The EU's AI Act has been rolling out in phases since its passage in 2024. On August 2, 2026, the final phase kicks in, applying the full weight of the regulation to high-risk AI systems. For companies that have been managing their exposure through earlier phases, the August deadline is when the requirements get most demanding.
The law uses a tiered risk framework. The first phase, which took effect in February 2025, banned the practices the EU considers unacceptable: social scoring, real-time biometric surveillance in public spaces, and manipulation systems that exploit psychological vulnerabilities. The second phase, in August 2025, established governance bodies and imposed obligations on general-purpose AI model providers. August 2026 is the third and final phase, covering high-risk systems across sectors including hiring, education, credit, law enforcement, and critical infrastructure.
What high-risk compliance actually requires
The requirements for high-risk AI systems are not minimal. Providers must establish and document risk management systems, implement data governance practices, create full technical documentation, enable automatic logging of system behavior, and ensure meaningful human oversight of consequential decisions. Before placing a system on the EU market, they must complete a conformity assessment, affix CE marking, and register the system in the EU's official AI database.
Once deployed, compliance does not end. Deployers are required to monitor system performance continuously and report serious incidents to national authorities. All AI-driven user interactions must be clearly disclosed as such, so users know when they are engaging with an automated system.
The penalties are significant
Fines under the AI Act exceed those available under GDPR. Maximum penalties reach €35 million or 7% of annual worldwide turnover, whichever is higher. According to analysis by Legal Nodes and Eversheds Sutherland, the August 2026 deadline is not expected to be delayed. Companies relying on a grace period extension should not assume one is coming.
A pattern forming across Asia too
The EU is no longer alone in having comprehensive AI legislation. South Korea's AI Basic Act has been in force since January 2026, requiring generative AI providers to label outputs and notify users when they are interacting with AI systems. Vietnam's national AI law took effect March 1, using a four-tier risk classification that broadly mirrors the EU's approach. Singapore has taken a different path, relying on voluntary governance frameworks rather than legislation, at least for now.
The regulatory map for AI is being drawn faster than most companies anticipated. August 2026 is not an endpoint for the EU's approach; it is more likely the point from which enforcement becomes routine.
Sources
- i. www.legalnodes.com
- ii. www.eversheds-sutherland.com
- iii. ppc.land
Commentarii · 0