The EU's AI Rulebook Went Live on August 2. The Chapter With Teeth Was Quietly Moved to 2027.
Labeling and disclosure duties arrived on August 2. The hiring, credit and policing rules slipped to December 2027. Here is what applies to you now, and what quietly moved.
I have been carrying a date around in my head since the summer of 2024, and repeating it to people who did not ask for it.
August 2, 2026. That was the day Europe's AI rules would stop being a press release and start being a bill you could actually be handed. I said it at dinners. I said it to a friend who builds recruiting software and made the mistake of asking what I was reading. I said it in the smug register of a man who has found a fact he likes — the Europeans are going to make the hiring algorithms show their work, and the rest of us will benefit by accident. I called it the toughest AI law in the world, because everyone did, and I never checked whether anyone official had.
Here is the part I am less pleased about. On July 24, 2026 — nine days before my date — a new regulation appeared in the Official Journal of the European Union and moved the half of the law I actually cared about. I did not read it. I did not know it existed. By the time I went looking, it had already entered into force, six days before the deadline it was rewriting.
The deadline was real. Something genuinely switched on. But the chapter I had been quoting at people for two years — hiring software, credit scoring, police systems — is not in force today. It is scheduled. A scheduled obligation and a live one are not the same object, however similar they look in a headline.
So this piece is my correction, filed publicly: what arrived, what did not, who moved it, and why the people who moved it had a better argument than I wanted them to have.
First, the part that genuinely arrived
Start with what is not in dispute.
The law is Regulation (EU) 2024/1689, published in the Official Journal on July 12, 2024 and known to everyone as the AI Act. The European Commission describes it as the first-ever comprehensive legal framework on AI worldwide — note the word, because I got it wrong for two years. The claim is first, not toughest; "toughest" was how the Act was sold and received, mostly by people like me. The same page records the two dates that matter: it "entered into force on 1 August 2024 and became applicable on 2 August 2026, with some exceptions."
Hold onto that last clause. The exceptions are the whole story.
On August 2, 2026 the Commission's AI Office, together with national authorities, began enforcing the Act. Europe's effort to regulate AI models, as one security trade outlet put it, moved from paper to practice. And the substantive duty that switched on that day is Article 50 — the transparency chapter, which the Commission confirms "applies as from 2 August 2026," binding providers and deployers alike.
What does Article 50 actually require? Three things you will recognize from your own week:
You must be told when you are talking to a machine. Providers of systems that interact directly with people must design them so the individual is "informed that they are interacting with an AI system, unless this is obvious."
Synthetic content must be marked so a machine can spot it. Providers of systems generating synthetic audio, image, video or text must ensure the output is "marked in a machine-readable format" — a watermark for software, not for your eyes.
Deepfakes must be declared to you, not buried in a policy. Deployers must "disclose deepfake content to a natural person upon first exposure at the latest," and the disclosure "should happen in a clear and distinguishable manner."
The law firm Cooley, in a client alert the day after the deadline, counts four scenarios in Article 50, split between provider and deployer duties. Breach them and the ceiling is real money: "fines of up to €15 million or 3% of worldwide annual turnover, whichever is higher."
Be precise about that penalty, though, because the shorthand everyone reached for that week was wrong — mine included. The penalty chapter did not "take effect" on August 2, 2026. Under Article 113 as originally enacted, most of it has applied since August 2, 2025, with a carve-out for the fining power over general-purpose AI models. What changed this month is not that the fines exist. It is that Article 50 finally exists for them to attach to.
One more piece of small print with large consequences, from the same Cooley alert: generative systems already on the market when the deadline hit have until December 2, 2026 to comply with the marking obligation. So if you find no machine-readable label on today's output, that is not necessarily anyone breaking the law. It is a grace window, and it closes in December.
So far, so good. Labeling, disclosure, enforcement powers, a serious number attached. That is a real law doing real work.
