2025, and the Article 5 prohibitions since February 2025. No blanket moratorium exists.
No. No article of the AI Act requires a general internal inventory of every AI system an organisation uses. The closest statutory mandate is registration of Annex III high-risk systems in the EU database under Articles 49 and 71. An inventory is how organisations reach defensible answers under the record-keeping and logging obligations, not a standalone legal requirement.
No to both. NIST publishes the AI Risk Management Framework as intended for voluntary use, and it has no certification scheme and no attestation scheme attached to it. The current document is AI RMF 1.0, NIST AI 100-1, published 26 January 2023, with a Generative AI Profile, NIST AI 600-1, published 26 July 2024.
For high-risk AI systems, providers must keep automatically generated logs for at least six months under Article 19, and deployers must keep the logs under their control for at least six months under Article 26(6). Technical documentation must be kept at the disposal of national authorities for ten years under Article 18.
The level of visibility here would save us weeks of manual audit preparation.
Generate defensible AI governance reports and continuous audit trails on demand.