惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

D
Darknet – Hacking Tools, Hacker News & Cyber Security
宝玉的分享
宝玉的分享
Hugging Face - Blog
Hugging Face - Blog
Recent Announcements
Recent Announcements
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Vercel News
Vercel News
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
T
The Blog of Author Tim Ferriss
博客园 - 司徒正美
Cyberwarzone
Cyberwarzone
S
Securelist
www.infosecurity-magazine.com
www.infosecurity-magazine.com
The GitHub Blog
The GitHub Blog
云风的 BLOG
云风的 BLOG
T
Tenable Blog
NISL@THU
NISL@THU
博客园 - 三生石上(FineUI控件)
V
Vulnerabilities – Threatpost
N
Netflix TechBlog - Medium
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
S
SegmentFault 最新的问题
WordPress大学
WordPress大学
C
CXSECURITY Database RSS Feed - CXSecurity.com
G
Google Developers Blog
Forbes - Security
Forbes - Security
月光博客
月光博客
博客园 - 叶小钗
Spread Privacy
Spread Privacy
Last Week in AI
Last Week in AI
H
Help Net Security
TaoSecurity Blog
TaoSecurity Blog
Scott Helme
Scott Helme
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
Stack Overflow Blog
Stack Overflow Blog
N
News and Events Feed by Topic
爱范儿
爱范儿
aimingoo的专栏
aimingoo的专栏
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
The Hacker News
The Hacker News
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
P
Privacy International News Feed
D
DataBreaches.Net
O
OpenAI News
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
Latest news
Latest news
J
Java Code Geeks
Project Zero
Project Zero
V
V2EX
Security Latest
Security Latest
AI
AI

