Introduction
August 2, 2026 has been circled on compliance calendars for two years as the date the EU AI Act's high-risk obligations would take effect. That is no longer accurate, and the confusion it is causing enterprise teams is itself a risk. In June 2026 the EU agreed to delay the compliance timeline for high-risk AI systems by 16 months for standalone systems and 12 months for product-embedded systems, pushing that deadline into December 2027. What did not move is Article 50: transparency duties for chatbots, AI-generated content labeling, and deepfake disclosure, along with the Commission's enforcement powers over general-purpose AI models, both of which are binding law as of this month.
What Is Actually Enforceable From August 2, 2026
Article 50 transparency obligations
Any organization deploying a chatbot, a system that generates synthetic audio, image, video, or text content, or an emotion-recognition or biometric-categorization system now has a binding obligation to disclose that fact to end users. AI-generated content that could be mistaken for authentic material must be machine-readably marked as artificial, and deepfakes must carry a clear disclosure. This applies regardless of whether the underlying system is classified as high-risk.
General-purpose AI model enforcement powers
The Commission's authority to enforce obligations on providers of general-purpose AI models - including the systemic-risk tier covering the largest foundation models - is also active from this date. Enterprises building on top of general-purpose models inherit downstream documentation obligations even where their own use case is not classified as high-risk.
What Was Delayed - and Why the Delay Doesn't Mean 'Wait'
High-risk systems now have until December 2027
Standalone high-risk systems - covering biometric identification, critical infrastructure, education and vocational training, employment decisions, access to essential services such as credit scoring and insurance, law enforcement, migration, and administration of justice - received an additional 16 months. Product-embedded high-risk systems under existing EU product-safety law, such as medical devices, toys, and lifts, received 12 additional months. Neither obligation disappears; both are still coming, on a schedule regulators have now made explicit.
Article 10's data governance requirement is the one to start now
When the high-risk obligations do land, Article 10 requires that training, validation, and testing datasets be relevant, sufficiently representative, and - to the extent possible - free of errors, with documented data governance and management practices appropriate to the system's intended purpose. This is not a checkbox exercise completed once before deployment; it requires an ongoing, defensible record of what data trained the system, where it came from, and whether it has been altered since. Building that evidence trail after the fact, in the final months before a December 2027 deadline, is materially harder than building it into the data pipeline now, while there is still runway.
- Live now: chatbot and AI-content disclosure obligations under Article 50
- Live now: Commission enforcement powers over general-purpose AI models
- Delayed to December 2027: standalone high-risk system obligations (16-month extension)
- Delayed to roughly December 2027: product-embedded high-risk systems (12-month extension)
- Unchanged: the underlying data governance bar in Article 10, which still requires documented, defensible dataset provenance
Treating the delay as permission to wait is the most common mistake enterprise AI teams are making this quarter. The obligations that matter most - defensible, continuously verifiable data governance - are the ones that take the longest to build properly. See how ROOTKey anchors AI training and inference data for continuous, audit-ready verification.
Recevez nos analyses sur la cyber-résilience par e-mail
Des conseils pratiques et prêts pour l'audit sur l'intégrité des données, la conformité et la continuité - dès leur publication.





