Understanding the EU AI Act: A Guide for Businesses
Updated: Sep 8
In July 2026, the EU adopted the Digital Omnibus (Regulation (EU) 2026/1744). This regulation moved the deadline for standalone high-risk AI systems, classified under Annex III, from 2 August 2026 to 2 December 2027. Additionally, high-risk AI integrated into regulated products (Annex I) now has a deadline of 2 August 2028. However, it's essential to note that this is just one tier of the Act, not the entire Act itself.
Current Obligations Under the EU AI Act
Several obligations are already in force and were unaffected by the recent delay:
Prohibited AI Practices (Article 5): These have been banned since 2 February 2025.
AI Literacy (Article 4): This requirement has been mandatory since 2 February 2025. See the AI literacy obligation.
General-Purpose AI Model Rules: These rules have been in effect since 2 August 2025, with EU-level enforcement powers and fines active from 2 August 2026.
Transparency Duties (Article 50): These duties were applied on 2 August 2026, exactly as originally scheduled. You can find the transparency rules that are already live.
National regulators and the EU AI Office are operational. If you assumed the delay provided you with breathing room, you may already be non-compliant. The penalties for non-compliance are significant. They can reach €35 million or 7% of global turnover for prohibited practices, and €15 million or 3% for most other breaches.
The Delay Isn’t a Reprieve
The high-risk deadline was moved because the technical standards were not ready, not because the requirements became easier. The substance of the regulations remains unchanged. The extra time allows you to do the necessary work properly, not to skip it.
The workload is substantial. The technical documentation required for a high-risk system (Article 11) is not something you can complete the week before the deadline. It is an evidenced record of design decisions, data governance, risk management, and human oversight, built up over months. Start now, and you will accumulate credible evidence over time. If you wait until mid-2027, you will find yourself assembling it under pressure, competing for scarce assessor capacity as everyone else rushes to meet the same deadline.
We have observed this pattern from within operations for years. The last-minute scramble is not merely a compliance failure; it is an operations failure. It is the predictable result of treating a known deadline as a future problem until it becomes an immediate one.
The Honest Position
Treating December 2027 as “the deadline” is a planning error with two failure modes. First, you risk missing obligations that are already live. Second, you underestimate how long the high-risk work will take. Neither of these situations is comfortable when explaining your position to a regulator. The organizations that navigate this landscape successfully are not the ones who waited; they are the ones who used the runway effectively.
Preparing for Compliance
To ensure you are on the right track, consider conducting an AI compliance readiness review. This review will provide you with a clear understanding of your current compliance status and help you identify areas for improvement.
Key Steps to Take Now
Assess Current Compliance: Review your existing AI systems and practices against the current obligations.
Document Everything: Begin compiling the necessary technical documentation as soon as possible.
Educate Your Team: Ensure everyone involved understands the importance of AI literacy and compliance.
Engage with Experts: If you’re unsure where you stand, reach out for professional guidance.
Let’s Talk
Veritas_fox was built by operators—people who have sat in the operations seat and faced regulations, deadlines, and a lack of clear roadmaps.
If you’re not sure where you actually stand, AI compliance readiness review is the honest place to start.
→ Schedule a call: Free Consultation - veritas_fox, or email laura@veritasfox.com.
AI compliance made easy.




Comments