The EU AI Act’s Big August Deadline Just Landed — But Not the Way Everyone Expected
The EU AI Act hit another major milestone this month, with most of its remaining provisions becoming applicable as of 2 August 2026. But the headline story isn’t quite what it looked like a few months ago — a last-minute legislative fix means the toughest part of the law, the rules for high-risk AI systems, actually got pushed back.
What Changed at the Last Minute
Back in November 2025, the European Commission tabled something called the Digital Omnibus on AI, aimed at giving companies more breathing room after it became clear that the standards and guidance needed to actually enforce high-risk obligations weren’t ready in time. After months of back-and-forth in Brussels — including one trilogue that collapsed entirely in April — EU institutions finally reached agreement in May, and the Omnibus was formally published in the Official Journal on 24 July, taking legal effect just days before the original deadline. The upshot: obligations for stand-alone high-risk systems (the kind covered under Annex III — things like credit scoring, biometric categorisation, hiring tools) are now deferred to 2 December 2027, while AI embedded in regulated products like medical devices or lifts gets until August 2028.
What Actually Kicked In This Month
That doesn’t mean nothing changed on 2 August. The transparency rules under Article 50 are still very much live — companies now have to disclose when someone’s interacting with an AI system, and generative AI providers need to label their outputs in a machine-readable way (deepfake content included), though systems already on the market get a short grace period until December to sort out the technical labelling piece. General-purpose AI model obligations, which kicked in back in August 2025, remain unchanged too, as does the EU AI Office’s enforcement authority.
One New Addition Worth Noting
Interestingly, the same Omnibus that delayed the high-risk rules also tightened the law elsewhere — it added an outright ban on so-called “nudifier” apps that generate non-consensual intimate imagery, along with AI-generated child sexual abuse material, a prohibition that takes effect 2 December 2026.
Why This Matters for Companies Building or Deploying AI
For businesses that had been racing to get conformity assessments and technical documentation ready for high-risk systems, the delay buys real time — but it’s not a reason to stop preparing. The penalty structure remains steep once the high-risk rules do land, with fines that can reach up to €35 million or 7% of global annual turnover, whichever is higher. Legal advisors are largely telling clients the same thing: treat the extra runway as a chance to get governance and data practices in order, not as a signal the requirements are going away. If anything, the drawn-out negotiation process itself is a preview of how messy enforcement of a regulation this ambitious is likely to get in practice.

