← All posts
Thought Leadership

The Human-Communication Layer of the EU AI Act, After the Omnibus

August 22, 2026 · 9 min read

In 2016 and 2017, an engineer at a major aircraft manufacturer typed a few lines into an internal instant-messaging window. One called the aircraft’s design the work of “clowns, who in turn are supervised by monkeys.” Another read: “I basically lied to the regulators (unknowingly).” No conformity assessment produced those sentences. No autonomous system generated them. A person wrote them at a keyboard, pressed send, and moved on. Years later they sat at the center of a USD 2.5 billion deferred prosecution agreement.

Hold that image while you read the rest, because it is the part of AI governance that the current regulatory debate keeps stepping around. The EU AI Act, and the Digital Omnibus that recently reshaped its timeline, governs how systems are built, assessed, and deployed. The message an employee writes about that system, to a colleague, a customer, or a regulator, is created somewhere the conformity file does not reach.

What the Omnibus actually changed, and what it did not

Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force on 27 July 2026. The headline effect was on sequencing. High-risk obligations that firms had been racing to meet were rephased, giving providers and deployers more runway before certain requirements bite. If you run a compliance function inside a regulated firm, this bought you calendar. It is worth reading the operative text rather than the trade-press summary, and it is worth pairing it with a plain-language walkthrough of the obligations that remain live. (General information here, not legal advice.)

What the Omnibus did not touch is the shape of the underlying risk. A deadline is a date. It moves. The mechanism by which most communication-and-AI exposure gets created does not move with it. That exposure is minted at the keyboard, in the sentences people write while using, describing, or reacting to these systems, and it is minted at the same rate whether a high-risk classification applies in Q3 2026 or Q1 2027.

This is the cornerstone thesis, stated plainly: regulation sets the floor. It defines the minimum a system must satisfy before it can be placed on the market. The human communication layer, the language your people commit to writing every day, sits above that floor and is still mostly left to chance. A firm can hold a spotless conformity file and lose a case on a single sentence one of its employees typed in a hurry.

Two execution moments, two different risks

The clearest way to think about AI-era communication governance is to separate two distinct moments where something irreversible happens. They look adjacent. They demand different controls.

The human before send

A person drafts a message and decides to send it. There is a pause, usually a second or two, between the last keystroke and the click. In that pause the risk is legible and the writer is a human who can reconsider. The aircraft-manufacturer messages lived entirely here. So did the private messages at a US cable-news network in which staff called broadcast claims false, later central to a USD 787.5 million defamation settlement. So did the message in which a food-delivery company’s staff arranged a no-poach and wage understanding, later a EUR 329 million cartel fine. Ordinary people, ordinary drafts, one line that reframed the whole record.

The autonomous agent at runtime

An AI agent generates and acts on output at machine speed, often without a human in the loop for any single step. Here the risk is a moving target: the agent can be prompt-injected, can hallucinate a commitment, can take an action a policy never contemplated, and can do it thousands of times before anyone reviews a log. The pause is gone. The control has to live in the runtime, in the system’s own guardrails, monitoring, and kill switches, because there is no human hand hovering over a send button to catch.

Conflating these two moments is where governance programs go soft. A runtime guardrail on an agent does nothing for the sentence a compliance analyst types into an email. A pre-send check on a human draft does nothing to constrain an agent acting autonomously at three in the morning. Each moment needs its own rail, and each rail belongs to a different owner.

The artifact: a two-control-point framing table

Use this to sort any AI-communication control you are asked to buy, build, or approve. Put the proposed control in one column and it will tell you what it can honestly cover, and what it cannot.

Dimension Human pre-send layer Agent runtime layer
Who acts A person writing a message An autonomous system generating output
When risk lands The pause before “send” The instant of generation or action
Speed Human speed, seconds to reconsider Machine speed, no natural pause
Failure mode Careless phrase, admission, disparagement, casual collusion Prompt injection, hallucinated commitment, unbounded action
Right rail Pre-send check that flags the phrase and offers a safer wording Runtime guardrails, sandboxing, monitoring, kill switch
Adversary model Well-intentioned employee who does not notice the line Includes a determined or malicious actor and a compromised agent
Owner Compliance, legal, communications, HR Security, ML engineering, platform
Relationship to archiving Front-end shield: fewer issues reach the archive at all Feeds logs into monitoring and incident response

The table does one useful thing under pressure: it stops a vendor from selling you a runtime tool as if it fixed your keyboard problem, and it stops you from mistaking a pre-send check for an agent security boundary. Both errors are common, and both leave a gap someone else finds later.

