What Most Companies Are Getting Wrong

August 2, 2026 has been circled in calendars across Europe as the day the EU AI Act truly arrives. Then, in June 2026, the EU moved the goalposts. Understanding what actually changed — and what didn't — is now more important than the original deadline ever was.

Companies that interpreted the deferral as breathing room are making a costly mistake. Those that understand what August 2 still triggers, and what the revised timeline demands, will be ahead. Everyone else is accumulating compliance debt they'll have to pay — with interest — in 2027.

What Is the EU AI Act?

Regulation (EU) 2024/1689 — the EU AI Act — is the world's first comprehensive legal framework governing artificial intelligence. It entered into force on August 1, 2024, and applies across all EU member states without requiring national transposition.

Unlike sector-specific regulation, the AI Act is horizontal: it covers AI systems across all industries and use cases. Its core mechanism is a risk-based classification that determines which obligations apply to a given system. The higher the risk, the stricter the requirements.

The Act distinguishes between two primary actors: providers (organizations that develop or place AI systems on the market) and deployers (organizations that use AI systems in their operations). Both carry obligations — though providers generally carry more.

Importantly, the AI Act's scope is not limited to EU-based organizations. Non-EU providers placing AI systems on the EU market carry the same provider obligations as EU companies. EU-based deployers are bound by their obligations regardless of where their AI vendor is located — compliance responsibility cannot be delegated to a non-compliant foreign supplier.

The Four-Tier Risk Framework

The AI Act classifies AI systems into four categories:

Prohibited AI (Article 5). AI practices that are banned outright — enforceable since February 2, 2025. These include: social scoring by public authorities, real-time remote biometric identification in publicly accessible spaces for law enforcement purposes (with narrow judicial exceptions), subliminal manipulation of behavior, exploitation of vulnerabilities based on age, disability, or socioeconomic situation, and AI that infers sensitive attributes such as race, political opinion, or religion from biometric data. Note: retrospective (post-event) remote biometric identification by law enforcement is not in this category — it is regulated as high-risk AI under Annex III, subject to prior authorization and strict conditions, but is not banned.

High-Risk AI (Annex I and Annex III). AI systems with significant potential impact on health, safety, or fundamental rights. Annex I covers AI embedded as a safety component in regulated products (machinery, medical devices, vehicles). Annex III covers use-based applications in critical infrastructure, education, employment (CV screening, hiring decisions), essential services (credit scoring), law enforcement, migration, and administration of justice.

Not every Annex III system automatically triggers full high-risk obligations. Article 6(3) allows providers to formally self-assess and document that their specific implementation does not present a significant risk to health, safety, or fundamental rights — for example, because it performs only a preparatory or ancillary function, or does not meaningfully influence individual outcomes. This requires structured analysis and documentation, but can materially reduce compliance burden. Classification work is the necessary starting point.

Limited-Risk AI. AI systems that interact with people or generate content. Subject to transparency obligations under Article 50 — the subject of this article's central argument.

Minimal-Risk AI. Spam filters, AI-enabled video games, and most recommendation systems. No specific AI Act obligations, though voluntary codes of conduct apply.

What Was Already Required Before August 2, 2026

Two significant waves of obligations preceded the August 2 date:

February 2, 2025 — Prohibited AI and AI Literacy. The Article 5 prohibitions became enforceable. Violations already carry fines of up to €35 million or 7% of global annual turnover. AI literacy obligations also took effect: both providers and deployers of AI must ensure their staff have adequate understanding of the AI systems they develop or use.

August 2, 2025 — General Purpose AI (GPAI). Obligations for providers of General Purpose AI models entered into application. All GPAI providers must produce technical documentation, maintain copyright compliance, and publish training data summaries. Providers of models posing systemic risk — those trained with compute above 10²⁵ FLOPs (the most computationally intensive frontier models; individual providers' threshold status is not always publicly confirmed) — must additionally conduct adversarial testing, report serious incidents to the EU AI Office, and implement cybersecurity measures.

