KPATH

The EU AI Act just passed a milestone. Here is what actually changed

On 2 August 2026 the EU AI Act reached one of its biggest dates, and most coverage misread it. The high-risk obligations were pushed back to December 2027. What switched on is enforcement, transparency and fines, and underneath all of it sits one question you should be able to answer today.

The scary part was deferred; enforcement, transparency and fines were not, and all of them run into the same inventory question.

If you run AI in your business, you probably saw a headline this weekend saying the EU AI Act “came into force” or “the big deadline hit”. Both are half true, and the half that is wrong is causing people to relax at exactly the wrong moment.

What moved, and what did not

The original Act made 2 August 2026 the day high-risk obligations became enforceable. Recruitment screening, credit scoring, education, essential services, and the rest of Annex III. Every compliance plan written in 2024 and 2025 was built around that date.

Then the Digital Omnibus happened. The Council gave it final sign-off on 29 June 2026, and it pushed the high-risk dates back. Stand-alone Annex III systems now apply from 2 December 2027. AI built into regulated products under Annex I moves to 2 August 2028.

So the scary part got deferred. That is real, and it is why half the market read the news as “the AI Act is delayed”.

It is not delayed. Three things still landed on schedule.

GPAI enforcement now has teeth. Obligations for general-purpose AI models have technically applied since August 2025, but the Commission could not act on them. From 2 August 2026 the AI Office can investigate, demand documentation, and fine up to 15 million euros or 3% of worldwide turnover, whichever is higher. If you fine-tune or white-label a model and put it on the EU market, check whether that makes you a provider. It might.

Article 50 transparency applies to almost everyone. This is the one that reaches ordinary businesses, and it got a fraction of the attention. If a person is dealing with an AI system, a support chatbot or a voice agent, they have to be told. AI-generated and manipulated content, deepfakes especially, has to be labelled. The human-facing disclosure duty is live now. The machine-readable watermarking part has a short grace period to 2 December 2026 while the standards catch up.

The penalty framework is operative. National authorities can act on the provisions already in force. Enforcement will be patchy for a while, because several member states have not stood up their market-surveillance bodies yet. Do not plan around that gap. A documentation request is cheap for a regulator to send, and it is usually the first move.

Why the deferral is not a reason to wait

Seventeen months of extra runway on high-risk is real. It is also runway for work with long lead times. Documentation packs, fundamental-rights impact assessments, vendor requalification. None of that gets done in a fortnight, and your buyers’ procurement teams will ask for it long before the regulator does.

Teams that downed tools when the delay was announced are spending their runway standing still.

The inventory question

Strip away the article numbers and the dates, and almost every path through this regulation runs into the same question:

Can you produce an inventory of the AI running in your business, with an owner and a purpose for each one, inside a week?

Most organisations cannot. And it is rarely because they lack a policy. It is because a real share of what is running is invisible to them. Agents wired up by one team last quarter. A model someone fine-tuned for a pilot that quietly went to production. Tools adopted without anyone asking.

That is a discovery problem before it is a legal one. You cannot disclose, govern, or prove anything about an agent you did not know existed.

What this actually asks of you

Read the obligations back through an agent lens and three of them get very practical.

First, you have to know what exists. Article 50 disclosure only works if you can find every customer-facing bot. A documentation request only gets answered if you have a live picture of what is running, including the agents nobody registered.

Then someone has to own each agent. “Who is responsible for this system” is the first thing an inquiry establishes. If the answer is a shrug, the rest of the conversation goes badly.

And you have to be able to prove what an agent did. Not logs that show inputs and outputs, but a tamper-evident account of which agent did what, on whose authority, that you can hand over. When a regulator asks you to show an agent behaved, “we think it was fine” is not an answer.

None of this is unique to the EU AI Act. It is the same discipline that keeps agent costs down and keeps projects out of the failure column. The regulation just turned good practice into something you may have to evidence.

Where to start

You do not need to solve compliance this week. You need to be able to answer the inventory question, because everything else depends on it.

Start there. Find what is actually running, put an owner on each one, and make sure you can prove what they did. That work is useful whatever the regulator does next, and it is exactly what December 2027 will expect of the high-risk systems anyway.

Monitor mode is built for the first step: connect the agents you have, enforce no policy, and let the inventory fill in from real calls, including the agents nobody registered. We wrote up how the EU AI Act lands specifically on AI agents, and how KPATH handles discovery, ownership and audit, on the EU AI Act and AI agents page.

The first step

Start in monitor mode. See everything before you enforce anything.

Deploy in monitor mode: observe only, enforce no policy, rewrite no agents. Flip to enforce by repointing egress. See the agents already running in your estate before you decide what to enforce.

Book a monitor-mode pilot See the platform