The AI Act date that started last week is not the high-risk date
From 2 August 2026 the Commission's AI Office and national authorities began enforcing prohibited practices, transparency duties and the GPAI rules. Annex III high-risk obligations were not in that tranche — under the Omnibus they move to 2 December 2027, with product-embedded high-risk following in August 2028. A great deal of secondary coverage says otherwise.
The Commission's own pages are unambiguous about which rules turned on. Prohibited practices — manipulation, vulnerability exploitation, rights-threatening social scoring, purely profiling-based individual predictive policing — are enforceable. So are the transparency rules requiring systems to disclose that a user is talking to an AI and that content was generated or altered by one. So are the GPAI obligations.
What did not turn on is the part most compliance programmes were built around: risk management systems, human-oversight design and conformity assessment for Annex III high-risk systems. That package now applies from 2 December 2027, and high-risk AI embedded in regulated products from 2 August 2028.
The error is worth naming because it is directional. Teams reading the wrong date either believe they are late when they are not, or assume a conformity-assessment obligation exists that no notified body is yet positioned to discharge. Sixteen extra months is real planning room, and it was granted deliberately to let standards mature.
European Commission — Commission starts enforcing AI Act rules and new transparency requirements on 2 August → · European Commission — Guidelines for providers and deployers of high-risk AI systems → · EU Artificial Intelligence Act — Implementation timeline →