Now the half that did not
The amending law has a name, and I would rather you learn it here than in a footnote: the Digital Omnibus on AI, formally Regulation (EU) 2026/1744 of July 8, 2026. It appeared in the Official Journal on July 24, 2026, carrying a recital explaining that it "should enter into force as a matter of urgency on the third day following that of its publication." It did — six days before the deadline it rewrote.
What it moved is written in the regulation itself, in one sentence, in the flat register big changes arrive in. The date of application for the high-risk chapter "is set to 2 December 2027 for AI systems classified as high-risk pursuant to Article 6(2) and Annex III," and "to 2 August 2028 for AI systems classified as high-risk pursuant to Article 6(1) and Annex I." The Commission's own implementation timeline now carries both: Annex III high-risk systems in December 2027, high-risk AI embedded in regulated products in August 2028.
The Register did the arithmetic on the first one: pushing Annex III systems to December 2, 2027 is a 16-month delay from the previous August 2, 2026 deadline, covering "biometrics, critical infrastructure, education, employment, migration, and border control." Let me be exact where the coverage often is not: sixteen months applies to that list. The Annex I regulated-product systems were never due in 2026 — they were due August 2, 2027 as originally written, so their move to 2028 is twelve months, not sixteen. Two delays, two sizes. Anyone telling you "everything slipped sixteen months" is rounding in a flattering direction.
And what exactly is on the moved list? Annex III is where the AI Act keeps the systems that decide things about people. It covers systems used "for the recruitment or selection of natural persons, in particular to place targeted job advertisements, to analyse and filter job applications, and to evaluate candidates." It covers systems used "to evaluate the creditworthiness of natural persons or establish their credit score" — with fraud detection expressly carved out, which is sensible and worth keeping straight. And it covers systems "intended to be used by or on behalf of law enforcement authorities."
Hiring. Credit. Policing. The three places where a wrong output costs a person something they cannot easily get back. Those are the rules that now begin in December 2027 instead of August 2, 2026.
One clarification that gets lost constantly: this delay is not conditional. The Commission's original proposal tied the postponement to the arrival of technical standards — no standards, no start. The co-legislators took that out. The agreed text, as Gibson Dunn puts it, replaced with these fixed dates the conditional trigger mechanism the Commission had proposed. So if you have read that the high-risk rules snap back as soon as standards land, that is no longer how it works. December 2, 2027 is a date on a calendar, and calendars are the part of a statute that can be moved again.
How sixteen months moves under the word "simplification"
Here I have to discipline my own instinct, because the story I wanted to tell was "nobody read it." That story is not supported, so I am not writing it. Four hundred and twenty-three members of the European Parliament voted for this thing. Somebody read it.
What the record does support is more interesting anyway, and it comes from Parliament's own research service. The European Parliamentary Research Service records, in its briefing on the file, that the Commission did not carry out a separate impact assessment, "arguing that the 'amendments put forward in the proposal are technical in nature'." The same briefing notes, drily, that "not all stakeholders agree with this argument," and that under the EU's own better-regulation toolbox an impact assessment is required for proposals expected to have a major impact.
That is the mechanism. Not secrecy — classification. Call a change technical and it travels through a lighter procedure, on a faster clock, with fewer people obliged to defend it in public.
The clock was genuinely fast. The Commission published the proposal on November 19, 2025. Negotiators reached provisional agreement in "the early morning hours" of May 7, 2026 — at 4 am on Thursday, as Euronews put it. Parliament's plenary approved the result on June 16, 2026, with 423 votes in favor, 57 against, and 174 abstentions. The file went to the IMCO and LIBE committees, with Arba Kokalari (EPP, Sweden) and Michael McNamara (Renew Europe, Ireland) as rapporteurs.
Read those numbers again, because the abstentions are the tell. A hundred and seventy-four members declining to say yes or no is not the profile of a technical clean-up. It is the profile of something a lot of people did not want to own.
