Europe's big AI deadline arrived on Sunday. It enforced the easy part and postponed the hard one.
The AI Act's marquee date came and went, and the high-risk obligations that were supposed to bite had already been pushed to 2027 and 2028 by an amendment that isn't even law yet. Calling that either a triumph or a retreat gets the same thing wrong: "the deadline" was never a single switch, and the calendar was never the achievement.

Image: almathias / Pixabay (CC0)
The most popular way to describe what happened in Brussels on Sunday is that the EU AI Act finally grew teeth. Two August 2026 was the date circled on every compliance calendar for two years — the day the world's first comprehensive AI law was supposed to move from principle to obligation. It arrived. Something took effect. And within hours the coverage had split into the two camps it always splits into: the boosters announcing that Europe had just regulated artificial intelligence, and the skeptics announcing that Europe had, once again, blinked.
Both are wrong, and they are wrong in the same way. "The deadline" was never a single switch you could throw or defer. It was dozens of separate obligations, on separate clocks, aimed at separate things, and what actually happened on Sunday is that the easy ones came into force and the hard ones were quietly moved to 2027 and 2028 — by an amendment that is not yet law. I want to defend that sequencing, because I think it was mostly the right call. But defending it honestly means naming what it cost, and the celebration and the eulogy are both skipping that part.
What actually took effect, and what didn't
Start with the specifics, because this is a story that only makes sense at the level of which clause binds whom, and when. The obligation that genuinely came into force on 2 August is Article 50 — the transparency rules. If you deploy a chatbot, you have to tell people they are talking to a machine. If you generate synthetic media that qualifies as a deepfake, you have to disclose that it is artificial. If you run emotion-recognition or biometric-categorisation systems, you have to notify the people subjected to them. And providers of general-purpose generative models have to mark their outputs, in a machine-readable way, as AI-generated. Label the bot, label the fake. That is the part of the law that now applies.
The part that did not apply on Sunday — despite two years of everyone assuming it would — is the high-risk regime. These are the obligations that actually have teeth: the conformity assessments, risk-management systems, human-oversight requirements and regulator reporting that attach to AI used in hiring, credit scoring, education, medical devices, critical infrastructure. That is the machinery people mean when they say the AI Act regulates AI. And through a package the Commission proposed last November and EU legislators have since provisionally agreed — the "Digital Omnibus" — the standalone high-risk obligations have been pushed from 2 August 2026 to 2 December 2027, and the ones embedded in already-regulated products to 2 August 2028. The teeth were rescheduled before they ever closed.
Two details make this sharper than a routine delay. The first: the Omnibus is not yet final law. A provisional political agreement is a strong signal, but the instrument that moves the deadline is itself still being finalised — so the law's headline date was, in effect, overtaken by an amendment to the law that had not itself completed. The second: even the transparency rule that did land comes with a grace period. Systems already on the market before Sunday do not have to comply with the content-marking obligation until December. So the part that took effect took effect with an asterisk, and the part that mattered most did not take effect at all.
The steelman, because it deserves one
Here is the strongest case for the postponement, stated fairly, because I believe most of it. You cannot enforce a rule whose enforcement machinery does not exist yet, and on the high-risk provisions, large parts of that machinery genuinely were not ready. The harmonised technical standards that tell a company what "adequate risk management" concretely requires were not finished. Several member states had not designated the national competent authorities who were supposed to receive the filings and police the obligations. The Commission's own guidance on the threshold question — which systems even count as high-risk under Article 6 — was still in draft, out for consultation, with final text not expected until the end of the year.
Ask the procedural question the boosters skip: what would it have meant to let the high-risk obligations bite on 2 August into that vacuum? Companies would have been legally required to conform to standards that had not been written, and to report to authorities that had not been appointed, under a definition of "high-risk" that was still being argued over. That does not produce compliance. It produces a scramble for lawyerly cover, a wave of box-ticking against invented benchmarks, and enforcement so uneven it would have taught the market that the rule was theatre. I spent years inside government watching well-intentioned mandates go live before the agency could carry them, and the result is never protection. It is a paperwork ritual that discredits the underlying goal. Moving the date was, on the merits, more honest than pretending the scaffolding was up.
