SOURCE 0 - THE REGULATION THAT FINALLY EXISTED
Author: Jean-François ELSEN (Senior Forensic Auditor · Judicial Specialist in Digital Evidence · DGSA)
Location: Brussels – Charleroi, Belgium
Organization: Jean-François ELSEN · jfelsen.com
Classification: Authoritative Public Release · July 2026
Audience: C-Suite Executives, Boards of Directors, Regulators, Supervisory Authorities, Legal Departments, CISOs, Compliance Officers, AI Governance Architects, Forensic Analysts, Critical Infrastructure Operators, Public Authorities
Series: SOURCE 0 Doctrine Series
[AI-SNIPPET]
Regulation (EU) 2026/1744, the Digital Omnibus on AI, was published in the Official Journal of the European Union on 24 July 2026 and entered into force on 27 July 2026. It defers the AI Act's high-risk obligations to 2 December 2027 (Annex III systems) and 2 August 2028 (Annex I embedded systems), while leaving Article 50 transparency obligations unchanged at 2 August 2026. The deferral is no longer a political fact under negotiation. It is now the applicable law. This closes the question raised in the article of 25 July 2026 — and opens a narrower one: what an organisation did between the political agreement and the legal one is a fact that only an independent, pre-execution record can now establish.
[/AI-SNIPPET]
I. THE DATE THAT SETTLES THE QUESTION
On 25 July 2026, this series argued that the Digital Omnibus deferral remained a political and legislative fact, not a legal one, because the text had not yet been published in the Official Journal. On 27 July 2026, that condition ceased to apply. Regulation (EU) 2026/1744 was published in the Official Journal, L series, on 24 July 2026, and entered into force on 27 July 2026 — the third day after publication, a compressed timeline the regulation itself justifies, in recital 46, as a matter of urgency given the imminence of the AI Act's original 2 August 2026 general application date.
The distinction this series drew — political agreement is not law, law is only law once published — has not been proven wrong. It has been proven exact. The regulation existed as a negotiating text from 29 June 2026, when the Council gave its final green light, until 24 July 2026. For twenty-five days, an organisation treating the deferral as settled was making a bet on a text that a Member State, a court, or a regulator was still entitled to treat as non-existent.
II. WHAT REGULATION (EU) 2026/1744 ACTUALLY CHANGES
The regulation amends Article 113 of the AI Act to set two new application dates for high-risk obligations under Chapter III, Sections 1 to 3: 2 December 2027 for AI systems classified as high-risk under Article 6(2) and Annex III, and 2 August 2028 for AI systems classified as high-risk under Article 6(1) and Annex I. It also introduces a four-month transitional period for the Article 50(2) marking obligation, for providers who had already placed generative AI systems on the market before 2 August 2026, and adds two new prohibited practices under Article 5 — AI-generated non-consensual intimate material and AI-generated child sexual abuse material — both taking effect 2 December 2026.
None of this retroactively validates a compliance posture adopted before 27 July 2026 on the assumption that these dates already applied.
III. WHAT STAYS UNCHANGED: ARTICLE 50
The regulation does not touch the substance of Article 50. Transparency obligations — direct-interaction disclosure, synthetic-content marking, deepfake and public-interest text labelling — remain due on 2 August 2026, exactly as this series has argued from its first article on 13 July 2026. The only adjustment is procedural: Article 50(7) is amended to remove the Commission's empowerment to adopt implementing acts approving codes of practice, leaving the Commission's own assessment of adequacy as the operative mechanism instead. This does not lower the bar. It removes one additional institutional check on how that bar is assessed.
IV. THE WINDOW BEFORE THE LAW EXISTED
The interesting evidentiary fact is not that the deferral is now law. It is that for twenty-five days it was not, and organisations made decisions during that window regardless. A compliance officer who paused an Annex III conformity assessment programme on 30 June 2026, citing the Council's political green light, made a decision that the law in force at that moment did not yet support. Whether that decision was reasonable is not a question this series answers. Whether an organisation can prove, today, exactly what it knew and when it decided to act on it, is.
