August 2 Came Anyway: What the AI Act Delay Did and Didn't Buy You
Two headlines, one misreading
In June, the headline that travelled was "EU delays the AI Act". We watched it land in real time: at least two clients paused compliance workstreams within the week, one of them on the explicit instruction of a board member who had read exactly one paragraph of coverage.
The second headline travelled much less. On 2 August 2026, right on the original schedule, the AI Act's transparency obligations became enforceable across the EU. The delay was real. The conclusion most boards drew from it was not.
What actually moved
On 16 June 2026, the European Parliament gave final approval to the Digital Omnibus amendments, and two deadlines shifted.
Obligations for standalone high-risk systems under Annex III, the category covering things like recruitment screening, credit scoring, and access to essential services, moved from August 2026 to 2 December 2027. Obligations for AI embedded in products already covered by EU safety regulation, the Annex I category, moved to 2 August 2028.
The stated reason is worth knowing because it tells you what the extra time is for: the harmonised standards and guidance companies were supposed to comply against simply weren't ready. This was a deferral born of the regulator's own backlog, not a softening of intent.
What refused to move
The omnibus left Article 50 exactly where it was, and Article 50 is the part your customers can see. Since 2 August, in force and enforceable:
People interacting with an AI system have to be told they are talking to a machine, unless it is genuinely obvious. Providers of generative systems have to mark synthetic output in a machine-readable way. Deployers have to disclose deepfakes, and label AI-generated text published to inform the public on matters of public interest. Anyone running emotion recognition or biometric categorisation has to tell the people exposed to it.
And these arrive on top of what was already live: the outright bans and the AI literacy duty since February 2025, and the general-purpose model obligations since August 2025. The popular mental model of the AI Act as "a 2027 problem" now covers only part of the law, and not the part the public interacts with.
What this means for you this quarter
For a mid-sized company, the honest to-do list is short and mostly unglamorous.
Start with the inventory. You cannot label systems you do not know you are running, and after what we wrote about shadow AI in May, you already know our view on how complete your current inventory is likely to be. Back then we said the EU had handed you a reprieve to deal with it. It turns out the reprieve had terms, and the first instalment was due on 2 August.
Then work through the visible surface. Does every customer-facing chatbot say what it is? Marketing has been generating product imagery and copy for two years now; is any of it in scope for labelling, and who checked? And your vendors: their tools generate content inside your processes, so their marking mechanisms are now your compliance surface. Ask how the marking works, and get the answer in writing, because "our platform handles that" has a way of dissolving under audit.
None of this is exotic. Most of it is a few weeks of coordinated effort between legal, IT, and marketing. The companies that struggle with it will struggle for the usual reason: nobody was named as the owner.
The trap hiding in the extra time
Sixteen months of deferral sounds generous until you look at what high-risk compliance is made of: risk management systems, data governance, logging, human oversight arrangements, quality management. That is not paperwork you draft in the final quarter. It is infrastructure, and it has lead times.
We have seen this movie. GDPR gave companies a two-year runway, and May 2018 was a scramble anyway, because a deadline far enough away gets treated as no deadline at all. If your organisation runs anything that will classify as high-risk, recruitment tooling is the classic sleeper, then December 2027 is not slack. It is roughly the runway the work actually needs, starting about now.
The delay bought you time. What it did not buy you is the option to look away.
Not sure which of your systems Article 50 touches, or what classifies as high-risk in 2027? Get in touch for a scoping session, or start with our piece on getting shadow AI under control.