MICKAI®ArticlesEU GPAI enforcement begins: what …
Article · 30 July 2026

EU GPAI enforcement begins: what an audit trail must prove

From 2 August 2026 the European Commission can compel general-purpose AI providers to prove their claims, and a signed audit record is what proof looks like.

Author
Micky Irons
Published
30 July 2026
Follow Micky Irons
LinkedInX
eu-ai-actgpai-enforcementai-audit-trailsovereign-aiopen-audit-record
EU GPAI enforcement begins: what an audit trail must prove

An AI audit trail must be able to prove four things: what a model was asked, what it returned, who authorised the action that followed, and that none of those records has been altered since. From 2 August 2026 that standard stops being good practice and becomes a matter of enforcement. On that date the European Commission gains enforcement powers over general-purpose AI providers under the EU AI Act, including the ability to request information, access models and impose fines, while the Act's Article 50 transparency obligations also become enforceable.

The date matters because it changes who carries the burden of proof. Until now, most transparency commitments in AI have been statements of intent, written by the provider and tested by nobody. From August, a supervisor can ask a provider to show its working, and the quality of the answer will depend entirely on what was recorded at the time. Regulated organisations everywhere should read that shift carefully, because the expectations it sets will travel downstream.

What changes on 2 August 2026?

From 2 August 2026 the European Commission can enforce the AI Act's general-purpose AI rules directly, with powers to request information from providers, to access models, and to impose fines. Article 50 transparency obligations become enforceable on the same date. In practical terms, the era in which a provider could describe its safeguards without ever demonstrating them is closing. A regulator with the power to compel information does not read marketing pages, it reads records.

What will an investigator actually ask a firm to prove?

An investigator will ask for evidence, not assurances: which model handled a task, what it was asked, what it produced, who reviewed or authorised the outcome, and when each of those steps happened. A policy document describes what should occur. An enforcement inquiry asks what did occur, in a specific case, on a specific date. That gap is where most organisations are exposed, because conventional logging was designed for debugging, not proof.

The Commission's new powers are aimed at general-purpose AI providers, and we will not pretend otherwise. But organisations that deploy AI inside regulated processes answer to their own supervisors, and those supervisors are watching the same shift from principle to proof. A bank, a hospital or a law firm that cannot reconstruct an AI-assisted decision will find that deferring blame to a model provider makes a thin defence.

Why is a signed audit record different from an ordinary log?

An ordinary log can be edited, truncated or quietly rotated away, which means it proves very little on its own. A signed audit record is different because every entry is cryptographically bound at the moment the action happens, so any later change is detectable. This is what our Open Audit Record subsystem is built to do. Every action taken through our operating system produces a record with the following properties:

  • Signed at the moment of action, not reconstructed afterwards, so the record and the event cannot drift apart.
  • Post-quantum secure signatures, so evidence captured today cannot be quietly forged or repudiated once quantum computers mature.
  • Tamper-evident structure, so an edited or deleted entry shows up as a break in the chain.
  • Verifiable offline, so an auditor can check the record without any connection to us or to the internet.
  • Bound to authorisation, with sensitive actions gated behind voice-biometric confirmation, so the record shows not only what happened but who approved it.

When an investigator asks who did what and when, the answer should be a signed record, not a reconstruction from memory. We built the Open Audit Record so the evidence exists the moment the action happens, on hardware the organisation controls.

Mickai

Does running AI on your own hardware make enforcement easier to survive?

Yes, because the evidence a regulator wants never leaves your control. When AI runs in a vendor's cloud, answering an inquiry means depending on that vendor's logs, retention policies and willingness to cooperate on your timetable. When the operating system runs on your own hardware, on premise and air-gapped where required, the complete decision history sits inside your perimeter, anchored to a hardware-held root of trust. You do not request your own evidence from a third party. You already hold it.

Sovereignty also simplifies the data questions that follow. A fully offline deployment means prompts, outputs and the audit trail never cross a border or transit an external service, removing an entire category of exposure.

How does Mickai approach this?

Mickai is a Sovereign Intelligence Operating System, a SIOS, that runs entirely on the customer's own hardware. Its work is organised into studios, 87 of them on one operating system, with ten production-ready at launch and 77 in development. Before any sensitive action runs, our cooperative multi-model consensus substrate requires specialist sovereign models to agree, so a single model's error cannot commit the organisation on its own. Every step lands in the Open Audit Record described above. The architecture is protected by 104 filed UK patent applications across 2,340 claims, held by Mickai LTD, though we treat those filings as a moat rather than the point.

None of this makes the AI Act's obligations disappear. What it changes is the cost of answering. An organisation whose AI produces signed evidence as a by-product of normal operation can respond to a supervisor in days, from records, rather than in months, from interviews and inference.

What should regulated organisations do before the powers bite?

Start by asking one question of every AI system you run: if a regulator asked us to prove what this system did last Tuesday, could we? If the answer depends on a vendor, a screenshot or someone's recollection, the honest answer is no. The standard the 2 August 2026 date sets, evidence over assertion, is coming for every regulated deployment. Building for it now costs far less than reconstructing under investigation later.

Frequently asked questions

When do the EU's enforcement powers over general-purpose AI begin?

On 2 August 2026. From that date the European Commission can request information from general-purpose AI providers, access their models and impose fines under the EU AI Act, and Article 50 transparency obligations also become enforceable.

What is Article 50 of the EU AI Act?

Article 50 contains the AI Act's transparency obligations. From 2 August 2026 those obligations become enforceable alongside the Commission's new powers over general-purpose AI providers, which turns transparency from a stated principle into a requirement that can be tested and fined.

Do the new powers affect organisations that only deploy AI?

Not directly, since the 2 August 2026 powers target general-purpose AI providers. Deployers still carry their own obligations under the Act and answer to their own sector supervisors, so the shift towards provable records is one every regulated organisation should prepare for.

What is the Open Audit Record?

The Open Audit Record is the Mickai subsystem that cryptographically signs every AI action at the moment it happens. Records are post-quantum secure, tamper-evident and verifiable offline, so an auditor can confirm what a system did without relying on us or on any external service.

Can AI audit evidence be verified without internet access?

Yes. Open Audit Record entries are designed to be verified fully offline, which matters for air-gapped estates and for any inquiry where an organisation must show its records are complete and unaltered without depending on a vendor connection.

What is MICKAI?

MICKAI is a Sovereign Intelligence Operating System, a SIOS, that runs on the customer's own hardware, on premise and air-gapped. Every action is signed into the Open Audit Record, which is post-quantum secure, tamper-evident and verifiable offline. The operating system spans 87 studios, with ten production-ready at launch and 77 in development, and is protected by 104 filed UK patent applications across 2,340 claims, filed rather than granted.

Subscribe
Get every new Mickai article by email.

Long-form essays on sovereign AI from Micky Irons. One email per article. No tracking, no marketing, no third parties. Every email includes a one-click unsubscribe link.

Prefer RSS? Subscribe at /articles/feed.xml.

Originally published at https://mickai.co.uk/articles/eu-ai-act-gpai-enforcement-august-2026. If you operate in a regulated sector or want sovereign AI on your own hardware, the audit form on mickai.co.uk is the entry point.
More articles