How three European regulations are simultaneously changing what compliance means — and why the companies with perfect files may be the most exposed.
Three compliant companies. Three companies at risk.
A Romanian aluminium importer receives an emissions declaration from its Turkish supplier and includes it in its CBAM reporting. The file is complete. Except nobody checked whether the figures match the installation's actual emissions — and since 1 January 2026, it is the importer who pays the difference.
An operator placing wood products on the EU market files a due diligence statement through the Commission's information system. The GPS coordinates of the production plot are the ones the supplier declared. The statement is accepted. Except the supplier declared the cooperative's coordinates, not the actual plot's — and the signatory is legally liable for the accuracy of every GPS point.
A software company launches a customer service chatbot and puts “Powered by AI” in the footer. AI Act transparency obligation, ticked. Except the European Commission's guidance, adopted on 20 July 2026, states explicitly: if the information can easily be overlooked or ignored under normal conditions of use, the obligation is not met — regardless of the notice technically existing somewhere in the interface.
Three companies. Three complete files. Three real exposures. What do they have in common?
All three treated compliance as a documentation exercise. The 2026 regulations ask for something else.
What changed: from “you filled it in” to “the effect occurred”
Look at CBAM, EUDR and the AI Act separately and you see three regulations in three different domains — carbon, deforestation, artificial intelligence. Look at them together and you see a single legislative design pattern the EU is applying on several fronts at once: the compliance standard is moving from input to outcome.
It is no longer enough to show you completed the required document. You must show that the information in it matches reality — and that the outcome the regulation targets actually occurred. Concretely:
CBAM
Regulation (EU) 2023/956 entered its definitive phase on 1 January 2026. Importers no longer merely report emissions — they accumulate real financial obligations, with certificates purchasable from February 2027. Art. 9 allows deducting the carbon price paid in the country of origin, on one condition: the price must be evidenced through a mandatory carbon pricing mechanism — an emissions trading system or a tax — either at the default value published by the Commission or at the effective value, independently certified. A supplier's declaration is not enough. If the supplier claims a price it cannot prove, the importer pays in full.
The least-discussed part, though, is not the certificates but the emissions. To declare actual values, embedded emissions must be verified by an EU-accredited verifier. The chain works like this: the non-EU installation operator engages the verifier, supplies the monitoring data and transmits the verification report through the CBAM Registry to every importer it supplies. You receive an audited emissions file once a year — but you did not choose the verifier and you do not control the quality of the monitoring behind it.
You are the one filing the annual declaration, however. The authorised declarant signs it and surrenders the certificates, so liability stays with the importer, regardless of who paid for the verification. This is the shift described above in its clearest form: you receive a formally complete document — a verification report, accredited and signed — and you still carry the risk if its figures do not survive an inspection. A verification report you have not read critically is a file, not evidence.
On top of this sits a timing gap that hits cash flow directly. From 2027, at the end of every quarter you must hold certificates covering at least 50% of the embedded emissions of goods imported since the start of the year — but the audited report arrives after year-end, and the declaration is filed by 30 September of the following year. The regulation partly bridges this: for the quarterly calculation you use the Commission's official default values, without the Annex IV mark-up, or the certificates surrendered the previous year where the CN codes and countries of origin match. In practice you pay on estimates all year and reconcile against audited data at the end — with the true-up risk that implies.
EUDR
Regulation (EU) 2023/1115 starts applying on 30 December 2026 for large and medium operators. Every due diligence statement must carry exact GPS coordinates — a point for plots under 4 hectares, a polygon above 4 hectares, at six decimal places of precision. Those coordinates are matched against the JRC Observatory reference layer — the 2020 forest cover map at 10-metre resolution — and against Global Forest Watch deforestation alerts.
That check is not an automatic gate at submission, though. The statement receives a reference number, and the actual comparison happens through national authorities' risk-based controls, at mandatory rates of 1%, 3% or 9% of operators per year, depending on the Commission's risk classification of the country of origin. What stops you at customs is a missing reference number; a mismatch between coordinates and map catches up with you at inspection. Legal liability sits with the signatory even when the error came from the supplier, and Art. 25 requires fines whose maximum must be at least 4% of annual EU-wide turnover, plus confiscation and exclusion from the market. We covered these mechanisms — and how widely they differ between member states — in “Who actually checks you”.
AI Act
The transparency obligations in Art. 50 of Regulation (EU) 2024/1689 apply from 2 August 2026. The Commission's final guidance, adopted on 20 July 2026, explicitly shifts the standard: transparency is not measured by the existence of a notice but by the user's perception. The information must be visible, distinct and intelligible under real conditions of use — not buried in manuals or terms and conditions. And the “it's obvious you're talking to an AI” exception must be read narrowly: if you cannot show the average user would immediately recognise the AI nature of the interaction, you notify.
Three regulations. Three domains. The same message: a complete file is no longer enough.
