Ethics & Governance
What the EU AI Act actually enforced on 2 August 2026, and what Europe deferred to 2027
The AI Act's high-risk rules did not arrive on 2 August 2026. Regulation (EU) 2026/1744 moved them to December 2027 and August 2028. What bound instead: GPAI enforcement powers, 3% fines and Article 50 transparency.

Gabriele Masetti ·
The date Europe had circled for two years arrived, and most of what was supposed to happen on it did not. On 2 August 2026 the AI Act's high-risk regime was due to bind: conformity assessments, technical documentation, logging, human oversight, registration in a public EU database.
Six days earlier, Regulation (EU) 2026/1744 — the Digital Omnibus on AI — entered into force and moved that regime to 2 December 2027 for stand-alone systems listed in Annex III, and to 2 August 2028 for AI embedded in products already covered by EU product-safety law. Annex III is where the Act puts the uses that touch people directly: recruitment and worker management, credit scoring, education, essential public services, migration, law enforcement.
What did bind on 2 August was narrower and, in its way, sharper. The Commission gained the power to investigate and fine providers of general-purpose AI models. The Article 50 transparency duties started to apply. The national supervision framework that is meant to carry everything else came formally into operation, in the member states that have built one. Europe did not abandon its rulebook; it enforced the part aimed at roughly a dozen model providers and postponed the part aimed at tens of thousands of deployers.
The regulation that moved the deadline
The Commission proposed the Digital Omnibus on 19 November 2025. A trilogue in April 2026 collapsed after twelve hours without agreement; negotiators reached a deal in the early hours of 7 May, and member state representatives confirmed it on 13 May.
The Internal Market and Civil Liberties committees approved the compromise on 2 June by 93 votes to 4 with 15 abstentions. Parliament adopted it in plenary on 16 June by 423 votes to 57 with 174 abstentions, the Council gave final approval on 29 June, and the text appeared in the Official Journal on 24 July. The whole passage took eight months, fast by the standards of the institution that spent three years on the Act itself.
The regulation states its own reason. Recital 40 points to "the delayed availability of standards, common specifications, and alternative guidance and the delayed establishment of national competent authorities", which it says jeopardise effective application and risk raising implementation costs without justification. The harmonised standards that would let a company demonstrate conformity were not finished. Neither, in most capitals, were the regulators.
The co-rapporteurs did not present it as a technical fix.
To all the entrepreneurs and engineers out there, we are pressing the pause button on the AI Act and we are reducing red tape. — Arba Kokalari, MEP (EPP, Sweden), co-rapporteur on the Digital Omnibus on AI
What actually became enforceable
The obligations on general-purpose AI models — model documentation, a copyright policy, a public summary of training data, and for models with systemic risk, adversarial testing and incident reporting — have applied since 2 August 2025. What ended a year later was the grace period on enforcement.
From 2 August 2026 the AI Office can demand technical documentation under Article 91, obtain access to a model and run its own evaluations under Article 92, and order corrective measures under Article 93, up to restricting a model's availability in the Union. Article 101 sets the penalty for a model provider at €15 million or 3% of total worldwide annual turnover, whichever is higher.
The Omnibus also concentrated supervision in the AI Office for general-purpose models and for AI integrated into very large online platforms under the Digital Services Act. Enforcement over frontier models is now a Brussels matter rather than a national one.
Article 50 arrived on schedule. Systems that interact with people must disclose that they are machines; generative outputs must carry machine-readable marks; deepfakes must be labelled; deployers of emotion recognition must tell the people exposed to it. The Commission published its final transparency guidelines on 20 July 2026. Systems already on the market before 2 August have until 2 December 2026 to meet the machine-readable marking requirement.
Alongside the guidelines the Commission opened a Code of Practice on Transparency of AI-generated Content, signed by around 190 organisations by the end of July 2026. The provider section lists Aleph Alpha, Anthropic, Black Forest Labs, Cohere, Google, Meta, Microsoft, Mistral, OpenAI and Synthesia; the deployer section runs to companies such as Getty Images, Lenovo and Lufthansa. Meta, which never signed the general-purpose AI code of practice, signed this one.
Who pushed for the delay
The pressure came from capitals as much as from boardrooms. Germany and France led the member states arguing that the original timeline would disadvantage European manufacturers, with Chancellor Friedrich Merz taking the case up personally and bringing Italy along; German demands for a broader carve-out of regulated sectors nearly broke the compromise in its final hours.
Corporate Europe Observatory measured the access. In its April 2026 analysis, 84% of Omnibus-related meetings held by the thirteen Commissioners involved were with business groups and 7.8% with civil society organisations. Valdis Dombrovskis held 182 of 184 such meetings with business; Stéphane Séjourné held 84, all of them with business. Participation in the Commission's Implementation Dialogues ran 71.1% business.
Michael McNamara, one of the two co-rapporteurs who negotiated the text, has said that many of the changes in the regulation mirrored those requested by US-based technology companies, and questioned how those demands fed into some member states' pleas for a delay.
Who objected, and on what grounds
The consumer group BEUC welcomed the new prohibitions but warned that simplification should make rules easier to apply and enforce rather than serve as cover for deregulation, and criticised leaving consumers without high-risk safeguards until late 2027 and, for AI inside products, 2028.
The sharper objection concerns what the extra time lets through. Under the Act's transitional rules, high-risk systems placed on the market before the new deadline fall outside the obligations unless they are later substantially modified, and regulators have not defined that threshold.
Laura Caroli, a former co-negotiator of the AI Act, told Tech Policy Press that high-risk hiring systems "may remain outside the AI Act indefinitely" if deployed before 2 December 2027. The Green MEP Sergey Lagodinsky described the same provision as a loophole creating "an incentive to put things on the market before the Act enters into force". Sixteen extra months is also sixteen months of grandfathering.
