The EU AI Act: What Actually Applies Since August 2026, and What Was Postponed0%
    Back to blog
    AI & Innovation·8 Sep 2026

    The EU AI Act: What Actually Applies Since August 2026, and What Was Postponed

    By Helion Cloud Team

    The Digital Omnibus pushed high-risk obligations to December 2027. Three obligations did take effect in August 2026, penalties included.

    Share

    If you have been following the AI Act timeline, you probably had 2 August 2026 marked as the moment everything changed. That is no longer quite true: a text adopted this summer pushed the heaviest obligations back by more than a year. But reading that as nothing happening would be a mistake, because part of the regulation did come into force, and the penalty regime is now active.

    01

    What the Digital Omnibus moved

    The original timeline made 2 August 2026 the application date for obligations on high-risk AI systems. The package known as the Digital Omnibus changed that deadline: obligations for the standalone systems listed in Annex III, which cover things like CV screening, school admissions, creditworthiness assessment and migration management, will apply on 2 December 2027. Those for AI embedded in already-regulated products such as medical devices, toys or machinery are set for 2 August 2028. The postponement was justified by delays in harmonised technical standards and Commission guidelines, without which companies had no enforceable reference framework to comply against.
    02

    Transparency obligations did come into force

    This is the part many companies missed. Since August 2026, a website, customer service desk or public body using a conversational agent must tell the user they are talking to an AI. Content generated or modified by an AI system must carry technical marking that identifies its artificial origin, whether through embedded metadata, provenance information or watermarking. And synthetic content depicting real people or events must be flagged visibly, so the audience clearly understands it is not watching an authentic scene.
    03

    The penalty regime is live

    This is what changes the nature of the subject. Breaching transparency obligations can be penalised up to 15 million euros or 3% of worldwide turnover, whichever is higher. Using a practice prohibited by the regulation exposes you to 35 million euros or 7% of annual turnover. The European Commission has also gained direct supervisory power over providers of large models, including the ability to request information from them and to impose sanctions.
    04

    The cheapest obligation is also the most overlooked

    Since 2 February 2025, a company deploying AI systems must be able to demonstrate that its teams have been made aware of the capabilities, limits and risks of those tools. This obligation requires neither an external audit nor certification: a documented awareness session, an internal framing note and a record of who was trained are enough to establish compliance. It is probably the best ratio between effort required and risk covered, and yet it is the line we most often find missing.
    05

    What this means if you are deploying Copilot

    Deploying Microsoft 365 Copilot does not make you the operator of a high-risk system, so the December 2027 postponement probably does not concern you. What does concern you already applies: user awareness, transparency if you expose a conversational agent to your customers, and marking the content you publish after generation. On top of that sits a common-sense requirement the regulation makes worth documenting: knowing which AI uses actually exist inside the company, including the ones nobody approved.
    06

    Beware of timelines that have not been updated

    The postponement is recent, and several reference pages, including institutional ones, still show the old timeline with 2 August 2026 as the application date for high-risk obligations. If you build a compliance plan or settle a budget on that basis, you risk provisioning in 2026 for work that is only due in 2027 or, worse, assuming everything has been deferred when transparency and penalties are in fact in force. Check when your sources were last updated before deciding.

    Summary

    The AI Act did not become harmless the day its main deadline moved: it simply separated what is immediately enforceable from what will wait until 2027. For an SME or mid-market company deploying Copilot or agents, the useful work today comes down to three things: inventory the real AI uses, document team awareness, and check the transparency of any interface exposed externally. Helion Cloud can run that inventory with you and attach it to your existing Microsoft 365 governance.

    Need support

    Our team of experts based in Lille supports companies across France, Belgium and Europe. Available Monday to Friday.