Updated: 14-08-2026
Reading time: 8 minutes

A comprehensive EU AI Act Summary [Aug 2026 update]

Software Improvement Group

In this article​

Executive summary

Our 2026 AI Boardroom Gap report examines why many organizations struggle to convert their AI ambitions into safe, scalable implementation.

One recurring theme is that leaders seek clear, practical guidance on how new AI regulations impact daily AI operations. This article serves as a follow-up deep dive into a key aspect of this issue: the EU AI Act.

This article explains what the EU AI Act is, how it categorizes AI based on risk, shares the relevant timelines, and helps organizations operating within the EU understand what they must do to remain compliant.

All without needing any prior legal knowledge.

Since the Act was first adopted in 2024, and since we last updated this guide in January 2026, its rollout has been anything but a straight line. Some parts, like the ban on unacceptable-risk AI and the rules for general-purpose AI models, are already active and being enforced today. Other parts, especially the toughest rules for high-risk AI, have been delayed. The process itself has drawn criticism from more than one direction: industry groups have pushed back on the pace and complexity of compliance, while civil-society and digital-rights organizations have warned that delaying enforcement weakens protections for the people the Act is meant to protect.

The vehicle behind that delay is a package of amendments the European Commission calls the “Digital Omnibus on AI.” Think of it as a legislative patch: it doesn’t rewrite the AI Act’s core structure or risk categories, it changes when certain obligations start applying. 

Below is where things actually stand today.

What’s new in this August 2026 update?

The Digital Omnibus has moved past the proposal stage. It was formally adopted as Regulation (EU) 2026/1744, published in the Official Journal on 24 July 2026, and entered into force on 27 July 2026, six days before the AI Act’s original high-risk deadline.

The Omnibus confirms two fixed dates for the Act’s toughest tier: high-risk obligations for stand-alone systems (Annex III, covering hiring, credit scoring, education, and critical infrastructure) are deferred to 2 December 2027, and high-risk AI embedded in already-regulated products (Annex I, covering medical devices, machinery, and toys) is deferred to 2 August 2028. Neither date is conditional on further Commission decisions. The earlier “6 or 12 months after standards are confirmed” mechanism was dropped from the final text.

Meanwhile, the transparency duties (Article 50) and the AI Office’s enforcement powers over general-purpose AI (GPAI) providers took effect exactly as scheduled on 2 August 2026 and were not delayed. The delay applies only to the high-risk tier.

The EU AI Act explained

The EU AI Act is the first of its kind—a law regulating the use of AI, and one which will impact many hundreds of thousands of businesses developing or implementing AI solutions in their operations.

The EU AI Act aims to make AI safer and more secure for public and commercial use, mitigate its risks, ensure it remains under human control, reduce any negative impacts of AI on the environment and society, keep our data safe and private, and ensure transparency in almost all forms of AI use.

The Act has defined four key risk categories into which different types of AI and their associated risks are grouped. Businesses need to be aware of each risk category, how their own AI systems might be categorized, and the regulatory implications on each system.

  1. Unacceptable-risk AI systems
  2. High-risk AI systems
  3. Limited-Risk AI systems
  4. Minimal-Risk AI systems

Is the EU AI Act's high-risk delay confirmed, or still a proposal?

Yes, it’s confirmed. The delay is binding law, in force since 27 July 2026, not a pending proposal.

The U.S. administration, U.S. tech companies and lobby groups have put heavy pressure on the European Union not to overregulate artificial intelligence. They have been among the most vocal proponents of a partial “pause” to the EU’s flagship AI laws.

In November 2025, the European Commission proposed a delay with the release of the “Digital Omnibus”, a plan meant to simplify the EU’s sweeping digital regulations. After several rounds of trilogue negotiation between the Commission, Parliament, and Council, the co-legislators reached final political agreement in May 2026.

The European Parliament formally adopted the text on 16 June 2026 and the Council gave its final approval on 29 June 2026. The regulation was signed on 8 July 2026, published in the Official Journal on 24 July 2026, and entered into force on 27 July 2026, completing its journey through the legislative process to become binding EU law.

