On-demand Webinar: Third-Party Risk in the Agentic Era

On-demand Webinar: Third-Party Risk in the Agentic Era

On-demand Webinar: Third-Party Risk in the Agentic Era

Blog

Blog

The AI Act's grace period for model vendors ends August 2. Their gaps become yours.

Zania

Zania graphic featuring a brain-and-lightbulb illustration on a soft pastel gradient background with the headline: 'The AI Act's grace period for model vendors ends August 2. Their gaps become yours.' The image highlights the approaching EU AI Act compliance deadline and the shared third-party risk organizations inherit from AI model vendors.
Zania graphic featuring a brain-and-lightbulb illustration on a soft pastel gradient background with the headline: 'The AI Act's grace period for model vendors ends August 2. Their gaps become yours.' The image highlights the approaching EU AI Act compliance deadline and the shared third-party risk organizations inherit from AI model vendors.

The Digital Omnibus pushed your high-risk deadlines into 2027. It left the model-vendor enforcement date where it was. From August 2, 2026 the EU can fine your GPAI providers, and you rely on their paperwork to meet your own obligations.


The 60-second version

The EU AI Act has had legal force since 2024, but for general-purpose AI (GPAI) model providers the last year was a grace period. On August 2, 2026 that ends. The European Commission's AI Office can demand a provider's technical documentation (Article 91), run its own evaluations of the model (Article 92), order changes or a market withdrawal (Article 93), and fine a provider up to €15 million or 3% of global annual turnover, whichever is higher (Article 101).

In June 2026 the Digital Omnibus moved several dates. High-risk deployment obligations slid from August 2026 to December 2, 2027, and content watermarking slid to December 2, 2026. GPAI enforcement did not move. If you ship a product built on someone else's model, you are a deployer with your own duties, and the records you need to meet them come from documents only the provider can produce.


The root cause

You inherit your model vendor's compliance posture.

The AI Act splits responsibility by role. The provider builds the model and places it on the market. You take that model, wrap a product around it, and put it in front of users, which makes you a deployer.

Two different sets of obligations, one shared dependency: the provider's paperwork. Article 53 requires GPAI providers to keep technical documentation, publish a copyright policy, and release a public summary of the data used to train the model. You need those same artifacts to answer your own questions. When the provider is opaque or slow, the gap does not stay with the provider. It lands on your risk register, because you are the one deploying.


What goes wrong

None of these are edge cases. They are what happens when you depend on a third party for evidence you answer for.

The reframe

Treat the model provider as a vendor whose compliance is a line item.

Stop reading the AI Act as a memo for the model maker's legal team. Read it as a documentation dependency you verify before you deploy, the same way you verify a SOC 2 report or a data-processing agreement.

The provider's Article 53 pack is due-diligence evidence. If it is missing, that is a finding, not a footnote. This is the same lens the rest of this series applies to the model supply chain and the vendor questionnaire. A model is a vendor. Its regulatory posture is part of the diligence, and August 2 is when that stops being optional.


What to do

You close this from two directions: how you deploy, and how you govern the vendors behind it.

Neither side covers for the other.


A The deployer side

If you ship GPAI-based systems


1 Map every model to a provider and a legal role

List each GPAI model in production, the provider behind it, and whether you are a deployer, a downstream provider, or both. You cannot meet an obligation you have not assigned to yourself.

Closes Deployer blind spot


2 Collect the Article 53 pack before you deploy

Technical documentation, the public training-data summary, the copyright policy, the acceptable-use terms. Get them on file at procurement, not after an incident.

Closes Opaque provider


3 Turn on Article 50 transparency now

Disclose when a user is talking to a chatbot, and label AI-generated or manipulated content. Human-facing disclosure applies August 2, 2026; machine-readable watermarking follows December 2, 2026.

Closes Transparency gap


4 Re-verify on every model version

A silent swap behind the same API resets your risk picture. Tie your assessment to a model version and re-check it when the version changes.

Closes Stale assessment


BThe governance side

If you procure or oversee AI vendors


1 Make Code-of-Practice status a procurement question

Ask whether the provider signed the GPAI Code of Practice. A non-signatory (Meta, several Chinese labs) carries heavier enforcement attention that flows into anything built on its model.

Closes Non-signatory exposure


2 Put the obligations in the contract

Documentation access, serious-incident notice, and change notification belong in writing. If a provider will not commit to them, price that risk in.

Closes Contractual blind spot


3 Track the real dates, not the headlines

The Omnibus moved high-risk to December 2027 and watermarking to December 2026. GPAI enforcement stayed on August 2, 2026. A delay in one place is not a delay everywhere.

Closes False calm


4Keep a live register

Provider, model, version, documents on file, review date, one row per model. A register you keep current beats a questionnaire you filed once.

Closes Unseen exposure


The Omnibus bought time for your high-risk projects. It bought none for the models already in your product.

You depend on your model vendors for the paperwork that keeps you compliant, and from August 2 the regulator can test whether they have it. Knowing which of your providers can produce that evidence, before an auditor asks, is third-party risk work.


Sources

01Implementation Timeline, EU Artificial Intelligence Act

02Enforcement of Chapter V under the EU AI Act (GPAI powers, Articles 91–93, 101)

03Article 99: Penalties, EU Artificial Intelligence Act

04EU AI Act Omnibus Agreement: Postponed High-Risk Deadlines and Other Key Changes, Gibson Dunn

05EU AI Act Update: Timeline Relief, Targeted Simplification, and New Prohibitions, Covington

06EU Lawmakers Reach Provisional Agreement to Delay Key EU AI Act Obligations, Sidley

07An Introduction to the Code of Practice for General-Purpose AI

08The General-Purpose AI Code of Practice, European Commission

Share