GPAI providers primarily demonstrate compliance through codes of practice developed under Article 56 in coordination with the EU AI Office — not solely through individual documentation. The AI Office has run an ongoing code of practice development process since 2025 with major model providers.

Important transitional provision (Article 101): GPAI providers whose models were already placed on the market before August 2, 2025 have a grace period until August 2, 2027 to achieve full compliance. In practice, this means most currently deployed frontier models — whose development predates August 2025 — operate under this two-year transition. New model releases after August 2025 carry no such grace period.

The Digital Omnibus: What the EU Just Changed

On May 7, 2026, EU negotiators reached a provisional agreement on the Digital Omnibus — a package of amendments to the AI Act and other EU digital regulations. The European Parliament formally endorsed it on June 16, and the Council gave its final green light on June 29, 2026. The key AI Act changes:

High-risk Annex III AI: deferred 16 months. The obligations for standalone high-risk AI systems (use-based applications in hiring, credit scoring, critical infrastructure, etc.) have been pushed from August 2, 2026 to December 2, 2027.

High-risk Annex I AI: deferred to 2028. AI embedded as a safety component in products already covered by EU harmonization legislation (machinery, medical devices, etc.) now has until August 2, 2028.

New prohibitions added. The Omnibus added two new banned practices applying from December 2, 2026: AI systems used to generate or distribute AI-generated child sexual abuse material, and AI systems used to produce non-consensual intimate images.

Simplified rules extended. The Omnibus extended simplified compliance rules to companies with fewer than 750 employees and €150 million in annual revenue. This covers many mid-market organizations not previously within scope of simplified provisions. Note that this threshold substantially exceeds the standard EU SME definition (under 250 employees, under €50M turnover) — it is a specific AI Act category, not the legal SME definition used elsewhere in EU law.

Why did this happen? The AI Act's original timeline was set in 2024. By 2026, it became clear that many organizations — and the notified bodies that certify compliance — were not prepared. The deferral is a pragmatic response to a readiness gap, not a signal that the obligations are less serious.

The Digital Omnibus addressed multiple EU digital regulations, not only the AI Act. Organizations subject to GDPR, the Data Act, NIS2, and related frameworks should verify whether those adjacent obligations were also modified by the same package. Application dates listed in this article are calculated from the Omnibus's expected date of publication in the Official Journal — readers should confirm final dates against the published text once available.

What August 2, 2026 Actually Triggers

Despite the Omnibus deferral of high-risk obligations, August 2, 2026 remains a real and important date.

Article 50 transparency obligations — fully in effect. Article 50 distributes obligations between providers and deployers. Providers must design AI systems to make disclosure possible; deployers must not disable that transparency function and carry independent obligations for the content and emotional analysis systems they deploy:

Chatbots and virtual assistants: Providers must ensure that AI systems designed for direct interaction with natural persons can inform users they are interacting with AI. Deployers must not suppress this function. Users must be informed in a way that is perceptible within the interaction itself — not buried in terms and conditions. This obligation applies to externally-facing customer systems; purely internal enterprise tools used only by employees involve different considerations
AI-generated text published to inform the public: Deployers using AI to generate or manipulate text published for the purpose of informing the public on matters of public interest must label that content as artificially generated. This applies to AI-assisted corporate announcements, press releases, investor communications, and regulatory filings — wherever the content is intended to inform the public
Deepfakes: AI-generated or AI-manipulated video, audio, and images must be labeled as artificially generated. This obligation applies in contexts where audiences might assume authenticity — clearly labeled creative, satirical, or fictional content falls under a specific exception. Not all AI-generated marketing imagery automatically triggers this obligation; context and the reasonable risk of deception determine applicability
Emotion recognition and biometric categorization: Deployers of these systems must inform the individuals being subject to them. This covers AI that infers emotional or psychological states from physiological or behavioral signals — including fatigue detection, stress monitoring, and driver alertness systems in logistics and production environments

GPAI codes of practice reach maturity. The codes of practice framework under Article 56 reaches its formal maturity point: GPAI providers should by now have committed to an applicable code or have documented alternative compliance. The EU AI Office has held full supervisory powers since August 2025 — August 2026 is not a new enforcement inflection point for GPAI, but it is the end of the code development phase.