As with the original proposal, the Omnibus is specifically about when certain high-risk obligations apply, and does not mean the entire AI Act legislation has been postponed. Prohibited AI practices, AI literacy duties, GPAI obligations, and the transparency duties under Article 50 are all unaffected and remain in force on their original schedule.

What changed once the Digital Omnibus entered into force?

The final text gives businesses and organizations deploying “high-risk” AI technologies a fixed, confirmed runway rather than a conditional one. The Commission had originally proposed linking the start date to a future Decision confirming that harmonized standards were ready, with a backstop deadline. That conditional trigger did not survive negotiation. Instead, the final Omnibus sets flat dates: 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems, regardless of whether the underlying technical standards are finished by then.

The driver behind the delay was more practical then political: the European standardization bodies CEN and CENELEC missed their original April 2025 deadline to deliver the harmonized technical standards that let providers demonstrate compliance, and are now targeting late 2026 at the earliest. Without those standards, or the Commission’s own Article 6 classification guidance (also delayed past its 2 February 2026 deadline), businesses due to comply from August 2026 would have faced obligations without a clear roadmap for meeting them.

What is the EU AI Act timeline now?

EU AI legislation is made applicable via a phased approach. The timeline below reflects the regulation as adopted (Regulation (EU) 2024/1689), as subsequently amended by the Digital Omnibus, Regulation (EU) 2026/1744).

  • The first phase of implementation happened on February 2nd, 2025. This means that AI systems that pose unacceptable risks are now banned and that organizations operating in the European market must ensure adequate AI literacy among employees involved in the use and deployment of AI systems.
  • On Aug 2nd, 2025 the second implementation phase took place, meaning that general purpose AI (GPAI) models have to abide by a specific set of rules. Including technical documentation and a public summary of training content (using the Commission template), alongside measures to comply with EU copyright rules.
  • On Aug 2nd, 2026, the Act’s main transparency duties (including Article 50) took effect as originally scheduled, and the AI Office’s enforcement powers over GPAI providers became active. The high-risk obligations that were also originally due on this date did not take effect. See below.
  • On Dec 2nd, 2027, the rules for stand-alone high-risk AI systems (Annex III) apply.
  • On Aug 2nd, 2028, the rules for high-risk AI systems embedded into regulated products (Annex I) apply.

What are the confirmed high-risk AI deadlines under the Digital Omnibus?

The Commission’s original proposal described a “moveable” start date for high-risk rules, tied to a future Decision on the availability of harmonized standards, with a long-stop deadline. That mechanism did not make it into the final law. What was adopted instead is simpler and fixed:

The Omnibus also simplifies compliance in a few other areas that the European Commission has confirmed: it lets providers and deployers process special categories of personal data, such as biometric or health data, specifically to detect and correct bias in their AI systems; it extends the lighter compliance rules originally built for small and medium enterprises to small mid-cap companies; and it creates a new EU-level AI regulatory sandbox that sits alongside the national sandboxes member states already run.

EU AI Act fines

The fines involved with the EU AI Act are significant and can have a severe impact. To help you get a general idea of the fines, we’ve made a simplified overview.

Generally speaking, non-compliance can lead to administrative fines or a set percentage of your organization’s total worldwide annual turnover for the preceding financial year, whichever is higher. That said, it’s important to understand that the numbers and percentages you see below are a maximum. For example, smaller entities like SMEs or startups are subject to lower maximum fines, based on thresholds set by member states.

Type of violation Applicable when: Max fine (€) Max % of global turnover

Forbidden AI practices

Violating the bans for unacceptable-risk AI systems.

€35 million

7% of global turnover

Non-compliance with provider or deployer duties

Failing to comply with obligations around providers, deployers, importers, distributors, authorized representatives, or notified bodies.

€15 million

3% of global turnover

Misleading
or inaccurate information

Providing incorrect, incomplete, or misleading information to authorities or notified bodies.

€7.5 million

1% of global turnover

GPAI model-specific violations

Violations by GPAI model providers (e.g., ChatGPT-like models), such as non-compliance with documentation, transparency, or not providing access for evaluation.

