
Image AI-generated. All text human-written.
There’s a compliance flyer doing the rounds with a red-alert headline: “On 2 August 2026, the EU AI Act becomes legally binding” for high-risk systems, and named executives are personally exposed if they can’t answer four questions about their AI stack. It’s a sharp piece of writing. It’s also describing a deadline that no longer exists. Before this lands in front of a board, here’s what’s actually true as of today.
The August 2, 2026 high-risk deadline was postponed — and it’s already law. The AI Act (Regulation (EU) 2024/1689) originally set 2 August 2026 as the date standalone high-risk AI systems under Annex III — CV screening, credit scoring, biometric categorisation, and similar — had to be fully compliant. That date moved. The European Commission proposed a “Digital Omnibus on AI” in November 2025 to buy time, because the national regulators and harmonised technical standards the Act depends on weren’t ready. Parliament and Council approved it, and it was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026 as Regulation (EU) 2026/1744. This isn’t a proposal anymore — it’s enacted law, and it took effect before the original deadline arrived.
Under it:
- Standalone high-risk systems (Annex III) now have until 2 December 2027
- High-risk AI embedded in already-regulated products (Annex I) has until 2 August 2028
What genuinely still lands on 2 August 2026: the Article 50 transparency rules — labelling AI-generated content, disclosing AI interactions to users, and similar obligations for new systems. Note also that the Omnibus tightened the window for labelling AI-generated/manipulated content already on the market: that grace period was cut from six months to three, moving that specific deadline to 2 December 2026 — the same date new prohibitions on AI-generated non-consensual intimate imagery and CSAM content take effect.
The penalty figures in the flyer are accurate. Article 99 of the AI Act sets three tiers, confirmed and unchanged by the Omnibus:
- Up to €35 million or 7% of global annual turnover — violations of the Article 5 prohibited practices
- Up to €15 million or 3% — non-compliance with provider obligations (Art. 16), deployer obligations (Art. 26), and transparency duties (Art. 50), among others
- Up to €7.5 million or 1% — supplying incorrect, incomplete, or misleading information to regulators or notified bodies
In each case it’s whichever figure is higher for large companies, and whichever is lower for SMEs and start-ups.
The “personal liability” framing needs a correction. These fines fall on the “operator” — the company — not on a named individual. The Act doesn’t contain a provision that personally fines an executive. What it does require, under Articles 16 and 26, is that providers and deployers of high-risk systems have clearly documented, accountable people responsible for governance and human oversight, produceable to a regulator on request. That’s a real obligation worth taking seriously — it’s just an internal accountability requirement, not a personal-fine clause. Any true personal liability for a director would come from separate national corporate-law or director-duty statutes, not from the AI Act’s text itself.
What’s actually worth doing now:
- Inventory which AI systems you use, build, or embed, and who owns each one — useful regardless of any deadline.
- Work out which of them could fall under Annex III’s high-risk categories. That classification work doesn’t get faster by waiting, even with the extra runway.
- Confirm Article 50 transparency obligations are handled for anything live now — that date didn’t move.
- Use the extended runway to actually build the governance documentation Articles 16 and 26 require, rather than treating “the deadline moved” as “there’s nothing to do.”
Regulatory timelines shift. The underlying need to know what your AI systems do, and who’s accountable for them, doesn’t. Worth checking any compliance materials circulating internally against Regulation (EU) 2026/1744 before they shape a board conversation.
EU AI Act Compliance Disclaimer
This article is provided for general informational and educational purposes only and should not be considered legal, regulatory, or compliance advice. The EU AI Act is evolving, and its requirements can vary depending on the organisation, AI system, role, and specific use case. For professional advice and guidance on EU AI Act compliance, visit www.exclevelai.eu.