AI Act 2026: What Was Delayed and What Wasn’t | Expert Opinion

The AI Act has not been postponed. Only the part that most likely did not apply to your organization has.

Expert Opinion — Cristina Paladeanu, Manager, Audit and Cybersecurity Governance

 

Three days

On 24 July 2026, the EU Digital Omnibus Regulation on AI was published in the Official Journal of the European Union. Three days later, on 27 July 2026, it entered into force. It is the first formal amendment to Regulation (EU) 2024/1689 since its adoption in June 2024.

The market reaction was, broadly speaking, one of relief, followed by an incorrect conclusion: “Everything has been postponed until 2027. We have time.”

Not quite.

Only the provisions applicable to high-risk AI systems have been postponed. In other words, the category that most companies making this assumption are unlikely to fall into, because they are not developing credit-scoring systems, automated CV screening tools, or AI systems for exam evaluation. Instead, they use a chatbot, an AI copilot, a content generator, and three integrations that no one has properly inventoried.

For those organizations, the timeline has not changed.

And 2 August 2026 was a Sunday—two days ago.

 

What Is Already Applicable—and Has Been for Some Time

This is where the first major misconception arises: the AI Act does not “enter into force” on a single date. It entered into force on 1 August 2024 and has been applied in phases, in accordance with Article 113, as amended by the Omnibus Regulation:

Date

What Becomes Applicable

Status

2 February 2025

Article 5 – Prohibited AI Practices
Article 4 – AI Literacy

Applicable for 18 months

2 August 2025

Chapter V – Obligations for General-Purpose AI (GPAI) Models. Governance. Penalty Framework.

Applicable for 12 months

2 August 2026

General applicability. Article 50 – Transparency obligations.

In force now

2 December 2026

Article 50(2) for AI systems already placed on the market. New prohibitions on non-consensual intimate image generation (“nudifiers”) and CSAM content.

3-month grace period

2 December 2027

Obligations for high-risk AI systems under Annex III

Postponed from 2 August 2026

2 August 2028

Obligations for high-risk AI systems integrated into regulated products under Annex I

Postponed from 2 August 2027

Read the table from the bottom up, and you’ll see how the myth was born. Read it from the top down, and you’ll see the real issue: the obligations that have already been in force for a year and a half are precisely the ones that almost no one has documented.

Article 4 requires providers and deployers of AI systems to ensure a sufficient level of AI literacy among their staff and any other individuals operating AI systems on their behalf, taking into account their technical knowledge, experience, education, and the context in which the systems are used. This obligation has been applicable since February 2025.

Now for the nuance that someone will inevitably raise as a counterargument: Article 4 is not explicitly listed in Article 99(4), which sets administrative fines of up to €15 million or 3% of total worldwide annual turnover. Formally, Article 4 does not carry its own dedicated penalty.

That is the weakest possible argument.

The absence of a specific fine does not turn a legal obligation into a recommendation. In any regulatory inspection, certification audit, or post-incident investigation, one of the first questions will be: “What AI training have you provided, and what evidence can you present?”

The lack of training evidence may not be sanctioned directly. Instead, it becomes evidence of a failure to exercise due diligence, supporting other findings of non-compliance.

 

Twist #2: “We’re Just Users”

The most common defensive position in the market is: “We don’t develop AI—we only use it, so the obligations fall on the provider.”

There are three problems with that argument.

First. Article 50(3) and 50(4) apply directly to deployers, not providers. A deployer using an AI system for emotion recognition or biometric categorization must inform the individuals concerned. A deployer using an AI system that generates or manipulates deepfake content must disclose its artificial nature. A deployer publishing AI-generated text to inform the public on matters of public interest must also disclose that the content was generated by AI—with one important exception worth remembering, because it is the only practical way out: the obligation does not apply where the AI-generated content has undergone human review or editorial oversight and a natural or legal person assumes editorial responsibility for its publication. In other words, you either disclose or take responsibility. There is no third option.

Second. Article 25 can turn you into a provider. If you place your name or trademark on an AI system, make a substantial modification to it, or change its intended purpose, you assume the obligations of a provider. An internal AI assistant built on top of a GPAI model, rebranded, equipped with its own system prompt, and connected to company data is precisely the kind of scenario this provision addresses.

Third. Deployers cannot demonstrate a provider’s compliance without verifying it first. And if you have not verified it, liability does not disappear—it is shared.

 

Twist #3: Romania Still Doesn’t Have an Implementing Law. And That Doesn’t Help You.

Under the memorandum adopted by the Romanian Government on 12 March 2026, ANCOM was designated as the proposed national market surveillance authority and the single national point of contact for the AI Act. The ASF and BNR are responsible for high-risk AI systems in the financial sector, the ANSPDCP oversees biometric AI systems used in law enforcement, border management, justice, and democratic processes, while the ADR has been designated as the notifying authority.

The EU deadline for appointing these authorities was 2 August 2025. Romania communicated its designations approximately seven months later, and the national implementing law defining their powers, cooperation mechanisms, and enforcement procedures is still under development. In practice, ANCOM cannot impose penalties until that legislation enters into force.

This is where the temptation begins—and where many organizations make a mistake.

The AI Act is an EU Regulation with direct applicability. Delays in national implementation do not suspend its obligations or exempt companies from compliance. What is delayed is the enforcement mechanism, not the compliance period itself. Once ANCOM becomes fully operational—realistically by the end of 2026 or early 2027—it will assess compliance for a period that began in February 2025. The question will not be “What are you doing today?” It will be “What have you done since then?”—and your answer will need to be supported by dated documentation.

