// blog · analysis · policy2026-08-08source: European Commission guidance and executive order

The date everyone got wrong

A large amount of coverage says the EU AI Act's high-risk obligations began on 2 August 2026. They did not. The difference is sixteen months and an entire compliance programme.

From 2 August the Commission began enforcing prohibited practices, transparency duties and the GPAI rules. Annex III high-risk obligations move to 2 December 2027 under the Omnibus, with product-embedded high-risk following in August 2028.

What actually turned on

Prohibited practices: manipulation, exploitation of vulnerabilities, rights-threatening social scoring, individual predictive policing based solely on profiling. Transparency: systems must disclose that a user is talking to an AI and that content was generated or altered by one. And the general-purpose model obligations, now with a regulator able to act on them.

What did not turn on is the part most compliance programmes were built around — risk management systems, human-oversight design and conformity assessment for Annex III high-risk systems.

Why the error is worth naming

Because it fails in both directions. A team reading the wrong date either believes it is sixteen months late when it is not, or assumes a conformity-assessment obligation exists that no notified body is yet positioned to discharge. Neither produces good decisions.

The extension was granted deliberately, to let harmonised standards mature before the assessment machinery switches on. Treating it as already-in-force wastes the room it was designed to create.

The other regime, same week

The US executive order builds a classified cyber-capability threshold with the NSA Director determining covered frontier model status, a voluntary 30-day pre-release access framework, and an explicit prohibition on any licensing or pre-clearance requirement.

Two regimes, opposite instruments. Europe publishes its obligations, phases them, and lets everyone read the timetable — badly, as it turns out, but publicly. Washington classifies the threshold and forgoes the enforcement power.

Both now depend on measurement they do not control. A government-authored cyber benchmark just leaked a model onto the open internet. A designation regime is only as sound as the harness underneath it, and that harness had a hole in it last week.

European Commission — Commission starts enforcing AI Act rules and new transparency requirements on 2 August → · EU Artificial Intelligence Act — Implementation timeline → · The White House — Promoting Advanced Artificial Intelligence Innovation and Security →