Why the human layer stays unmanaged

Regulated firms already invest heavily in the moments after send. Archiving and supervision platforms capture and review what went out. The off-channel recordkeeping cases show what happens when that capture fails: the SEC and CFTC levied over USD 2 billion in penalties across firms whose staff communicated on unmonitored channels. That is real money, and it explains why the supervision budget is large.

But archiving is a system of record and review. By the time a message reaches the archive, it has already been sent. If the sentence created exposure, the exposure exists. Supervision can find it, sample it, and escalate it, and it does valuable work doing so, and every one of those reviews is triggered by a message that already left. The moment where the outcome could still change, the pause before send, has almost no coverage in most programs. It is left to individual judgment, which is fine on a good day and expensive on a bad one.

This is the layer VerbaPulse works on. It runs a pre-send check on a human draft, flags the specific phrase that creates exposure, and offers a safer way to say the same thing, or says plainly when the safest move is to cut the line. On the aircraft-manufacturer text, the actual product output is short and phrase-level:

  • CRITICAL, legal: “I basically lied to the regulators (unknowingly).” Flagged as an admission of misleading a regulator. Recommendation: remove the sentence, since no compliant rewording preserves the meaning.
  • HIGH, reputational: “This airplane is designed by clowns, who in turn are supervised by monkeys.” Flagged as disparagement of the design team. Recommendation: remove the sentence.

That is the real register of the tool: catch the careless line a well-intentioned person did not notice, at the one moment removing it still costs nothing.

Where a pre-send check fits, honestly

Being precise about scope is part of the pitch, so here is the honest boundary. A pre-send check operates on the human layer, on the draft a person is about to send. It is not agent-runtime governance. It does not sit inside your AI agents, and it will not stop a prompt-injected system or a determined attacker who has already decided to do harm. Those are runtime problems, and they need runtime controls in the right column of the table above.

Nor does a pre-send check replace archiving and supervision. It complements them. Think of it as the front-end shield: it reduces the number of risky messages that ever reach the archive, so your Smarsh or Proofpoint queues carry fewer genuine issues and your reviewers spend their time on the ones that matter. Supervision still runs. The archive is still the record. The pre-send layer simply moves the first line of defense earlier, to the point of writing, where a fix is a keystroke instead of a filing.

Two rails, two owners, one clear division. Runtime governance guards the machine. The pre-send check guards the human. A firm that manages only one of these is exposed on the other, and after the Omnibus reshuffled the calendar, the human side is the one most firms still have not staffed.

The takeaway

Do this: take the two-control-point table into your next AI-governance review and sort every existing and proposed control into the correct column. Wherever the “human pre-send” column is empty, you have found the layer regulation does not cover and most programs have left to chance. Start by mapping which of your outbound channels (email, chat, LinkedIn, regulator correspondence) has any check at all before a human hits send. For a plain walkthrough of which AI Act obligations remain live after the Omnibus, and how they sit against this human layer, work through our EU AI Act resource hub.

The floor is set by the regulation. The sentence your employee is about to send is still up to you. This is general information and not legal advice; check specifics with your own counsel.

See it on your own emails

VerbaPulse flags risky wording as you write in Outlook and Gmail, then offers a safer phrasing before you send. Run it against your own messages and your own rules in a 30-day pilot.

Start a pilot

Up to 10 seats. EUR 120, credited to your plan if you continue.

See how VerbaPulse flags risk before an email is sent, right inside Gmail and Outlook.

See VerbaPulse in action →
← Upload Your Own Rules: Turning Your NDA, Brand Guide, and Policy Into a Live Pre-Send Check MNPI and market abuse: the everyday phrases that cross the line →