There is another important point to consider. For many of the same AI use cases, other authorities are already empowered to act. The ANSPDCP can enforce compliance under the GDPR (Regulation (EU) 2016/679), while the DNSC has enforcement powers under Emergency Ordinance No. 155/2024 for entities within the scope of NIS2. An incident involving an AI system does not wait for Romania’s AI Act implementing law before triggering, for example, a 24-hour notification obligation.

 

Twist #4: Transparency Is Not Security

Article 50 requires AI-generated content to be labelled in a machine-readable format that can be detected as artificially generated or manipulated, using effective, interoperable, reliable, and robust technical solutions, where technically feasible.

This is a transparency requirement, not a security measure. And that is where one of the least discussed risks lies.

Your contract with an AI provider does not transfer responsibility for the data you submit to its systems. A data leak caused by shadow AI—tools adopted by employees without approval, assessment, or contractual oversight—remains your organization’s security incident, not the provider’s. Prompt injection against an AI agent with write access to internal systems remains an access control issue, not a transparency issue. Likewise, an AI model making decisions based on data you have never classified is fundamentally a data governance problem—one that has existed for decades, merely wrapped in new technology.

The AI Act does not require you to be secure. It requires you to be transparent.

Security remains entirely your responsibility. And for organizations within the scope of NIS2, it is already a separate legal obligation with its own enforcement and penalties.

 

What You Need to Do—In Practice

The ten minimum areas you should address, together with the evidence required for each. If there is no evidence, then from an audit perspective, the control does not exist.

#

Area

What Must Be Implemented

What You Need to Do – Practical Evidence

1

AI Governance

AI usage policy and clearly defined roles and responsibilities

AI policy, approval decision

2

AI Inventory

Record of all AI systems in use

AI Register

3

Use Case Classification

Identification of GPAI systems and potential high-risk AI systems

Assessment / Classification Document

4

AI literacy

Training program for personnel using AI systems

Training plan, materials, attendance records

5

Risk Assessment

Analysis of risks arising from AI use

Risk assessment

6

Data Management Rules

What data can and cannot be entered into AI systems

Policy, internal guidelines

7

Vendor Management

Assessment of AI providers and contractual terms

Due diligence, contracts

8

Transparency

Informing users where required (chatbots, deepfakes, public interest text)

Information notices, procedures

9

Incident management

Handling AI-related incidents

Incident procedure and register

10

Monitoring

Periodic review of AI usage

Internal audits, reports

 

Tips and tricks — what works in practice

  • Do not build a parallel system. If you already have ISO/IEC 27001 implemented, do not create a second set of policies. Extend it. The asset register becomes an AI asset register. The risk assessment gains a new scenario. A.5.19–A.5.23 already cover supplier management and cloud services. A.8.10 and A.8.12 already cover information leakage. An existing ISMS can get you to 60% of the AI Act requirements in three weeks. A new project built from scratch takes three months and produces documents nobody reads.
  • Start the inventory from invoices, not interviews. If you ask departments what AI tools they use, you will get a polite and incomplete list. Extract the list from corporate card expenses, proxy logs, and OAuth-connected applications in your Microsoft 365 or Google Workspace tenant. The difference between the two lists is your shadow AI report.
  • Classify by use case, not by tool. The same GPAI model is a low risk when drafting a marketing email and something entirely different when filtering job candidates. A vendor-based register will never show you that. A process-based register will.
  • Date everything. It is the only advice in this article that costs nothing and will matter the most. The policy approved through a dated decision. Training with a signed attendance list. Risk assessment with version control and review date. Retroactive compliance cannot be reconstructed; it can only be documented on time.
  • Fix the chatbot disclosure this week. It is the cheapest compliance action in the entire regulation: one sentence, clearly and separately displayed, no later than the first interaction, according to Article 50(5). If you do not have it by 2 August, you will be non-compliant with a requirement that can be resolved in twenty minutes of work.
  • Add a transparency clause to supplier contracts. You need the provider to confirm in writing whether and how it marks generated content in accordance with Article 50(2), and to notify you of model changes. Without this clause, your transparency obligation depends on an assumption.
  • Follow the code of practice. Article 50(7) provides that the AI Office encourages and facilitates the development of Union-level codes of practice for the effective implementation of detection and labelling obligations. The Commission has already published guidance and a draft code on transparency. Alignment with this is, in practice, the closest form of presumption of conformity currently available.
  • Do not declare what you cannot support. An inventory stating “we do not use high-risk AI systems” without a classification document behind it is more dangerous than having no inventory at all. Article 99(5) provides for fines of up to EUR 7,500,000 or 1% of annual turnover for providing incorrect, incomplete, or misleading information to authorities.

 

Magnitude

For context, not for dramatization: Article 99(3) — up to EUR 35,000,000 or 7% of total worldwide annual turnover for prohibited practices under Article 5. Article 99(4) — up to EUR 15,000,000 or 3% for other obligations, including transparency obligations under Article 50. Article 99(5) — up to EUR 7,500,000 or 1% for misleading information.

These are figures comparable to GDPR. And, as with GDPR, the first two years were a period when everyone considered the text theoretical.

 

Conclusion

The Omnibus bought sixteen months for high-risk AI systems. It did not buy a single day for AI inventory, training, prohibited practices, governance, or transparency.

The difference between these two categories of obligations is that the first requires consultants, harmonized standards, and conformity assessments. The second requires a spreadsheet, a policy, an attendance list, and five days of serious work.

Two days ago, one of these categories became applicable. The question is whether you have already taken the necessary steps—or whether it would be wise to engage effective consultants.

Related articles