

By: Ralf Ellspermann
25-Year, Multi-Awarded BPO Veteran
Published: 28 September 2026

Reviewed By: John Maczynski
Former EVP, World's Largest Contact Center
Updated: 28 September 2026
By supplying the evidence a European provider needs to discharge its own obligations: documented provenance for every training sample, records of how data was prepared, and bias examination results. The Act imposes nothing on an annotation vendor directly, so everything it owes arrives through the contract rather than through the statute.
Key Takeaways
- The high-risk deadline moved, and most coverage has not caught up. The Digital Omnibus entered into force on 27 July 2026, deferring Annex III high-risk obligations from 2 August 2026 to 2 December 2027 and Annex I to 2 August 2028.
- Article 50 transparency has applied since August 2026 and was not deferred. Nor were the prohibitions or the general-purpose model rules. The deferral is narrower than it is usually reported.
- The Act does not regulate your annotation vendor. Obligations attach to providers and deployers. A supplier cannot be non-compliant with the Act; it can only fail to supply what its client needs.
- Multi-tier annotation review is Article 10, not Article 14. Human oversight means a person able to interpret, override and stop a running system. Nothing an annotation pod does reaches that duty.
- Build provenance in rather than retrofitting it. The two cost the same when a fifth of the corpus cannot be evidenced. Above that threshold, and mixed-source corpora routinely are, building it in was always cheaper.
- A Philippine facility cannot offer data residency. It can support a lawful transfer, which needs Article 46 safeguards because the Philippines holds no adequacy decision. The controls are right; the label often is not.
Which EU AI Act Obligations Actually Apply, and When?
Prohibited practices since February 2025, general-purpose model obligations since August 2025, and Article 50 transparency since August 2026. High-risk obligations for Annex III stand-alone systems now apply from 2 December 2027, and for Annex I product-embedded systems from 2 August 2028.
The timeline changed materially in 2026 and a great deal of guidance in circulation still describes the original schedule. Getting this right determines whether a programme is preparing for something imminent or planning against a deadline fourteen months out.

Figure 1. What applies now, and what moved.
The Digital Omnibus was signed on 8 July 2026 and entered into force on 27 July 2026. It deferred the high-risk obligations by over a year. It did not defer the prohibitions, which have applied since February 2025, the general-purpose model rules in force since August 2025, or the Article 50 transparency duties that took effect in August 2026 — those include disclosing when a user is interacting with an AI system and labelling AI-generated or manipulated media, with the provider-side watermarking requirement following in December 2026.
For a buyer commissioning training data now, the practical reading is that the deferral is runway rather than relief. Fourteen months is comfortably long enough to build provenance discipline into a corpus being collected today, and comfortably too short to reconstruct it for a corpus already assembled without it. The organisations that treat the extension as permission to defer will be doing the expensive version of this work in late 2027.
Who Actually Bears These Obligations?
Providers and deployers. A provider that develops a system or places it on the EU market carries the full weight of Articles 9 to 15; a deployer using the system carries use obligations, operational oversight and disclosure duties. An annotation supplier carries nothing under the Act itself.
This is the structural point that reframes the whole procurement question, and it is routinely described the other way round — as though a Philippine provider could be AI Act compliant or non-compliant in its own right.

Figure 2. Where the obligations land.
It is neither a loophole nor a comfort. A European provider remains fully liable for a dataset whose provenance it cannot evidence, and no contractual arrangement transfers that liability to the supplier that prepared it. What the provider can do — and what this entire category of engagement is really for — is buy the artefacts that let it discharge Article 10 itself: the provenance ledger, the preparation records, the bias examination, the documented design choices.
That has three consequences for how the relationship is written. Compliance obligations belong in the contract in the form of deliverables rather than warranties of compliance, because a warranty of compliance with an act that does not bind the warrantor is close to meaningless. Audit and evidence-production rights need to survive termination, since the provider may need them years after the work ends. And the format of the evidence matters as much as its existence, because it has to slot into a technical documentation pack the buyer assembles.
What Does Article 10 Require, and What Does Article 14 Not Cover?
Article 10 requires training, validation and testing datasets that are relevant, sufficiently representative and as far as possible free of errors and complete, with documented collection origins, preparation steps and bias examination. Article 14 requires that a person can oversee the system while it is running — which annotation work cannot supply.
These two are conflated constantly in compliance mapping for this market, and the conflation produces a table that looks complete while leaving a genuine obligation unaddressed.