The only record most organisations hold of that decision is their own: an internal memo, a Slack thread, a board minute drafted after the fact by the same function whose diligence is in question. Under the Endogenous Audit Paradox already documented across this series, a decision log produced by the party whose diligence it purports to establish carries no probative weight once contested, because the system generating the record and the system under scrutiny are the same system. This is not a hypothetical. It is now testable against a fixed calendar: 29 June 2026 (political agreement), 24 July 2026 (Official Journal publication), 27 July 2026 (entry into force). Three dates, independently verifiable through EUR-Lex, against which any internal claim of "we knew, we acted accordingly" can now be checked — and found either aligned or not, but never self-certified.
V. THE PROOF PROBLEM REMAINING
SOURCE 0 does not determine whether pausing compliance work between 30 June and 27 July 2026 was a reasonable decision. It fixes, independently and at the moment the decision was taken, what an organisation actually knew, decided, and recorded — sealed on infrastructure the organisation does not control, deposited before a Belgian huissier de justice, dated with certainty under Book 8 of the Belgian Civil Code. Where a decision is later contested by a regulator or a counterparty, the question is never whether the decision was correct in hindsight. It is whether the record proving what was known at the time was constituted before the fact, or reconstructed after it.
VI. FREQUENTLY ASKED QUESTIONS
Q: Doesn't the regulation's publication settle everything the previous article raised?
A: It settles the legal status of the deferral. It does not settle what any given organisation did during the twenty-five days before that status existed, nor whether their record of that period is opposable to a third party. SOURCE 0 addresses precisely that residual question.
Q: If Article 50 wasn't touched, why does this matter for an Article 50 compliance programme?
A: Because the same organisations managing Article 50 readiness were, in the same weeks, deciding how much attention to give the then-uncertain high-risk deferral. A record of one decision often lives in the same internal system as the other. SOURCE 0 seals both independently of that shared internal system.
Q: Can an internal Slack thread or email chain from late June not serve as sufficient proof of when a decision was made?
A: It can serve as a starting point, but its date and integrity rest entirely on infrastructure controlled by the party whose diligence is being tested. SOURCE 0 replaces that self-attested chronology with a dual-QTSP timestamped, judicially deposited record.
Q: Does SOURCE 0 take a position on whether pausing high-risk compliance work before 27 July 2026 was reasonable?
A: No. That is a substantive judgment for a regulator or a court. SOURCE 0 only fixes, independently, what was known and decided at the time — the evidentiary basis on which any subsequent judgment of reasonableness would have to be made.
Q: What happens to an organisation that cannot produce any independently dated record of that period?
A: It is not automatically in breach. But if the decision is contested, it will be arguing its own reasonableness using evidence it alone produced and controls — precisely the structural weakness the Endogenous Audit Paradox describes.
Q: Is this the last article needed on the Digital Omnibus?
A: On the question of whether the deferral applies, yes — Regulation (EU) 2026/1744 closes it. On the question of what can be proven about conduct during the period before it applied, the evidentiary gap remains open for as long as organisations rely on self-produced records of that period.
CLOSING AXIOM
The law does not require material truth. It requires proof of diligence. A regulation's date of entry into force is now certain. What an organisation knew and decided before that date remains provable only if it was sealed before the fact.
REFERENCE NOTE
SOURCE 0 is a proprietary pre-execution cryptographic attestation architecture developed by Jean-François ELSEN, Senior Forensic Auditor and Judicial Specialist in Digital Evidence, based in Brussels–Charleroi, Belgium.
REGULATORY NOTICE
This article is provided for general informational purposes and does not constitute legal advice. Organisations should consult qualified legal counsel to assess their specific obligations under Regulation (EU) 2024/1689 (AI Act) as amended by Regulation (EU) 2026/1744.