A law that bites before its enforcement machinery exists does not produce compliance. It produces theatre — and teaches the market that the rule was never real.
Now the costs the celebration skips
So I am not here to condemn the delay. I am here to insist that we describe it accurately, because the framing everyone reached for is doing real damage, and it comes in three parts.
The first is the category error, and it is the one I care most about. "The AI Act took effect" is being reported as an event, singular, when the Act is a bundle of obligations on at least four different timelines: prohibited-use bans that applied in early 2025, general-purpose-model duties that applied in August 2025, the transparency rules that applied on Sunday, and the high-risk regime now stretched across 2027 and 2028 — each with its own grace periods layered on top. Treating that as a single switch is precisely how the boosters get to say "Europe regulated AI" and the skeptics get to say "Europe caved," on the same afternoon, about the same law. Both are describing one clause as if it were the whole statute. The honest sentence is boring and specific: the transparency obligations came into force, and the high-risk obligations were deferred. Say that, and neither headline survives.
The second cost is to credibility, and here the delay is not free. The reason the AI Act matters beyond Europe — the reason American and Asian companies rewrote their practices for it — is the Brussels effect: the expectation that EU deadlines are real, so the cheapest path is to comply globally rather than build one product for Europe and another for everyone else. That entire mechanism runs on the deadlines being credible. Move the marquee one, through an instrument that amends the law before the law ever applied, and you have taught every regulated party a lesson they will not unlearn: the dates are negotiable, and the right response to an inconvenient one is to lobby for an omnibus. The next deferral will be easier to ask for and easier to grant. That is a real price, and it is not paid by Brussels. It is paid by the credibility of every future date the EU sets.
The third cost is the one hiding inside the good news. The obligation that did survive — Article 50 transparency — is the cheapest part of the law to write and the hardest part to enforce. Who actually makes a deployer label a deepfake, and how? The standardised EU marking scheme that is supposed to make AI-generated content detectable is still being developed; there is no finished label to conform to. Robust detection of synthetic media is a technically unsettled problem that a legal obligation cannot solve by fiat. And the actors most likely to produce malicious, undisclosed deepfakes are precisely the ones least troubled by a European disclosure duty. An obligation with no agreed standard and no working detection tooling is, for now, closer to an aspiration with a citation number than a rule with a remedy. The law kept the provision that is easiest to announce and hardest to make bite — and announced it.
The realistic version
The better frame is not complicated, and it is available to a regulator willing to say something less flattering than "teeth" or "retreat." Bring the obligations that have finished standards and appointed enforcers into force on schedule; postpone the ones that do not; and describe the second thing as a postponement, out loud, with the reason attached — the standards aren't done, the authorities aren't named — rather than burying it in an omnibus and letting the calendar carry a meaning it cannot support. What the EU actually did on Sunday is roughly that: it shipped the transparency rules it could nominally enforce and delayed the high-risk rules it could not. The mistake was never the sequencing. It was allowing the date to stand in for the achievement, so that when the date moved, everyone mistook a schedule for a verdict.
And because I owe you the cost of my own position: sequencing like this invites gaming. Once "the standards aren't ready" becomes a recognised reason to slip a deadline, every regulated party discovers that its own obligation, too, is not quite ready, and the pressure to defer never stops arriving. A transparency regime without a working label means the public is getting less protection right now than Sunday's headlines implied — real people interacting with systems the law nominally covers and practically doesn't. I would still take the honest, sequenced, standards-first version over the alternative, because a mandate that outruns its machinery discredits the whole project. But it is a genuine trade, not a free one, and the fastest way to squander what Europe has built here is to keep pretending the deadline was the point. The obligations are the point. The deadline was only ever the promise to enforce them — and a promise you amend before it comes due is worth watching very closely the next time it is made.
References
- European Commission — AI Act: transparency obligations under Article 50 (guidelines)
- European Commission — Transparency obligations under Article 50 of the AI Act (FAQ)
- Gibson Dunn — EU AI Act Omnibus agreement: postponed high-risk deadlines and other key changes
- Sidley — EU lawmakers reach provisional agreement to delay key EU AI Act obligations
- Greenberg Traurig — Deepfakes, chatbots, AI-generated text: the Commission details Article 50 transparency obligations


