For most of the last year, EU AI Act planning had one number in it: August 2, 2026. Budgets, hiring plans, vendor scopes, and board updates were all pinned to that date. It was treated as the moment the law arrived.
That date has now split into two. One clock started ticking on August 2 with real enforcement behind it. The other was pushed out to December 2027 and August 2028. They are both part of the same regulation, and they are moving at completely different speeds. A compliance budget built around a single deadline is now, almost by definition, pointing money at the half that isn’t due yet.
Two Clocks, Different Speeds
Here is what actually went live on August 2, 2026.
GPAI enforcement got teeth. Obligations for providers of general-purpose AI (GPAI) models have technically applied since August 2, 2025, but for the first year the European Commission could not fine anyone for missing them. From August 2, 2026, it can — including, in principle, for conduct during that first year. Under Article 101, the Commission and its AI Office can now demand documentation, run technical evaluations of a model, require risk-mitigation measures, restrict or pull a model from the EU market, and impose fines of up to €15 million or 3% of global annual turnover. Stalling on any of those requests is itself finable.
Article 50 transparency duties took effect on schedule. These were not deferred. If your product has a chatbot or conversational feature, it has to disclose that users are talking to an AI. If it generates synthetic images, audio, video, or text, that output has to be labeled as AI-generated. Emotion-recognition and biometric-categorization features have to disclose their use to the people they’re applied to. One narrow carve-out: the AI-content marking sub-duty under Article 50(2) has a grace period to December 2, 2026, but only for systems that were already on the market before August 2, 2026.
Prohibited practices have been enforceable since February 2, 2025. Article 5 bans — social scoring, manipulative techniques, certain biometric uses — carry the top penalty tier: up to €35 million or 7% of turnover.
And here is what moved. The Digital Omnibus (Regulation (EU) 2026/1744), in force since July 27, 2026, deferred the high-risk conformity-assessment regime. Standalone Annex III high-risk systems — hiring tools, credit scoring, biometric identification, education assessment, essential public services — now have until December 2, 2027. High-risk AI embedded in products already covered by EU product-safety law (Annex I) has until August 2, 2028.
So the same law now contains obligations you can be fined for today and obligations whose deadline is 16 to 28 months away. Scope, in both cases, follows the EU market rather than where your company is headquartered: a vendor selling into the EU or reaching EU users is in scope regardless of home country.
Why This Breaks a 2026 Budget
If you built a compliance budget in late 2025 or early 2026, it almost certainly has a single line for “AI Act readiness” sized against August 2, 2026. Most of that work — conformity assessments, technical documentation packs, a quality-management system, third-party audit engagement — is high-risk work. That is precisely the part that just moved to 2027 and 2028.
Meanwhile the obligations that now carry live enforcement risk — GPAI provider duties if you fine-tune or distribute models, Article 50 disclosure on every AI-facing feature — tend to be smaller, more product-side, and easy to under-scope when they’re bundled into the same line as a conformity programme. The result is a budget that is over-funded against a 2027 deadline and thin against an August 2026 one that already has fines attached.
The teams handling this well aren’t spending more. They’re re-pointing what they already allocated.
The Audit That Tells You Which Obligation Applies to Which Product
Katerina Gurba, executive leadership at Muteki Group:
“The mistake I keep seeing is budgeting against a category instead of a product. ‘We need to be AI Act compliant’ isn’t a scope — it’s a wish. The artifact that actually lets you allocate money is an obligation-to-feature map: every AI-touching feature in your product on one axis, every relevant obligation on the other, and a real answer in each cell. Does this chatbot trigger Article 50 today? Does this scoring feature land in Annex III, and if so, is it the December 2027 track or something we’ve mislabeled? Are we a GPAI provider because of how we ship a fine-tuned model, or just a deployer?
Once that grid exists, the budget writes itself, because you can see which cells are live now and which have runway. Without it, you’re funding a feeling. It takes a couple of weeks with someone who knows both your codebase and the regulation, and it’s the cheapest thing you’ll do all year.”