Why this differs from everything before it
GDPR was the first generation of this shift. It asked organisations to declare what they do with personal data — privacy policies, legal bases, records of processing. It was a massive documentation exercise, and many organisations treated it as exactly that: policies drafted by lawyers, published on the website, ticked off a checklist.
2026 is the second generation. Declaring is no longer enough. You must show the declaration matches reality — and that the intended outcome occurred. The difference is not one of intensity but of kind:
| First generation (the GDPR model) | Second generation (2026) | |
|---|---|---|
| What is checked | The document exists | The information in it is correct |
| Who checks | The auditor, periodically | The authority, against independent data — plus the auditor |
| Who is liable | The organisation | Including the individual signatory |
| The consequence | A fine | Fine, operational blocking, criminal liability |
| The standard | You declared it | The effect occurred |
CBAM checks declared emissions against evidence of the price paid. EUDR matches geolocation against a satellite reference layer. The AI Act requires demonstrating perception, not the existence of a notice. And Directive (EU) 2024/1203 on the protection of the environment through criminal law, with a transposition deadline in May 2026, adds personal criminal liability for serious breaches — prison sentences for natural persons and, for legal persons, fines whose maximum must be no less than 5% of worldwide turnover.
The move from directives to regulations — directly applicable, with no national transposition — removes the last layer of variation: you can no longer argue that “in our national transposition, the requirement is read differently”.
What does not work yet
The legislative pattern is clear. The implementation ecosystem is not.
- CBAM: the Commission published the draft regulation on carbon price deductions only on 13 May 2026, more than four months into the definitive phase, with consultation running to 10 June. Importers accumulated financial obligations from 1 January without knowing exactly how deductions are calculated — and the rules will apply retroactively across 2026. Worse: accredited verification of emissions has been mandatory since 1 January 2026, yet the first CBAM verifiers are expected to be accredited only around September 2026. The obligation started nine months ahead of the infrastructure that makes it possible.
- EUDR: the information system ran in restricted mode from 16 February 2026 until July, accepting no statements. Implementing Regulation (EU) 2026/1565, formalising the system's functionality, was adopted on 13 July 2026 — five and a half months before the deadline. Meanwhile, most smallholders in the supply chains have never had their land GPS-mapped.
- AI Act: the final Art. 50 guidance was published on 20 July 2026 and the obligations apply from 2 August 2026. Thirteen days between guidance and deadline.
A frequently confused point: for high-risk systems under Annex III, the deadline was postponed to 2 December 2027 by Regulation (EU) 2026/1744, finally adopted in June 2026. What applies from 2 August 2026 are the Art. 50 transparency obligations — a different category, not postponed. The postponement does not help companies that have not even done the classification, though: which of their systems fall under Annex III? Without that answer, the 16 months gained are spent on nothing. We covered the full timeline in our guide to the AI Act obligations.
If the pattern sounds familiar, it is: complete legislation, absent implementation ecosystem. The law exists. The instrument that makes the law workable does not.
What to do concretely — a framework, not a checklist
The natural reaction to the 2026 convergence is to build separate checklists for each regulation. That is wrong — and expensive. All three require, each in its own way, the same thing: an infrastructure of verifiable data, not completed documents. Three steps, in order:
- First: classify. Before any reporting, identify which activities fall under which regulation. Importing aluminium from Turkey? CBAM. Placing wooden furniture on the EU market? EUDR. Running a customer service chatbot? Art. 50 of the AI Act. Using a candidate scoring system? Annex III, high risk. Classification is free, needs no software and is not optional — it is the precondition for any compliance. And it is the step most companies have not taken.
- Second: map the data gaps, not the documentation gaps. Not “do we have the policy?” but “do we have verifiable data?”. On CBAM: do we have the supplier installation's actual emissions, or an unvalidated declaration? On EUDR: do we have plot-level coordinates at six decimals, or the cooperative's name? On the AI Act: do we have evidence the user perceived the notice, or a banner in the footer?
- Third: build the data infrastructure before the reporting layer. Reports and declarations are outputs. The inputs are the data — verified, traceable, auditable. Build reporting without the data channel and you produce files you fill with what you have, not with what is required.
The next 12 months
2026 is the year several major European regulations converge on the same companies, with overlapping deadlines, unsynchronised penalties and no common enforcer. “Compliance fatigue” is not a rhetorical phrase — it describes an operational reality.
But the convergence carries an advantage few see: the data one regulation requires serves the others too. Emissions verified for CBAM feed sustainability reporting. Traceability built for EUDR satisfies supply chain due diligence requirements. The classification done for the AI Act informs network security risk assessment. Build the data infrastructure once, properly, and you solve several compliance obligations at the same time. Build separate files per regulation and you solve each one individually, incompletely and expensively.
The next 12 months will separate the companies that have compliance from those that have files.
How we can help
Speed Flow works precisely on the data infrastructure side: CBAM Manager for collecting and validating emissions data, EUDR Manager for supply chain traceability and plot geolocation, and AI governance consulting for system inventory and classification. If you are not sure where you stand, take the quick CBAM / EUDR test — five questions, under a minute.