Figure 3. Two articles that describe different moments.
Article 10 is where annotation work does its regulatory job. The article explicitly covers data preparation including annotation and labelling, requires documentation of collection origins and design choices, and requires examination for biases likely to affect health, safety or fundamental rights. A well-run annotation engagement generates most of this as a by-product, and the difference between a compliant supplier and a merely competent one is whether it retains and exports the records rather than whether it makes them.
Article 14 concerns something else entirely: whether a natural person can understand the deployed system’s limitations, resist automation bias, interpret its output, override or disregard it, and interrupt it through a stop function. That is a design property of the system and an operational practice of the deployer. Multi-tier annotation review is a real and valuable control, and it is an Article 10 data-quality measure. Listing it against human oversight leaves the buyer believing an obligation is covered when nothing has touched it.
How Should Provenance and Copyright Be Tracked?
Through a ledger recording the origin and licensing status of every training sample at the point of ingestion, legal and ethical review of collection campaigns, filtering for unverified personal data and toxic content, and retained audit trails capable of supporting a later conformity assessment.
The mechanics described in this market are sound: timestamped ingestion, recorded licensing clearances, demographic tagging and immutable audit trails. What is usually missing is the economic case for doing it up front rather than when it becomes urgent.

Figure 4. Building provenance in against retrofitting it.
Provenance-tracked collection carries a premium commonly quoted at 15% to 25%, applied across the whole corpus. Retrofitting means re-collecting whatever cannot be evidenced, at full cost, for that share only. The two are equal when about a fifth of the corpus fails — and any corpus assembled from mixed sources, inherited datasets or web-derived material routinely fails a far larger share than that. Above the threshold the premium was never overhead; it was the cheaper path all along.
The cost comparison also understates the case, because it prices re-collection at the original rate. In practice the alternatives to re-collection are licensing a substitute source, which may not exist, or discarding the capability the data supported. And re-collection restarts a schedule against a fixed regulatory date, whereas the premium is absorbed inside a schedule already running.
What to specify in the ledger
For each sample: source identifier, date and method of collection, licensing basis with evidence, consent status where personal data is involved, any transformation applied, and the annotation and review history. The last item is the one most often omitted and the one an Article 10 file most needs, because it evidences the preparation step the article names explicitly.
Can a Philippine Facility Satisfy European Data Residency?
No. Residency means the data remains physically within the EU or EEA, and offshore processing is a transfer by definition. What a Philippine facility can support is a lawful transfer under Article 46 safeguards, since the Philippines holds no adequacy decision — standard contractual clauses with a transfer impact assessment.
This distinction matters because the claim commonly made in this market is the one a buyer’s legal review will test first, and it is the one that fails.