The Commission put a price on the exercise: the amendments "could save up to €429.5 million in administrative costs per year," of which the timeline change accounts for "between €68 million and €204 million." Keep the "could" and keep the range — these are estimates by the body proposing the change, not measured outcomes.
And then the fact I keep turning over. The same briefing records that CCIA Europe, an industry association whose members it notes include "some of the biggest US technology companies, such as Amazon, Apple, Google, Intel and Meta," proposed "fixed deadlines of 2 December 2027 and 2 August 2028, rather than deadlines that depend on the availability of standards."
Those are the two dates. Both of them — including the choice to make them unconditional rather than standards-triggered.
I want to be careful here: a coincidence of dates is not proof of causation, and lobbying in the open is lobbying done properly — that is what an association is for. But the briefing also records the wider consultation: "several business representatives called for revising the timeline of high-risk rules," while "NGO representatives and citizens contested the need for this revision," and small and medium businesses asked for guidance and simplified compliance "rather than legal changes." One of those constituencies got its proposal enacted verbatim. Draw your own conclusion; I have drawn mine.
The Commission's own framing was sunnier. Executive Vice-President Henna Virkkunen, announcing the deal: "Our businesses and citizens want two things from AI rules. They want to innovate and feel safe. Today's agreement does both."
Not everyone agreed. A coalition of "127 civil society organisations, trade unions and defenders of the public interest" signed an open letter arguing that the Commission "has not gathered the necessary evidence and consulted sufficiently, nor has it conducted the necessary impact assessment." On publication day, the digital rights network EDRi called it a major rollback of EU digital protections. Those are advocacy characterizations, held by named organizations, and I label them as such rather than launder them into narration.
The case for the delay is better than I wanted it to be
Now the uncomfortable part, and the reason I could not write the piece I originally planned.
The delay was not conjured out of nothing. The machinery the high-risk chapter depends on genuinely did not exist. Parliament's briefing describes the consultations as surfacing "critical bottlenecks, including delays in designating national competent authorities and conformity assessment bodies, and the absence of harmonised standards, guidance and compliance tools for high-risk AI requirements," which "created a heavier compliance burden for businesses and public authorities than was initially anticipated."
Translate that. A high-risk obligation is not self-executing. To comply, a company needs a standard telling it what "adequate risk management" concretely means; to be assessed, it needs an accredited body; to be policed, it needs a national regulator that exists. In the summer of 2026, all three were partly missing.
The standards community said so plainly. The AI Standards Hub, hosted by The Alan Turing Institute, wrote that as the deadline approached "it has become clear that the harmonised standards will not be ready in time." CEN and CENELEC — the European bodies actually drafting them — adopted an exceptional package of measures in October 2025, including a small drafting group to finalize six of the most delayed drafts, described in their own words as "an exceptional and temporary measure, designed to help."
The academic read is sharper still. Marta Cantero Gamito, of the University of Tartu and the European University Institute, argues that a standards process "designed for consensus has entered crisis mode" — the original deadline of April 30, 2025 passed with many work items expected only in mid-2026 or later, and accelerating a consensus process by exception means "exceptionality displaces consensus-based legitimacy." That is a criticism of the delay's cause, not a defense of it. But it means the alternative to postponing was not "strong rules on time." It was rules with no ruler, assessed by no assessor, against a standard nobody had finished writing.
And here is the counterweight I would be dishonest to leave out: the very same amendment that postponed also prohibited. The Digital Omnibus added two new prohibitions to Article 5, aimed at AI systems that generate or manipulate realistic non-consensual intimate imagery of identifiable individuals without their consent — including so-called "nudifier" applications — and at child sexual abuse material. Those bans apply from December 2, 2026.
Even the sharpest consumer critic of the package concedes the point. BEUC, the European consumer organization, called the new ban a welcome, albeit long overdue, response — while stating in the same breath that "the most consequential change is the delay of key safeguards, particularly for high-risk AI systems."
