// blog · analysis · policy2026-08-21source: Primary Commission publications and enforcement reporting

The Act that is in force is not the Act being sold

Three weeks of EU AI Act commentary has been describing a regime that does not apply yet, while the regime that does apply gets treated as a footnote. The mistake is not academic — it is where the compliance money is going.

Two sets of obligations became enforceable in the European Union on 2 August 2026: the duties on general-purpose AI models, and the transparency duties. Those are the rules with teeth right now. A great deal of the guidance published since then says something else.

The specific error

The claim circulating in vendor guides and compliance newsletters is that the majority of remaining provisions, high-risk duties included, apply from the August date. They do not. Stand-alone high-risk systems under Annex III were moved to 2 December 2027. High-risk components embedded in regulated products under Annex I go to 2 August 2028. The delay was granted because the harmonised standards were not finished — which is itself worth noticing, because a conformity-assessment regime without standards to assess against is not a regime, it is a deadline.

Why the error is expensive in both directions

A company that believes the wrong date over-builds. It stands up a conformity-assessment programme eighteen months early, against standards that do not exist yet, and will have to redo the work when they do. That is waste, but it is survivable waste.

The costlier version is the one nobody bills for. When high-risk compliance is treated as the main event, transparency becomes a line item inside it — one row on a readiness matrix, owned by whoever owns the matrix. But transparency is the obligation that is live, and it does not live in the legal department. It lives in the product. Whether a chatbot discloses that it is a chatbot is a UI decision. Whether generated media carries a label is a pipeline decision. Both are made by engineers who are not reading conformity-assessment documentation.

The next date that is real

The prohibitions on certain content and practices are a separate track with a separate clock, and December is the one worth putting in the calendar. It is close, it is not contingent on standards work, and it is the sort of obligation that gets discovered by an enforcement action rather than by an audit.

How to read regulatory coverage from here

Ask three questions of any AI Act summary before acting on it. Which provision, by article rather than by theme. Which date, and whether the writer distinguishes Annex I from Annex III. And whether the guidance was published by someone selling the remediation it recommends. The third question disqualifies more of the current corpus than the first two combined.

The Act is long, staged and genuinely complicated. That is exactly why the summaries get read instead of the text, and exactly why a summary with the dates wrong propagates further than the regulation it describes.

European Commission — Commission starts enforcing AI Act rules and new transparency requirements on 2 August → · European Commission — AI Act — regulatory framework → · Help Net Security — EU begins enforcing AI Act, putting AI models under the microscope →