DEV Community

Authentication Security Deep Dive: From Brute Force to Salted Hashing (With Java Examples) Why AI Systems Don’t Fail — They Drift Spilling beans for how i learn for exam😁"Reinforcement Learning Cheat Sheet" I Replaced Chrome with Safari for AI Browser Automation. Here's What Broke (and What Finally Worked) How Python Borrows Other People's Work The $40 Architecture: Processing 1 Billion API Requests with 99.99% Uptime Vibe Coding: A Workflow Guide (From Zero to SaaS) Most webhook security guides protect the wrong side. The scary part is delivery. Headless CMS for TanStack Start: Build a Blog with Cosmic EU Age Verification App "Hacked in 2 Minutes" — What Actually Happened Comfy Cloud’s delete function does not actually remove files Running AI Models on GPU Cloud Servers: A Beginner Guide Event-driven media intelligence with AWS Step Functions and Bedrock I scored 500 AI prompts across 8 quality dimensions — here's what broke How to Call Google Gemini API from Next.js (Free Tier, No Backend Needed) The Portal Protocol: Reclaiming Human Connection in the Age of AI How to Fix Your Team's Scattered Knowledge Problem With a Self-Hosted Forum Intro to tc Cloud Functors: A Graph-First Mental Model for the Modern Cloud Designing Multi-Tenant Backends With Both Ownership and Team Access I Built a Neumorphic CSS Library with 77+ Components — Here's What I Learned PostgreSQL Performance Optimization: Why Connection Pooling Is Critical at Scale Cómo construí un SaaS multi-rubro para gestionar expensas en Argentina con FastAPI + Vue 3 🚀 I Built an Ethical Hacking Scanner Tool – Open Source Project I Replaced /usage and /context in Claude Code With a Single Statusline A Pythonic Way to Handle Emails (IMAP/SMTP) with Auto-Discovery and AI-Ready Design I Collected 8.9 Million Polymarket Price Points — Here's What I Found About How Markets Really Move EcoTrack AI — Carbon Footprint Tracker & Dashboard Everyone's Using AI. No One Agrees How. 5 self-hosted ebook managers worth trying in 2026 Building Your First AI Agent with LangChain: From Chatbot to Autonomous Assistant Common SOC 2 Failures (Real World) Stop Vibe-Checking Your AI App: A Practical Guide to Evals How to Use SonarQube and SonarScanner Locally to Level Up Your Code Quality Your Next To-Do App Is Dead — I Replaced Mine with an OpenClaw AI Sign a Nostr event in 60 lines of Python using coincurve — no nostr-sdk, no nbxplorer, no rust toolchain ITGC Audit Explained Like You’re in Big 4 Patch Tuesday abril 2026: Microsoft parcha 163 vulnerabilidades y un zero-day en SharePoint Stop scraping everything: a better way to track competitor price changes Listing on MCPize + the Official MCP Registry while routing payments OUTSIDE the marketplace — how I kept 100% of my x402 revenue Building an AI-Powered Risk Intelligence System Using Serverless Architecture Why We Ripped Function Overloading Out of Our AI Toolchain Testing AI-Generated Code: How to Actually Know If It Works SaaS Churn Is Killing Your Business. Here Is What to Do About It (Without a Support Team) The Speed of AI Is No Longer Linear - And Self-Improving Models Are Why How to Implement RBAC for MCP Tools: A Practical Guide for Engineering Teams From Standard Quote to Persuasive Proposal: AI Automation for Arborists I built a CLI that scaffolds complete multi-tenant SaaS apps Axios CVE-2025–62718: The Silent SSRF Bug That Could Be Hiding in Your Node.js App Right Now The dashboard that ended our friendship Data Pipelines Explained Simply (and How to Build Them with Python) The Hidden Cost of AI Systems Nobody Talks About. undefined vs undeclared, and how typeof behaves Switching from file-based jobs to NATS/Kafka in Rust without changing code io_uring Adventures: Rust Servers That Love Syscalls Why Agentic AI is Killing the Traditional Database The POUR principles of web accessibility for developers and designers Quantum Neural Network 3D — A Deep Dive into Interactive WebGL Visualization How To Install Caveman In Codex On macOS And Windows Automation Pipeline Reliability: Why Your Workflow Breaks When Nobody Is Watching I Built an 'Open World' AI Coding Agent — It Works From ANY Folder From Freelancing to Product: A Tech Service Company's SaaS Transformation China's AI Giants: Adding Tencent Hunyuan & ByteDance Doubao to AI University (74 Providers) On the Vibe Coders and Their Lies clerk: Auto-Summarize Your Claude Code Sessions AI Weekly — 2026/04/10–04/17 | The Model Lockdown Is Here, but the Toolchain Is the Real Battleground AI 週報 — 2026/04/10–2026/04/17 模型封鎖潮來了,但工具鏈才是真戰場 Maybe this is how Open-Source apps are born... 🚀 Fine-Tune LLMs with LoRA and QLoRA: 2026 Guide tRPC v11 + Next.js App Router: End-to-End Type Safety Without the Boilerplate ShadCN UI in 2026: Why I Stopped Installing Component Libraries and Started Owning My Components SaaS Billing in React Server Components: Stripe + Supabase Without a Single `useEffect` Join our DEV Weekend Challenge — $1,000 in Prizes Across TEN winners! Submissions Due April 20 at 6:59 AM UTC. Implementing FSRS Spaced Repetition in Flutter + Supabase — Adding Memory Science to an AI Learning App "I Texted My Localhost From the Train — Claude Code Fixed the Bug Before I Got Home" I Built a Sales Prep AI and It Went Deeper Than Expected Design to Code #2: One JSON, Eleven Outputs Solving the 100M-Row Problem: A Summary Table Pattern for High-Volume Push Notification Logs Flutter Web With Wasm: What Actually Changes For Developers I Built 50 Royalty-Free Soundtracks for My Side Project in a Weekend Using AI Music Generation The Vibe Coding Security Checklist: 7 Things to Check Before You Ship Stop Letting Googlebot Guess Fix Your React App's SEO Right Desconstruindo o Streaming do LinkedIn: Como Criar um Engine de Extração de Vídeo de Alta Performance com HLS e FFmpeg (EDA Part-1) EDA (Exploratory Data Analysis) Explained With Real Life — Why Looking at Your Data Is the Most Important Step in Machine Learning Brand Relationship Management at Scale: Our 4-Touch Outreach System for 200+ Brands Why String.fromEnvironment() Might Return an Empty String in Dart JGuardrails 1.0.0 — Hardening Java LLM Apps Against Jailbreaks, Toxicity, and Prompt Injection Plan and Schedule a Full Week of Threads Content From One Claude Conversation Coding Cat Oran Ep3, Five Tables Changed Everything Updated: BFF Pattern I'm done watching freelancers get buried by 200 proposals. So I'm building the alternative. This is my first post BFS Algorithm in Java Step by Step Tutorial with Examples Tracking LLM Pricing Monthly: An Open Dataset for 22 AI Models How We Measure Content ROI on a Comparison Site: Revenue Attribution Without Perfect Data Introducing Nova AI Ops: The AI-Native Operating System for SRE Teams I built a free desktop video downloader for Windows — Grabbit How Talkie OCR Helps Vision-Impaired & Dyslexic Users Read the World Around Them VRCFaceTracking安装和iPhone面捕配置教程,有bug Even CrowdStrike Can't See Your Agents The Automation Gold Rush: What n8n Workflows and Claude Are Opening Up for Developers Right Now
The EU AI Act in 2026: Reading the Law After the Omnibus
Matthias | S · 2026-05-25 · via DEV Community

