The EU AI Act Delay That Isn't: What Actually Goes Live on August 2
// Security

The EU AI Act Delay That Isn't: What Actually Goes Live on August 2

Late last year a wave of headlines announced that the EU had blinked. After months of lobbying from Washington and from the largest model providers, Brussels agreed a “Digital Omnibus” that pushed a set of AI Act deadlines back by more than a year. A lot of executives read the word “delay,” filed the AI Act under “next year’s problem,” and moved on.

That reading is wrong in a way that could cost real money. The delay was surgical. It moved the obligations for stand-alone high-risk systems, the ones covering hiring, credit scoring, insurance underwriting and access to public services, from August 2, 2026 to December 2, 2027.1 It left almost everything else where it was. And the part it left in place is the part that touches the widest set of companies: the rules for general-purpose AI models, and the transparency duties that apply the moment your product puts AI-generated content in front of a person.

Those switch on, with real enforcement teeth, on August 2, 2026. That is roughly a week from now.

What the calendar actually says#

The AI Act has always been a staggered rollout rather than a single switch. The prohibited-practices rules landed in February 2025. The obligations for providers of general-purpose AI (GPAI) models took effect on August 2, 2025, but with a one-year grace period before anyone could be fined.2

August 2, 2026 is when that grace period ends. From that date the European Commission gains supervision and enforcement powers over GPAI providers. Under Article 101, it can impose fines of up to 3% of a provider’s total worldwide annual turnover or 15 million euros, whichever is higher.2 For a company at the frontier, 3% of global revenue is a board-level number, not a rounding error.

The Commission also gets a toolkit short of fines. Articles 91 to 93 let the AI Office demand technical documentation, run its own evaluations of a model, and require remedial action up to and including pulling a model from the EU market.2 A regulator that can order your model off the shelf holds a kind of power that a one-time penalty does not.

The Digital Omnibus did not touch any of this. It also left most of the Article 50 transparency obligations sitting on the August 2 date: telling users when they are talking to a chatbot, marking AI-generated audio, images, video and text in machine-readable form, disclosing deepfakes, and notifying people subjected to emotion-recognition or biometric categorization.1 So the two things landing next week are the enforcement of GPAI rules and the transparency duties that reach into ordinary consumer and enterprise products.

Why this reaches you even if you do not build models#

Most companies reading this are not GPAI providers. They are deployers. They buy or call a model from OpenAI, Anthropic, Google, Mistral or an open-weight provider, and they build something on top. It is tempting to assume the GPAI rules are somebody else’s compliance headache.

Two things break that assumption.

First, the Act has extraterritorial reach. It applies to providers placing a general-purpose model on the EU market regardless of where the provider sits, and it applies to deployers whose systems are used inside the EU. A company in Hong Kong or California with European users is inside the perimeter, the same design choice the GDPR made in 2018.

Second, obligations flow downstream through documentation. GPAI providers now have to hand deployers a standardized Model Documentation Form describing training, capabilities and limitations.3 That paperwork exists precisely so that you, the deployer, can meet your own duties. If your vendor is scrambling to produce it, your product is exposed. If you have never asked for it, you are the one carrying the risk when a regulator or an enterprise customer asks how your AI feature was trained and tested.

The transparency rules land squarely on deployers. If your app has a chatbot, users need to know it is a machine. If you generate marketing images, synthetic voices or drafted text with AI, that output needs a machine-readable label. These are product and engineering decisions with a legal deadline attached, and they are the kind of thing that takes a quarter to retrofit, not a weekend.

The small club that carries the heaviest load#

A narrower set of rules applies to the most capable models, the ones the Act calls general-purpose AI with systemic risk. The trigger is a compute threshold: a model is presumed to carry systemic risk if the cumulative computation used to train it exceeds 10^25 floating point operations.4 Roughly a dozen models cross that line today, from a handful of labs including OpenAI, Google, Anthropic, Meta and Mistral.5

Providers of those models owe more than documentation. Under Article 55 they have to run adversarial testing to surface harmful outputs, evaluate models against state-of-the-art benchmarks, report serious incidents to national authorities, and cooperate with the AI Office on demand.5 This is where the AI Act starts to look like the security practices a mature red team already recognizes: structured attempts to break the system before it ships, incident reporting with real timelines, and evidence you can put in front of an auditor.