Both of those things are true. A law that bans nudifier apps and postpones hiring oversight in one instrument is not a story about villains. It is a story about which deadlines survive contact with a competitiveness argument, and which do not.
There was a second problem: the referee had not shown up either
Suppose the high-risk rules had landed on August 2, 2026 as planned. Who, exactly, would have enforced them?
Member States were required to designate their competent authorities and single points of contact by August 2, 2025. As of March 2026, an EPRS blog post records, the Commission's list comprised eight single contact points, out of 27. That is specifically the single-contact-point count, not a claim that only eight countries have any AI regulator — but it is not reassuring either. A running tracker of national implementation notes bluntly that "many Member States failed to meet the deadline" for establishing both a market surveillance authority and a notifying authority, and its count of states that have designated both is a live figure that moves as governments catch up.
Then there is the structural wrinkle, and I am keeping its hedges exactly where their author put them. Writing in Tech Policy Press, Joana Soares argues that because the Act is not retroactive, pushing back the high-risk rules could leave some of the most sensitive applications permanently outside its oversight — a hiring system placed on the market before December 2, 2027 "may remain outside the AI Act indefinitely."
Could. May. That is a structural risk being argued, not a finding, and reporting it as settled would harden a hedge into a headline. But it reframes the delay: sixteen months is not only sixteen months of waiting. It is also sixteen months of shipping.
BEUC puts the consumer-facing version more modestly: as a result of the change, consumers "may interact with these systems for several more years without the protections that were originally expected to apply from August 2026."
Seoul kept its date and moved the punishment instead
If you want to know whether a deadline can survive an industry that dislikes it, look at Seoul. South Korea ran the same experiment, on a nearly identical clock, and made a different choice about which end of the law to soften.
Korea's statute is the Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust, known locally as the AI Basic Act. The English translation published by Georgetown's Center for Security and Emerging Technology carries both dates in its header: enforced January 22, 2026; enacted January 21, 2025. The commencement date was fixed a full year in advance and did not move. The Future of Privacy Forum, writing well before commencement, recorded that the Act was promulgated on January 21, 2025 "and will take effect on 22 January 2026" — a forward-looking sentence that turned out to be simply correct, which is rarer than it should be. The US International Trade Administration confirms that the Act and its Enforcement Decree took effect on January 22, 2026.
The Stimson Center's Seungmin (Helen) Lee describes it as the world's first official national comprehensive AI legal framework — and, in the same analysis, warns that "numerous implementation challenges remain and raise questions about the Act's ability to achieve its goals," noting that the definition of "high-impact AI systems" "remains unclear." Korea is not a clean success story. Hold both halves.
Now the hinge. Korea's "high-impact AI" category expressly reaches judgments or evaluations with significant impact on individual rights and obligations, "such as employment and loan assessments."
Employment and loan assessments. The two use cases the European Union just moved to December 2027 are, in Korean law, live obligations today. The employment firm Littler reads that definition as one that "may encompass workplace technologies" — resume screening tools, candidate ranking systems, AI-based skills assessments, performance evaluation algorithms and the rest of the HR stack. That is a lawyer's read of scope, hedged as such, not a regulator's list. High-impact providers, Littler adds, "are expected to" implement risk management planning, documentation demonstrating safety and reliability, human oversight and user protection measures. Sound familiar? It is roughly the shape of Annex III compliance, running in one country while it waits in another.
Korea also legislated its own version of Article 50, and did it earlier. Operators of high-impact or generative AI must notify users in advance that AI is being used, and generative AI operators must also include a label indicating that content was machine-produced. The Ministry of Science and ICT implements the regime.
So Korea kept its date and Europe moved its date, and the moral writes itself?
No. And this is where the comparison earns its keep.
