Most of what you will read about the EU AI Act is out of date, and it went out of date recently enough that the authors have not noticed.
On 27 July 2026 the AI Omnibus entered into force and moved the obligations that everyone had spent eighteen months preparing for.1 Articles written before that, including a good deal of what currently ranks well, confidently tells you that high-risk obligations start in August 2026. They do not. If you are budgeting against that date, you are budgeting against a deadline that no longer exists.
This is the corrected picture, written for people who have to make decisions rather than pass an exam.
What is already in force
Prohibitions, since 2 February 2025. Eight categories of AI practice are simply banned in the EU: harmful manipulation, social scoring, certain facial recognition uses and so on. There is no compliance pathway for these. If your product does one of them, it does not go to Europe.
AI literacy, since 2 February 2025. Organisations must ensure staff dealing with AI systems have a sufficient level of understanding. This one is widely ignored because it is vague and unenforced, but it is a live obligation and it costs almost nothing to satisfy honestly.
General-purpose AI model obligations, since 2 August 2025. These fall on whoever puts a foundation model on the EU market. If you use OpenAI, Anthropic, Google or Mistral rather than train your own, this is their problem, not yours. It becomes your problem the moment you fine-tune a model substantially enough to be considered a provider yourself, which is a line worth getting legal advice on before you cross it.
Transparency, since 2 August 2026. This is the one that landed this month, and for most ordinary businesses it is the only part of the Act that touches them. If people interact with your AI system, they have to be told. If it generates synthetic audio, image, video or text, that has to be disclosed and marked. Systems already on the market before 2 August have until 2 December 2026 to comply with the machine-readable marking requirement in Article 50(2).2
What is still coming
2 December 2026 brings a new prohibition covering non-consensual intimate imagery and child sexual abuse material, added by the Omnibus.
2 December 2027 is the date that matters if you build anything consequential. High-risk systems under Annex III - biometrics, critical infrastructure, education, employment, access to essential services including credit scoring, law enforcement, migration - become subject to the full regime. That is Articles 9 to 15: risk management, data governance, technical documentation, logging, human oversight, accuracy and cybersecurity. It was August 2026. You now have sixteen months.
2 August 2028 covers high-risk AI embedded in products already regulated under EU product safety law - medical devices, machinery, lifts, toys.
2 August 2030 is the backstop for public authority deployers and providers.
What the Omnibus changed besides dates
Four things worth knowing, none of which made the headlines.
The small mid-cap category is new. Simplified compliance, previously reserved for SMEs, now extends to companies with fewer than 750 employees and up to €150 million turnover. That captures a great many businesses that assumed the full apparatus applied to them.
Bias detection got easier. Processing special-category personal data - health, biometrics, race - specifically to detect and mitigate bias in models now has a clearer legal basis under GDPR, with safeguards. Before this, teams faced the absurd position of being told to eliminate bias while being unable to lawfully hold the data needed to measure it.
The safety component definition narrowed. A system now counts only if its intended purpose is preventing or mitigating risks to health and safety. A number of products that were arguably caught by the old wording are not caught by the new one.
Registration was simplified. Providers who conclude their system is not high-risk because its task is narrow or procedural no longer have to register it in the EU database.
The part nobody reads carefully: are you a provider or a deployer?
This distinction decides how much of the Act lands on you, and most companies guess wrong.
A provider develops an AI system and places it on the EU market under its own name. Providers carry the heavy obligations - conformity assessment, technical documentation, CE marking for high-risk systems, and if they sit outside the EU, an authorised representative established inside it.
A deployer uses an AI system under its own authority. Deployer obligations are real but far lighter: use it as instructed, ensure human oversight, keep logs, inform affected people in certain cases.
Almost every business we talk to is a deployer. They buy tools. They are not placing AI systems on the market. The compliance burden they are bracing for is not the one they actually face.
The trap is that you can become a provider without meaning to. Put your own name on a system, substantially modify a high-risk one, or change an existing system’s intended purpose so that it becomes high-risk, and the obligations transfer to you. A white-labelled AI feature in your product is the common way businesses walk into this.
Who is in scope if you are not in the EU
Establishment is irrelevant. The Act applies to providers placing AI systems on the EU market regardless of where they are based, and to third-country providers and deployers where the output of the system is used in the Union.3
That last clause is broad, and deliberately so. A US company with no EU entity, no EU staff and no EU servers is in scope if its system’s output is used in Europe. We have written separately about what this means for companies outside the EU and, more specifically, about supplying technology services to EU clients from the UK.
What the penalties actually are
Up to €35 million or 7% of global annual turnover for prohibited practices, whichever is higher. Lower tiers apply to other breaches. SMEs face the lower of the two figures rather than the higher.
These numbers get quoted to frighten people, and they are worth keeping in proportion. The 7% headline attaches to the practices that are outright banned. Nobody is going to be fined 7% of turnover for a missing chatbot disclosure. But the reputational and contractual consequences arrive long before any regulator does, which is the practical reason to be tidy about this.
What we would actually do about it
If you use AI tools internally and ship nothing AI-powered to customers: write down which tools you use and what data goes into them, tell staff what the rules are, and stop. You are a deployer with transparency obligations that probably do not bite. Our AI governance policy guide has the template.
If you have an AI feature in a product available in Europe: work out whether you are provider or deployer, then classify the feature against the four risk tiers. Most features land in the transparency tier, which means disclosure and marking. Do that now - it applies today.
If you are anywhere near an Annex III use case: you have sixteen months, which sounds generous and is not, because Articles 9 to 15 change how you build rather than what you document. That is a separate piece: what the EU AI Act means for software development.
The most common mistake is treating this as a legal project. The legal analysis takes a week. The engineering consequences - logging, data lineage, human oversight designed into the product rather than bolted on - take considerably longer, and they are the part that cannot be bought in at the end.
If you want an outside read on which of these applies to your business, book a free half-hour. If it turns out the answer is “the transparency bit and nothing else”, we will tell you that and you can stop worrying about it.
References
- European Commission - Regulatory framework for AI. Application dates checked 20 August 2026.
- Orrick - EU AI Act Update: Digital Omnibus Finalizes 8 Compliance Changes, July 2026.
- Regulation (EU) 2024⁄1689, Article 2, on EUR-Lex.