Skip to content

The EU AI Act's August deadline just moved.

Here's what you still need to know.

GL
Grange Labs
20 July 2026 · 5 min read

For two years, 2 August 2026 has sat in every compliance calendar as the date the EU AI Act's high-risk rules switched on. That date has now moved, but not all of it, and not for everyone, and the paperwork confirming it may not even be finished yet. 

If you advise clients on this, or run a firm that's a deployer of any of the tools caught by it, you need to read this.

The short version

The Commission proposed delaying the high-risk rules back in November 2025. Parliament and Council spent six months arguing over it, reached political agreement in May, Parliament voted it through on 16 June, the Council gave final sign-off on 29 June, and the finished text was signed on 8 July. What hasn't happened yet, as of this writing, is publication in the Official Journal, which is the step that actually makes it law. It has to publish before 2nd August for the new dates to apply in time. Most trackers expect that between 18 and 25 July, with 30 July as the hard cut-off. Until it publishes, the original 2 August 2026 deadline is still what the law says.

Assume the delay lands, because every signal points that way. But don't build a client conversation on a law that technically isn't in force yet without saying so.

What's actually being delayed

The core high-risk obligations under Annex III of the Act, covering standalone systems used in employment, access to essential services, education, law enforcement and a handful of other categories, move from 2 August 2026 to 2 December 2027. 

High-risk systems embedded in already-regulated products (think medical devices, machinery) move further out, to 2 August 2028. That's a genuine sixteen-month runway most firms didn't expect to get.

What isn't being delayed

Three things stay exactly where they were, and this is the part that gets lost in "the AI Act was delayed" headlines:

Article 50 transparency stays on schedule. If a client's chatbot, image generator or AI system interacts with the public, the obligation to disclose that it's an AI system still lands on 2 August 2026 (with a narrower carve-out for labelling AI-generated content on systems already on the market, pushed to 2 December 2026).

The Commission's enforcement powers over general-purpose model providers switch on. The big labs, OpenAI, Anthropic, Moonshot and the rest, have been under Chapter V obligations since August 2025. From 2 August 2026, the Commission can actually investigate, demand documentation and fine them for breaches. This doesn't touch your firm directly, but it changes the leverage you have if a vendor's model behaves badly.

Article 4 AI literacy was never on the delayed list, because it's already been law since 2 February 2025. Every organisation using AI professionally is required, right now, to ensure staff have adequate understanding of what the systems do, what they can't do, how to read their output, and what the risks are. Nobody is enforcing this hard yet, but it's not a 2027 problem. It's a today problem that most SMEs haven't touched.

Why this matters specifically for law, accountancy, insurance and architecture firms

Annex III catches two categories that turn up constantly in professional services, even after the delay:

Employment-related tools. Recruitment screening, candidate ranking, performance evaluation, task allocation, worker monitoring, and decisions on promotion or termination are all named. If your firm or your client uses an AI-assisted applicant tracking system, or a monitoring tool on staff, that's the category, and it's the one now sitting at December 2027 rather than August 2026.

Access to essential private services. Creditworthiness assessment and insurance risk-scoring or pricing both sit in Annex III. For an insurance brokerage this is the most direct hit in the whole Act, and it's worth checking now whether any underwriting or pricing tool a client uses falls inside that definition, because the answer changes what they need to have in place and by when.

Most firms buying these tools off the shelf are deployers, not providers, under the Act's split of responsibility. That's a materially lighter obligation set than what falls on the company that built the system, but it's not nothing.

What deployers are actually on the hook for

Article 26 sets out the deployer's duties, and they don't disappear just because the deadline moved to 2027. When the obligations do land, they include:

  • Using the system strictly according to the provider's instructions
  • Assigning human oversight to people with the competence, training, authority and time to actually exercise it, not just a name on an org chart
  • Monitoring the quality of the data going in
  • Keeping logs for at least six months
  • Telling workers before a high-risk system is used on them, and telling affected individuals when a decision touches them
  • Reporting incidents to the provider and the relevant authority without delay
  • Not using a system that hasn't been registered where registration is required

Certain deployers, including those providing services to the public such as insurance and banking, also owe a fundamental rights impact assessment under Article 27 before putting a high-risk system into use. That obligation moves with the same delayed timeline, but the analysis behind it is worth starting now rather than in 2027, because it takes longer to do properly than most firms expect.

What to actually do this week

Map what you and your clients are using. Not a formal audit, just an honest list of anything that screens candidates, monitors staff, or prices risk. Most firms find they have at least one tool in scope once they actually look.

Don't read the delay as permission to stop. The breathing room is real, but Article 4 literacy is binding today, and the 2027 and 2028 dates will arrive exactly the way 2026 did: later than expected, then suddenly not. Firms that use the runway to build proper governance now will meet the real deadline without a scramble. Firms that treat the delay as a reason to shelve the conversation will be back here in eighteen months having the same panic a second time.

Check before you say anything definitive to a client. If you're advising anyone on this before the Official Journal publication actually happens, say clearly that the new dates are agreed but not yet legally binding. It's a small caveat that protects your credibility if publication slips past 2 August for any reason.

Use this as the expertise-building conversation it is. Most of the market is currently confused between "the AI Act was delayed" and "the AI Act doesn't apply to us until 2027." Neither is quite right. A firm that can explain the actual, current state of play, calmly and accurately, is the firm a client trusts to build the compliant system for them when the real deadline arrives.


Sources: European Parliament and Council press releases and the Consilium record of the Digital Omnibus on AI's legislative timeline; legal analysis from Freshfields, Gibson Dunn, DLA Piper, Addleshaw Goddard, Travers Smith and the IAPP; and the consolidated Article 26 and Article 4 texts published via the EU AI Act Service Desk.

Share this post
X LinkedIn Facebook Email
StrategyAI EU AI ActAI Governance
- Next step

Want this in your business?

Book a 30-minute scope call. No pitch, just a straight answer.