KPATH
ProductConsultancyBlogBook a consultation
KPATH

Helping organisations scale AI with confidence.

Member of NVIDIA Inception

Pages

ProductConsultancyBlogAgentic commerce

Services

Strategic advisoryAI security & governanceAgentic frameworksAutomation & AI readiness

Topics

Shadow AI agent discoveryEU AI Act and AI agents

Connect

LinkedIn

Newsletter

© KPATH AI. 2026.

Terms & conditions·Privacy policy
Home/Blog/Blog Details

The EU AI Act Just Passed a Milestone. Here Is What Actually Changed

On 2 August 2026 the EU AI Act hit a key date, but the headline is misread. Here is what came into force, what got deferred, and the one question you need to be able to answer.

Aug 3, 2026Consulting
The EU AI Act Just Passed a Milestone. Here Is What Actually Changed

The EU AI Act Just Passed a Milestone. Here Is What Actually Changed

The short version: on 2 August 2026 the EU AI Act reached one of its biggest dates. Most of the coverage got it wrong. The high-risk obligations everyone spent 2025 preparing for were pushed back to December 2027. What did switch on is enforcement, transparency, and fines. And underneath all of it sits one question you should be able to answer today.

If you run AI in your business, you probably saw a headline this weekend saying the EU AI Act "came into force" or "the big deadline hit." Both are half true, and the half that is wrong is causing people to relax at exactly the wrong moment.

Here is the accurate version.

What moved, and what did not

AI Act Timeline

The original Act made 2 August 2026 the day high-risk obligations became enforceable. Recruitment screening, credit scoring, education, essential services, and the rest of Annex III. Every compliance plan written in 2024 and 2025 was built around that date.

Then the Digital Omnibus happened. The Council gave it final sign-off on 29 June 2026, and it pushed the high-risk dates back. Stand-alone Annex III systems now apply from 2 December 2027. AI built into regulated products under Annex I moves to 2 August 2028.

So the scary part got deferred. That is real, and it is why half the market read the news as "the AI Act is delayed."

It isn't. Three things still landed on schedule.

GPAI enforcement now has teeth. Obligations for general-purpose AI models have technically applied since August 2025, but the Commission could not act on them. From 2 August 2026 the AI Office can investigate, demand documentation, and fine up to 15 million euros or 3% of worldwide turnover, whichever is higher. If you fine-tune or white-label a model and put it on the EU market, check whether that makes you a provider. It might.

Article 50 transparency applies to almost everyone. This is the one that reaches ordinary businesses, and it got a fraction of the attention. If a person is dealing with an AI system, a support chatbot or a voice agent, they have to be told. AI-generated and manipulated content, deepfakes especially, has to be labelled. The human-facing disclosure duty is live now. The machine-readable watermarking part has a short grace period to 2 December 2026 while the standards catch up.

The penalty framework is operative. National authorities can act on the provisions already in force. Enforcement will be patchy for a while, because several member states have not stood up their market-surveillance bodies yet. Do not plan around that gap. A documentation request is cheap for a regulator to send, and it is usually the first move.

Why the deferral is not a reason to wait

Seventeen months of extra runway on high-risk is real. It is also runway for work with long lead times. Documentation packs, fundamental-rights impact assessments, vendor requalification. None of that gets done in a fortnight, and your customers' procurement teams will ask for it long before the regulator does.

Teams that downed tools when the delay was announced are spending their runway standing still.

The one question that actually matters

Strip away the article numbers and the dates, and almost every path through this regulation runs into the same question:

Can you produce an inventory of the AI running in your business, with an owner and a purpose for each one, inside a week?

AI Act Inventory

Most organisations cannot. And it is rarely because they lack a policy. It is because a real share of what is running is invisible to them. Agents wired up by one team last quarter. A model someone fine-tuned for a pilot that quietly went to production. Tools adopted without anyone asking.

That is a discovery problem before it is a legal one. You cannot disclose, govern, or prove anything about an agent you did not know existed.

What this actually asks of you

Read the obligations back through an agent lens and three of them get very practical.

First, you have to know what exists. Article 50 disclosure only works if you can find every customer-facing bot. A documentation request only gets answered if you have a live picture of what is running, including the agents nobody registered.

Then someone has to own each agent. "Who is responsible for this system" is the first thing an inquiry establishes. If the answer is a shrug, the rest of the conversation goes badly.

And you have to be able to prove what an agent did. Not logs that show inputs and outputs, but a tamper-evident account of which agent did what, on whose authority, that you can hand over. When a regulator asks you to show an agent behaved, "we think it was fine" is not an answer.

None of this is unique to the EU AI Act. It is the same discipline that keeps agent costs down and keeps projects out of the failure column. The regulation just turned good practice into something you may have to evidence.

Where to start

You do not need to solve compliance this week. You need to be able to answer the inventory question, because everything else depends on it.

Start there. Find what is actually running, put an owner on each one, and make sure you can prove what they did. That work is useful whatever the regulator does next, and it is exactly what December 2027 will expect of the high-risk systems anyway.

We wrote up how the EU AI Act lands specifically on AI agents, and how the KPATH platform handles discovery, ownership, and audit, here: EU AI Act and AI agents.

If you would rather just talk it through, we run a free 30-minute session on your agent estate and where the gaps are. No pitch, no prep.

Book a free 30-minute consultation →

KPATH gives enterprises a platform that enforces agent policy, plus a practice that works out what to enforce. We build secure AI with UK research partners, the Artificial Intelligence Collaboration Centre (AICC) and the Centre for Secure Information Technologies (CSIT) at Queen's University Belfast.

Sources: Council of the EU, final approval of the Digital Omnibus (29 June 2026); European Commission AI Act framework; Gibson Dunn client alert on the Omnibus agreement (May 2026); Regulation (EU) 2024/1689. This post is general information, not legal advice. Dates and obligations should be checked against primary sources and your own counsel.

More blogs

MCP Security: What Has Gone Wrong in 2026
Jul 21, 2026

MCP Security: What Has Gone Wrong in 2026

What an AI Agent Control Plane Actually Does
Jul 17, 2026

What an AI Agent Control Plane Actually Does

The Death of the Aggregator: How the Agentic Web Will End the Platform Tax
Feb 7, 2026

The Death of the Aggregator: How the Agentic Web Will End the Platform Tax

Agents are already doing business. Make sure they are doing it with you.

Start with a free 30 minute consultation on your highest-stake decision.

Book a free 30 minute consultation →