AI Code Governance

The EU AI Act's August 2 Obligations Are Live: How to Be Evidence-Ready

The EU AI Act's next wave of obligations is now in effect (as of August 2, 2026). Here's a practical, evidence-first checklist for engineering and security leaders — starting with the code AI is already writing.

DP
Diwo Provenance Team
Head of Product
August 20, 20265 min read
The EU AI Act's August 2 Obligations Are Live: How to Be Evidence-Ready

As of August 2, 2026, the EU AI Act's next wave of obligations now applies. If your organization builds or operates AI systems that touch the EU market, the era of "we'll deal with it when it's enforced" is over — the obligations are live now.

Most readiness guides for the Act talk about model cards, risk tiers, and conformity assessments. This one is about something those guides skip — the part of your AI footprint that grew fastest and quietest over the last two years:

AI is writing your code.

Not the code of your AI systems — all of your code. Copilots and coding agents now open pull requests across the whole estate: payment services, customer-data pipelines, the infrastructure your regulated workloads run on. Across recent industry surveys the pattern is consistent: nearly every enterprise now has AI-generated code in production, and most security teams lack full visibility into it.

That gap is exactly where an audit goes wrong. Because when a regulator, auditor, or insurer shows up, they don't ask for your policy. They ask for evidence.

The four questions you'll be asked

Whatever framework the request arrives under — the EU AI Act, NIST AI RMF, your insurer's questionnaire, a customer's security review — the evidence questions about your codebase reduce to four:

1.        Which of our code did AI write?

2.        Was a human in the loop when it merged?

3.        What does the security evidence say about it?

4.        Can we show our decisions — who accepted which risk, when, and why?

Read those again. None of them can be answered by a policy document, and none of them can be answered by another scanner. They're provenance questions — chain-of-custody questions about how your software actually came to be. If you can answer all four from evidence, you're in strong shape for these obligations and for everything that follows them. If you can't, here's how to get there.

Step 1: Inventory where AI touches your estate

You can't govern what you haven't mapped. Start with two lists:

•          AI workloads — the systems where AI is part of the product (models, agents, LLM-backed features). These are what the EU AI Act regulates directly, and they need to be classified by risk.

•          AI-written code — everywhere coding assistants and agents commit, across all systems. This is the blast radius most inventories miss: an AI-written pull request merged into a payments service without human review is a governance fact, whether or not that service "is AI."

If the second list surprises you, you're in the majority.

Step 2: Weight it by business criticality

Fifty thousand findings with no order is noise. The question an executive — or an auditor — actually cares about is not "how many alerts?" but "what's unwatched in the places that can hurt us?"

Classify your repositories by what they do: internal tooling, public-facing, customer-data, regulated, payment-critical. Then look at where AI-written code and security blind spots overlap with the critical end of that spectrum. That intersection is your real exposure, and it's usually a short list. Governance becomes tractable the moment it's ranked.

Step 3: Put decisions on the record

Here's the uncomfortable truth about audit-readiness: findings are not the story — decisions are. Every organization has findings. What separates a defensible posture from an indefensible one is being able to show that a named human looked at the material ones and decided — fix, waive, or accept — with a rationale, an owner, and a date.

If your current process resolves risk in Slack threads and closed Jira tickets, you have decisions without custody. Start recording them somewhere append-only: what the evidence showed at the moment of decision, who made the call, and why. Frozen, attributable, board-ready. That record is the difference between "we take security seriously" and proof.

Step 4: Map evidence to the frameworks — don't duplicate the work

The EU AI Act and NIST AI RMF overlap heavily in what they actually ask you to demonstrate: risk management that operates continuously, technical documentation, logging, human oversight. The efficient move is to maintain one evidence base — your estate's real signals and your recorded decisions — and map it outward to each framework, rather than running a separate questionnaire exercise per regulation.

A posture that's derived from the estate's own evidence survives scrutiny. A posture that's declared on a survey is one deposition away from being a liability.

Step 5: Rehearse the ask

Run the drill now: pick one critical repository and try to produce, within an hour, the answers to the four questions above — with artifacts, not recollections. Who wrote it, who reviewed it, what the scanners said, what you decided. If the drill takes a week instead of an hour, you've found your gap while it's still cheap to fix.

Where Provenance fits

This is the problem Diwo Provenance was built for. It's not another scanner — it's the AI code governance layer that sits above the scanners you already run: it reads which code AI wrote — from the authorship signal — and whether a human reviewed it, weights findings by business criticality, records every fix/waive/accept decision with its evidence snapshotted, and maps the whole picture to the EU AI Act and NIST AI RMF — continuously, not annually.

Two things we say plainly, because trust is the product: Provenance reads code signals, never your source — your code never leaves your estate. And what you get is evidence readiness, not a legal determination — we grade the evidence; your counsel makes the legal call.

You can see your own estate's posture — your score, your blind spots, your unanswered questions — in about 15 minutes, free, with a read-only connection: Connect your estate free.

August 2 was not a deadline to fear. It's the day "trust us" stopped being an acceptable answer — and for teams that can show their evidence, that's a competitive advantage.

Diwo Provenance is the governance layer for AI-written code — above all your scanners. Your scanners detect. Provenance decides.

TagsAI Code GovernanceEU AI ActNIST AI RMFAI AGENTSDATADOG
See it in action
Your scanners detect. Provenance decides.