For two years the EU AI Act was a date on a slide. On 2 August 2026 it became something you can be fined for. That's when the European Commission's supervision and enforcement powers over general-purpose AI (GPAI) providers came into force — the GPAI obligations themselves applied a year earlier, with a twelve-month grace period that has now expired. The penalties are not symbolic: up to €15M or 3% of global turnover for most breaches, rising to €35M or 7% for prohibited practices. If your organisation builds or uses AI, this is now a live compliance question.
What was deferred — and what wasn't
You may have heard the Act was "delayed." That's half true — and the half that matters most to ordinary businesses was not delayed. The Digital Omnibus on AI (Regulation (EU) 2026/1744, now in force) deferred the highest-friction deadlines without reopening the Act's underlying risk framework:
- Deferred. Standalone high-risk systems under Annex III now apply from 2 December 2027; embedded high-risk systems under Annex I (for example, AI inside medical devices regulated under MDR/IVDR) move to 2 August 2028.
- Not deferred. The Article 50 transparency duties, unchanged, applying since 2 August 2026 and enforceable today — alongside the GPAI supervision powers above.
- Newly added. Two further prohibited practices phase in on 2 December 2026.
So if your AI is genuinely high-risk, you have more runway than you may have feared. But if your AI simply talks to people or generates content — which covers most mid-market use — your obligations are live right now, and "it's been postponed" is the wrong conclusion to draw.
"This doesn't apply to us" — two risky assumptions
Two beliefs get mid-market leaders into trouble:
- "We're not an AI company." You don't have to build models to have obligations. Deploying AI — using an AI feature in a product, a vendor tool, or an internal process — carries duties too. Most mid-market firms are deployers, which is lighter than being a provider, but not nothing.
- "We're in the UK, so we're out of scope." The Act is extraterritorial. If the output of your AI system is used in the EU, you can be in scope regardless of where you're based. The UK is pursuing its own lighter-touch, principles-based approach — but for any firm selling into or operating across the EU, the AI Act is fast becoming the de facto standard to design against.
A pragmatic checklist to get oriented
You don't need a legal department to start. You need an inventory and a classification:
- Inventory your AI. List every AI system and feature you build or buy, and what each is used for. You can't govern what you haven't written down — the same first move as any governance programme.
- Classify by risk. The Act is tiered — prohibited, high-risk, limited (transparency), and minimal. Most ordinary business uses fall into limited or minimal, but a few (e.g. AI in hiring, credit, or biometrics) can be high-risk, and you need to know which is which — because the tier now also tells you your deadline: transparency duties are live today, high-risk lands in December 2027.
- Meet transparency obligations. AI that generates synthetic audio, image, video, or text — or that interacts directly with people — generally must disclose that it's AI. Since 2 August 2026 that's an active obligation, not best practice.
- Know your role. Provider (you build or brand the system) and deployer (you use it) carry different duties. Get this right and the obligations become manageable.
- Put the basics in place for higher-risk uses. Human oversight, documentation, and data quality — especially anywhere an AI decision affects a person's rights or livelihood.
If you're running AI agents, this checklist compounds with the operational controls in closing the AI-agent governance gap: the Act asks whether you may use a system and how transparently; agent governance asks how to let it act safely. You need both.
Compliance as a trust asset
The reframe that separates leaders from laggards: this isn't only a cost. A firm that can show it governs AI properly — an inventory, a risk classification, clear transparency — earns trust with customers, insurers, and boards, and answers due-diligence questions its competitors stumble on. It's the same dynamic that turned Cyber Essentials from a checkbox into a procurement door-opener. Governance done early is a differentiator; governance done under an enforcement notice is just expensive.
The bottom line
The EU AI Act is no longer a horizon item — it's enforceable, extraterritorial, and applies to firms that merely use AI. The good news is that getting oriented is tractable: inventory, classify, meet the transparency duties, and know your role. Do it as a trust-building exercise, not a fire drill, and it becomes an advantage. Turning regulation into a board-ready position — tied to the P&L, not just the risk register — is exactly the remit of our Executive Advisory work.
Need to know where your AI use stands against the Act? Let's get you oriented.