Korea did not skip the softening — it moved it to the other end of the law. The Ministry of Science and ICT is running a grace period of at least one year, the trade administration reports, during which administrative fines will generally be deferred. The Seoul firm Shin & Kim puts it most fully: the ministry granted the period "to minimize confusion for businesses and provide sufficient time for preparation," and during it a guidance period applies and fact-finding investigations will be conducted "only in very exceptional circumstances, such as cases involving serious social issues including loss of life or human rights violations."
And the critique of that arrangement is blunt. Writing for the IAPP, Kyoungsic Min — privacy counsel and Asia regional lead at VeraSafe — notes that the maximum administrative fine "is a mere KRW30 million — approximately USD22,500, a nominal sum that further diminishes the regulation's potential," and that the ministry's own official documents state the grace measure is intended to achieve "an effect identical to a regulatory moratorium." In practice, he writes, "companies will face no financial penalties for violations such as failing to notify users they are interacting with AI." (Consumer press reporting at commencement put the same ceiling at about $20,400; exchange rates move, the point does not.)
Nor is the criticism one-sided. From the market end, Sejin Kim and Hodan Omaar at the Information Technology and Innovation Foundation argued before commencement that Korea's blunt regulatory mandates "risk dragging down the strengths of the rest," and that "heavy-handed tools such as labeling requirements, compute thresholds, and process-heavy reporting will waste resources." Both flanks are unhappy, which is often the sign of a law that did something.
So here is the honest comparison, and it is sharper than "Korea has teeth and Europe doesn't."
Europe moved the obligation. Korea moved the punishment. Both are ways of not enforcing a rule in 2026. But they leave different residues, which is why I keep thinking about it. A duty that exists but is not currently fined still exists — it sits in the statute book, a company's lawyers read it, a compliance function gets built around it, and the day the grace period lapses the duty is simply there, unchanged. A duty that does not yet exist gives a builder nothing to build toward and a court nothing to notice, and it can be moved again before it ever arrives.
That is my read, not a finding, and a Korean regulator with no appetite to fine anyone in 2027 would make me look naive. But if I had to choose which softening to live under as a job applicant, I know which one I would pick.
Run the calendar forward
Let me be explicit that what follows is speculation — plausible, I think, but speculation.
It is October 2027. A vendor selling interview software to European employers has a launch date circled, and it is not a coincidence: shipping before December 2, 2027 is now a strategic question, given the argument that systems placed on the market before that date may fall outside the regime. Whether it holds is for lawyers and eventually courts. But you do not need it to hold for it to shape a roadmap. You only need a product manager to have heard it.
Meanwhile the technology has moved underneath the categories. Annex III was drafted in 2024 around software that scores an application — a model that reads a CV and emits a number. By late 2027 the thing rejecting you may not score anything. It may conduct the interview: an agent that asks follow-ups, adapts to your answers, decides when to stop, and writes the summary a manager skims for eleven seconds before agreeing. Under the rules live in Europe today, that agent must tell you it is a machine — genuinely worth having. Under the rules not yet live, it would have to be documented, risk-managed and humanly overseen. Guess which of those the 2027 version of you would rather have.
And then the thing that worries me most, which is not about AI at all. It is about the technique. The joint civil-society analysis signed by EDRi, ARTICLE 19, Access Now, AlgorithmWatch, Amnesty International, Danes je nov dan, ECNL, Lafede-justícia global and Politiscope makes the point precisely: the Omnibus proposals were presented as a technical exercise with a clearly-limited scope but "have become vehicles for substantive political deregulatory changes," and "once this procedural shortcut is normalised, it can be used by any political majority to reopen settled safeguards."
That is the escalation I would actually bet on. Not a dramatic repeal — nobody repeals a flagship law. Just a second omnibus, then a third, each technical, each urgent, each moving one more date. A law can be hollowed one application date at a time without a single headline saying so, because "the date of application is set to" is a sentence no news editor has ever led with.
What the people who watch this for a living are saying
Let me lay the spectrum out plainly, because on this file the disagreement is not left versus right. It is speed versus sequence, and the sides do not line up the way you would expect.
