Six days before the EU AI Act's August 2, 2026 deadline, Brussels deferred its high-risk rules to December 2027. The delay is not a reprieve: transparency obligations took effect on schedule; earlier rules are already enforceable, with fines up to 35 million euros or 7% of global turnover; and the Act reaches US companies whose AI outputs are used in Europe.
August 2, 2026, was supposed to be the day the EU AI Act's high-risk regime became binding, the most consequential compliance date in enterprise AI to date. It arrived, and most of it moved. On July 27, 2026, six days before the deadline, the EU's Digital Omnibus package (Regulation (EU) 2026/1744) entered into force and pushed the high-risk obligations back by sixteen months. The European Parliament approved the deferral on June 16, 2026, by a vote of 423 to 57.
It would be easy for a US leadership team to read that headline and file the whole topic under 2027 problems. That would be the wrong lesson. The transparency obligations under Article 50 took effect on August 2, as scheduled. The prohibited practices regime and the rules for general-purpose AI providers have been in effect since 2025. And the readiness picture is poor: a Cloud Security Alliance research note reports that more than half of organizations still lack a systematic inventory of the AI systems they have deployed, the basic prerequisite for any compliance plan. This article covers what actually changed on August 2, which obligations apply to US companies right now, and how to use the sixteen months the EU just handed back.
What Happened to the EU AI Act's August 2026 Deadline?
The EU AI Act's August 2, 2026 deadline for high-risk AI systems was deferred at the last minute. The Digital Omnibus, in force since July 27, 2026, moved standalone high-risk obligations to December 2, 2027. Article 50 transparency rules remain in effect as of August 2, 2026, and prohibitions and general-purpose AI obligations remain enforceable.
The deferral was driven by logistics, not by a change of heart. Compliance with the high-risk regime depends on harmonized technical standards that companies can certify against, and those standards ran late: the first one, prEN 18286, entered public inquiry in October 2025, roughly eight months behind its original target. Regulators concluded that holding companies to a deadline before the measuring stick existed would produce paperwork, not safety. The Cloud Security Alliance's August 2026 research note captures the right framing in its title: the deadline is deferred, not canceled.
Does the EU AI Act Apply to US Companies?
Yes, and this is the point most US teams underestimate. The Act's scope is extraterritorial. It covers providers and deployers, regardless of where they are established, whenever an AI system is placed on the EU market, or its output is used in the EU. A US SaaS product with European users, a customer-service chatbot that serves EU visitors, or a screening model whose results are used by a European subsidiary can each bring a company inside the regulation without a single EU office.
The penalty structure makes the scope question worth taking seriously. Violations of the prohibited practices rules carry fines up to 35 million euros or 7% of global annual turnover, whichever is higher. Most other violations, including the transparency obligations that just took effect, carry fines up to 15 million euros or 3% of global turnover. For a mid-size US company, 3% of worldwide revenue is not a European line item. It is a board-level risk.
Which Obligations Are Live Right Now?
The Omnibus moved the high-risk regime, but it left a full stack of obligations in force. Four matters most to US companies.
Prohibited practices, enforceable since February 2, 2025. Social scoring, manipulative techniques that cause harm, and certain biometric applications are banned outright. The Omnibus added two new prohibitions on AI systems that generate non-consensual intimate imagery or child sexual abuse material, with a transition period for technical safeguards running to December 2, 2026. These carry the top fine tier.
General-purpose AI obligations, enforceable since August 2, 2025. Providers of general-purpose models must meet transparency requirements, maintain a copyright policy, and publish summaries of training data. If your product wraps or fine-tunes a foundation model for EU users, this layer already touches you.
Article 50 transparency, in force since August 2, 2026. This is the new one. People must be informed when they are interacting with an AI system; deepfakes must be disclosed; and synthetic audio, image, video, and text must be marked in a machine-readable format. New systems must comply immediately. Systems already on the market before August 2, 2026, have until December 2, 2026, to implement machine-readable marking.
AI literacy, in effect since February 2, 2025. Organizations must support AI training for staff who operate AI systems. The Omnibus softened this obligation to supporting training rather than guaranteeing individual competence levels, but it did not remove it.
What Got Delayed, and Until When?