Article 50 is broader than it first appears. If your organization deploys customer-facing chatbots, uses AI to generate public-facing content, produces AI-manipulated media, or monitors workforce emotional states — you need to be compliant on August 2.

The Revised Compliance Timeline

Feb 2, 2025  Prohibited AI (Article 5) + AI literacy — ALREADY IN FORCE
Aug 2, 2025  GPAI obligations — IN FORCE for new models; transitional period (Art. 101) for models placed on market before this date → until Aug 2, 2027
Aug 2, 2026  Article 50 transparency (chatbots, AI-generated public text, deepfakes, emotion recognition) — 3 WEEKS
Dec 2, 2026  New Omnibus prohibitions: AI-generated CSAM, non-consensual intimate images
Aug 2, 2027  GPAI transitional grace period (Art. 101) ends — all GPAI providers fully in scope
Dec 2, 2027  Annex III high-risk AI: hiring tools, credit scoring, critical infrastructure, law enforcement
Aug 2, 2028  Annex I high-risk AI: safety components in regulated products (machinery, medical devices)

Application dates for Omnibus-amended provisions are calculated from the regulation's expected Official Journal publication date.

Why the Deferral Is Not Permission to Wait

The 16-month extension for high-risk AI sounds generous. It isn't — not if you understand what compliance for Annex III actually requires.

AI system classification takes longer than expected. Determining whether a given AI system falls under Annex III requires legal analysis, technical documentation, and often external expertise. Organizations with dozens or hundreds of AI deployments face months of classification work alone. This work also opens the path to Article 6(3): only once you've done the classification can you build the structured argument that a system doesn't present significant risk.

Technical documentation must be built — not found. High-risk AI requires detailed documentation of training data, model architecture, testing methodology, performance metrics, and ongoing monitoring processes. For AI systems already deployed, this documentation often doesn't exist and must be reconstructed.

Deployers have independent obligations under Article 26. Companies deploying third-party high-risk AI — not building it themselves — are not off the hook. Article 26 requires deployers to: register their use of high-risk systems in the EU database, implement the human oversight measures specified by the provider, monitor systems for unexpected risks during deployment, and report serious incidents to the national competent authority. Assuming the AI vendor handles all compliance is a significant and common mistake.

Human oversight mechanisms require organizational change. Article 14 requires meaningful human oversight of high-risk AI decisions — not a checkbox, but actual processes where humans can intervene, override, or halt AI outputs. Building this into existing workflows takes time.

Post-market monitoring is a continuous obligation (Article 72). High-risk AI providers must establish monitoring systems that track model performance after deployment, collect relevant data, and feed findings back into risk documentation. Compliance is not a one-time exercise completed at launch — it is an ongoing operational commitment.

Notified body capacity is limited. For AI systems requiring third-party conformity assessment, the supply of accredited notified bodies in the EU is constrained. Organizations that wait until late 2027 may face queues.

December 2027 is 17 months away. For organizations with complex AI deployments, that is not a long time.

Penalties: What Non-Compliance Costs

The AI Act's fine structure is tiered by violation severity:

Prohibited AI practices (Article 5): up to €35 million or 7% of global annual turnover — whichever is higher
High-risk AI violations and Article 50 non-compliance: up to €15 million or 3% of global annual turnover
Providing incorrect, incomplete, or misleading information to authorities: up to €7.5 million or 1.5% of global annual turnover

For companies with fewer than 750 employees and €150 million in annual revenue — the category extended by the Omnibus — the lower of the two thresholds (the percentage cap or the absolute figure) applies. This provides proportionate protection, but does not exempt these organizations from the underlying obligations.

Enforcement is a national competency — each EU member state designates a national competent authority responsible for high-risk AI in their territory. The AI Office handles GPAI models and cross-border cases directly. Germany, France, and the Netherlands are among the member states that have published their supervisory structures.

The Double Obligation: AI Act Meets Cyber Resilience Act

For manufacturers of connected products that incorporate AI — industrial equipment, smart devices, edge computing systems — the AI Act does not operate in isolation. The Cyber Resilience Act (CRA, Regulation (EU) 2024/2847) applies in parallel.

