CiteOnly

Research

What regulators will ask you to prove

Across three regimes with nothing else in common, the demand is the same: not that the system was right, but that you can show what it said and what it based that on.

The EU AI Act, as the dates now stand

The timetable changed in 2026. Under the Digital Omnibus agreement, the high-risk regime was pushed back, so the current position is roughly this:

  • 2 August 2026. Transparency obligations under Article 50 apply. One carve-out: providers of systems already on the market have until 2 December 2026 to meet the Article 50(2) marking requirement for AI-generated content.1
  • 2 December 2027. High-risk obligations for Annex III systems: risk management, data governance, logging, human oversight, technical documentation, conformity assessment and registration.2
  • 2 August 2028. The same regime for Annex I systems embedded in regulated products.3

The delay is worth reading carefully. Logging and technical documentation are not features you add near a deadline. They are properties of how a system was built, and retrofitting a provenance record onto a system that never kept one is the expensive version of this project.

Rules that already apply

There is no comprehensive federal AI statute, which is often misread as an absence of obligation. In regulated industries the obligations arrive through existing rules that do not care what produced the record.

In April 2026 the OCC, the Federal Reserve and the FDIC replaced the SR 11-7 model risk framework, and explicitly excluded generative and agentic AI from the new guidance while opening a separate request for information. A Federal Reserve governor confirmed the narrower scope shortly afterwards.1

That is a gap in AI-specific guidance, not a suspension of anything else. Recordkeeping under SEC Rule 17a-4, FINRA Rule 4511 and Investment Advisers Act Rule 204-2 continues to apply to the records a firm creates, including the ones an AI assistant helped create. If a system influences a decision or touches regulated customer data, the firm has to show which controls governed it and produce evidence that they operated.2

The strictest version, already written

Regulated life-science records have carried explicit audit trail requirements for years. Under 21 CFR Part 11 and EU GMP Annex 11, records must be attributable, time-stamped and retrievable, so a later reviewer can establish who did what and on what basis.1

Applied to an AI system, industry guidance reads that as covering the prompt, the output and the source documents relied on, each logged, time-stamped and associated with an identified user. Pharmacovigilance practice adds version control over successive drafts of a narrative, so an inspector can compare what changed.

This sector is the clearest illustration of the general point. Nobody wrote these rules with language models in mind. They were written because a conclusion is only worth what the trail behind it is worth, and that principle does not change when the author is a machine.

One demand, three regimes

Strip away the jurisdictions and the same requirement appears in all three: for any statement a system produced, be able to show where it came from. Not an accuracy figure, not a benchmark, not a model card. A trail from the statement to the source.

Organizations meeting that today mostly do it by building a logging layer beside an AI system that does not natively produce provenance, then reconciling the two. The alternative is a system where the trail is what producing the answer consists of, so there is nothing to reconcile.

That is the argument for CiteOnly. The sector-specific version is on the financial services and healthcare and life sciences pages.