Arguing the delay was necessary: the industry association DIGITALEUROPE and co-signatories asked for it in writing, calling on legislators to "postpone the upcoming AI Act application deadlines" because "Europe must strengthen its digital sovereignty and competitiveness," which "will only be possible if unnecessary regulatory burdens are removed." Parliament's own survey of expert reaction records that "Daniel Schnurr, from the Centre on Regulation in Europe (CERRE), considers the extension of the timeline for high-risk rules to be reasonable."
Arguing it was a rollback dressed as housekeeping: the Civil Liberties Union for Europe called the process, given the pace and the fact that parts of the Act had yet to take effect, a defeat for the rule of law — its characterization, not a finding — while reporting accurately that Parliament adopted the text "by a large majority of 423 votes in favour." EDRi argues the Omnibus "weakens the AI Act before key safeguards have even started to apply," and that the process was "marked by weak evidence, no proper impact assessment, insufficient public-interest consultation, and a rushed timeline." And in the same Parliament briefing that carries Schnurr's view, Joshua Franco, a senior research advisor at Amnesty Tech, warns that the changes leave people with "even less protection against harmful AI systems" by further weakening "the already weak transparency requirements for high risk systems."
Notice that almost nobody there argues the high-risk rules are a bad idea. They argue about whether a rule that cannot yet be complied with is a rule at all — a genuinely hard question, and one I would rather see settled in an impact assessment than at four in the morning.
So what does this actually mean for you?
If you live in the EU, sell into it, or simply want to stop being fooled by "the AI law took effect" headlines, here is the practical residue.
Learn the three dates. December 2, 2026: the marking duty bites for generative systems already on the market, and the two new prohibitions begin. December 2, 2027: the Annex III high-risk rules — hiring, credit, policing — finally apply. August 2, 2028: high-risk AI inside regulated products follows.
Know which right you actually have today. It is a right to know: to be told you are dealing with an AI system, and to have deepfake content disclosed at first exposure. It is not yet a right to human oversight of a decision about your job or your loan. Ask anyway — just expect "not until December 2027."
Do not read a missing label as a human author. Generative systems already on the market have until December 2026 to comply with the marking duty. Until then, absence of evidence is genuinely not evidence of absence.
If you build or buy this software, plan against the fixed dates, not the standards. The delay is unconditional. Waiting for harmonized standards before starting compliance work means starting late, twice.
Check whether your own country has designated a regulator. A rule with no authority behind it is a rule nobody is checking — an unglamorous and effective thing to email a representative about.
When any government says a law "took effect," ask which chapter. That question would have saved me two years of confident nonsense at dinner parties, and it works on every jurisdiction — including my own favorites.
The lesson, as I read it
I got this wrong in a specific and instructive way. I treated a law as an event — a thing that happens on a day — when a law this size is a stack of dates, and the dates are the softest material in the structure. Text is hard to change; amending substance means arguing about substance in public. But "the date of application is set to" can be edited by a regulation that files itself under simplification and enters into force as a matter of urgency six days before the deadline it rewrites.
That is not a European failing. It is how deadlines behave anywhere an industry with a competitiveness argument gets a hearing — and Europe at least published the vote, the abstentions, the consultation split and its own research service's discomfort, which is more than most jurisdictions offer about their own retreats.
So hold both halves. Something real did arrive on August 2, 2026, and Europe deserves credit for shipping a framework this comprehensive at all. And the part I cared about — whether a machine gets to decide your job, your loan, or whether the police take an interest in you — is now a promise about December 2027, made by institutions that have just demonstrated that promises about dates are revisable.
My vote? Stop celebrating entry into force. Start reading application dates. That is where laws are actually won, and quietly given back.
The HAIA Foundation spends its time on the boring half of AI policy — the application dates, the annexes, the amendments that move a duty sixteen months while everyone is watching the launch. If you would rather know what is actually in force than what was announced, subscribe — that is the entire offer, and it is free.





