The EU AI Act's Big August Deadline Just Passed. Here's What Actually Landed.
4 min read
For most of this year, August 2, 2026 sat on compliance calendars as the date EU AI Act enforcement got real. That was the deadline for "high-risk" AI systems โ tools used in hiring, credit scoring, biometric identification, education access, and similar decisions โ to have completed conformity assessments, finalized technical documentation, affixed CE marking, and registered in an EU database. Law firms spent the first half of 2026 publishing client alerts about it, including Holland & Knight's warning that U.S. companies selling into the EU needed to take it seriously too. Then, three months out, the EU changed the deadline.
On May 7, 2026, the Council of the EU and the European Parliament reached a provisional agreement on what's been called the "Digital Omnibus" โ a package of amendments that pushed most of the high-risk obligations out. The deal entered into force on July 27, 2026, after publication in the Official Journal a few days earlier. Under it, the conformity assessment, registration, risk management, and human oversight requirements for standalone high-risk systems (the Annex III category โ hiring tools, credit scoring, and the like) don't actually apply until December 2, 2027. High-risk systems embedded in regulated physical products, like medical devices or machinery, get until August 2, 2028.
So if you run a company that spent the last year bracing for August 2, the expensive part of that bracing turned out to be premature. But it would be a mistake to read this as the EU quietly shelving the AI Act, and a bigger mistake to treat it as license to stop preparing.
What still landed on August 2
The delay was targeted, not blanket. Article 50 of the Act โ the transparency obligations โ was untouched by the omnibus and took effect exactly on schedule. That's the provision requiring disclosure when a person is interacting with an AI system rather than a human, and requiring AI-generated or manipulated content (including deepfakes) to be machine-readably labeled. Anthropic, for one, built exactly this kind of watermarking into Claude models launched in the EU from August 2 onward. General application of the Act as a whole also proceeds on schedule; it's specifically the heaviest Annex III and Annex I machinery โ the part that required building or buying a compliance program most companies hadn't finished โ that moved.
That distinction matters because the two categories of obligation are not comparably burdensome. Labeling AI-generated content is a front-end change. Standing up a conformity assessment process, a risk management system, a logging regime, and EU database registration for every high-risk deployment is a different order of work entirely: a multi-quarter program, often requiring outside auditors and harmonized technical standards that, as of the delay, still weren't finalized. The industry pressure behind the omnibus was less "we object to AI regulation" and more "the standards this law expects us to comply with don't fully exist yet."
The catch in "you have more time"
The EU's own framing of the delay is worth reading closely: the agreement explicitly states it's meant to give businesses additional preparation time, while underscoring that implementation efforts should already be underway. That's a deliberate hedge, not boilerplate. Nobody at the Commission is promising a second delay in 2027, and a company that reads this as a two-year reprieve and shelves its compliance work risks a version of the scramble it just avoided, on a deadline that this time has already survived one round of industry pushback and political horse-trading.
It's also not the first AI Act date to move, and the pattern โ announce a hard deadline, watch industry lobby against readiness gaps, push it back close to the date rather than well ahead of it โ has its own cost separate from the substance. Legal teams at companies operating across the EU and U.S. are now planning against a regulatory timeline that has proven itself movable under pressure, which makes compliance spending harder to budget for, not easier. That's an awkward position for anyone signing off on a multi-year AI governance budget this year, not unlike the broader gap between AI spending and provable return that's shown up across enterprise AI in 2026.
The practical read for any company deploying AI in or into the EU: the disclosure and labeling rules are live now, not eventually. The much larger compliance build-out for high-risk systems has real runway again โ through late 2027 for most of it โ but that runway exists because the EU expects it to be used, not banked.