On 2 August 2026 the EU AI Act hit a key date, but the headline is misread. Here is what came into force, what got deferred, and the one question you need to be able to answer.

The EU AI Act Just Passed a Milestone. Here Is What Actually Changed
The short version: on 2 August 2026 the EU AI Act reached one of its biggest dates. Most of the coverage got it wrong. The high-risk obligations everyone spent 2025 preparing for were pushed back to December 2027. What did switch on is enforcement, transparency, and fines. And underneath all of it sits one question you should be able to answer today.
If you run AI in your business, you probably saw a headline this weekend saying the EU AI Act "came into force" or "the big deadline hit." Both are half true, and the half that is wrong is causing people to relax at exactly the wrong moment.
Here is the accurate version.

The original Act made 2 August 2026 the day high-risk obligations became enforceable. Recruitment screening, credit scoring, education, essential services, and the rest of Annex III. Every compliance plan written in 2024 and 2025 was built around that date.
Then the Digital Omnibus happened. The Council gave it final sign-off on 29 June 2026, and it pushed the high-risk dates back. Stand-alone Annex III systems now apply from 2 December 2027. AI built into regulated products under Annex I moves to 2 August 2028.
So the scary part got deferred. That is real, and it is why half the market read the news as "the AI Act is delayed."
It isn't. Three things still landed on schedule.
GPAI enforcement now has teeth. Obligations for general-purpose AI models have technically applied since August 2025, but the Commission could not act on them. From 2 August 2026 the AI Office can investigate, demand documentation, and fine up to 15 million euros or 3% of worldwide turnover, whichever is higher. If you fine-tune or white-label a model and put it on the EU market, check whether that makes you a provider. It might.
Article 50 transparency applies to almost everyone. This is the one that reaches ordinary businesses, and it got a fraction of the attention. If a person is dealing with an AI system, a support chatbot or a voice agent, they have to be told. AI-generated and manipulated content, deepfakes especially, has to be labelled. The human-facing disclosure duty is live now. The machine-readable watermarking part has a short grace period to 2 December 2026 while the standards catch up.
The penalty framework is operative. National authorities can act on the provisions already in force. Enforcement will be patchy for a while, because several member states have not stood up their market-surveillance bodies yet. Do not plan around that gap. A documentation request is cheap for a regulator to send, and it is usually the first move.
Seventeen months of extra runway on high-risk is real. It is also runway for work with long lead times. Documentation packs, fundamental-rights impact assessments, vendor requalification. None of that gets done in a fortnight, and your customers' procurement teams will ask for it long before the regulator does.
Teams that downed tools when the delay was announced are spending their runway standing still.
Strip away the article numbers and the dates, and almost every path through this regulation runs into the same question:
Can you produce an inventory of the AI running in your business, with an owner and a purpose for each one, inside a week?

Most organisations cannot. And it is rarely because they lack a policy. It is because a real share of what is running is invisible to them. Agents wired up by one team last quarter. A model someone fine-tuned for a pilot that quietly went to production. Tools adopted without anyone asking.
That is a discovery problem before it is a legal one. You cannot disclose, govern, or prove anything about an agent you did not know existed.
Read the obligations back through an agent lens and three of them get very practical.
First, you have to know what exists. Article 50 disclosure only works if you can find every customer-facing bot. A documentation request only gets answered if you have a live picture of what is running, including the agents nobody registered.
Then someone has to own each agent. "Who is responsible for this system" is the first thing an inquiry establishes. If the answer is a shrug, the rest of the conversation goes badly.
And you have to be able to prove what an agent did. Not logs that show inputs and outputs, but a tamper-evident account of which agent did what, on whose authority, that you can hand over. When a regulator asks you to show an agent behaved, "we think it was fine" is not an answer.
None of this is unique to the EU AI Act. It is the same discipline that keeps agent costs down and keeps projects out of the failure column. The regulation just turned good practice into something you may have to evidence.
You do not need to solve compliance this week. You need to be able to answer the inventory question, because everything else depends on it.
Start there. Find what is actually running, put an owner on each one, and make sure you can prove what they did. That work is useful whatever the regulator does next, and it is exactly what December 2027 will expect of the high-risk systems anyway.
We wrote up how the EU AI Act lands specifically on AI agents, and how the KPATH platform handles discovery, ownership, and audit, here: EU AI Act and AI agents.
If you would rather just talk it through, we run a free 30-minute session on your agent estate and where the gaps are. No pitch, no prep.
Book a free 30-minute consultation →
KPATH gives enterprises a platform that enforces agent policy, plus a practice that works out what to enforce. We build secure AI with UK research partners, the Artificial Intelligence Collaboration Centre (AICC) and the Centre for Secure Information Technologies (CSIT) at Queen's University Belfast.
Sources: Council of the EU, final approval of the Digital Omnibus (29 June 2026); European Commission AI Act framework; Gibson Dunn client alert on the Omnibus agreement (May 2026); Regulation (EU) 2024/1689. This post is general information, not legal advice. Dates and obligations should be checked against primary sources and your own counsel.
Start with a free 30 minute consultation on your highest-stake decision.