A machine with an AI-based predictive maintenance system faces obligations under both frameworks. The first question a manufacturer must resolve is whether the AI component functions as a safety element of the product. An AI system that can trigger emergency shutdowns or control safety-critical processes is likely a safety component of the machinery and therefore high-risk under Annex I. An AI system used purely for operational efficiency — scheduling maintenance intervals without safety implications — may not meet the high-risk threshold. This classification determines whether AI Act obligations apply at all, before CRA obligations are layered on top.

For manufacturers with AI embedded in regulated products, conformity assessment under the AI Act is designed to integrate with existing product-sector conformity assessment procedures — for example, Machinery Regulation CE marking. A separate parallel AI Act conformity assessment process is generally not required; manufacturers should confirm with their existing notified body how AI Act requirements are incorporated into ongoing product certification.

Where the CRA governs the cybersecurity of the connected product as a whole: it requires a Software Bill of Materials (SBOM), a vulnerability management process, and a three-stage incident reporting obligation for actively exploited vulnerabilities — a 24-hour early warning to the national CSIRT (Computer Security Incident Response Team, such as BSI in Germany), followed by a full incident notification within 72 hours, and a final report within 14 days. Reports flow through national CSIRTs to ENISA, not directly to ENISA as primary recipient.

Organizations that treat AI compliance and cybersecurity compliance as separate workstreams will pay twice: once in effort and once in risk. The smarter approach is an integrated compliance architecture that addresses both frameworks simultaneously.

What to Do Before August 2 — and After

If you use customer-facing or public-content AI: audit your chatbots, AI-generated content pipelines, voice assistants, and any AI used to generate public-facing text now. Article 50 compliance is not optional from August 2, and it's not complex to implement — but it requires deliberate action. Disclosure mechanisms need to be built into products and workflows, not bolted on after an enforcement notice.

If you develop or deploy high-risk AI: use the 17-month extension wisely. Start with a complete inventory and risk classification of your AI systems — including formal Article 6(3) self-assessments where applicable. Build documentation practices into your development process today, not in Q3 2027. Identify which systems will require third-party conformity assessment and engage notified bodies early. If you are a deployer using third-party AI, review your Article 26 obligations now — your compliance exposure does not sit solely with your vendor.

If you're an AI provider: check whether your models fall under the Article 101 transitional provision (placed on market before August 2, 2025) or carry immediate obligations (new releases after August 2, 2025). If your models are in full scope, or if the transitional period ends in August 2027, your adversarial testing, incident reporting, and codes of practice commitments need to be in place. The AI Office is actively supervising.

The EU AI Act is not a future problem. Parts of it are already law, enforcement is operational, and the August 2 date — though no longer the high-risk deadline — is a real transparency enforcement inflection point. The companies that will navigate this well are those that build compliance capability now, systematically, rather than in response to a deadline that's already arrived.

I'm happy to discuss what the AI Act means for your specific AI deployments and how it intersects with other regulatory obligations. Feel free to connect or reach out directly.

Sources & References

Regulation (EU) 2024/1689 — EU AI Act, Official Journal of the European Union — eur-lex.europa.eu
EU Council: Final green light for AI Omnibus (June 29, 2026) — consilium.europa.eu
Gibson Dunn: EU AI Act Omnibus Agreement — Postponed High-Risk Deadlines and Other Key Changes — gibsondunn.com
AI Act Service Desk: Implementation Timeline — ai-act-service-desk.ec.europa.eu
Article 50: Transparency Obligations — EU AI Act — artificialintelligenceact.eu
Greenberg Traurig: European Commission Details Transparency Obligations Under the AI Act (June 2026) — gtlaw.com

The EU AI Act (Regulation (EU) 2024/1689) and the Digital Omnibus amendments are directly applicable across all EU member states. Obligations vary by actor type (provider/deployer), AI system classification, and organization size. Application dates for Omnibus provisions are subject to the regulation's Official Journal publication date. This article reflects my professional assessment and does not co