Two Clocks, One Deadline

Return to Part 0: Table of ContentsPrevious Article: Part 29, The Benchmark You Cannot Audit: A Launch-Day Leaderboard Is a Vendor's Account of Its Own Product


Picture the board meeting. Your compliance lead is asked two questions inside the same ten minutes: are we exposed to the fines that started this month, and do we still need to finish the high-risk-system audit by August? Both questions point at "2 August 2026" as though it names one deadline. It does not, and the honest answer to each question runs in the opposite direction from the other.

Start with what is actually live. On 2 August 2026, the European Commission's AI Office gained working powers under the EU AI Act to investigate, evaluate and, if necessary, order the withdrawal of general-purpose AI (GPAI) models from the European market. The same date brought transparency and AI-content-marking duties into force for any system whose output reaches someone in the European Union. Both apply to a New Zealand business regardless of where its servers sit.

Six days earlier, on 27 July, a separate piece of EU legislation entered into force and moved a different, much larger category of obligation sixteen months in the opposite direction. Almost none of the plain-language coverage of "2 August" mentioned it.

What actually went live

Chapter V of the EU AI Act gives the European Commission, acting through its AI Office, direct supervisory powers over the companies that build general-purpose AI models, the GPT, Gemini, Claude and Llama class of system, rather than the narrower category of "high-risk" applications built on top of them. Those powers activated on 2 August 2026, a year after GPAI providers' own documentation obligations began. [1]

Three articles do the work. Article 91 lets the Commission demand technical documentation from a provider, who may not supply incorrect, incomplete or misleading information. Article 92 lets the Commission evaluate a model directly, including through independent experts, to check compliance or investigate systemic risk. Article 93 lets the Commission order corrective measures, up to restricting, withdrawing or recalling a model from the EU market outright. A national regulator can ask the Commission to use these powers; a downstream provider can lodge a complaint that triggers the same request.

The fine structure behind this is where plain-language coverage most often goes wrong. GPAI enforcement is not the Act's largest financial exposure. Article 101, the GPAI-specific regime the Commission alone enforces, caps fines at the higher of fifteen million euro or three per cent of worldwide turnover. [1] The bigger number, up to thirty-five million euro or seven per cent, sits in Article 99 and applies to prohibited practices under Article 5, enforced by national regulators, not by the Commission's GPAI powers. [2] A GPAI provider only reaches that higher tier if its conduct separately breaches a prohibited practice. Two regimes, two enforcers, two ceilings, and coverage that flattens them into one number describes neither correctly.

None of this is confined to companies with a Dublin or Frankfurt office. Article 2 of the Act states plainly that it binds "providers placing on the market or putting into service AI systems or placing on the market general-purpose AI models in the Union, irrespective of whether those providers are established or located within the Union or in a third country," and separately binds any provider or deployer "located in a third country, where the output produced by the AI system is used in the Union." [3] A Wellington-based exporter selling a GPAI model into the EU, or a Wellington-based deployer whose AI system's output is read by someone in Paris, sits inside that perimeter on the plain text, regardless of where the company is registered.

Alongside the GPAI powers, Article 50's transparency duties also became operative on 2 August. Four separate obligations, not one: disclose that a person is talking to an AI system unless that is already obvious; mark AI-generated or manipulated content in a machine-readable way; tell people when an emotion-recognition or biometric-categorisation system is reading them; and label deepfake content, a category the Commission's own guidance of 20 July 2026 extends to anything depicting a scenario that "could exist" even where it did not, judged against what the audience would reasonably expect. Generative AI systems already on the market before 2 August get a four-month grace period on the machine-readable marking duty alone, extending that one requirement to 2 December 2026. The other three duties carry no grace period. [4]

The deferral almost nobody reported correctly

Here is what most "2 August" coverage missed. On 27 July 2026, five days before the powers above went live, the Digital Omnibus on AI, Regulation (EU) 2026/1744, entered into force. It had been published in the Official Journal three days earlier, on 24 July, a faster turnaround than the usual twenty-day gap, timed so the amended calendar would be settled before 2 August. It is the first amendment to the AI Act since its original adoption in 2024. [5]

What it changed: the compliance date for stand-alone high-risk AI systems under Annex III, the category covering recruitment and hiring tools, credit-scoring, biometric identification and similar consequential automated decisions, moved from 2 August 2026 to 2 December 2027. Sixteen months. High-risk systems embedded in products already covered by other EU safety law, Annex I, medical devices, machinery, vehicles, moved from 2 August 2027 to 2 August 2028. The underlying obligations were not softened. Risk management, data governance, logging, human oversight: none of it changed. Only the clock did, and even that clock is conditional. The Commission can bring the Annex III date forward once it certifies the necessary technical standards exist. [5]

The Digital Omnibus left the two obligations described above, GPAI enforcement and Article 50 transparency, completely untouched. It deferred exactly one category, the one requiring the conformity infrastructure furthest from ready, and left the two that were ready to proceed on schedule.

