Since August 2, 2026, the bulk of the European Union's Artificial Intelligence Act has been in force, giving national regulators enforcement powers over high-risk AI systems for the first time. But a last-minute change to the law's timeline means the single biggest category of obligations — rules covering high-risk uses under Annex III — won't actually bind most companies until December 2027, more than a year later than originally planned.
What kicked in on August 2
The August milestone activated several things that were already scheduled: full enforcement of the prohibited-practices rules that first applied back in February 2025 (covering social scoring, exploitative manipulation and several categories of biometric profiling), the general-purpose AI model obligations that took effect a year earlier, and new Article 50 transparency requirements covering AI-generated content and chatbots. Penalties for violations of these provisions can reach into the tens of millions of euros or a percentage of a company's global annual turnover, whichever is higher.
Finland became the first member state with fully operational enforcement infrastructure at the start of 2026, and other national regulators — including bodies in France, Germany and the Netherlands — have since issued their own compliance guidance for businesses in their jurisdictions.
What got pushed back, and why
The more consequential change is what didn't happen on schedule. Annex III covers what the Act considers genuinely high-risk uses of AI: biometric identification, critical infrastructure, education and exam scoring, employment screening, and migration or border-control decisions. Those rules were originally due to apply on the same August 2026 date. Under a "Digital Omnistop-the-clock" mechanism proposed by the European Commission in November 2025, the Annex III deadline is now tied to the availability of harmonized technical standards and compliance tooling, pushing the effective date out to December 2, 2027 at the latest. Rules for high-risk AI embedded in already-regulated products, such as medical devices and vehicles, move out even further, to August 2028.
Notably, the substance of what counts as high-risk under Annex III hasn't changed — no new use case was added or removed. What changed is purely the timeline, giving both regulators and the companies building high-risk systems considerably more runway to get technical documentation, conformity assessments and EU database registrations in place.
Why it matters beyond Europe
The delay comes against a backdrop of broader friction between the EU and the United States over AI policy, following a brief U.S. export-control suspension of certain Anthropic models earlier in 2026 that some European officials pointed to as evidence of how exposed the bloc is when it depends on non-European AI infrastructure. That debate is likely to keep shaping how aggressively EU regulators choose to use the enforcement powers they now formally hold, even as the highest-stakes rules on the books wait until the end of 2027 to bite.