The EU AI Act's high-risk obligations (Annex III) were pushed to December 2027 via the Digital Omnibus, but Article 50 transparency requirements still apply from 2 August 2026. For .NET teams, this means chatbots and AI-interactive systems must disclose their AI nature with a durable audit trail — not just a UI string. The post covers the provider vs. deployer distinction, what Annex IV technical files must contain, ASP.NET Core middleware for logging disclosure audit events, structured model interaction logging for Article 12, an IHostedService-based override-rate drift monitor for Article 72, and a prioritized checklist of what to ship before August versus what can be built properly over the next 18–24 months.

18m read timeFrom daily-devops.net
Post cover image
Table of contents
What Changed, and Why It Matters More Than the HeadlineThe Four Risk Categories, As WrittenProvider or Deployer? The Distinction .NET Teams Get WrongThe Technical File: What Annex IV Actually ContainsTransparency Obligations: Where .NET Code Actually Touches, Starting in WeeksLogging for Article 12: Recording What the Model Actually DidRisk Management: A Process, Not a SpreadsheetWhat I Recommend Doing Before August, and What Can WaitWhat This Post Is Not
2.6K Impressions