Michael Aim
Founder & CEO
In the AI Act's original calendar, 2 August 2026 was to mark the entry into application of most high-risk system obligations: documented risk management, training data governance, technical documentation, human oversight, registration in the European database. With fines up to 15 million euros or 3% of worldwide turnover attached.
Then the Digital Omnibus simplification package moved from political agreement to law: Regulation (EU) 2026/1744, published in the Official Journal on 24 July and in force since 27 July 2026, moves these obligations to 2 December 2027 for Annex III systems, and to August 2028 for high-risk systems embedded in regulated products.
The GDPR precedent
Recent regulatory history has already played this scene. GDPR left two years between adoption and application; part of organisations used that time to build their arrangement, the other part watched it pass. In May 2018, the former were ready; the latter improvised in a hurry, and some are improvising still.
A regulatory delay is never time gained: it is time allocated. The question is not “when is the deadline?” but “what must be built by then?”, because the content of the obligations does not move: system inventory, risk qualification, governance, documentation, evidence.
Who is actually concerned by “high risk”
Annex III covers uses many organisations practise without thinking about it: CV screening and HR decisions, credit scoring, access to education, biometrics, critical infrastructure management, essential public services. And the obligations do not weigh only on the providers of these systems: deployers, the organisations using them, have their own, from human oversight to monitoring of operation.
Many companies are therefore deployers of high-risk systems without knowing it, through an HR tool or a scoring module bought off the shelf. The first question is not legal but factual: which systems, bought or built, actually run in our organisation, and for which uses?
What already applies, delay or not
The delay debate must not hide the essential: part of the regulation already applies. Prohibited practices, from social scoring to certain biometric identification, have been banned since February 2025. Transparency obligations for general-purpose models have run since August 2025. And the AI literacy requirement already concerns every employer deploying these systems. As for Article 50 transparency, applicable on 2 August 2026, the Commission adopted its final guidelines on 20 July: conversational systems must disclose themselves from the first exchange, generated content must carry machine-readable marking, with no retroactivity for earlier content.
In other words, the discussed delay only concerns the high-risk block; the base is in force. An organisation waiting for “calendar clarification” to get moving is already late on the stabilised part of the text.
Spending the delay as a trajectory
The rational approach therefore does not change by a day: map your AI uses, including those entering through off-the-shelf tools; measure your governance's maturity against a structured framework; and convert the gaps into a dated action plan, aligned with whatever calendar is finally adopted. Those who measure today will choose their pace; those who wait for the final text will endure its pace.
Our catalogue holds 19 data and AI frameworks to equip that trajectory, from governance frames to specific regulatory requirements. The calendar may move again; your starting position can be known right now.