Enforcement of the EU AI Act began on August 2, 2026. Most of the requirements organizations spent two years preparing for did not. The distance between those two facts is now a professional skill in itself.
Six days before the date the European compliance community had circled, the law changed. On July 24, 2026, Regulation (EU) 2026/1744, the Digital Omnibus on AI, was published in the Official Journal of the European Union. It amends the AI Act, the Basic Aviation Regulation, and the Machinery Regulation, and it entered into force on July 27, 2026, on the third day after publication rather than the customary twentieth. The Regulation states the reason: with the general application of the AI Act imminent, legal certainty could not wait.
The result is that much of the analysis published between 2024 and mid-2026 now describes a timeline that no longer exists. An AI Act program built around August 2, 2026 was aimed at a target that moved while it was being watched.
What started on August 2
The European Commission’s AI Act Service Desk describes August 2, 2026, as the date on which most of the AI Act’s rules come into force, and enforcement begins for the rules that apply. Three things are worth isolating.
Transparency obligations under Article 50 now apply. Systems that interact directly with people must make clear that a person is dealing with a machine. AI-generated or manipulated content must be marked in a machine-readable format. Deepfakes must be disclosed, as must AI-generated text published to inform the public on matters of public interest where no human review applies. Emotion recognition and biometric categorization systems must inform the people exposed to them.
Enforcement began. National market surveillance authorities and the European Commission may now act on general-purpose AI models, on the prohibitions in Article 5, on the transparency obligations, and on AI literacy. The Digital Omnibus also strengthened the European AI Office, which now holds market surveillance powers, including the power to request information, order corrective action, and impose administrative fines.
Measures in support of innovation began. Sandboxes, real-world testing provisions, and their supporting architecture entered into application, although the deadline for Member States to have a national sandbox operational moved to August 2, 2027.
None of this is minor. Article 99 sets administrative fines of up to EUR 35 million or 7% of total worldwide annual turnover for breaches of the prohibitions, up to EUR 15 million or 3% for most other infringements, and up to EUR 7.5 million or 1% for supplying incorrect, incomplete, or misleading information to an authority.
What did not start
The requirements for high-risk AI systems, set out in Chapter III, Sections 1, 2, and 3, did not enter into application on August 2, 2026. They now apply from:
- December 2, 2027 for AI systems classified as high-risk under Article 6(2) and Annex III, which covers standalone systems in areas such as employment, education, credit, essential services, law enforcement, and migration
- August 2, 2028 for AI systems classified as high-risk under Article 6(1) and Annex I, meaning AI embedded as a safety component in products already covered by Union harmonization legislation
Recital 40 of the Digital Omnibus gives the reasoning plainly. The standards, common specifications, and guidance that providers need were delayed, as were the national competent authorities and conformity assessment structures. Keeping the original date would have raised implementation costs without a corresponding gain in protection.
Two further dates deserve a place in any board paper written this quarter. On December 2, 2026, two new prohibitions enter into application, covering AI systems that generate or manipulate non-consensual intimate material and child sexual abuse material. The same date closes the transitional window for providers of generative AI systems already on the market before August 2, 2026 to meet the machine-readable marking obligation.
The postponement is narrower than the relief suggests
It is tempting to read the Omnibus as a general softening. That reading does not survive contact with the text.
The risk tiers survived. The prohibitions survived, and two were added. The transparency obligations arrived on schedule. Enforcement arrived on schedule. What moved was three sections of one chapter, and it moved because the machinery needed to comply with them was not ready, not because the obligations were judged unnecessary.
The AI literacy obligation in Article 4 illustrates the pattern. It was rewritten rather than removed. Providers and deployers must still take measures to support AI literacy among their staff and among others operating AI systems on their behalf, but the amended text adds that this does not require any organization to guarantee a specific level of AI literacy in any individual. Recital 8 explains the change candidly: a stringent obligation was not suitable for every provider and deployer, and it created a compliance burden, particularly for smaller enterprises. The same recital states that AI literacy should be a strategic priority regardless of regulatory obligations and potential sanctions.