Two weeks ago, the EU Council and Parliament reached a provisional deal that pushed the AI Act's biggest enforcement wave back by sixteen months. That sounds like a win for everyone behind on compliance. It is not. The August 2, 2026 deadline still triggers a long list of obligations, and the part of the law that moved still becomes binding on December 2, 2027. Eighty days is a short window if your AI inventory is still a guess and your transparency wiring is still a wishlist.

This is the map we use at StudioMeyer to think about the law, the dates, and the engineering work that has to happen between now and the end of next year. We host AI products in Frankfurt and we build memory systems for European customers. We have written this once for ourselves, and we are writing it again here because most of the things published about the AI Act this month are either too legal to be useful or too vague to be wrong. We also offer dedicated advisory engagements for teams that want help mapping their systems to the law, so the second half of this article describes how we approach that work in practice.

The deadlines that already happened

The Act (Regulation (EU) 2024/1689) entered into force on 1 August 2024 and is being switched on in phases. Two of those phases are already behind us.

On 2 February 2025, the prohibited practices in Article 5 became enforceable. Social scoring, manipulative subliminal techniques, untargeted facial image scraping, biometric categorisation that infers sensitive attributes, and emotion recognition in workplaces and schools are all banned outright. The fine for breaking these rules is up to €35 million or 7 percent of global annual turnover, whichever is higher. On the same date, the AI literacy obligation in Article 4 turned on, requiring providers and deployers to make sure their staff understand the systems they ship and use.

On 2 August 2025, the rules for general-purpose AI models in Articles 51 to 56 became binding. Foundation model providers (Anthropic, OpenAI, Google, Mistral, Meta, and others) now have to publish a training data summary, maintain technical documentation, share information with downstream providers, and follow a copyright compliance policy that respects the Text and Data Mining opt-out. The voluntary GPAI Code of Practice published on 10 July 2025 is the Commission's preferred route to demonstrate compliance and reduce administrative burden, and most major providers have signed it.

If your team uses Claude or GPT-4 through an API, you do not inherit the model provider's obligations. You inherit the obligations of being a deployer or, more often, a provider of the system you built on top.

The shift that happened on 7 May 2026

For the past year, every compliance article ended with the same sentence: 2 August 2026 is the date the rest of the Act becomes enforceable. That sentence is now partly wrong.

On 7 May 2026, the Council and Parliament announced a provisional political agreement on the Digital Omnibus, a targeted simplification package the Commission proposed in November 2025. The reason was prosaic. Harmonised standards are not finished, notified bodies are not in place, and most member states are behind on designating their competent authorities. The Commission decided that demanding compliance with a framework that does not yet have the supporting infrastructure was setting the law up to fail.

If the agreement is formally adopted, four things change. Annex III high-risk AI systems (standalone systems used in employment, credit, education, biometrics, critical infrastructure, law enforcement, migration, and justice) become enforceable on 2 December 2027 instead of 2 August 2026, as confirmed by both Hogan Lovells and Orrick. Annex I high-risk AI inside regulated products (medical devices, vehicles, machinery, lifts) moves from August 2027 to 2 August 2028. The Article 50(2) watermarking obligation for AI content providers shifts to 2 December 2026 instead of August. And the deadline for member states to set up an AI regulatory sandbox moves from August 2026 to August 2027, with a parallel EU-level sandbox operated by the AI Office for SMEs, start-ups, and small mid-caps.