€15 million

3% of global turnover

* Note: This table summarizes the main penalties in the EU Artificial Intelligence Act. However, for complete and up-to-date information, please refer directly to Article 99 or 101 of the legislation.

The need for the EU AI Act

Artificial Intelligence (AI) is an emerging technology which is changing the face of international business and, on a broader scale, everyday life—both online and off. AI has already been implemented across a diverse range of sectors, from predictive text and data processing and analysis to game design, climate prediction, and industrial automation.

Indeed, the evolution of AI has been met with positivity from most business leaders. 

In January 2026, BCG also reported that 65% of CEOs say accelerating AI is one of their top three priorities. McKinsey reports that 88% of organizations already use AI in at least one business function.

That said, EY stated in their recent global survey findings that the majority of C-suite leaders feel that non-compliance with AI regulations is the most common AI risk.

On top of this, poor-quality AI systems  can present numerous threats, including risks to privacy, data misuse, and the undermining of individual autonomy. These concerns extend to broader social and environmental impacts, which has prompted international regulatory bodies to take action.

The EU AI Act is one such landmark piece of legislation, the first of its kind in the world, aimed at regulating AI use in the European Union to the benefit of trust and safety in this new technology.

What is the EU AI Act?

The European AI Act, adopted by the European Parliament in March 2024 and approved by the Council in May 2024, is the first comprehensive law regulating artificial intelligence (AI) in the world.

Before the European Union AI Act, The EU had already established Guidelines on Ethics in AI—a set of non-binding guidelines for safe and ethical AI implementation introduced in 2019. These provided a framework for developing and deploying AI systems in a manner which aligned with European values, and emphasized seven key requirements: including human oversight, privacy, and non-discrimination.

The EU AI Act builds upon these principles by making them legally binding.

The act classifies AI systems based on the risk they pose to users, with corresponding levels of regulation intended to keep AI systems used in the EU safe, transparent, and non-discriminatory, with meaningful human oversight to help prevent harmful outcomes.

Three people discussing the EU AI Act

The EU AI Act risk categories

By emphasizing a risk-based assessment approach, the European AI Act aims to ensure AI systems are classified by their potential risk to individuals and society, and imposes corresponding regulations to each category to enhance safety and compliance.

The Act has defined four key risk categories into which different types of AI and their associated risks are grouped. Businesses need to be aware of each risk category, how their own AI systems might be categorized, and the regulatory implications on each system.

  1. Unacceptable-risk AI systems
  2. High-risk AI systems
  3. Limited-Risk AI systems
  4. Minimal-Risk AI systems

AI risk category 1: Unacceptable-Risk AI (e.g., social scoring by governments)

Chapter 2 of the EU AI Act defines the ‘Unacceptable Risk’ category for AI systems and the regulations applied to them.

Definition: Systems considered a threat to individuals, such as those manipulating vulnerable groups, engaging in social scoring, or using biometric identification and categorization.

Regulation: These systems are banned, including real-time and remote biometric identification like facial recognition, except under strict law enforcement conditions which first gain court approval.

As of the Digital Omnibus, this ban has been extended to explicitly cover AI-generated non-consensual intimate imagery (“nudifier” apps) and CSAM.

AI risk category 2: High-Risk AI (e.g., healthcare applications)

Chapter 3 of the EU AI Act defines the ‘High Risk’ category for AI systems and the regulations applied to them.

Definition: Systems impacting safety or fundamental rights, including AI in toys, medical devices, critical infrastructure, education, employment, essential services, law enforcement, migration, and legal interpretation.

Regulation: These systems must be registered in an EU database, thoroughly risk-assessed and regularly reported on to ensure strict compliance and oversight. Assessment will have to be conducted prior to high-risk AI systems being put on the market and monitored throughout their lifecycle. People will also have the right to lodge complaints against AI systems to their designated national authorities.

Obligations: Businesses must group any high-risk AI they employ into one of two subcategories: high-risk systems used in products covered by the EU’s product safety legislation and those which fall into other specific areas, such as those listed in the definition above.

