Two years ago, the EU AI Act entered into force as the first comprehensive, risk-based framework for regulating AI.
August 2, 2026 was set to be a significant milestone in that rollout: the entirety of the Act was due to apply with the remaining delayed application provisions set to take effect (high-risk system rules, covering areas like hiring, credit scoring, and biometric identification, transparency requirements such as watermarking for deepfakes, etc.)
However, that timeline has now changed again after EU institutions adopted the AI simplification proposal, which entered into force on July 27. Most notably, the Annex III high-risk obligations have been delayed until December 2, 2027 for standalone AI systems, while product-embedded high-risk systems (Annex I) are punted further to August 2, 2028. Watermarking requirements (Article 50(4)) for deepfakes were delayed until December 2 of this year.
While those delays have commanded most attention, it’s only part of the picture. A meaningful set of obligations is still taking effect on schedule this August 2, just not the ones most people were expecting.
What’s Due on August 2, 2026
Here’s what stays on the original timeline:
- Enforcement powers activate. National competent authorities and the EU AI Office gain the authority to investigate and sanction, with maximum penalties of €35 million or 7 percent of global annual turnover, a threshold even greater than the GDPR’s.
- Disclosures for AI interactions. The European Commission published its final guidelines on Article 50 transparency obligations in July ahead of these obligations taking effect. The provision requires AI providers and deployers to disclose when users are interacting with an AI system – think chatbots, virtual assistants. Watermarking and disclosure requirements for AI-generated content with synthetic audio, image, or video (deepfakes) are delayed until December 2.
- Machine-readable watermarking. Generative AI providers must embed permanent, machine-readable metadata into synthetic outputs for any new system placed on the market from this date, with a short grace period for systems already in market.
- AI literacy enforcement. The Article 4 obligation has technically applied since February 2025; enforcement of it begins now.
Put simply: it’s not accurate to say “the AI Act got delayed.” The classification-heavy, back-office compliance work moved, but the customer-facing, product-design obligations did not. For many BSA members, that second category has turned out to be the more demanding piece of engineering work.
How Our Members Are Reading the Moment
We asked members to reflect on the past two years: what’s surprised them, what’s actually consumed their time, and how the deferral has changed their priorities. Here are some excerpts from what we heard back:
Workday framed the past two years as the practical work of translating principle into operating reality:

“Over the past two years, implementing the AI Act has reflected the scale of translating a comprehensive, risk-based framework into operational reality. The AI Office’s sustained stakeholder engagement has been welcome. At the same time, developing the secondary acts, standards, and codes needed to make the framework practical is complex work — and it must enable businesses to comply confidently and efficiently. At Workday, we support the updated application date for high-risk rules because companies need finalized, harmonized standards to demonstrate compliance. However, this extra time should not mean pausing preparation: businesses should continue strengthening governance, documentation, and risk-management practices.” — Marco Moragón, Director, Public Policy, Workday
Box took a similar view but sharpened the point into a strategic principle: the deferral is breathing room, not an off-ramp.
![]()
“Two years since the EU AI Act entered into force, its rollout has proven that static compliance is no longer viable; enterprises must build agile, resilient strategies to navigate a shifting legal landscape. At Box, we anticipated this shift early, establishing a cross-functional AI Governance program to operationalize trust. While the EU regulatory landscape continues to shift, including recent updates on general-purpose AI model rules and the deferral of high-risk obligations, our momentum remains unchanged. For Box, regulatory preparation is not a checklist exercise, but a strategic commitment to sustainable innovation, durable governance, and long-term customer trust.” — Leah Perry, VP of Legal (Privacy, Public Policy, AI Governance & Regulatory (Digital)), Box
Asana pushed on a different thread entirely, wondering whether the underlying classification logic is right in the first place:

“The EU AI Act’s high-risk framework is built to catch systems that make or shape consequential decisions, and that’s the right instinct. What it hasn’t fully worked out is how that instinct applies to general-purpose software with built-in controls and human oversight. Asana has built its AI so actions are auditable and reversible, because that’s what makes the tooling usable inside an organization. Classification should follow that same logic: what a system was actually built to do, not the one edge case a customer might invent for it. The transparency and AI literacy obligations already move in that direction, the classification rules should catch up to them.
Heading into the next phase, our main hope is that regulators keep listening the way they have through this process. Companies that already design this way shouldn’t have to choose between being useful and being compliant, and regulators shouldn’t have to choose between precision and speed. Getting this right benefits everyone still working through implementation.” — Poonam Singh, Deputy General Counsel, Head of Corporate Legal, Stock and Government Affairs, Asana
Bentley Systems highlighted the need for surgical interpretations of “high risk” AI to enable the use of AI for infrastructure development:

“AI is already transforming how infrastructure is designed, built, and maintained, helping engineers act with greater speed and precision by automating routine work and expanding the art of the possible. In infrastructure engineering, a critical distinction must be maintained: AI tools that inform and support human technical decision- making differ fundamentally from those that autonomously control or operate a road system, power grid, or other critical infrastructure. Sound guidance from the European Commission on the AI Act’s ‘high risk’ provisions is therefore essential. If ‘high risk’ is interpreted too broadly, it will delay AI adoption and hinder the deployment of the infrastructure Europe needs. Two years in, our ask is simple: ensure the AI Act focuses on genuine risk, while enabling responsible AI use in engineering to support the EU’s competitiveness and resilience ambitions.” – Bernardo Matos, Senior Director, EU Government Relations, Bentley Systems
The Takeaway
Two years on, the EU AI Act’s timeline looks different than it did at the outset. The provisions that drew the most attention in 2024, the high-risk rules, won’t apply in earnest until late 2027. But the provisions arriving this August are, in some ways, more visible to end users: disclosure requirements, content watermarking, and, for the first time, real enforcement powers.
Across the responses we’ve gathered, one theme comes through even where emphasis differs: the additional time is being treated as an opportunity to strengthen governance, not a reason to pause it.
