
If you have been waiting for “the EU AI Act deadline” to plan around, you have been waiting for the wrong thing. The Act was never a single date. It is a rolling series of obligations that started taking effect in 2024 and will keep unfolding through 2027 and beyond. Some of that timeline just shifted again. Some of it did not move at all and is already enforceable.
That distinction matters more than almost anything else in the current conversation about the Act. Treating every provision as equally “not yet in effect” is how organizations end up caught off guard by rules that have quietly already applied to them for over a year, while also over-planning around requirements that just got pushed back.
Here is what is actually true as of now, split into what is settled and what is still moving.
What Is Already In Effect
The EU AI Act entered into force in August 2024, and its phase-in began almost immediately. As of today, two major categories of obligation are live and enforceable, not upcoming.
First, the Act’s prohibited practices became applicable in February 2025. These are the outright bans: social scoring, certain forms of biometric categorization, manipulative AI systems designed to exploit vulnerabilities, and a handful of other uses the Act treats as unacceptable risk regardless of sector or size. If your organization is deploying anything close to these categories, that is not a future compliance project. It is a present one.
Second, obligations for general purpose AI models became applicable in August 2025. Providers of general purpose models, the foundation models many enterprise AI systems are built on top of, are already expected to meet transparency, documentation, and in some cases systemic risk requirements. If your AI stack includes third party foundation models, this is worth confirming with your vendors now rather than assuming it is still pending.
Both of these dates already came and went. That is the first correction worth making to how most teams are thinking about the Act: parts of it are not a 2027 problem. They are a today problem.
What Just Moved, and Why It Matters
The part of the Act that governs high risk AI systems, listed under Annex III, was originally set to become applicable in August 2026. That is the deadline most enterprise governance teams have had circled for the past two years, and it is the one that just changed.
In May 2026, the European Commission proposed an Omnibus package intended to simplify and adjust parts of the Act’s rollout. On June 29, 2026, the EU Council formally adopted that package. As a result, the applicability date for most Annex III high risk system obligations has moved to December 2, 2027. High risk systems that are embedded components within products already covered by other EU safety legislation, listed under Annex I, now have until August 2, 2028.
This is a real, adopted change, not a proposal still working through committee. If your compliance roadmap was built around an August 2026 deadline for high risk system obligations, that roadmap now has more runway than it did six months ago. That is worth communicating clearly to any internal stakeholders who were planning around the old date, since an outdated deadline can cause just as much confusion as a missed one.
It is worth being precise here, because this is exactly the kind of detail that is easy to get wrong in either direction. The delay applies to the high risk system obligations under Annex III and the embedded systems under Annex I. It does not undo the prohibitions or the general purpose AI rules that are already in force. An extension on one part of the Act is not a pause on the whole Act.
What Is Still Unsettled
Alongside the timeline shift, there is a second, separate thread that has not resolved yet: how “high risk” actually gets defined and classified in practice.
The European Commission published draft guidelines on the classification of high risk AI systems in May 2026. Those guidelines went through a public consultation period that closed in July 2026. As of now, no finalized version has been published. The interpretive detail, the specific criteria that will determine whether a given AI system counts as high risk under Annex III, is still being worked out.
This is the piece that deserves the most caution right now. It is tempting to treat a longer deadline as a longer runway for uncertainty too, but the two are not the same thing. The extended timeline gives organizations more time to prepare for high risk obligations. It does not yet give a finalized answer for exactly which systems those obligations will apply to. Guidance that treats the classification question as settled, whether from a vendor, a consultant, or an internal deck, should be read with that caveat in mind until an official finalized version is published.
Where This Leaves You
Put together, the honest 2026 picture of the EU AI Act looks like this: prohibited practices and general purpose AI obligations are live now. High risk system obligations have real breathing room, pushed to December 2027 and August 2028 depending on category. And the specific rules for what counts as high risk are still being finalized, with no confirmed publication date yet.
None of that is a reason to wait. It is a reason to build AI governance that does not depend on getting the exact classification right on the first try, because the classification itself is still moving.
An AI governance program that can show, at any point, exactly what models and agents are running, what data they touch, and what oversight applies to them is in a far stronger position to adapt as the rules solidify than one that is trying to hit a single static compliance target.
The Act rewards visibility and ongoing oversight more than it rewards guessing correctly about a moving deadline. Discover what you have. Govern it continuously. The specific dates will keep shifting. That discipline will not.
Regulatory timelines change, and this article reflects publicly available information as of the article’s publish date. It is not legal advice. Confirm current requirements and their application to your organization with qualified counsel.
Every enterprise AI program will eventually need to answer the same question a regulator or auditor will ask: what is actually running, and who governs it. Building that answer now, ahead of any specific deadline, is how you stay ready no matter how the timeline moves.
Put these ideas to work.
Schedule a 30-minute walkthrough with our team.