The EU AI Act’s next major milestone officially landed on 2nd August, and businesses operating high-risk AI models are now working to decipher what exactly has, and hasn’t, changed. After months of ongoing negotiations, the so-called “Digital Omnibus” simplification package has reshaped parts of the timeline, but not all of it, leaving organisations with a more specific set of obligations to act on now that the date has passed.
The experts at ISOQAR have been monitoring these developments closely, and below share their insight on what the Act’s update actually means, where AI compliance is heading next, and what businesses can do to stay ahead of the curve.
A timeline that’s shifted, not disappeared
Since the Act came into force in August 2024, its obligations were phased in gradually. This included prohibited practices and AI literacy requirements from February 2025, governance rules and obligations for general-purpose AI (GPAI) models from August 2025, and the bulk of high-risk and AI transparency obligations that were originally due from 2nd August 2026.
Join The European Business Briefing
New subscribers this quarter are entered into a draw to win a Rolex Submariner. Join 40,000+ founders, investors and executives who read EBM every day.
SubscribeFrom there, it was a simple matter of political agreement in May, formal endorsement by the European Parliament in June, and entry into force in late July. After all that, the simplification package has now deferred the compliance deadline for standalone high-risk AI systems to 2nd December 2027, with product-embedded high-risk systems pushed back further still to 2nd August 2028.
For many businesses, this will understandably provide some breathing room, but relaxing compliance efforts altogether will likely cause more harm than good.
What actually landed on 2nd August
It’s important to understand that not everything moved in this latest update. Article 50 transparency obligations, covering chatbot disclosure, the labelling of AI-generated content, and deepfake marking, all took effect as planned on 2nd August 2026 – as did the enforcement powers of the EU AI Office over GPAI models. From this date, the AI Office and national authorities have also gained the ability to request technical documentation, evaluate models, demand corrective action, and even issue fines for non-compliance.
The revised package has also introduced a new prohibition covering the generation of the unauthorised use of a person’s likeness in AI-generated imagery, and has reinstated the requirement for providers claiming exemption from high-risk classification.
What happens next?
Kirsty Wakefield, Information Security Sector Manager at ISOQAR comments: “What we’re looking out for isn’t another deadline, it’s for how the enforcement actually plays out in practice. What is defined as high-risk is still being tested at the edges, and we expect the AI Office’s early cases will do more to shape real-world compliance expectations than the legislation’s text alone. Businesses that wait for a ruling or an enforcement notice to find out where they stand will already be behind. Our advice is to build governance that can flex as interpretation becomes clearer, rather than build something entirely around the rulebook of today.”
How to prepare
Extended timeline aside, organisations should treat this most recent update as a checkpoint, rather than a reprieve, and work to prepare for the future ahead of time.
Classify and document now
Businesses should continue classifying AI systems against criteria laid out in Annex I and Annex III, even where high-risk obligations have been deferred. This is to ensure that conformity assessments (which can take up to 12 months) are not left until there is a new deadline looming.
Prioritise what is currently live
Article 50 transparency duties and GPAI obligations were not delayed and are now in force. Businesses producing content generated by AI or operating public-facing AI interfaces should ensure their disclosure and labelling practices are in place and up to scratch, and addressing any gaps as a top priority.
Review registration status
Businesses that have previously assumed they are exempt from high-risk classification should recheck their position in light of reinstated registration requirements.
Build governance early
Structured frameworks – such as ISO/IEC 42001 – allow businesses to embed AI risk management, oversight and documentation into everyday operations, as opposed to treating compliance as a last-minute exercise ahead of each new deadline.
This latest update to the EU AI Act doesn’t remove pressure on businesses working with high-risk AI systems – it reshapes it. With some obligations deferred and others coming into force from 2nd August, organisations that utilise the time available to strengthen governance – as opposed to pausing it – will be best placed as compliance expectations continue to evolve into 2026 and beyond.




































