← All insights

The August clock

By Gary Trautmann · · eu ai act · board governance · vendor management · trace framework · brief

The general-purpose AI obligations of the EU AI Act enter the enforcement phase on August 2, 2026. That is three weeks from this issue. For anyone in financial services, healthcare, or HR tech who operates models in the EU market or processes EU data subjects, the calendar has shifted from preparation to evidence.

This is the first Veracity Brief. Each Tuesday I will send three things. The week’s read on the AI governance question your board most needs to understand. A worked example using the TRACE framework. One specific action you can take this week.

The week’s read

The provisions enforced August 2 are the ones that apply to providers of general-purpose AI models. The four obligations regulators will check for first are documentation of training data and methodology, copyright compliance procedures, transparency to downstream deployers, and serious-incident reporting. Each obligation requires written artifacts. None of them are satisfied by attestation alone.

The downstream effect is broader than most boards have priced in. If you deploy a third-party AI system in production, you inherit dependency on that provider’s compliance posture. Their gaps become your enforcement exposure. The vendor questionnaire process most enterprises run today does not yet ask the right questions. The Article 50 transparency obligations on the deployer side, which extend to AI-generated content disclosure and emotion recognition systems, also tighten the requirements on internal documentation.

The pattern boards should see is not a regulatory event. It is a documentation event. Companies that lose under enforcement will not lose because they were doing AI badly. They will lose because they could not produce evidence of what they were doing. That is a governance failure, not a technology failure.

The worked example

A regional health plan deploys a third-party AI tool to triage member appeals. The vendor markets the tool as an efficiency accelerator. Member services routes denial appeals through the tool, which surfaces a recommended disposition. A nurse reviews and finalizes the disposition.

Run TRACE on it.

Traceability. Can you point to the specific model version, training methodology, and update history of the vendor system? Most contracts as written today say no. The vendor reserves the right to update the model. You inherit dependency on a moving target.

Responsibility. Who at the health plan is named as accountable for the AI’s outputs? If the answer is the nurse who clicks accept on the disposition, you have moved compliance risk to a clinical reviewer with no authority over the model itself. That is a misallocation of accountability that will not survive scrutiny.

Authority. Does the nurse have authority to override the AI? Yes. Does the nurse have authority to stop using the AI for a category of cases that show drift? Usually no. Authority that exists at the case level but not at the system level is performative authority.

Change. When the vendor pushes a model update, what triggers your re-review? The standard answer is nothing. The model changed and operations continued. That is a regulatory finding waiting to happen.

Evidence. Can you produce, on a specific case from six months ago, the exact recommendation surfaced, the data inputs, the model version, and the human override decision? Most health plans cannot. The vendor system was not designed to make this exportable to the deployer.

A TRACE assessment on this scenario typically returns Partial. Not Operational. Not Gap. Partial. The architecture is reasonable, the human review is real, the intent is clear. The structural documentation is not in place. That is the most common finding pattern across health, financial services, and HR tech right now.

The action this week

Pull the contract on your most operationally significant third-party AI system. Read three specific sections. First, does the contract require the vendor to notify you when the model materially changes. Second, does the contract obligate the vendor to provide documentation that survives enforcement scrutiny under the EU AI Act, the Colorado AI Act, or NYC Local Law 144 if any of those apply to you. Third, does the contract specify what audit cooperation looks like in the event a regulator requests evidence.

If those three sections do not exist, or read as vendor-favorable boilerplate, you have a documented gap. That gap is the basis for either a vendor remediation request, a contract amendment, or a re-procurement decision. None of those are immediate. All of them are time-sensitive given the August calendar.

If you want to compare your current TRACE posture against the framework, the 20-minute diagnostic returns a tier classification and a worked finding. Free, no email required to take it.

The next Brief lands Tuesday. The topic will be the Colorado AI Act consumer notice provisions and what they actually require versus what vendor templates are providing.

Gary