Standalone high-risk systems under Annex III now comply by December 2, 2027. This is the category most enterprise deployments fall into: AI used in recruitment and hiring, credit and insurance decisions, education, essential services, and critical infrastructure. The full obligation set, risk management, data governance, technical documentation, logging, human oversight, and registration, now lands in December 2027.
AI embedded in regulated products under Annex I will now comply by August 2, 2028. Systems built into machinery, medical devices, vehicles, and other products covered by EU sectoral safety law get the longest runway, aligned with their existing certification cycles.
Regulatory sandboxes arrive by August 2, 2027. Each member state must establish at least one national sandbox, providing companies with a supervised environment to test systems against the rules before the high-risk deadline.
Sixteen months sounds generous. Measured against what the high-risk regime demands, it is not. The Cloud Security Alliance's readiness research, citing an appliedAI analysis of 106 enterprise AI systems, found that 40% could not be clearly classified under the Act's risk tiers and estimated initial compliance investments of $ 8 to $ 15 million for large enterprises and $ 2 to $ 5 million for mid-size organizations. Companies that started in 2027 the first time around were the reason a deferral became necessary. The EU is unlikely to blink twice.
How Should US Companies Use the Next Sixteen Months?
Build the AI inventory first. More than half of organizations cannot list the AI systems they run, according to the Cloud Security Alliance. Every downstream compliance task, classification, documentation, and monitoring depends on this list existing and staying current. It is also the same asset that shadow AI audits and cost governance require, so the work pays for itself outside the compliance file.
Classify against the risk tiers, and expect ambiguity. With 40% of systems in the appliedAI sample defying clean classification, borderline calls are the norm, not the exception. Document the reasoning behind each classification now, while the December 2027 date is far enough away to fix what the analysis surfaces.
Close the transparency gap immediately, because it was not deferred. If your chatbot, content generator, or recommendation layer touches EU users, disclosure and machine-readable marking are live obligations today. Systems that were on the market before August 2 have until December 2, 2026, for the marking requirement. That is under four months away, and it is an engineering task, not a policy memo.
Treat compliance as an engineering discipline, not a legal one. Logging, human-oversight mechanisms, documentation pipelines, and bias testing are built, not written. That means the binding constraint is engineering capacity, the same constraint we examined in our guide to AI staffing models. Teams that cannot hire fast enough domestically are increasingly closing the gap with nearshore AI talent working in US time zones.
Fold compliance into the systems you are building anyway. Retrofitting documentation and oversight onto a deployed system costs multiples of building it in. If new AI systems are on your 2026 roadmap, specify the Act's requirements in the build. A development partner that engineers for production, the discipline behind our AI development services, should be delivering audit-ready logging and documentation as standard output, and the spend belongs in the same portfolio view you use to track where AI returns actually land.
Common Questions About the EU AI Act
Is the EU AI Act delayed?
Partially. The Digital Omnibus, in force since July 27, 2026, deferred obligations for standalone high-risk systems to December 2, 2027, and for AI embedded in regulated products to August 2, 2028. Prohibited practices, general-purpose AI rules, and the Article 50 transparency obligations that began on August 2, 2026, were not delayed.
Does the EU AI Act apply to US companies with no offices in Europe?
Yes, if their AI reaches the EU. The Act applies to providers and deployers outside the EU whenever an AI system is placed on the EU market, or its output is used inside the EU. A US product with European users falls within scope even without a European legal entity.
What are the penalties for violating the EU AI Act?
Fines for prohibited practices reach 35 million euros or 7% of global annual turnover, whichever is higher. Most other violations, including the transparency obligations now in force, carry fines up to 15 million euros or 3% of global turnover, with reduced caps for small and mid-size enterprises.
What should a US company do first?
Inventory every AI system in use, classify each against the Act's risk tiers, and fix transparency compliance for anything user-facing. More than half of organizations lack that inventory today, and existing systems have only until December 2, 2026, to implement machine-readable marking of AI-generated content.
If your roadmap includes shipping AI to European users and your compliance plan still assumes the old deadlines, the next sixteen months are the cheapest they will ever be. Talk to the Golabs team about building an inventory, closing the transparency gap, and staffing the engineering work the Act actually requires.