There is a sequence worth being precise about here, because getting it wrong in either direction misreads the story. On 3 July 2025, forty-six chief executives of major European companies, among them Airbus, BNP Paribas, Carrefour, Lufthansa, Mercedes-Benz, TotalEnergies, Philips and ASML, wrote to the Commission asking for a full two-year pause covering both the high-risk-system obligations and the GPAI obligations. [6] Within days, a Commission spokesperson, Thomas Regnier, told reporters there would be no stop the clock, no grace period and no pause. [7] That exchange is a full year older than the Digital Omnibus itself. The Commission proposed the Omnibus on 19 November 2025, roughly four and a half months later. [8] The European Parliament approved it on 16 June 2026, 423 votes to 57 with 174 abstentions. [9] The Council gave final approval on 29 June 2026, before the Omnibus reached the Official Journal in July. [8]

That timeline supports neither of the two easy readings. It does not show the Commission holding an unmoved line, because a substantial piece of what the CEOs asked for did eventually arrive, a year later and through a different legislative instrument than the one their letter addressed. It does not show the CEOs' letter working, either. A year, a full legislative process through Parliament and Council, and a formal Commission proposal sit between the letter and the deferral, and the public record does not establish what, if anything, connects them. What it does show is that "the Commission said no" and "the Commission moved the deadline" are both true, describe different obligations, and are separated by twelve months in which the account either side gave at the time did not change.

The practical read for a compliance-planning audience: the deferral applies to Annex III and Annex I high-risk systems only. GPAI enforcement and Article 50 transparency proceeded exactly as scheduled. Reading "no pause" as meaning nothing moved, or reading the Omnibus as meaning everything moved, are both wrong, in the direction that leads a business to over-invest in high-risk conformity work that now has until December 2027, or to under-invest in the GPAI and Article 50 exposure that is live today.

Four questions settle it before the board meeting, faster than any headline will. Which track does the obligation in front of you sit on, GPAI and transparency, or Annex III high risk? Which date actually applies to that track, 2 August 2026 or 2 December 2027? Who enforces it, the Commission directly, or a national regulator? And has anything about the underlying obligation changed, or only the clock attached to it?

What this means for a New Zealand business this month

New Zealand's own approach carries no equivalent trigger. MBIE published the country's AI Strategy and accompanying Responsible AI Guidance for Businesses in July 2025, both explicitly voluntary and framed around alignment with OECD AI principles rather than binding obligation. Neither document mentions the EU AI Act, extraterritorial compliance or export exposure. That is a description of what the framework covers, not a criticism of it; a voluntary guide and a binding foreign regulation are answering different questions. [10]

Into that gap, New Zealand's private advisers have already moved. MinterEllison New Zealand published guidance on the four Article 50 duties on 30 July, stating that the rules apply regardless of where a business is based, so long as its systems reach EU users or their output is used inside the Union. [4] The German-New Zealand Chamber of Commerce published its own guidance on 2 August, the enforcement date itself: fines, enforcement orders that can require removal of a non-compliant tool, and reputational exposure in privacy-conscious markets as the risks; an audit of every AI touchpoint, added disclosure statements and a stated internal AI-use policy as the response. [11] No New Zealand government agency, not MBIE, not Digital.govt.nz, not the Department of Internal Affairs, has yet published guidance connecting the EU AI Act to New Zealand's own export or compliance position. That is a description of where the guidance currently sits, not a claim about who should close the gap.

The discipline this month rewards is not knowing that the EU AI Act exists. Sovereignty Agility, in the sense this series has used it since Part 9, has always meant more than moving fast when the regulatory ground shifts. It means moving on the right axis. An organisation that reads 2 August as one deadline and reacts to it as one thing gets the direction wrong twice over: it either pours effort into a high-risk conformity programme that now has until December 2027, or it assumes GPAI and transparency exposure bought the same sixteen months of room that high-risk systems did, when neither obligation moved at all.

Two dates entered into force six days apart this year on two different tracks, in a regulatory environment that had already shown, a year earlier, that a public no and a slower, partial yes can both be true about the same regulator. The next EU AI Act headline will very likely compress two things into one date again, because that is what a wire headline does. The question worth asking before your board's next meeting is not whether you read the headline. It is whether you checked which specific obligation, on which specific track, the date in that headline actually names.

  • GPAI enforcement (Articles 88, 91 to 93) and the Article 50 transparency duties became operative on 2 August 2026, exactly as scheduled, and apply to a New Zealand provider or deployer regardless of where it is based, under Article 2's extraterritorial trigger.
  • Article 101 caps GPAI-specific fines at the higher of 15 million euro or 3% of worldwide turnover, enforced by the Commission alone. The higher Article 99 ceiling, 35 million euro or 7%, applies to prohibited practices under Article 5 and is a national-authority matter, not a GPAI one. Conflating the two overstates a compliant GPAI provider's exposure.
  • The Digital Omnibus on AI, in force since 27 July 2026, deferred stand-alone high-risk system compliance (Annex III) to 2 December 2027, sixteen months out, and left GPAI enforcement and Article 50 completely untouched. Reading 2 August as a single deadline misreads both halves of the story.
  • No New Zealand government agency has yet published guidance connecting the EU AI Act to New Zealand's export or compliance position. Two private advisers, MinterEllison NZ and the German-New Zealand Chamber of Commerce, have already published dated, practical guidance in that gap.