The smaller changes that came with it
Deferral was the headline; the regulation carries several other adjustments. Companies classed as small mid-caps — broadly those above the SME line but under roughly 750 employees and €150 million turnover — gain simplified documentation templates, proportionate quality management and priority in regulatory sandboxes.
Providers and deployers may now process special categories of personal data to detect and correct bias, subject to pseudonymisation, access controls, limits on sharing and deletion. The AI literacy duty was softened from a strict obligation to an obligation of means. The Machinery Regulation was moved inside Annex I, with the Commission to specify equivalent requirements by 2 August 2028.
The prohibition the Omnibus added
The delay was not a pure subtraction. The regulation writes a new practice into Article 5, the tier of outright bans: AI systems that generate or manipulate realistic material depicting an identifiable person's intimate parts or sexual activity without that person's explicit consent, and AI systems that generate child sexual abuse material. The ban reaches providers whose general-purpose image or video tools produce such output as a reasonably foreseeable and reproducible result without adequate safeguards.
It applies from 2 December 2026, with no exemption for tools already on the market, and it sits in the Act's highest penalty tier.
They impact real people, overwhelmingly women, with the purpose of humiliating, degrading and objectifying them. — Michael McNamara, MEP (Renew, Ireland), co-rapporteur on the Digital Omnibus on AI
What the fines are, and who would issue them
The penalty ceilings were not touched by the Omnibus.
| Violation | Maximum fine | Share of worldwide annual turnover |
|---|---|---|
| Prohibited practices under Article 5 | €35 million | 7% |
| Other obligations, including Article 50 transparency | €15 million | 3% |
| Incorrect, incomplete or misleading information to authorities | €7.5 million | 1% |
| General-purpose AI model obligations (Article 101) | €15 million | 3% |
Whether those numbers mean anything depends on who is holding them. Member states were required to designate market surveillance and notifying authorities by 2 August 2025. Most missed the deadline.
An implementation tracker run by the Future of Life Institute counted, on 17 June 2026, nine member states with both authorities clearly designated, twelve with partial arrangements or pending legislation, and six with neither. Italy is the outlier in the other direction: Law 132/2025, in force since 10 October 2025, made it the first member state with a national AI statute sitting alongside the EU regulation.
The Commission's own recital, in other words, is candid about the position. The deadline moved partly because the machine that would have enforced it does not yet exist in eighteen member states.
Meta, open weights, and an exemption that does not apply
Meta's withholding of frontier Llama models from the EU was the test case for the Act's reach over open-weight models. Meta's own decision has overtaken that framing.
On 8 April 2026 Meta Superintelligence Labs released Muse Spark, its first frontier model and its first without open weights, locked behind an API rather than published for download. Version 1.1 shipped closed. Meta has said it still intends to release weights for version 1.2, and as of 2 September 2026 had not decided for version 1.3. The Llama line's later licences already excluded users in the European Union.
The regulatory point survives the product change, inverted. Article 53 exempts genuinely free and open-source general-purpose models from parts of the documentation duty, but only where weights, architecture and usage information are public without a non-commercial clause — and a model designated as carrying systemic risk owes every Article 53 obligation whatever licence it carries. For a frontier model, opening the weights buys no relief from Brussels. The question Meta answered in April was commercial, not legal.
The rest of the world in September 2026
| Jurisdiction | Where it stands |
|---|---|
| European Union | AI Act in force; GPAI enforcement and Article 50 live since 2 August 2026; high-risk regime 2 December 2027 and 2 August 2028 |
| United Kingdom | No AI statute; a Regulating for Growth Bill creating cross-economy sandboxing powers announced in the King's Speech of 13 May 2026, in the 2026-27 legislative programme |
| United States | No federal AI statute; Executive Order 14365 (11 December 2025) set a DOJ task force against state laws; states keep legislating |
| China | No omnibus law; CAC labelling measures in force since 1 September 2025 requiring visible and metadata marks on synthetic content |
| Council of Europe | Framework Convention (CETS 225) opened 5 September 2024; EU ratification effective 1 September 2026; not yet in force |
The American contrast is the instructive one. Executive Order 14365, signed on 11 December 2025, set federal policy against "excessive state regulation", and the Justice Department announced an AI Litigation Task Force on 9 January 2026 to sue states over their AI laws. By April it had brought no case of its own: its first appearance in a challenge to a state AI law was a motion to intervene in xAI's suit against Colorado, filed on 24 April 2026.
The first constitutional challenge to Colorado's AI Act came instead from a company: xAI, on 9 April 2026. Colorado responded by repealing and re-enacting its framework in SB 26-189, signed on 14 May 2026, with developer and deployer duties now starting on 1 January 2027. Two jurisdictions, opposite methods, the same result — the rules that were meant to bite in 2026 bite in 2027.
Britain has gone further towards deregulation without needing to repeal anything, because it never legislated. The Ministry of Justice announced the first sector-specific AI Growth Lab for legal services on 8 June 2026, and it is advisory: regulators sit with firms to explain how existing rules apply to an AI product, and participation "will not constitute regulatory approval, endorsement or authorisation. Legal and regulatory requirements will remain the same."
Three dates now carry the European framework: 2 December 2026 for the nudifier and CSAM ban and the end of the watermarking transition, 2 December 2027 for Annex III high-risk systems, and 2 August 2028 for AI inside regulated products. The part of the Act that binds a small number of large model providers is running. The part that would have bound the hospital, the bank and the recruitment agency is sixteen months away, and it will arrive only if the standards and the authorities arrive first.