Compliance obligations for this category apply from 2 December 2027 (Annex III) or 2 August 2028 (Annex I). See the timeline above.

Important for deployers: Fundamental Rights Impact Assessment (FRIA)

For certain high-risk AI deployments, deployers must conduct a Fundamental Rights Impact Assessment (FRIA) before first use and update it if conditions change.

Three lawyers discussing about category 2: high risk AI

AI risk category 3: Limited-Risk AI (e.g., AI systems with transparency obligations)

Chapter 4 of the EU AI Act defines the ‘Limited Risk’ category for AI systems and the regulations applied to them.

Definition: The limited-risk category includes AI systems with specific transparency duties (including certain generative AI system uses under Article 50).  General-purpose AI (GPAI) models (e.g., foundation models) are regulated separately under the AI Act’s GPAI rules.” These are not high-risk per se but must meet transparency requirements and publish a public summary of the training content using the Commission’s template, while implementing measures to comply with EU copyright rules. In July of 2025, The Commission published the General-Purpose AI Code of Practice to help providers demonstrate compliance.

Regulation: Providers of limited-risk AI models and applications must disclose to users that their content is AI-generated, must prevent illegal content generation, and must also publish summaries of copyrighted data used for training. High-impact AI models must undergo thorough evaluations and report serious incidents to the European Commission. AI-generated or modified content (e.g., deepfakes) must be clearly labeled as such.

The Commission’s Code of Practice on marking and labelling AI-generated content underpins these obligations, which took effect as scheduled on 2 August 2026. Providers with systems already on the market before that date have until 2 December 2026 to implement machine-readable marking; new systems must comply from 2 August 2026.

What is Article 50?

Article 50 states that providers must ensure that AI systems intended to directly interact with individuals are designed and developed so that those individuals are informed they are engaging with an AI system.

Article 50 transparency duties typically apply in the following situations:

  1. When you deploy a system that interacts with people (e.g., chatbots), users must be informed unless it is obvious that they are interacting with a system.
  2. When you use emotion recognition or biometric categorization, users must be informed, although there are limited exceptions.
  3. When you generate or manipulate synthetic content (e.g., deepfakes), this content must be marked or labeled in relevant contexts.

AI risk category 4: Minimal-Risk AI (e.g., AI used in games or spam filters)

Chapter 5 of the EU AI Act defines the ‘Minimal Risk’ or ‘General Purpose’ category for AI systems and the regulations applied to them.

Definition: These applications are already widely deployed and make up most of the AI systems we interact with today. Examples include spam filters, AI-enabled video games and inventory-management systems.

Regulation: Most AI systems in this category face no obligation under the AI Act, but companies can voluntarily adopt additional codes of conduct. Primary responsibility will be shouldered by the “providers” of AI systems, though any business which utilizes them should remain vigilant of their compliance obligations.

What this means for business owners and executives: As a business owner utilizing minimal-risk AI from a third-party vendor, it is necessary for you to responsibly source, employ, and risk-assess the adoption of each new AI system, though you will not be required to comply with the EU AI Act.

Which parts of the EU Act are already legally binding?

Phase 1: The ban of AI systems that pose unacceptable risks (Active since 2nd February 2025)

Organizations operating in the European market to ensure adequate AI literacy among employees involved in the use and deployment of AI systems.  

Adequate AI literacy required for all EU organizations

As part of the phased compliance rollout, the EU AI Act emphasizes the importance of AI literacy among employees to ensure safe and compliant AI usage.  

Since February 2, 2025, the EU AI Act requires organizations in the European market to ensure employees involved in AI use and deployment have adequate AI literacy. This applies to both AI system providers and users. 

According to Article 4 of the EU AI Act: 

“Providers and deployers of AI systems shall take measures to ensure, to their best extent, a sufficient level of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf, taking into account their technical knowledge, experience, education and training and the context the AI systems are to be used in, and considering the persons or groups of persons on whom the AI systems are to be used.” 

Practical guidance: In February 2025, the European Commission published guidelines on prohibited AI practices and guidelines clarifying the AI system definition to support the first provisions applying in February 2025.