Figure 5. Two claims that are frequently merged.
The technical controls described — isolated virtual environments with no local storage, encryption at rest and in transit, restricted-access clean rooms, biometric authentication — are genuinely valuable and are precisely the supplementary measures a transfer impact assessment looks for when evaluating whether a transfer to a non-adequate country can proceed safely. They make the transfer defensible. They do not make it a non-transfer, and encryption or routing arrangements do not change where processing occurs.
Stated correctly, the proposition is strong: a provider that can evidence its technical and organisational measures makes its client’s transfer impact assessment considerably easier to complete. Stated as residency, it invites the single objection it cannot answer. Where a buyer genuinely requires residency — because a regulator or an internal policy demands it — the work has to be performed inside the EEA, and that is a different sourcing conversation rather than a controls question.
What Should a Buyer Specify in the Contract?
Evidence deliverables rather than compliance warranties, with defined formats, retention periods and post-termination access. The supplier cannot be compliant with the Act on the buyer’s behalf, so the contract has to name the artefacts the buyer will need to demonstrate its own compliance.
- Classify the system before sourcing begins. Whether it falls in Annex III determines which obligations apply and from when. It is the buyer’s determination and it drives everything downstream.
- Contract for artefacts, not for assurances. A provenance ledger in a defined format, preparation records, bias examination results and review history — each with a specified schema.
- Make evidence rights survive termination. The buyer may need to produce this material years after delivery, potentially to a market surveillance authority.
- Put the transfer instrument in place before work starts. Standard contractual clauses with a transfer impact assessment, supported by documented technical measures.
- Keep Article 14 on your own side of the line. Operational oversight is a design and deployment duty. No annotation arrangement discharges it, and no supplier should be asked to.
- Agree the retention period for audit trails explicitly. Immutable logging is only useful if it is still available when the conformity assessment happens.
What Do Industry Leaders Say About Regulatory Readiness?
That compliance has to become an operational discipline across the workforce rather than an administrative checklist — which is the right framing, because the artefacts a provider needs are generated during the work rather than assembled afterwards.
The distinction between discipline and checklist is exactly the one the retrofit arithmetic demonstrates.
Achieving regulatory compliance for European markets requires transforming data governance from an administrative checklist into a core operational discipline across every tier of the workforce.
— John Maczynski, CEO, Cynergy BPO
A checklist is completed at the end and can only record what happened to be captured. A discipline is embedded in the workflow, which means the provenance ledger, the preparation record and the review history accumulate as the work proceeds and cost the premium rather than the reconstruction. That is the whole of the economic argument in Figure 4, expressed operationally rather than financially.
How Did One European Fintech Source a Compliant Partner?
A European fintech developing a customer-facing multilingual advisory model needed 1.5 million audited, copyright-compliant conversational turns and could not verify which prospective vendors held the necessary governance evidence. Three of more than a hundred providers qualified; the engagement finished four weeks early with no deficiencies found in later audits.
The striking figure is the shortlist. Three qualifying providers out of a network exceeding a hundred is not a failure of the market so much as a description of where it currently stands: evidence discipline of this kind is not yet widely held, which is what makes screening for it early so valuable.

