On 2 August the European Union's AI Act reaches the deadline that actually bites. Articles 9 to 17 and Article 26 become enforceable, covering organisations that deploy high-risk AI systems as defined in Annex III: hiring tools, credit scoring, education, essential services, and the rest of the list.
The obligations are not light. Deployers need a working risk management process, documented data governance, technical documentation, logging and record keeping, transparency to affected people, meaningful human oversight, and demonstrated accuracy and robustness. Article 50 also takes effect, which is the one most people will notice: disclosure when a human is dealing with an AI system, machine-readable labelling of synthetic content, and watermarking obligations on deepfakes.
Fines run to 15 million euros or 3 percent of global turnover, whichever is larger, for deployer breaches. The Commission's own implementation timeline confirms the date.
The delay that has not happened
Here is where it gets awkward. On 7 May, EU negotiators reached a political agreement to push the high-risk deadlines back, in some accounts as far as December 2027. That agreement has not been enacted. It is a deal about a law, not yet the law.
Which means 2 August is still the operative date. Travers Smith and Holland & Knight have both told clients the same thing, and the advice is uncomfortable: build for August, because betting on a delay that has not cleared the legislative process leaves you exposed if it arrives late or arrives changed.
Plenty of organisations appear to be taking that bet anyway. Kiteworks puts the share with an established AI governance policy at 37 percent. Compliance surveys are self-selecting and the numbers move around, so treat the precise figure loosely. The direction is not really in dispute.
Why the readiness gap is not just laziness
Some of it is ordinary procrastination. But a good deal of the exposure is structural. Most firms do not have a reliable inventory of the AI systems already running inside them, because staff adopted tools without telling anyone. Kiteworks reports more than 80 percent of employees using AI tools their employer has not approved.
You cannot do risk management on a system you do not know you operate. That is the actual problem, and it explains why a compliance programme started in July does not finish in July. Discovery comes first, and discovery is slow.
The other complication is that liability follows use, not nationality. A US company with no European entity can still land inside scope by deploying a high-risk system whose output affects people in the EU. The extraterritorial reach here works much as it did under GDPR, and the lesson from GDPR is that enforcement starts slowly, then arrives.
Two weeks is not enough time to build a governance function. It is enough to find out what you are running and write it down, which is where anyone starting now should probably begin.
Commentarii · 0