The open-source dimension here is not the models. It is the tooling that will end up proving compliance. Article 50's machine-readable marking duty and Article 53's GPAI technical-documentation obligation both assume a verifiable record of what a system produced and how it was built. The leading candidate for that record is not proprietary. The Coalition for Content Provenance and Authenticity, a Joint Development Foundation project under the Linux Foundation formed in 2021 from Adobe's Content Authenticity Initiative and Microsoft and the BBC's Project Origin, now counts more than 120 member organisations building to one open specification for content provenance credentials rather than competing closed formats. [12] The same pattern played out a decade earlier with software supply-chain documentation: an audit mechanism became workable once its format stopped belonging to one vendor. A compliance programme built on an open, inspectable provenance standard is auditable in a way a closed one cannot be.

The implication on the sovereignty side is one Article 2 does not put in its own headline. The same article that pulls a Wellington-based deployer inside the Act's civilian perimeter, two subsections later, pulls an entire category out: Article 2(3) excludes AI systems developed or used exclusively for military, defence, or national security purposes from the Regulation's scope, regardless of what kind of entity carries out the activity. [3] Chapter V's evaluation and corrective-measures powers, the Article 53 documentation duty, the Article 50 transparency regime described above: none of it reaches a defence AI system operating under that exclusion. That split is deliberate, and it mirrors how allied states have long kept defence procurement outside civilian product-safety regimes. It also means the accountability architecture built for enterprise generative AI over the past two years, evaluation, documentation, human oversight, sits entirely outside the systems where an accountability gap carries the highest stakes.

When your compliance team next reports on "the EU AI Act," do you know which of its two clocks they are actually reporting on, and could they tell you if you asked this afternoon?


The views expressed in this article are entirely my own, informed by more than 30 years of professional experience in architecture, security, and technology leadership in New Zealand. They do not represent the views of my employer, any government agency, or the New Zealand government. My commentary on legislation and policy is analytical, drawing on publicly available sources and my professional expertise in architecture, security, and AI governance. I follow the Public Service Commissioner's Code of Conduct for the Public Sector and social media guidance.


Andreas Hamberger is a New Zealand leader in Architecture & Security and Associate Member of the Institute of Directors. The Hamberger Report: Generative AI 2026 provides enterprise leaders with evidence-based analysis of the AI landscape.


I use AI tools, including Sudowrite, Claude, Perplexity AI, DeepSeek AI, ChatGPT, Grok, Copilot, Openart and Gemini, as deliberate production tools, not ghostwriters. This is consistent with my position: AI amplifies human judgement; it does not replace it. The frameworks, arguments, and editorial decisions in this series are original work. AI accelerated the process. The thinking is mine.


[1] artificialintelligenceact.eu. "Enforcement of Chapter V under the EU AI Act." 2026. https://artificialintelligenceact.eu/enforcement-of-chapter-v-under-the-eu-ai-act/

[2] artificialintelligenceact.eu. "Article 99: Penalties." Regulation (EU) 2024/1689. https://artificialintelligenceact.eu/article/99/

[3] artificialintelligenceact.eu. "Article 2: Scope." Regulation (EU) 2024/1689. https://artificialintelligenceact.eu/article/2/

[4] MinterEllison New Zealand. "AI transparency: global obligations for NZ businesses." 30 July 2026. https://minterellison.co.nz/insights/ai-transparency-global-obligations-for-nz-businesses

[5] European Commission, Digital Strategy. "AI Omnibus enters into force." 2026. https://digital-strategy.ec.europa.eu/en/news/ai-omnibus-enters-force

[6] mlq.ai. "Top European CEOs call for two-year delay in EU AI Act implementation." 3 July 2025. https://mlq.ai/news/top-european-ceos-call-for-two-year-delay-in-eu-ai-act-implementation/

[7] IAPP. "European Commission holds firm on AI Act implementation timeline." 2025. https://iapp.org/news/a/european-commission-holds-firm-on-ai-act-implementation-timeline

[8] NicFab Blog. "Digital Omnibus AI: Council adoption." 2026. https://www.nicfab.eu/en/posts/digital-omnibus-ai-council-adoption/

[9] howtheyvote.eu. "Vote record: Digital Omnibus on AI, 16 June 2026." https://howtheyvote.eu/votes/193665

[10] Ministry of Business, Innovation and Employment. "Artificial Intelligence Strategy and business guidance now available." 8 July 2025. https://www.mbie.govt.nz/about/news/artificial-intelligence-strategy-and-business-guidance-now-available

[11] German-New Zealand Chamber of Commerce (AHK NZ). "Doing business in Europe: new AI disclosure rules are here." 2 August 2026. https://neuseeland.ahk.de/en/neuigkeiten/2026/jul-2026/doing-business-in-europe-new-ai-disclosure-rules-are-here

[12] C2PA (Coalition for Content Provenance and Authenticity). "C2PA: Providing origins of media content." Joint Development Foundation, Linux Foundation. Independently verified at write time, 6 August 2026. https://c2pa.org/

Next
Next

The Benchmark You Cannot Audit