KaNun Advisory Book a briefing
Insight 002 — August 2026 · M. Kanaventi · 6 min

Compliance has a date. Your agents don't.

On 2 August 2026 — yesterday — the European Union's AI Act reached its most consequential milestone yet. Transparency obligations under Article 50 came into force: systems that converse with people must disclose that they are AI, and synthetic media must be labelled. On the same date the Commission and the AI Office gained the power to investigate and fine providers of general-purpose AI models, up to €15 million or 3% of global turnover, whichever is greater.

Two weeks earlier, the Digital Omnibus moved the Act's high-risk obligations — the Annex III categories covering hiring, credit, education, and essential services — from this month to December 2027. Annex I product-safety obligations moved to August 2028.

If your organisation reads those two facts and concludes it has sixteen months, this essay is for you.

What the deadline actually measured

Article 50 is a disclosure regime. It asks whether a user knows they are talking to a machine, and whether generated content is labelled as generated. These are worthwhile requirements. They are also, in control terms, close to free: a banner, a footer, a watermark, a paragraph in the terms of service.

Nothing that came into force yesterday asks whether an AI system in your environment can take an action. Nothing asks what credentials it holds. Nothing asks whether you would notice if it used them at three in the morning.

That is not a criticism of the Act. Regulation sets a floor and moves slowly by design. It is a caution about what a compliance date can be mistaken for. A company that satisfies Article 50 has published a disclosure. It has not established that anything in its environment can stop an agent.

The gap the calendar hides

Consider what the same twelve months produced outside the regulatory timeline.

Check Point's 2026 AI Security Report documents intrusions in which AI ran exploitation workflows autonomously — thousands of commands across dozens of sessions, with minimal human direction — and notes that the interval between a vulnerability becoming public and a working exploit existing is now measured in hours. Between October 2025 and May 2026, the report finds, the overwhelming majority of organisations experienced at least one high-risk AI interaction every month.

The infrastructure layer tells the same story. The Model Context Protocol, which connects AI agents to tools and data across a growing share of enterprise deployments, accumulated a documented incident record through the first half of 2026: a trojanised package distributed through public registries harvesting developer credentials in February; an authentication bypass in an exposed management endpoint in March; a transport-layer flaw in April affecting tooling with more than 150 million downloads. The recurring pattern in every one of them is the same — over-privileged credentials meeting untrusted input.

Meanwhile Darktrace's 2026 survey of 1,500 security professionals found 92% concerned about the security impact of AI agents, and only 37% able to say their organisation has a formal AI policy at all. The report's own framing of the core problem is worth quoting directly: security teams struggle to identify all the agents acting within their environment and supply chain.

Not govern. Identify.

Three questions the deadline never asks

In the first of these essays I set out four questions most management teams cannot yet answer about the AI systems operating inside their environment. The regulatory milestone adds three more, and these are the ones a director should raise at the next audit or risk committee.

  1. Which of our AI systems are in scope for Article 50, and who determined that? The answer reveals whether anyone has an inventory. A company that cannot scope the disclosure requirement does not know what it is running — and the scoping exercise is the cheapest inventory you will ever commission.
  2. What did we do about the high-risk deferral — pause the work, or re-plan it? December 2027 is a date to prepare against, not a reprieve. Teams that stood down after the Omnibus will restart in 2027 with the same gaps and less time.
  3. For each commitment in our AI policy, what technically enforces it? This is the question that separates governance from paperwork, and it is answerable in an afternoon. Count the commitments whose answer is "nothing." That number is your actual position.

What good looks like this quarter

Three moves, none of which requires waiting for a regulator.

Treat the Article 50 scoping exercise as an inventory. You are already required to determine which systems interact with people. Extend the same exercise one column to the right: which systems can take actions, hold credentials, or reach production data. You will have built the agent inventory as a by-product of compliance work already budgeted.

Set permission boundaries before the next integration, not after. Every MCP incident this year traces back to a credential that was broader than the task required. Scoped tokens, expiry, and isolation are unglamorous and they are the whole ballgame.

Run one tabletop where the adversary is your own agent. One afternoon, executive team, a scenario in which an authorised system with legitimate access acts outside intent. The exercise surfaces detection and reconstruction gaps faster and more cheaply than any assessment, including mine.

The companies that come out of this period well will not be the ones that adopted AI most slowly or documented it most thoroughly. They will be the ones that can demonstrate — to a board, a regulator, or a customer — that what their policy promises, their environment enforces.

Regulators publish deadlines. Agents do not.