In short, the legislature relaxed the wording of an obligation while explaining, in the same breath, that organizations should treat the underlying capability as a strategic priority anyway.
The asymmetry, and what lives inside it
This produces an unusual regulatory position: supervision is live, but the substantive high-risk requirements are not.
An organization deploying AI in Europe today can be supervised, investigated, and fined in relation to prohibitions, transparency, general-purpose AI, and AI literacy. At the same time, the detailed requirements it will eventually meet for its high-risk systems, covering risk management, data governance, technical documentation, human oversight, accuracy, robustness, and cybersecurity, sit sixteen months away for standalone systems and two years away for embedded ones.
Meanwhile, the Commission’s guidelines on the classification of high-risk AI systems remain in draft. The public consultation closed on July 23, 2026, and formal adoption has not yet followed. Organizations are being asked to determine whether their systems are high-risk against guidance that is still being finalized.
No deadline forces anyone to resolve this in the next twelve months. That is precisely the problem, and precisely the opportunity.
When a deadline drives a program, the program has a shape imposed from outside. When the deadline moves, the shape must come from inside the organization. Someone has to decide which systems get inventoried first, what “high-risk” means in a specific operational context, whether an existing data protection impact assessment can carry part of a future fundamental rights impact assessment, how transparency labeling is implemented across a content supply chain, and what evidence of AI literacy measures would satisfy an authority that asked.
Those are not legal questions, nor engineering ones. They are governance questions, and they will separate the organizations that use the next sixteen months from those that discover in late 2027 that nothing happened.
The next sixteen months should not be treated as a regulatory pause, they are a window to build the people, processes, and evidence that high-risk AI governance will eventually require.
Organizations can use this period to establish an AI system inventory, clarify ownership, develop classification processes, map existing controls against the AI Act, define documentation practices, and train the people responsible for making and defending those decisions.
This requires a combination of regulatory understanding, technical awareness, risk management, documentation, and governance skills. It does not mean everyone needs to become an AI engineer; it means the people responsible for AI governance need to understand enough of each discipline to connect them.
Who answers
Capability does not build itself! Behind every governance process is a person responsible for making it work. Someone who marks the content, classifies the system, maintains the documentation, briefs top management on what changed in July, and ultimately takes the call from the market surveillance authority.
In many organizations, that person does not yet exist as a role. The work is distributed across a data protection officer who did not ask for it, a compliance lead already carrying three regulations, an IT director who understands the system but not the statute, and a general counsel who understands the statute but not the system.
The European Commission’s own response is instructive. In July 2026, it opened a call for expressions of interest to strengthen the enforcement team of the European AI Office in Brussels, estimating approximately 40 contract agent opportunities across 2027 dedicated to enforcing the AI Act. Four profiles were invited: technology specialist, legal officer, operations specialist, and paralegal. Three of the four are not engineering roles.
The regulator has concluded that governing AI is a multidisciplinary job. It requires people who can read a regulation, follow a process, manage a case file, and hold a technical conversation without necessarily being the person who trains the model. That conclusion is not a marketing claim; it is a hiring decision, published in a recruitment document, with a deadline of September 8, 2026.
Where the competence comes from
The skills involved are learnable and increasingly definable. They include reading the AI Act as amended and knowing which provisions apply on which date, classifying systems against Article 6 and Annex III, understanding how transparency obligations operate across a value chain, building an AI governance structure that connects legal requirements to technical implementation, and documenting decisions in a form that would survive scrutiny.
This is what the Certified EU AI Governance Professional program is built to develop and validate. PECB delivers it in a blended format, with an online phase on September 21 to 22, 2026, and an in-person phase on October 5 to 6, 2026, in Rome, connected with PECB Conference 2026. The course is led by Peter Geelen, a governance, risk, and compliance specialist with more than 25 years of experience, and it requires no prior AI knowledge. Participants who pass the exam receive certification and 31 CPDs.
The timing is not a coincidence, but neither is it the point. The point is that the second clock is now running quietly, and the organizations that fare best when it stops will be the ones that used the interval to build a capability rather than wait for a date.
One clock started. One did not. The difference is governance.