RAIDS AI's Nik Kairinos on what the EU AI Act has not fixed
Article 50 of the EU AI Act has applied since 2 August 2026. Organisations must tell people when they are interacting with an AI system, and certain AI-generated or AI-manipulated content must be labelled as such, including in a machine-readable form. At the same time the European Commission's Digital Omnibus package has pushed back the compliance timetable for high-risk AI systems, the category that covers biometrics, credit, employment and access to essential services.
Nik Kairinos is chief executive and co-founder of RAIDS AI, a behavioural monitoring platform that watches AI systems in production and flags unsafe behaviour before it becomes a failure, a regulatory breach or a reputational problem. He has worked in AI and deep learning for more than 40 years. He answered The Datatech Times' questions in writing on what Article 50 has changed in practice, where the transparency obligation is hardest to meet, and why he thinks a written AI policy is where governance starts rather than where it ends.
A month into the Article 50 regime, Kairinos said most of what has changed is at the surface. "Chatbots say they are chatbots, and a lot of content now carries a line saying AI was involved somewhere in the making of it." The harder obligation is the machine-readable marking of synthetic content, and that is where he sees most organisations falling short. "Watermarks and provenance metadata survive badly once a file is cropped, re-encoded or passed through someone else's platform, so a marker that was present when the content was created is often gone by the time anyone sees it."
His test for whether a disclosure is genuine is whether there is a record behind it. "If a company can show which system produced a piece of content, when and under what settings, the label means something. If it cannot, the label is a statement of intent. Most of what I see today is the second."
Where disclosure breaks down
Disclosure is hardest, he said, when the AI is not the company's own. Third-party models, vendor features switched on quietly and multi-step agent chains mean an organisation cannot disclose what it cannot see, and few have a reliable inventory of where AI runs inside their operations. The problem gets worse in live settings such as voice calls and customer service, "where commercial pressure pushes companies to shorten disclosures until they no longer tell customers anything meaningful".
Readiness, in his view, tracks how used a sector already is to regulatory scrutiny. "Financial services and pharma are the furthest along, because their regulators already require evidence and documentation", so AI disclosure becomes one more item in a compliance system that already exists. "Recruitment, marketing and publishing are the furthest behind, since AI adoption in these fields happened quickly and with little oversight." The public sector sits in the middle: the intent is there, but slow procurement means much of the AI already in use arrived bundled inside software bought years earlier, before anyone was thinking about disclosure.
Monitoring after launch
Kairinos has argued publicly that transparency alone is not enough. Asked what meaningful oversight looks like for a company that has already shipped an AI system, he put the weight on what happens after launch rather than before it. Pre-launch testing and compliance checks matter, "but it is only when systems are continuously monitored, and that monitoring is audited, that organisations can truly have confidence in their AI deployments".
"A company deploying an AI model into its ecosystem, no matter how far removed their systems are, needs a constant audit trail to identify and report incidents. These incidents are going to happen, no matter how thorough the pre-launch testing is." A successful deployment, he said, is one where the organisation can prove on an ongoing basis that the system is behaving as intended and that deviations are caught quickly. "Anything else, and they are playing a risky game."
On what monitoring for bias, hallucination, model drift and unintended behaviour actually requires, his answer starts with visibility. "For a monitoring solution to be successful, the most important element is full visibility into the real-world use of the end model, alongside a baseline for expected behaviour. In short, they need to know what rogue activity looks like and have the means to spot it when it happens." Production data, monitoring tools and human-reviewed processes are the components, with a live audit trail as the most important output. Without full access to the model's output, he said, the strength of the monitoring is irrelevant, because most failures become near impossible to investigate if you cannot prove what the model did once it went live.
The delayed high-risk timetable
The categories most exposed by the delay to the high-risk rules are, for Kairinos, the ones where AI can directly affect safety or rights: privacy, access to services, and life-changing decisions in biometrics, credit, employment and justice. These "create the worst possible outcomes for people and risk the greatest reputational damage for the organisations responsible". Enough systems are already live in real operational environments that he does not regard the risks as hypothetical. "Delaying the timetable for high-risk systems is more than just a bureaucratic decision designed to give organisations a little breathing space, it is a gamble being played with people's wellbeing."
If the deadline keeps moving, what gets a board to act anyway? Compliance will still drive some investment in monitoring and reporting tools, he said, but regulatory exposure is only one of the risks of a system failing or going rogue. "There are commercial and ethical imperatives that should guide their decision-making, as if an AI system produces a discriminatory outcome, exposes sensitive data, misleads a customer, or takes an action nobody can properly explain, the organisation would still have to deal with the consequences." There is a positive case as well: procurement teams are increasingly making AI governance part of their purchasing process, and being able to show a fully monitored deployment "would be a major boon for sales teams".
Policy versus governance
Asked what separates an organisation doing this well from one that has written an AI policy and stopped, Kairinos said the difference is the ability to evolve, and that it mirrors the difference between pre-launch testing and real-time monitoring. "An organisation that takes AI seriously and is doing everything it can to avoid failures has to know where AI is being used, who owns each system, and what happens when something goes wrong. An AI policy is a good foundation for a successful deployment, but it cannot reflect the complexity and volatility of live AI use. Governance is how you react to and prepare for the lifecycle of the AI product: continuous reassessment, incident response, audit trails."
He has watched earlier attempts to govern the technology, and said the difference this time is pace. For much of the last 20 years progress was slow enough for fixed regulation to keep up. "Right now, we are seeing day-to-day advances in AI that would have seemed impossible just ten years ago." What strikes him about this moment is "how hesitant regulators are to impede the AI revolution, despite the obvious risks of AI deployment at massive scale without sufficient safeguards". Regulators, he said, are not trying to regulate the AI of today but what it might become in a matter of years or months, and the guardrails set now will reach sectors far beyond technology.
On dates, Kairinos points first to 2 December 2026, which he describes as a transitional deadline for providers of AI systems already on the market before 2 August to comply with the Article 50(2) obligation on marking AI-generated content. For higher-risk systems he cites 2 December 2027 for the Annex III use cases and 2 August 2028 for high-risk systems embedded in regulated products. He expects the goalposts to keep moving, and argues that working to the dates is the wrong attitude in any case: "AI vendors have a responsibility to ensure that their products are safe and to be able to prove it; otherwise, we risk reaching a point where the issues are too deep-rooted to be resolved in time for a particular day."