Figure 6. Reported outcomes from a compliance-led sourcing process.
One determination should have preceded the sourcing exercise, and it is the determination that governs everything else. Whether the system is high-risk under Annex III is a classification question the client owns. Creditworthiness assessment of natural persons is expressly high-risk; a general customer advisory assistant may well not be, in which case the obligations engaged are Article 50 transparency rather than the full Article 9 to 15 regime, and the evidence requirements are correspondingly different.
That matters commercially as well as legally. Specifying a full high-risk evidence package for a system that is not high-risk buys a premium the programme did not need, and the reverse error is worse. The classification is cheap to establish and expensive to get wrong in either direction, which makes it the right first step rather than an assumption carried into the vendor brief.
Why Do Organizations Work with Cynergy BPO on Compliant Sourcing?
Cynergy BPO is an independent, vendor-neutral outsourcing advisory firm headquartered in Manila, representing a vetted network of more than 100 Philippine providers. It maps requirements against performance data to produce a shortlist within days and manages competitive negotiation on the buyer’s behalf.
Who Is Cynergy BPO?
Cynergy BPO is an independent outsourcing advisory and consultancy firm headquartered in Manila, founded by industry veterans with more than 65 years of combined operational experience governing major global accounts. It specialises in connecting mid-market and enterprise organisations with vetted Philippine BPO providers across voice, back-office and AI data operations.
How Does Cynergy BPO Differ from Traditional Outsourcing Brokers?
Traditional brokers are transactional and are compensated by the providers they place, which shapes which provider is recommended. Cynergy BPO applies an advisory-led methodology, mapping exact technical, regulatory and commercial requirements against performance data rather than against availability. Where only a small minority of providers hold the evidence discipline this work requires, an adviser with no placement incentive is what keeps that minority visible.
How Does Cynergy BPO’s Network of 100+ Vetted Philippine BPO Providers Benefit Organizations?
The network establishes which providers genuinely operate provenance ledgers and retain preparation records, rather than which describe themselves as compliance-ready. In a category where the qualifying share is small, screening across a large vetted network is what makes a usable shortlist possible at all.
How Does Cynergy BPO’s Advisory-Led Vendor Matching Process Work?
Requirements are mapped against operational, regulatory and commercial criteria, a tailored shortlist of vetted providers is delivered within a few working days, and the firm then manages competitive proposal and negotiation processes on the buyer’s behalf. Evidence deliverables, transfer instruments and retention obligations are settled as part of that process rather than after selection.
Why Do Organizations Use Cynergy BPO?
Because verifying regulatory evidence discipline from outside the market is close to impossible, and the cost of discovering its absence is measured in re-collection rather than in rework. Establishing which providers hold it before contracting is where the value sits.
Frequently Asked Questions
When do EU AI Act high-risk obligations actually apply?
From 2 December 2027 for Annex III stand-alone systems and 2 August 2028 for Annex I product-embedded systems, following the Digital Omnibus that entered into force on 27 July 2026. Prohibitions, general-purpose model rules and Article 50 transparency were not deferred and already apply.
Is a Philippine annotation provider subject to the AI Act?
Not directly. The Act imposes obligations on providers, deployers, importers and distributors. An annotation supplier is a service supplier to the provider, and its duties arise entirely from the contract. That is why the contract should specify evidence deliverables rather than compliance warranties.
Can a provider guarantee EU data residency from Manila?
No. Residency means the data stays inside the EU or EEA, and offshore processing is a transfer. What is achievable is a lawful transfer under Article 46 safeguards, since the Philippines has no adequacy decision: standard contractual clauses plus a transfer impact assessment, supported by documented technical measures.
Does multi-tier annotation review satisfy the human oversight requirement?
No. Article 14 concerns a person able to oversee, interpret, override and stop the system while it is in use. Annotation review is a data-quality control under Article 10. Both are worth having; only one of them is discharged by annotation work.
What is the cost premium for provenance-tracked annotation?
Commonly quoted at 15% to 30%, applied to the whole corpus. Set against re-collecting whatever cannot later be evidenced, the two break even when about a fifth of the corpus fails, which mixed-source corpora routinely exceed.
What should a provenance ledger record?
For each sample: source identifier, collection date and method, licensing basis with evidence, consent status where personal data is involved, transformations applied, and the annotation and review history. The last is most often omitted and is the one Article 10 names explicitly.
How long does it take to deploy a compliance-trained team?
Four to eight weeks depending on scale, covering recruitment, vetting, governance training and pilot validation — longer than a standard annotation ramp because the evidence workflow has to be configured and tested, not just the labelling one.
Who decides whether a system is high-risk?
The provider, before sourcing begins. Creditworthiness assessment of natural persons is expressly high-risk under Annex III; many customer-facing assistants are not, in which case Article 50 transparency applies instead. The classification drives the evidence requirement and belongs at the start of the process.
Unlock cost-efficient growth with expert BPO guidance!
Partner with Cynergy BPO to connect with top outsourcing providers.
Streamline operations, cut costs, and scale your business with confidence.

Ralf Ellspermann is the Chief Strategy Officer (CSO) of Cynergy BPO and a globally recognized authority in business process and contact center outsourcing. With more than 25 years of experience advising enterprises and SMEs, he provides strategic guidance on vendor selection, CX optimization, and scalable outsourcing strategies across global markets. His expertise spans fintech, ecommerce and retail, healthcare, insurance, travel and hospitality, and technology (AI & SaaS) outsourcing.
A frequent speaker at leading industry conferences, Ralf is also a published contributor to The Times of India and CustomerThink, where he shares insights on outsourcing strategy, customer experience, and digital transformation.
