The EU AI Act Just Went Live β€” and It’s Not the Law Everyone Thought

The EU AI Act Just Went Live β€” and It’s Not the Law Everyone Thought

Part: One

πŸ”Š Listen to this article (~11 min)

On 2 August 2026, the most consequential AI regulation in history went live. But if you read anything about it before July this year, you’re probably working from the wrong calendar.

For two years, 2 August 2026 sat in every compliance calendar as the moment the EU AI Act would switch on across the single market. It’s Regulation (EU) 2024/1689 β€” the first comprehensive AI law from any major regulator β€” and it entered into force on 1 August 2024 with a deliberately staggered timetable.

The date arrived. But it arrived carrying far less than anyone planned. A late amendment package β€” the AI Omnibus, part of the Commission’s wider Digital Package on Simplification β€” split the calendar into two speeds. The transparency rules landed on schedule. The heavy high-risk regime didn’t.

This article is the first of two. Here, we lay out what the AI Act actually is, what really switched on in August, what got pushed back β€” and why the deadline confusion itself is the story. In the second, we’ll look at the strategic opportunity hiding inside the timing.


What the AI Act is β€” and how it sorts AI

The AI Act works on a simple premise: not all AI deserves the same treatment. It sorts applications into risk categories, and the category decides the obligation.

  • Unacceptable risk β€” banned. The Act prohibits nine practices, including harmful manipulation and deception, social scoring, untargeted scraping of the internet or CCTV for facial-recognition databases, emotion recognition in workplaces and education, and real-time remote biometric identification for law enforcement in public spaces. These prohibitions (1–8) have applied since 2 February 2025, per the European Commission.
  • High risk β€” regulated. AI that can meaningfully affect people’s rights or safety β€” hiring, credit, education, critical infrastructure β€” carries a full set of legal requirements.
  • Limited and minimal risk β€” mostly transparency. Chatbots, deepfakes, and the general run of business AI largely sit here.

The risk-based architecture itself was never on the negotiating table. The Omnibus changed the timing β€” and, as we’ll see, added one new prohibition and some targeted simplifications β€” but not the design.

New law most people don’t know about yet: the AI Omnibus added a ninth prohibition β€” a ban on AI systems that generate non-consensual sexually explicit and intimate content or child sexual abuse (CSAM) material, such as AI “nudification” apps. Per the Commission, it comes into effect in December 2026.


The two speeds of the August deadline

Speed one β€” transparency went live on 2 August 2026

The part of the Act that survived the reshuffle intact is Article 50 β€” the transparency layer. From 2 August 2026, any AI system placed on the EU market must now:

  • Say it’s a machine. Systems that interact directly with people must make clear you’re dealing with AI, unless it’s obvious from context.
  • Label synthetic content. Deepfakes and manipulated audio, image, or video must be disclosed as artificially generated.
  • Flag biometric manipulation. Emotion-recognition and biometric-categorisation systems must inform the people exposed to them.

There’s a sting in the timing here. The machine-readable watermarking obligation β€” marking synthetic audio, image, video, and text so it can be traced β€” applies to newly placed systems from 2 August. But recital (38) of the AI Omnibus Regulation grants a four-month transitional period to providers who already placed their generative-AI systems on the market before 2 August 2026 β€” meaning those systems get until 2 December 2026 to comply. It’s a concession aimed at patching existing products rather than forcing a redesign.

Speed two β€” high risk slid, not vanished

The heavier obligations β€” the ones that were supposed to make 2026 the big year β€” were pushed out by the Omnibus:

  • Standalone high-risk AI (Annex III: hiring, credit scoring, biometric categorisation, critical infrastructure, education, law enforcement) now applies from 2 December 2027.
  • High-risk AI embedded in already-regulated products (Annex I: medical devices, automotive, machinery, aviation, toys) now applies from 2 August 2028.

The timeline behind the change, per the Commission: the proposal was adopted on 19 November 2025, a political agreement was reached on 7 May 2026, the Council gave its final green light on 29 June 2026, and the Omnibus entered into force on 27 July 2026 β€” before the August deadline even arrived.

