The short answer: right now, most of the time — nobody genuinely qualified to do it. Sunday, 2 August 2026 was the day the European Artificial Intelligence Regulation (AI Act) was to become fully applicable, including for high-risk systems. That deadline was postponed, through the Regulation (EU) 2026/1744 (“Digital Omnibus on AI"), published in the Official Journal on 24 July 2026 — adopted in final form by the European Parliament on 16 June and by the Council on 29 June 2026, in force since July — to 2 December 2027. Many read the postponement as a pause. That is a dangerous reading: public institutions are already buying “AI-powered" solutions through public procurement, and those solutions are evaluated with criteria written for classic software, by committees that do not have — and until now had no reason to have — the competence to verify an AI model. Postponing the obligations does not postpone the risks. It only leaves them unsupervised for longer.

Where we actually stand with the AI Act (no myths)

Regulation (EU) 2024/1689 entered into force on 1 August 2024, with staggered application. The timeline, in short:

DeadlineWhat applies
2 February 2025
in force
Prohibitions on unacceptable-risk practices (social scoring, subliminal manipulation, certain biometric uses) and the AI literacy obligation for staff — for any organisation using AI systems, public institutions included
2 August 2025
in force
Rules for general-purpose AI models (GPAI)
2 August 2026 Transparency obligations (Art. 50): users must be informed when interacting with a chatbot, AI-generated content must be marked
2 December 2026 Machine-readable marking of generated content, for systems already placed on the market before 2 August 2026 (Art. 50(2)); the new prohibition inserted by the Omnibus into Art. 5 — AI systems creating non-consensual intimate imagery
2 December 2027
postponed
Full obligations for high-risk systems in Annex III — including systems used by public authorities to assess eligibility for essential benefits and services
August 2028
postponed
AI embedded in regulated products (Annex I)

What was postponed is therefore the heaviest block. What is already mandatory — and applies today, not in 2027 — has not moved.

Two up-to-date clarifications: systems already placed on the market before 2 August 2026 have until 2 December 2026 to implement machine-readable marking of generated content (Art. 50(2)), and the Omnibus inserted a new prohibition directly into Art. 5, applicable from 2 December 2026: AI systems that create non-consensual intimate imagery (“nudifiers").

One myth worth dismantling, because I hear it constantly: “the AI Act is a tech company problem." It is not. The regulation creates explicit obligations for deployers — that is, for anyone who uses an AI system, not only for whoever builds it.

For public institutions deploying high-risk systems, the list in Art. 26 is concrete: use in accordance with the instructions, designated and competent human oversight, retention of system-generated logs for at least 6 months, and informing the people affected by decisions. Art. 27 adds, specifically for public bodies: a fundamental rights impact assessment before use.

And where Romania stands

The government adopted the memorandum proposing the national authorities only in March 2026 — seven months after the European deadline: ANCOM as market surveillance authority and single point of contact, ASF and BNR for the financial sector, ANSPDCP for sensitive domains, ADR as notifying authority. The verb matters: the document proposes rather than designates, and the designation itself requires an organic law.

In its statement of 24 July 2026, ANCOM confirms the consequence: the competent authorities "will be able to verify and sanction non-compliance with the Regulation only after the entry into force of the national act currently being drafted". That law is still in preparation, and the proposed authorities have not yet published guidance for organisations.

Worth remembering, as the public debate has stressed: the regulation is directly applicable — the absence of operational national procedures does not suspend obligations already in force.

Translated for a contracting authority: the framework that should help you verify AI is itself still under construction. The supervisory authorities are only now recruiting their technical experts. If you wait for verification to come “from above", you will be waiting long after the solutions have gone live inside your institution.

The governance gap: when the supplier evaluates itself

The problem is not a Romanian one; it is documented at European and international level, and the mechanism behind it is worth understanding precisely.

Governance decisions about technology are made, in practice, at the procurement stage — that is when it is settled what the institution buys, under what requirements and with what control mechanisms. Analyses built on UK National Audit Office reports show that real oversight requires officials able to interpret suppliers' claims about model performance, to assess documentation about training data, and to identify the risks of algorithmic decisions. Where those competences are missing, responsibility for the evaluation migrates, de facto, to the supplier. In other words: the supplier evaluates itself.

The OECD, in “Governing with AI" (2025), identifies digital skills gaps as one of the major obstacles to using AI in public procurement. The UK Parliament's Public Accounts Committee asked the government to explain how it is addressing the digital skills shortfall, noting also the absence of a systematic mechanism for learning from pilot projects. And in the US, the Code for America assessment found states weakest precisely on building internal AI capacity. The shared conclusion, as formulated by the Open Contracting Partnership, is simple and uncomfortable: buying AI is not enough; you also have to understand it.

Romania has no equivalent study — but it has every ingredient of the problem: digitalisation accelerated by European funds, suppliers adding “AI" to any technical proposal to score points, evaluation committees trained in procurement law rather than model assessment, and a supervisory framework still being built.

What an institution can do now — without waiting for 2027

The good news: nothing below requires AI laboratory expertise. It requires procurement discipline — exactly the competence institutions already have.

1. The inventory

Before anything else: which systems with AI components already exist in the institution — bought, delivered as part of other contracts, or used informally by staff? More than half of organisations have no systematic inventory of their AI systems. You cannot govern what you do not know you have.

2. Verifiable requirements in the tender documentation

“The solution uses artificial intelligence" is not a requirement; it is a slogan. Verifiable requirements are:

  • a description of the AI function and of its limits;
  • the provenance of, and rights over, the training data;
  • the performance metrics measured, and the conditions under which they were measured;
  • decision logging (who, what, when — at least 6 months, aligned with Art. 26);
  • the human oversight mechanism;
  • the institution's right to audit;
  • the exit plan — what remains with the institution if the contract ends.

3. Three internal competences, not a new department

One person who can read a model datasheet critically and ask the questions above; one who assesses risks against the institution's own process (not technology in the abstract); one who monitors the system in operation. These can be part-time roles, they can be built through training — but they cannot be outsourced entirely to the very party being evaluated.

4. Preparing for the impact assessment

For public bodies, the fundamental rights impact assessment (Art. 27) becomes mandatory for high-risk systems. Institutions that start the exercise now — on the systems already in use — will have a routine by December 2027; the others will have a crisis.

The conclusion

The Digital Omnibus postponement moved the deadlines, not the question. Systems are entering institutions now, through contracts signed now, evaluated against today's criteria. The difference between a prepared institution and an exposed one is not made by the regulation — it is made by the ability to ask, at the moment of procurement, the questions the supplier cannot dodge.

Public procurement has always been about exactly this: decisions that hold up under scrutiny. AI does not change the principle. It only raises the stakes.

I work with contracting authorities on exactly this intersection — public procurement since 2009, AI governance with ISO/IEC 42001 expertise. If your institution is buying or already using AI-based solutions and you want a practical discussion about requirements and competences, write to me.