The clock is ticking, and for once the warnings aren’t just legal hype. As of mid-2026, the EU Artificial Intelligence Act has moved from “something to watch” to “something that can fine you.” The next big enforcement milestone lands on 2 August 2026 — and if your organisation builds, sells, or even uses AI in ways that touch people in the European Union, this affects you.
Here’s the catch most companies are getting wrong: the rules recently shifted, but not in the way everyone assumed. A wave of reporting suggested the whole regime got delayed. It didn’t. Some obligations were pushed back. Others are landing right on schedule. Confusing the two could be an expensive mistake.
Let’s break down where things actually stand, what changed, and exactly what your company should be doing before the deadline arrives.
Why the EU AI Act Matters to You (Even If You’re Not in Europe)
The AI Act is the world’s first comprehensive law governing artificial intelligence. It entered into force on 1 August 2024 and applies in phases through 2027 and beyond. Like the GDPR before it, its reach is extraterritorial — meaning a startup in San Francisco, a manufacturer in Mumbai, or an agency in London can all fall under it the moment their AI system affects people inside the EU.
And the penalties are not symbolic. Breaching the rules on prohibited AI practices can cost up to €35 million or 7% of global annual turnover, whichever is higher. That’s steeper than the GDPR’s headline fines. For most businesses, this is no longer a compliance footnote. It’s a board-level risk.
What’s Already in Force
A lot of people think the AI Act “starts” in August 2026. In reality, parts of it have been live for over a year:
- Since 2 February 2025: Bans on “unacceptable risk” AI — things like social scoring by governments, manipulative systems that exploit vulnerabilities, and most real-time biometric surveillance in public spaces. The AI literacy obligation also kicked in here, requiring organisations to make sure staff working with AI actually understand it.
- Since 2 August 2025: Rules for general-purpose AI (GPAI) models — the large foundation models behind tools like ChatGPT, Claude, and Gemini. Governance bodies such as the EU AI Office were stood up, and member states put their penalty frameworks in place.
If you’ve been treating the Act as a future problem, that framing is already a year out of date.
The Plot Twist: What the “Digital Omnibus” Actually Changed
In May 2026, EU negotiators reached a provisional agreement on a package of amendments known as the Digital Omnibus on AI — the first real changes to the law since it was adopted. Final adoption is expected over the summer, with publication anticipated before the August milestone.
This is where the confusion exploded. Headlines blurred together, and many compliance teams quietly assumed they’d been handed a reprieve across the board. They hadn’t. Here’s the honest version of what moved:
Deadlines that got pushed back:
- High-risk AI systems (use-based, the “Annex III” category): Compliance shifted from 2 August 2026 to 2 December 2027 — roughly a 16-month extension. This covers AI used in areas like hiring, credit scoring, education, and access to essential services.
- High-risk AI built into regulated products (the “Annex I” category): Pushed from August 2027 to August 2028.
- National regulatory sandboxes: Member states now have until August 2027 to set these up.
- Content-labelling for systems already on the market before August 2026: a short four-month grace period, to 2 December 2026.
Deadlines that did not move — still 2 August 2026:
- Enforcement powers over general-purpose AI models. From this date, the Commission can open formal investigations, issue binding corrective measures, and impose fines on GPAI providers.
- Transparency obligations for new AI systems under Article 50 — including disclosing AI-generated or manipulated content (deepfakes, synthetic media, chatbots that should identify themselves).
In short: the heavy, documentation-intensive high-risk obligations got breathing room. The enforcement teeth and transparency rules did not. If you assumed everything slid to 2027, you may be walking into August unprepared.
There’s also a notable addition. From 2 December 2026, the Act will explicitly prohibit using AI to generate non-consensual intimate imagery and child sexual abuse material — a direct response to the deepfake abuse crisis.
What Companies Must Do Before the Deadline
Enough context. Here’s the practical checklist that turns anxiety into action.
- Build an AI inventory
You can’t comply with rules for systems you haven’t catalogued. Map every AI tool your organisation develops, buys, or embeds — including the quiet ones inside HR software, customer-service bots, and marketing platforms. Shadow AI adopted by individual teams is where most companies have blind spots.
- Figure out your role
The Act assigns different duties depending on whether you’re a provider (you build or rebrand the system), a deployer (you use it in your operations), an importer, or a distributor. Many companies are surprised to learn they’re “providers” the moment they substantially modify or rebrand a third-party tool. Your obligations — and your liability — hinge on this classification.
- Classify the risk
Sort each system into the Act’s tiers: prohibited, high-risk, limited-risk (transparency obligations), or minimal-risk. High-risk systems carry the most demanding requirements — risk management, data governance, technical documentation, human oversight, logging, and conformity assessment. Even with the extended deadline, these take many months to build properly.
- Get transparency right now
This one’s urgent because it isn’t delayed for new systems. If you deploy chatbots, generate synthetic media, or produce AI content that could be mistaken for human-made, you need clear disclosure and machine-readable labelling. Start auditing your customer-facing AI today.
- Take AI literacy seriously
The obligation has softened slightly — from “ensure” literacy to “take measures to support” it — but it’s still a live requirement. Document your training programmes. Regulators will want evidence, not good intentions.
- Pin down GPAI and supply-chain duties
If you build on top of foundation models, understand what your model provider must give you: technical documentation, known limitations, and testing access. The amendments sharpened these value-chain obligations, and breaches of certain information-sharing duties can now trigger fines of up to 3% of worldwide turnover.
- Stand up governance
Assign clear ownership — many organisations are appointing an AI governance lead or committee that bridges legal, technical, and product teams. Create a repeatable process for assessing new AI before it goes live, not after.
Common Mistakes to Avoid
The biggest one is treating the recent extension as a free pass. The second is assuming “we don’t build AI, so we’re fine” — deployers have real obligations too. The third is leaving documentation until the last quarter; conformity assessments and data-governance evidence cannot be reverse-engineered overnight.
The Bottom Line
The EU AI Act isn’t a single deadline — it’s a staggered rollout, and the next gate is weeks away, not years. The smartest move right now is to separate fact from headline: confirm which obligations apply to your systems, act immediately on the ones that haven’t been delayed (transparency, GPAI enforcement, prohibited practices), and use the extra time on high-risk systems to do the hard documentation work properly.
Companies that start now won’t just avoid fines. They’ll build the kind of trustworthy, well-governed AI that customers and regulators increasingly demand — and that’s a competitive advantage no countdown can take away.