The Commission also maintains an “AI literacy” Q&A with practical examples of what training and guidance can look like in different organizations

What is AI literacy?

AI literacy, or artificial intelligence literacy, refers to the understanding, utilization, monitoring, and critical reflection on AI applications. 

What does this AI literacy requirement mean for your organization?

In layman’s terms, organizations must ensure their staff is sufficiently educated in the operation and use of AI systems. This emphasis on education goes beyond regulatory alignment. It also helps mitigate risks such as unauthorized data exposure or biased outputs. 

For example, engineers who aren’t aware of security risks might accidentally share sensitive code with external AI systems, or HR staff using AI in hiring may overlook potential biases in the AI’s recommendations. 

Are there fines if your organization doesn’t comply?

AI literacy forms a crucial part of a robust AI governance framework. 

While there are no direct fines for non-compliance with Article 4, ensuring AI literacy may influence the severity of penalties in cases of other violations. 

How can your organization comply with AI literacy requirements?

With phase one of the EU AI Act in effect, incorporating the AI literacy and upskilling requirements is no longer a nice-to-have, it’s mandatory.   

Phase 2: Obligations for providers of general-purpose AI models (Active since 2nd August 2025)

Providers of General-Purpose AI (GPAI) models, including large language models such as ChatGPT and Claude, now face horizontal obligations that go well beyond the February ban on unacceptable AI.   

What is a General Purpose AI (GPAI)?

Picture a single, pre-trained “Swiss-army-knife” model like ChatGPT or Claude, that has learned from oceans of diverse text, images, and code. Because it isn’t built for one narrow job, the same core model can be plugged into almost any downstream product: a customer-service bot today, an image annotator tomorrow, or your firm’s coding assistant next week.  

The EU AI Act labels such adaptable building blocks General Purpose AI (GPAI) models and regulates them separately from application-specific systems precisely because one tweak or fine-tune can ripple across countless use-cases and users. 

What happened exactly on Aug 2nd 2025?

As of Aug 2nd, 2025, every GPAI provider must keep a private “black-box” dossier that shows regulators exactly how the model was built and tested; publish a short, public summary of the copyrighted material used for training; give customers a compact “model card” that spells out what the model is (and isn’t) meant to do; and prove that EU copyright rules are respected, whether by licences, opt-outs, or clear attribution. 

In addition, models classed as posing systemic risk must also perform adversarial testing, log and report serious incidents, and disclose energy-efficiency metrics to the newly operational EU AI Office and national supervisors.  

Are there fines involved?

Yes. The rules for general-purpose AI (GPAI) models took effect on Aug 2nd 2025, but the powers for enforcing those rules, Article 101 EU-level fines  for GPAI providers, only apply from Aug 2nd 2026. From that date, non-compliance attracts administrative fines of up to €15 million or 3% of global turnover (rising to €35 million / 7% for prohibited practices).

While GPAI models already on the market get a two-year transition window, until 2 August 2027, providers must still show they are taking necessary steps toward full conformity, guided by the Commission’s Code of Practice released earlier this year.

When will the other parts of the EU AI Act become legally binding?

With the Digital Omnibus now in force, the EU’s AI legislation will apply to high-risk AI systems from 2 December 2027 (Annex III, stand-alone systems) and 2 August 2028 (Annex I, systems embedded in regulated products), not the original 24- and 36-month post-launch dates.

Complying with the EU AI Act is a must for almost any business operating in the EU and incorporating AI somewhere in its value chain. Compliance paradigms are set to include:

  • Identifying the categories of AI your organization utilizes
  • Assessing their risk levels
  • Implementing robust AI governance frameworks
  • Ensuring transparency in AI operations

The extra runway on the high-risk tier is worth using deliberately. The obligations themselves have not changed, only the date they start biting. Organizations that use the time to build a complete AI inventory and risk-classification process now will be in a materially stronger position than those that treat the delay as a reason to pause.

International trends and themes in AI regulation

While the European Union is pioneering with its AI Act, AI regulation is being developed across the world. 