Two important caveats. The Omnibus is a provisional agreement, not adopted law. It still has to go through formal trilogue confirmation and publication in the Official Journal. Until then, the current legal baseline remains 2 August 2026. And every obligation that is not on the postponement list still hits in August.

What still triggers on 2 August 2026

The deployer-facing parts of Article 50 are not delayed. If your chatbot speaks to people, every conversation must start with a disclosure that the user is interacting with AI. If your product generates synthetic content, the output must be marked. If a deepfake leaves your system, the recipient must be told. Voice agents that ring real callers are bound by the same rule, even though the underlying compute lives in California.

GPAI enforcement powers also become fully active. The European AI Office gains the ability to request information from model providers, demand access to the models themselves, and issue corrective measures or recalls if a foundation model violates Articles 53 to 55. The penalty ceiling for GPAI breaches is €15 million or 3 percent of global turnover.

National competent authorities must be designated and operational. Penalty regimes have to be written into national law. And the entire enforcement framework around Annex III, even with the Omnibus delay, has to be ready to switch on, because December 2027 is closer than it looks.

Risk tiers in plain language

The Act sorts every AI system into one of four risk tiers, and your tier decides your work.

Unacceptable risk is the Article 5 list above. No deployment in the EU, no exceptions.

High risk is the long list in Annex III plus AI embedded in regulated products. If your system makes or shapes decisions in employment, credit, education, essential services, law enforcement, biometrics, justice administration, or migration, you are likely high risk. The obligations are heavy. Documented risk management (Article 9), training data governance (Article 10), Annex IV technical documentation (Article 11), automatic logging with at least six months of retention (Article 12), transparency to deployers (Article 13), human oversight that allows intervention and override (Article 14), and demonstrated accuracy, robustness, and cybersecurity (Article 15). For deployers in this tier, a fundamental rights impact assessment is required before first use (Article 27).

Limited risk is the chatbot tier. Your obligation is Article 50 transparency, which is short to read and not short to implement well. Tell the user they are talking to AI at the start of the conversation, give them a path to a human if the conversation goes off the rails, and label any AI-generated content the system emits.

Minimal risk is everything else. Spam filters, recommendation engines that do not touch protected decisions, autocomplete, and the long tail of internal tooling. No specific AI Act obligations, although GDPR and sector law still apply.

The boundary case that catches most teams is the AI agent that takes actions on a user's behalf. A customer support chatbot is limited risk. The same chatbot wired to a CRM that can refund payments, send emails, or delete records is closer to high risk. The classification follows the consequences, not the model.

What this means for AI agent builders

We build agents for a living. The Article 14 and Article 15 requirements are the ones that change how you write code, not just how you write policy.

Article 14 requires that an operator can interrupt the agent. In our base agent class, that translates to iteration limits, hard timeouts, and a kill switch the operator can fire mid-execution. Tool calls that do anything irreversible (sending email, moving money, deleting data, calling an external API that costs real money) need an explicit human approval step. The phrase the Act uses is "effective human oversight", and effective is doing the heavy lifting.

Article 12 requires automatic logging of events over the system's lifetime. That means every tool call, every LLM round-trip, every decision branch, every input the agent saw, and every output it produced. Logs must be retained long enough to support post-market monitoring and incident reporting (Articles 72 and 73), and deployers must keep their copies for at least six months under Article 26.

Article 15 requires robustness. Input validation that catches prompt injection, output validation that stops hallucinated data from propagating, resource limits that prevent token-bombing and runaway loops, and adversarial testing against known agent failure modes. None of this is novel security engineering. The change is that for high-risk agents, it is now legally required, with documentation.

Germany: the Bundesnetzagentur takes the wheel

For teams in DACH, the practical question is who knocks on your door if something goes wrong. On 11 February 2026, the German Federal Cabinet approved the KI-MIG draft bill (KI-Marktüberwachungs- und Innovationsförderungsgesetz), and the answer is the Bundesnetzagentur, the Federal Network Agency. It will serve as Germany's primary market surveillance authority, notifying authority, and single point of contact under the Act.

