Since this summer, two seemingly contradictory headlines about the EU AI Act have been circulating. First: the strictest compliance obligations have been pushed back by more than a year. Second: on August 2, 2026, a new enforcement phase took effect. Both statements are accurate, and the resulting confusion is precisely why many companies are currently doing nothing at all.
I am not an attorney, and this article does not constitute legal advice. It is a practical assessment from someone running AI systems across their own companies who had to answer this exact question firsthand.
First: Does This Even Apply to You?
The AI Act makes a clear distinction between providers who develop an AI system and bring it to market under their own name, and deployers who utilize third-party systems internally. The typical medium-sized enterprise belongs strictly to the second category. You license software, subscribe to a service, or connect to a foundational model via API, and the overwhelming majority of the regulation is not addressed to you.
This is the first evaluation step, not risk classification. Anyone who skips it wastes time unraveling requirements that were never intended for them. However, the distinction flips under specific conditions: if you market a system under your own brand or fundamentally modify and redistribute a third-party tool, you can become classified as a provider. For internal operations, this is not an issue. For a custom assistant offered directly to your clients, it certainly is.
What Actually Came into Force on August 2, 2026
The transparency requirements set out in Article 50 of the EU AI Act. They are the only regulatory change this summer that directly affects everyday business operations, and they are refreshingly tangible.
Anyone deploying a chatbot or conversational voice assistant must ensure users clearly understand they are interacting with an automated system. In most scenarios, a well-placed explanatory note is entirely sufficient. If you generate synthetic media (deepfakes) or publish AI-assisted text on matters of public interest, that content must be labeled. For providers of generative systems, outputs must also carry machine-readable watermarks or markers, a requirement placed on software vendors, not end users.
Simultaneously, administrative enforcement has begun: the European Commission can now impose fines on providers of general-purpose AI models. In Germany, market surveillance is handled by the Federal Network Agency (Bundesnetzagentur), which runs a centralized reporting office. Competitors can also submit complaints there; anyone assuming the issue will resolve itself through inattention underestimates market dynamics.
The effort required for an ordinary business: roughly one afternoon, provided you know where chatbots and assistants are running across the company. In practice, that is precisely the challenging part.
What Was Postponed
On July 27, 2026, the Digital Omnibus Regulation on AI entered into force, Regulation (EU) 2026/1744 of 8 July 2026, amending the AI Act. It substantially postpones the enforcement timeline for high-risk systems: standalone systems under Annex III are deferred to December 2, 2027, while systems embedded into regulated products under Annex I are delayed to August 2, 2028. Both were originally scheduled for August 2026; for Annex III, this grants an additional sixteen months.
Annex III is the list most likely to touch medium-sized businesses. It includes systems used in recruitment, employee evaluation, workforce management, and creditworthiness assessments for individuals. If you employ AI-driven candidate screening, you now have until late 2027 to meet the full compliance criteria.
Furthermore, the Omnibus narrowed the statutory definition of high-risk systems. Tools that merely assist human operators, optimize operational workflows, or check quality are now only deemed high-risk if their failure would pose a genuine threat to health, safety, or fundamental rights. While this excludes numerous everyday applications, it requires a substantive risk assessment rather than simply referencing a static checklist.
Two facts belong to an honest picture. The Omnibus postpones deadlines; it does not eliminate obligations. The substantive core of the law remains intact. Alongside this temporary relief, regulatory oversight was reinforced: the EU AI Office received increased staffing and broader investigative powers, including enforceable on-site inspections.
What Has Applied All Along and Remained Untouched
Amid the excitement surrounding extended deadlines, two critical points are frequently overlooked.
First, the prohibited practices under Article 5 have been in effect since February 2025 and subject to penalties since August 2025. While most are irrelevant for standard businesses, one is not: emotion recognition in the workplace. Anyone considering software that monitors employee sentiment, common in customer support and call centers, must proceed with extreme caution.
Second, the mandate for AI literacy under Article 4 has also applied since February 2025. Staff operating AI systems must possess sufficient competence. The Omnibus softened the wording slightly but did not repeal the requirement. As a result, it remains the only obligation in the regulation affecting virtually every company deploying AI, regardless of risk tier, headcount, or sector. It is also the one requirement that cannot be solved overnight. Deadlines can be waited out; an educated workforce cannot.
Four Actionable Steps I Recommend
First, compile an inventory: identify which AI-powered tools are actually in use across departments, who uses them, and for what purpose. This takes half a day and is routinely the most surprising part of the project, as every organization runs more software than leadership realizes.
Second, determine your role for each application: purchased software or self-hosted and marketed.
Third, ensure chatbots and conversational interfaces carry clear transparency notices. That obligation is active today, not in 2027.
Finally, review the select applications touching HR evaluation or credit checks. You now have adequate breathing room for these, but time is not a pass to ignore the issue; it is an opportunity to structure your processes properly without the pressure of an imminent deadline.
As of August 2026. Regulatory frameworks in this domain evolve rapidly; substantive business decisions should always involve qualified legal counsel.
Sources
- Regulation (EU) 2024/1689 (EU AI Act), consolidated version of 27 July 2026 – EUR-Lex
- Regulation (EU) 2024/1689, Official Journal version – EUR-Lex
- Regulation (EU) 2026/1744 of 8 July 2026 (Digital Omnibus Regulation on AI), in force since 27 July 2026
- Article-by-article readable version of the EU AI Act – ai-act-law.eu
How this article was written: Grounded in the statutory regulatory text in its consolidated version in force since 27 July 2026 and operational evaluations of systems running inside HBC ventures. As of August 2026.
About the Author
Philip Hohn advises medium-sized enterprises on deploying artificial intelligence. He is Managing Director of HBC Hohn Business Consulting UG and runs several of his own companies and projects, including Edura Akademie GmbH, an AZAV-accredited vocational training provider for AI enablement. Previously, he led an agency with 70 employees across four locations as well as a software development firm with fifteen engineers. He is not an attorney; legal observations in his texts do not constitute legal counsel in individual cases.