According to the May 2025 Global AI legislation tracker countries around the world are developing and implementing AI governance legislation and policies. Efforts include creating comprehensive laws, specific regulations for particular use cases, and voluntary guidelines and standards.  

Stanford University has noted a significant increase in the number of countries with AI-related laws; legislative mentions of AI rose 21.3% across 75 countries since 2023, marking a ninefold increase since 2016. 

While individual regions, including the EU and the US, are advancing their own frameworks, multilateral coordination is also on the rise. This includes adopting AI principles from the Organization for Economic Co-operation and Development, and discussions within the United Nations and the G7. The Centre for Strategic & International Studies highlights that these efforts aim to balance the potential risks of AI against the benefits it offers. 

McKinsey reports that different countries are taking varied approaches to AI regulation, which is why it is so pressing for IT organizations around the world to consult their legal teams as to their AI compliance requirements.

Despite regional differences in AI regulation, certain common themes are emerging globally. Understanding these themes can help businesses prepare for future compliance across various markets. Below, we briefly define these key trends in AI regulation: 

Human agency and oversight

AI systems should support people’s autonomy, uphold human dignity, and remain under human control. Regulators emphasize the need for appropriate human oversight to ensure AI serves humanity’s best interests.

Accountability

There is a demand for mechanisms that ensure responsibility and accountability for AI systems. This includes top management commitment, organization-wide education, and clear individual responsibilities.

Technical robustness and safety

AI systems must be robust, stable, and capable of correcting errors. They should include fallback mechanisms and be resilient against malicious attacks or manipulation.

Diversity, non-discrimination, and fairness

Ensuring that AI systems are free from bias and do not cause discrimination or unfair treatment is a top priority.

Privacy and data governance

AI systems should comply with existing privacy and data protection laws—such as GDPR in the European Union—ensuring high standards of data quality and integrity.

Transparency

Regulators are pushing for AI systems to produce clear, traceable outputs. Users should be informed when interacting with AI, understand their rights, and be aware of the system’s capabilities and limitations

Social and environmental wellbeing

AI should contribute to sustainability and be environmentally friendly, benefiting society at large. Continuous monitoring of AI’s long-term effects on individuals, communities, and democracy is essential.

Conclusion

On 1 August 2024, the European Union implemented the world’s first legislation governing the use of AI in both public and private sectors—the EU AI Act. This act aims to mitigate the various potential risks associated with AI while ensuring that it is safer and more secure for businesses operating within the EU.

The AI Act applies in phases rather than all at once: key obligations started applying from 2 February 2025 (notably prohibited practices and AI literacy), GPAI obligations from 2 August 2025, and the Act’s transparency duties and GPAI enforcement powers from 2 August 2026. Following the Digital Omnibus (Regulation (EU) 2026/1744, in force since 27 July 2026), the high-risk tier now applies from 2 December 2027 for stand-alone systems (Annex III) and 2 August 2028 for AI embedded in regulated products (Annex I).

In the UK, there is still no single cross-economy AI law as of August 2026. The government’s “Regulating for Growth Bill”, announced in the King’s Speech in May 2026, would introduce cross-economy AI sandboxing powers rather than a binding horizontal AI law; its AI Growth Lab sandbox went live in June 2026, starting with legal services, while broader legislation remains pending.

Business leaders can take several actionable steps now to facilitate future compliance and fully capture the benefits of safe and secure AI adoption. Now is the ideal time to review your AI strategies and ensure they align with both current and anticipated regulatory requirements.

To help, we released our AI Maturity Guide 2026 for organizations.

This guide provides 20 practical steps for leaders on AI governance, risk management, development, and security. For more information on how we can help you move faster, responsibly, please visit our website.

Download the AI Boardroom Gap Report

This field is for validation purposes and should be left unchanged.
Name*
Privacy*

This field is for validation purposes and should be left unchanged.
Name*
Privacy*

This field is for validation purposes and should be left unchanged.
Name*
What type of partnership are you interested in?*
Privacy*

Register for access to Summer Sessions

This field is for validation purposes and should be left unchanged.
Name*
Privacy*