All posts

Policy2 min read

The EU AI Act is now enforceable: what applies today and what was delayed

The AI Office's enforcement powers took effect on August 2. Transparency and general-purpose AI rules apply now, while high-risk obligations moved to 2027 and 2028. A practical guide for teams shipping AI in Europe.

A soft radar sweep of concentric rings over a pale violet gradient

Since August 2, 2026, the European Commission's AI Office and national authorities have been able to enforce the EU AI Act. A month in, the most common question we hear from clients is simple: what actually applies to us right now?

The answer is more targeted than many people expected, because the AI Omnibus amendments pushed the heaviest obligations back.

Timeline: enforcement live August 2 2026, expedited bans December 2 2026, Annex III high-risk obligations December 2 2027, Annex I high-risk obligations August 2 2028
Key EU AI Act dates after the AI Omnibus amendments.

What applies now

Transparency obligations

If your product talks to people or generates content, these rules probably apply to you already:

  • Chatbots must say they're automated. Users must be told they're interacting with an AI system.
  • Deepfakes must be labelled.
  • AI-generated or manipulated content must carry machine-readable markings so it can be detected automatically.

Obligations for general-purpose AI providers

Providers of general-purpose AI models must document their models and share that information with authorities and downstream providers, have a copyright policy, and publish detailed summaries of their training data sources. Providers are also expected to address systemic risks, including chemical, biological, radiological and nuclear misuse, loss of control, offensive cyber capabilities, harmful manipulation and threats to fundamental rights.

Enforcement powers

The AI Office can now request technical documentation, run evaluations, require corrective action and issue fines. For the obligations covered here, penalties can reach €15 million or 3% of worldwide annual turnover, whichever is higher.

What was delayed

The Omnibus moved the high-risk obligations:

  • December 2, 2027. Stand-alone high-risk systems (Annex III), covering areas like hiring, credit scoring and education.
  • August 2, 2028. High-risk AI built into products that are already regulated (Annex I).

It also brought forward one set of rules: bans on AI-generated child sexual abuse material and non-consensual sexually explicit content take effect on December 2, 2026.

"The Act gives innovators legal certainty while protecting the public interest." — Henna Virkkunen, Executive Vice-President for Tech Sovereignty

A practical checklist for teams shipping agents in the EU

  1. Audit every user-facing surface. Any chat widget, voice agent or automated email that might pass as human needs a clear disclosure.
  2. Mark generated media. If your product outputs images, audio or video, add machine-readable provenance marks, not just a visible caption.
  3. Know your role in the chain. Most companies are deployers of models from general-purpose AI providers. Get the documentation you'll need from your vendors now.
  4. Use the high-risk delay, don't ignore it. If your agent screens candidates, assesses creditworthiness or makes decisions in education, December 2027 is closer than it looks. Risk management, logging, human oversight and data governance take time to build.
  5. Keep evidence. Evaluation results, incident logs and design decisions are what you'll show a regulator. Start recording them now.

The bottom line

The AI Act's first enforcement phase is mostly about being honest with users and documenting what you build. Those are good engineering practices anyway, and the delay on high-risk systems gives teams time to get the harder parts right.

Keep reading

All posts ↗