Runway Is Only Worth Something If You Build With It
Viktoriia Maksymova, governance and operations at Muteki Group:
“The deferral to 2027 and 2028 is genuinely useful, but I’d push back on how most teams are treating it. The plan for August 2026 was, for a lot of companies, a sprint — pull people off roadmap work, cram against the date, get to a defensible state, move on. If you use the extra 18 months to schedule the exact same sprint for late 2027, you’ve gained nothing except a later panic.
What the runway is actually for is capability. A named owner for AI governance. A lightweight review step so new features get classified when they’re designed, not audited in a rush afterward. Documentation habits that produce the conformity pack as a byproduct of how you build. That’s the difference between a company that treats each deadline as an emergency and one that has this handled as a standing function. The date moved; the opportunity is to stop needing the date.”
Most Plans Still Point at the Old Number
Houssam Zaki, operations and growth at Muteki Group:
“Across the teams we’ve talked with this quarter, the pattern is consistent: the compliance plan still has August 2, 2026 as its organizing date, and the budget hasn’t been touched since the Omnibus landed. Not out of negligence — it’s just that a plan agreed at board level has inertia, and ‘the deadline moved, but also some of it didn’t’ is an awkward update to give.
The teams that have already redirected did one small thing first: they separated the line item into ‘enforceable now’ and ‘due 2027+’ and looked at what was funded against each. In most cases the now column was underfunded and the 2027 column had money sitting in it doing nothing until next year. Moving that isn’t a big program decision. It’s a re-label and a reallocation, and it’s the highest-leverage hour a compliance owner can spend right now.”
What to Do Before Year-End
- Split the line item. Break “AI Act compliance” into “enforceable now” (GPAI duties, Article 50 transparency, Article 5) and “deferred” (Annex III to Dec 2027, Annex I to Aug 2028). Look at what’s funded against each.
- Map obligations to features. For every AI-facing feature, get a real answer on whether it triggers Article 50 today, whether it’s heading for high-risk classification, and whether your model-shipping model makes you a GPAI provider.
- Fund the live half properly. Article 50 disclosure work is usually small engineering changes plus copy and UI. GPAI documentation is a real effort if it applies to you. Neither should be a rounding error inside a conformity budget.
- Schedule the deferred half as a build, not a sprint. Put the Annex III runway into standing capability — classification at design time, documentation as a byproduct — rather than a 2027 cram.
- Re-brief whoever signed off on the original number. The board approved a plan around a date that no longer exists as one thing. That update is overdue.

FAQ
What EU AI Act obligations are enforceable right now?
GPAI provider obligations (with Commission penalty powers applicable since August 2, 2026), Article 50 transparency duties (chatbot disclosure, AI-content labeling, emotion/biometric disclosure), and the Article 5 prohibited-practices regime (enforceable since February 2, 2025).
What did the Digital Omnibus delay?
The high-risk conformity-assessment regime. Annex III standalone high-risk systems moved to December 2, 2027; Annex I product-embedded high-risk AI moved to August 2, 2028. Transparency, GPAI, and prohibited-practices rules were left on their original schedule.
We’re not in the EU. Does this affect our budget?
Yes, if your product is sold into the EU or reaches EU-based users. Scope follows the market, not your headquarters.
What are the fines?
Up to €35 million or 7% of global turnover for prohibited practices; up to €15 million or 3% for high-risk and other obligations, including Article 50 and GPAI provider duties; up to €7.5 million or 1% for supplying misleading information to authorities.
Is the 2027 deferral a reason to pause compliance spend?
No — it’s more time to build a real programme instead of sprinting to a date. The work that carries enforcement risk today isn’t on the 2027 clock.
Where This Leaves You
The AI Act didn’t get easier on August 2, 2026. It got more precise about which parts it will enforce now and which it will wait on. A budget that still treats it as a single event is funding the wrong half — heavy on a 2027 deadline, light on obligations that already have fines attached.
We work on EU AI Act readiness the way we work on any engineering problem: mapping obligations to actual product features, then building the changes and the documentation habits that keep you compliant without a scramble every time a deadline shifts. If your compliance plan still points at a date that’s since split in two, talk to us about re-scoping it against what’s actually live.
Image credits: Row of European Union flags photo by Guillaume Périgois on Unsplash. Open monthly planner on a desk photo by Eric Rothermel on Unsplash.
Katerina Gurba