The industry split over how to comply is worth watching, because it tells you where the friction is. The Commission published a voluntary GPAI Code of Practice in July 2025, built around three chapters covering transparency, copyright, and safety and security.3 Signing it is the low-friction route to demonstrating compliance. OpenAI, Anthropic, Google, Microsoft and Mistral signed.6 Anthropic announced its intent to sign on July 21, 2025, with OpenAI following.5

Meta refused. Its chief global affairs officer, Joel Kaplan, said the Code introduced “legal uncertainties for model developers” and measures that “go far beyond the scope of the AI Act,” and warned that Europe was “heading down the wrong path on AI.”6 xAI took a middle position and signed only the safety and security chapter. That divergence is what matters for you. The companies you depend on do not agree on whether these obligations are reasonable, so the terms, indemnities and documentation you get from each of them will differ, and you need to read them rather than assume parity.

The trap in the word “delay”#

The dangerous version of this story is the one where a senior leader hears “the EU delayed the AI Act,” relays it as reassurance, and the organization stands down. The delay is real but it applies to a category most companies are not even in yet. The obligations that were left in force are the ones with the broadest reach and the nearest deadline.

There is a useful parallel in how the GDPR played out. Companies that treated 2018 as a paperwork exercise spent the following years reacting to enforcement, subject-access requests and cross-border complaints they had not designed for. The ones that treated it as a product and data-governance change absorbed it and moved on. The AI Act is following the same shape, and the deployers who win are the ones who build the labeling, disclosure and vendor-documentation habits into the product now, while the requirements are still light, rather than after the first fine makes the news.

What to have done before August 2#

If you lead a team that ships anything with AI in it, five things are worth confirming this week.

  1. Know your role in writing. Decide, per product, whether you are a provider or a deployer under the Act, because the obligations differ sharply. Ambiguous cases (fine-tuning an open model, wrapping a foundation model in a new service) can flip you into provider territory.
  2. Inventory where you touch GPAI. You cannot govern what you have not mapped. List every model your products call, who provides it, and whether it sits above the systemic-risk threshold.
  3. Collect the documentation from your vendors. Ask each model provider for its Model Documentation Form and its position on the Code of Practice. A vendor that cannot produce either is a risk you are absorbing silently.
  4. Ship the transparency basics. Chatbot disclosure, deepfake and synthetic-media labeling, and notices for any emotion-recognition or biometric features. These are concrete engineering tickets, and they have a hard date.
  5. Assign an owner. GDPR taught most organizations that “everyone is responsible” means no one is. Name a person accountable for AI Act compliance and give them the standing to say no to a launch.

None of this requires a model of your own or a systemic-risk designation. It requires treating the AI Act as what it is, a product and governance obligation that arrived on a published schedule, most of which is now here. The companies that read the delay as permission to wait are the ones most likely to learn the rest of the timeline from a letter with the Commission’s letterhead on it.


  1. “Yes, August 2 Still Matters: The EU Approved a High-Risk AI Delay, but Most Transparency Obligations Remain,” Jones Walker LLP, https://www.joneswalker.com/en/insights/blogs/ai-law-blog/yes-august-2-still-matters-the-eu-approved-a-high-risk-ai-delay-but-most-trans.html ↩︎ ↩︎

  2. “Enforcement of Chapter V under the EU AI Act,” EU Artificial Intelligence Act, https://artificialintelligenceact.eu/enforcement-of-chapter-v-under-the-eu-ai-act/ ↩︎ ↩︎ ↩︎

  3. “The General-Purpose AI Code of Practice,” European Commission, Shaping Europe’s Digital Future, https://digital-strategy.ec.europa.eu/en/policies/contents-code-gpai ↩︎ ↩︎

  4. “Article 51: Classification of General-Purpose AI Models as General-Purpose AI Models with Systemic Risk,” EU Artificial Intelligence Act, https://artificialintelligenceact.eu/article/51/ ↩︎

  5. “EU AI Act Systemic Risk: What the 12 Models Now in Scope Actually Have to Do Before August 2026,” Tech Jacks Solutions, https://techjacksolutions.com/ai-brief/eu-ai-act-systemic-risk-what-the-12-models-now-in-scope-actu/ ↩︎ ↩︎ ↩︎

  6. “Tech giants split on EU AI code as compliance deadline looms,” AI News, https://www.artificialintelligence-news.com/news/eu-ai-code-tech-giants-microsoft-meta-split-compliance/ ↩︎ ↩︎