The EU AI Act is no longer a matter of the future — it is applicable law, and enforceable since 2 August 2026. For IT leaders, the question is therefore no longer whether, but which obligations already apply today and where there genuinely is still time. This is exactly where many organisations are confused — not least because one central deadline recently shifted.
What really applies in 2026 — and what was postponed
The so-called Digital Omnibus (Regulation (EU) 2026/1744, in force since 27 July 2026) reshuffled the deck. Anyone still working from the old calendar is planning against reality. The current status:
- Binding since February 2025: The prohibition of certain AI practices (Art. 5) and the AI-literacy obligation for staff (Art. 4). If you never documented the latter, you are already in breach.
- Binding since August 2025: The obligations for providers of general-purpose AI models (GPAI) — technical documentation, training-data summaries, copyright strategy.
- Enforceable since August 2026: The transparency obligations under Art. 50 (labelling of chatbots, deepfakes and AI-generated content) and the full penalty framework — up to EUR 15 million or 3% of worldwide annual turnover.
- Postponed to December 2027: The full obligations for high-risk AI systems under Annex III. Product-embedded high-risk AI under Annex I even has until August 2028.
The practical consequence: today's time pressure is not on the elaborate conformity assessment for high-risk systems, but on the baseline obligations that are already running — literacy, transparency, governance.
The four priorities for IT leaders
From our consulting practice, four topics stand out that IT organisations should tackle in a structured way now:
- Build an AI inventory: Most companies don't know where AI is in use — from embedded features in SaaS tools to home-built assistants. No inventory, no risk classification.
- Assign risk classes: Not every AI is high-risk. The bulk of business applications falls into "limited" or "minimal" risk — with correspondingly lean obligations. A clean classification saves considerable effort.
- Evidence AI literacy: Art. 4 requires that staff using AI are competent to do so. That is not a certificate, but a documented process — training, guidelines, points of contact.
- Implement transparency: Chatbots must identify themselves as such, AI-generated content must be labelled. For many customer touchpoints this means concrete technical changes.
Why panic is the wrong approach
The postponement of the high-risk deadlines shows: anyone who launched expensive conformity projects under time pressure in early 2026 may have mis-prioritised resources. The EU AI Act rewards structure over speed. A robust inventory, a clean risk classification and documented governance are the foundation — everything else builds on that and can be scheduled deliberately.
For IT leaders this is also a strategic opportunity: setting up AI governance professionally now not only reduces regulatory risk, it creates the basis of trust to deploy AI more broadly and faster across the company.
Conclusion
The EU AI Act is real, staggered and enforceable — but it does not apply overnight. The baseline obligations are already running, the demanding high-risk requirements have shifted to the end of 2027. The smart move is to use this lead time to build inventory, risk classification and governance cleanly, rather than lapsing into panic. We are happy to support you with a structured AI Act assessment for your IT organisation.