EU AI Act: What Went Live This Week and What's Delayed
August 2, 2026 was the calendar date compliance teams had circled for eighteen months. It came and went with less noise than the Act's opponents predicted and more paperwork than its supporters admitted.
EU AI Act: What Went Live This Week and What’s Delayed
August 2, 2026 was the calendar date compliance teams had circled for eighteen months. It came and went with less noise than the Act’s opponents predicted and more paperwork than its supporters admitted.
What is now enforceable
As of this week, the governance architecture of Regulation (EU) 2024/1689 is operational. Member State notifying authorities, market surveillance bodies, and the European AI Office can now issue formal requests, coordinate cross-border investigations, and levy penalties. Article 99 sets the ceiling at €35 million or 7% of global turnover for prohibited-practice breaches — whichever is higher.
General-purpose AI (GPAI) provider obligations are also in force. Providers must publish training-data summaries, maintain technical documentation, and — for models classified as posing systemic risk under Article 51 — notify the AI Office within two weeks of crossing the 10^25 FLOPs training-compute threshold. The GPAI Code of Practice remains the reference text for compliance.
Transparency requirements from Article 50 apply too: users interacting with a chatbot must be told, deepfake output must carry machine-readable provenance markers, and emotion-recognition systems must inform affected persons.
What is still on the shelf
High-risk AI systems listed in Annex III — CV screening, credit scoring, biometric categorization, critical-infrastructure control — get another year. Their conformity assessments, post-market monitoring, and CE-marking obligations apply from August 2, 2027, per Article 113(c). Annex I systems (embedded in regulated products like medical devices or machinery) have until August 2, 2028.
That gap is where most of our client conversations sit. A bank running a legacy credit-scoring model does not have to file conformity paperwork this week, but it does have to answer AI Office questions about its risk-management plan. Our Lexnomia regulatory tracker publishes the quarterly recalibration.
ai_act_readiness:
gpai_documentation: complete # Art. 53
systemic_risk_notification: n/a # under 10^25 FLOPs
transparency_labels: deployed # Art. 50
high_risk_conformity: draft # target Q2 2027
fundamental_rights_impact: pending # Art. 27
Where teams are miscalibrating
The most frequent error: treating GPAI compliance as a legal-only workstream. Article 53’s training-data summary requires engineering evidence — dataset lineage, deduplication logs, opt-out honoring — that legal teams cannot produce alone. Pair the compliance officer with the ML platform lead now, not in Q4.
The second error is underestimating enforcement appetite. The AI Office coordinates with ENISA on cybersecurity requirements under Article 15. Fines will likely follow the GDPR pattern: quiet for eighteen months, then a signalling case that sets the reference tariff.
CAI Technology’s position: treat this week as the start of an operational rhythm, not a deadline. If your AEGIS incident logs cannot answer “what model made this decision, on what data, with what confidence” in under an hour, the 2027 milestone will hurt. Book a slot with our monthly compliance clinic to pressure-test that answer.