News

The EU AI Act Deadline That Mostly Did Not Happen

High-risk AI obligations slipped to 2027 and 2028, but the August 2 transparency rules and penalties are live. What applies now, and who is selling you fear.

Editorial Team ·
5 min read intermediate

The date everyone circled has been quietly split in two

The EU AI Act became broadly applicable on 2 August 2026. That sentence is true and it is being sold to you in the wrong shape.

What actually started on 2 August: the Article 50 transparency duties — chatbots must disclose that they are chatbots, AI-generated content must be marked, deepfakes must be labelled. The European Commission’s enforcement powers over general-purpose AI models also switched on, and so did the penalty regime.

What did not start: the headline high-risk obligations, the ones every consultancy slide deck has been counting down to since 2024.

Under the AI Omnibus amendments — politically agreed in May 2026 — high-risk systems in sensitive areas moved to 2 December 2027. High-risk systems embedded into already-regulated products moved to 2 August 2028. That is a sixteen-month slip on the first tranche.

The categories affected are the consequential ones: biometric identification, critical infrastructure, education, employment, credit scoring and insurance, law enforcement, migration, and the administration of justice.

Timeline confirmed on the European Commission’s own page; the deferral is analysed by Norton Rose Fulbright.

Two groups are getting this wrong, and only one of them is innocent

The first group genuinely misread a messy amendment. That is forgivable; the Commission changed a flagship deadline while the original date remained printed in every conference deck published since 2024.

The second group is selling. If a vendor pitched you urgent “AI Act high-risk readiness” this month, ask them one question: which article, and which date? The ones who cannot answer are not confused, they are trading on your confusion. Manufactured deadlines are the oldest instrument in the compliance industry.

The Commission has not helped itself here either. Moving a landmark obligation by sixteen months, after four years of public countdown, is how good regulation earns a bad reputation — and it hands genuine bad actors a talking point about regulatory unseriousness that they did not have to earn.

What This Means For You

If you deploy AI in the EU or to EU users: the transparency duties are live now, not in 2027. If your product talks to people, it has to say it is not a person. If it generates images, audio or video, that output has to be marked. These are the cheap obligations and they are the ones with a date already behind them.

Do not, however, stand down your high-risk work. December 2027 sounds distant until you count what it involves: risk management systems, data governance, technical documentation, logging, human oversight, and accuracy and robustness testing for systems that may already be in production. Sixteen extra months is relief, not reprieve.

If you are building anything that scores, screens, ranks or filters people — for a job, a loan, a place at a school, a visa — assume you are in scope and start the documentation now. The organisations that get hurt in 2027 will be the ones that read the delay as permission to stop.

Before you sign anything: open the Commission’s page yourself and read the dates. It is free, it is authoritative, and it takes five minutes. Compliance advice that cannot survive that check is not advice.

The verdict: the deadline did not vanish, it fragmented — and a fragmented deadline is the ideal habitat for people selling certainty. The transparency rules are real and enforceable today. The high-risk cliff is real and arrives in December 2027. Anyone telling you something different this month should be asked to cite an article number.

References

  1. [1]
  2. [2]
    The EU AI Act: when does it become enforceable now?Data Protection Report, Norton Rose Fulbright, 2026
  3. [3]