The BNetzA is not building this from scratch. It already runs market surveillance for the Radio Equipment Directive and the Ecodesign rules, and it coordinates the German implementation of the Digital Services Act. A new internal body, the independent AI Market Surveillance Chamber, will handle sensitive cases (law enforcement, border management, justice), and a Coordination and Competence Centre called KoKIVO will pool AI expertise across sectors.

Two things matter in the meantime. The KI-Service Desk inside the BNetzA has been operational since July 2025 and is one of the few live SME compliance support channels in the EU. And BaFin retains sector-specific authority for high-risk AI directly tied to regulated financial activities, so banks and insurers will face two supervisors, not one. The KI-MIG is still going through Bundestag and Bundesrat, with second and third readings expected before the summer recess.

How we keep our own AI products compliant

We run our products on European infrastructure. Memory MCP and the rest of our SaaS surfaces are hosted on Hetzner in Frankfurt, not on AWS Frankfurt, which sits under the US CLOUD Act regardless of the data centre. The distinction matters more than most procurement teams realise.

Our code is open where it can be. The MCP server implementations for memory, CRM, GEO, and crew live on the studiomeyer-io GitHub organisation under MIT, so customers can read what we do with their data before they sign anything. Multi-tenant isolation runs at row level with explicit tenant IDs threaded through every query, and a static test in CI breaks the build if a handler forgets to include the tenant filter.

The memory product itself is built around an audit trail. Decisions, learnings, and entity observations carry a source, a date, and a confidence score. That is useful for the AI engineer who wants to know why a memory was stored, and it is the same shape of artefact the AI Act asks for when it talks about traceability and post-market monitoring. We did not build it for compliance. We built it because we got tired of memories that lied to us. The compliance fit is a bonus.

Every chatbot we ship discloses its nature on first contact, and the Article 50 transparency wiring is shared across our products through a single library. We also maintain a DACH Legal Playbook inside the Academy that walks through GDPR, AI Act, and German implementation overlaps for the teams who work with us.

How we help customers comply

Most of the EU AI Act work for a small or mid-sized AI shop is not legal work. It is engineering and documentation. We offer dedicated advisory engagements for teams that want to stop guessing where they stand.

A discovery workshop maps every AI system in your stack to its risk tier. We have done this for chatbots that turned out to be high-risk agents, and for elaborate ML pipelines that turned out to be minimal-risk infrastructure. The classification is half the battle. The other half is knowing which obligations attach.

For deployers and providers heading into high-risk territory (the December 2027 cliff if the Omnibus passes, August 2026 if it does not), we set up the Annex IV technical file, the Article 9 risk management process, and the Article 12 logging that an audit team can actually read. We integrate the Article 14 human oversight pattern into your agent framework instead of bolting it on afterwards.

For chatbot and voice-agent teams, we wire the Article 50 transparency disclosure into your existing UX without breaking conversation flow, build the human escalation path, and document the result for your file.

For teams whose AI memory or knowledge layer sits on a US cloud and now has to move, we have done the Hetzner Frankfurt migration on our own products and on customer systems. The trade-offs (latency, region pinning, DPA chains, Schrems II evidence) are concrete and known.

Engagements range from a half-day classification workshop to a full audit-readiness package with documentation, logging, and oversight patterns deployed in code. We do not sell certifications, and we do not pretend to be lawyers. We sit between the legal advice you already have and the systems you actually have to ship.

The one thing to do this week

Pick the single highest-risk AI system you have in production or in development, and write down its classification under Annex III in one paragraph. If you cannot finish the paragraph, that is the gap. If the paragraph is easy, do it for the next system. The shape of an EU AI Act compliance programme is not different from the shape of any other engineering programme. The first thing you build is a list of what you have. Everything else follows.

The Digital Omnibus may give you sixteen more months on the heavy work. The deployer transparency obligations, the GPAI enforcement, and the national supervisor switches do not wait. August 2 is still a date that matters. So is December 2 if your training data summary is incomplete or your watermarking logic is not in code yet. And December 2027 sounds far until you start writing a fundamental rights impact assessment from scratch.

If you want help reading your stack against the law, we are here. The map is easier to draw with two pairs of eyes on it.


Originally published on studiomeyer.io on May 14, 2026. StudioMeyer is an AI and design studio on Mallorca — we build memory-first AI systems and AI-ready websites for European SMBs. Open-source MCP servers on GitHub.