Read this carefully: the extension is a grace period, not a reprieve from the substance. The core obligations β€” conformity assessment, quality management systems, technical documentation, registration, CE marking β€” are substantively unchanged for most providers. The Omnibus did introduce limited simplifications (below), but the fundamental compliance burden did not shrink.


What else the Omnibus changed (beyond the calendar)

The headline was the timeline, but it wasn’t the only change. Per the Commission, the Omnibus also:

  • Simplified requirements for smaller companies β€” the relief previously granted to SMEs was extended to small mid-cap companies (SMCs), including simplified technical documentation requirements.
  • Reinforced the AI Office β€” stronger powers and more centralised oversight of AI systems built on general-purpose AI (GPAI) models, reducing governance fragmentation.
  • Expanded regulatory sandboxes β€” more innovators get access, including a new EU-level sandbox to test AI in real-world conditions.
  • Clarified the interplay with product safety law β€” particularly the Machinery Regulation, avoiding duplication between sectoral and AI rules.

None of this changes the direction of travel. It changes how much runway you have.


Why the delay happened (and what it signals)

The Commission’s stated rationale for the Omnibus was to keep the rules “clear, simple, and innovation-friendly” β€” and to give businesses the support tools, such as standards, needed to implement the Act properly. In practice, the delay reflects a blunt reality: the harmonised technical standards that conformity assessments depend on were not finalised in time, and the enforcement infrastructure β€” notified bodies, national authorities, the AI Office β€” needed more time to become operational.

That’s worth sitting with. The EU is admitting, in effect, that its own ecosystem couldn’t absorb the law on schedule. That’s not cynicism to exploit β€” it’s a timing signal. And as we’ll explore in the second article, the businesses that treat the extra year and a half as a head start rather than a reprieve will be the ones nobody can catch even after the new dates land.


What the fines look like (this is the part people underrate)

Enforcement isn’t symbolic. From 2 August 2026, the AI Office and Member State authorities are responsible for implementing, supervising, and enforcing the Act β€” and the AI Office holds direct enforcement powers over GPAI models. Per the European Commission’s own AI Act Service Desk, Article 99 lays out fines that scale with size:

  • Prohibited practices: up to €35 million, or 7% of total worldwide annual turnover, whichever is higher.
  • Most other violations: up to €15 million, or 3% of worldwide turnover.
  • Supplying incorrect or misleading information to authorities: up to €7.5 million, or 1%.

General-purpose AI model providers face a separate regime under Article 101.

The 7% figure is the one that commands attention β€” it’s a turnover-linked penalty, not a flat fee. For a large company, that’s not an inconvenience; in a bad year it’s existential. And the range here is higher than most comparable regimes, which tells you the EU intends the AI Act to be taken as seriously as GDPR β€” which many expect it to join as a de-facto global standard.


What to do now (transparency is already live)

If you deploy AI in a way that touches EU users β€” even from outside the EU, because the Act reaches providers and deployers who put systems on the EU market β€” the transparency layer is the part already binding you today. A practical checklist:

  • Audit what you ship. Where does your product use AI that talks to people? Chatbots, copilots, support assistants β€” those are the obvious ones.
  • Add the disclosure. Make it structurally impossible to miss that a user is interacting with a machine, not a human.
  • Get ahead on watermarking. If you generate synthetic content, the retrofit deadline is 2 December 2026. Building the marking in now is cheaper than retrofitting it.
  • Map your high-risk systems anyway. Even with the 2027/28 dates, the gap between “knowing” and “complying” is measured in months. The companies that wait until 2027 to start will be exactly the ones scrambling.
  • Watch the December 2026 prohibition. If your product or supply chain touches synthetic intimate content, the ninth prohibition lands in December 2026 β€” not 2027.

The bottom line

The AI Act’s big date arrived carrying a surprise: the transparency rules are law, and the heavy regime is later β€” not lighter. Anyone still working from pre-July guidance is building on a wrong map.

For builders who internalise the real calendar, the opportunity is unmistakeable: use the window before 2027/28 to make compliance a design property, not an emergency. As we’ll see in the second article, that’s the difference between treating the AI Act as a cost and treating it as a moat.

This article is informational and does not constitute legal advice. The AI Act is evolving; timelines and guidance may be updated by the European Commission and the AI Office. Information reflects the position as of August 2026.


Sources (primary)