{"id":19545,"date":"2026-07-09T13:50:05","date_gmt":"2026-07-09T11:50:05","guid":{"rendered":"https:\/\/haimagazine.com\/uncategorized\/ai-act-in-stages-deadlines-pushed-back-but-the-regulations-remain\/"},"modified":"2026-07-17T11:28:55","modified_gmt":"2026-07-17T09:28:55","slug":"ai-act-in-stages-deadlines-pushed-back-but-the-regulations-remain","status":"publish","type":"post","link":"https:\/\/haimagazine.com\/en\/hai-premium-2\/ai-act-in-stages-deadlines-pushed-back-but-the-regulations-remain\/","title":{"rendered":"\ud83d\udd12 AI Act in stages. Deadlines pushed back, but the regulations remain"},"content":{"rendered":"<p class=\"wp-block-paragraph\">The EU Council has given final approval to simplifications to the AI Act under the Omnibus VII package. The key change concerns high-risk systems. The new deadlines are December 2, 2027 for stand-alone high-risk systems, and August 2, 2028 for AI systems embedded in regulated products.<\/p><p class=\"wp-block-paragraph\">That doesn\u2019t mean, though, that the AI Act has been put on hold. The regulation took effect on August 1, 2024, but its most important obligations are being phased in. Some took effect in 2025, some are still scheduled for 2026, and some have just been pushed back.<\/p><p class=\"wp-block-paragraph\">Therefore, let&#8217;s sort out where things stand: which provisions are already in force, which will take effect in the coming months, and which the European Union has phased in over a longer period?<\/p><p class=\"wp-block-paragraph\"><strong>What&#8217;s already in effect?<\/strong><\/p><p class=\"wp-block-paragraph\">The first key phase began on February 2, 2025. As of that date, the AI Act&#8217;s definitions, bans on the riskiest applications of AI, and the requirement for so-called AI literacy, meaning competencies related to understanding and using artificial intelligence, took effect.<\/p><p class=\"wp-block-paragraph\">AI literacy sounds technical, but in practice it&#8217;s about something very simple: a company, a public agency or a school that uses AI should make sure the people using these tools understand what they&#8217;re dealing with. It&#8217;s not about a mandatory exam or a certificate. The European Commission explains that organizations should ensure a &#8220;sufficient level&#8221; of knowledge, depending on employees&#8217; roles, the type of system and the risks associated with its use.<\/p><p class=\"wp-block-paragraph\">For example, if a marketing department uses ChatGPT, Copilot or Gemini to create copy, proposals or translations, the company doesn\u2019t need to build a full-blown compliance system right away. However, it should know who\u2019s using these tools and for what, what data they can paste into those tools, what\u2019s off-limits, who reviews the output and how to handle the risk of errors or hallucinations.<\/p><p class=\"wp-block-paragraph\">As of February 2, 2025, bans on AI uses deemed unacceptable also took effect. That\u2019s the highest risk level under the AI Act. This includes, among other things, manipulating people\u2019s behavior, exploiting their age, disability or vulnerable circumstances, social scoring, certain forms of predictive assessment of the risk of committing a crime, mass facial scanning from the internet or CCTV cameras to build facial recognition databases, and emotion recognition systems in the workplace and education.<\/p><p class=\"wp-block-paragraph\">This means, for example, that an employer can&#8217;t just deploy a system that analyzes camera footage or an employee&#8217;s voice to assess their emotions at work. A school can&#8217;t use a similar system to evaluate students&#8217; emotional state in class. Such solutions aren&#8217;t treated as ordinary automation, but as an intrusion into a particularly sensitive area.<\/p><p class=\"wp-block-paragraph\"><strong>What goes into effect as of August 2025?<\/strong><\/p><p class=\"wp-block-paragraph\">The next phase began on August 2, 2025. That\u2019s when the rules for general-purpose AI models, or GPAI (General-Purpose AI), took effect. These aren\u2019t ordinary applications used in a company, but models that can handle many different tasks and become the foundation for many other services. This category includes large language and multimodal models that power chatbots, assistants, search engines and tools for writing, coding, document analysis and image generation.<\/p><p class=\"wp-block-paragraph\">The obligations primarily apply to providers of such models, not to every company that uses an off-the-shelf tool. For a typical company, this means that if you&#8217;re using an off-the-shelf tool based on a large AI model, you should understand whether you&#8217;re just a user or you&#8217;re deploying an AI system in a process that could affect other people&#8217;s rights or life opportunities.<\/p><p class=\"wp-block-paragraph\"><strong>What was supposed to happen on August 2, 2026?<\/strong><\/p><p class=\"wp-block-paragraph\">August 2, 2026 caused the biggest stir. Many companies treated that date as the cutoff after which the AI Act would really start to &#8220;bite&#8221;. It was largely about obligations for high-risk systems.<\/p><p class=\"wp-block-paragraph\">Not every AI tool is a high-risk system. So it\u2019s not about a company using a text generator to draft a LinkedIn post or a meeting summary. The operation of a high-risk system can genuinely affect a person\u2019s health, safety, rights or life opportunities. What matters isn\u2019t just the model itself, but above all the purpose AI is used for.<\/p><p class=\"wp-block-paragraph\">This category includes, among others, systems used in recruitment, education, critical infrastructure, access to public and private services, creditworthiness assessment, migration, border control, law enforcement and the justice system. The Commission cites examples such as systems for filtering job applications, evaluating candidates, assessing learning outcomes, detecting exam fraud, assessing creditworthiness, assessing risk in health and life insurance and certain applications in migration and the justice system.<\/p><p class=\"wp-block-paragraph\">In that case, the system provider would be responsible for risk assessment, data quality, documentation, system resilience, cybersecurity, system activity logging and a human oversight capability. The organization using such a tool, in turn, would need to follow the instructions, monitor its operation, respond to risks and assign a person responsible for oversight. The Commission also notes that the AI Act sets penalties for violations, which depend on the type of obligation and the size of the entity.<\/p><p class=\"wp-block-paragraph\"><strong>What has been postponed?<\/strong><\/p><p class=\"wp-block-paragraph\">Following the changes adopted under Omnibus VII, the obligations for standalone high-risk systems are set to take effect on December 2, 2027. That includes, among other things, systems used in biometrics, critical infrastructure, education, employment, migration, asylum and border control.<\/p><p class=\"wp-block-paragraph\">The deadline has been pushed back even further for AI systems built into products covered by sector-specific safety and market surveillance regulations. Here, the new date is August 2, 2028. This includes AI in products like elevators, toys, machinery and other devices regulated by separate EU rules.<\/p><p class=\"wp-block-paragraph\">That&#8217;s an important distinction. You need to treat a standalone AI system used in hiring differently from an AI feature in a product that already falls under separate safety regulations. The EU is trying to limit regulatory overlap here\u2014that is, situations where a company has to meet similar obligations multiple times, in different procedures and before different authorities. The Council of the EU notes that the new rules are meant to help resolve conflicts between the AI Act and sector-specific regulations, for example in the areas of medical devices, toys, elevators or watercraft.<\/p><p class=\"wp-block-paragraph\"><a>Not everything has been pushed back, though. August 2, 2026 still remains an important date in the AI Act calendar, but not <\/a>because that&#8217;s when all the obligations take effect. From that date, further rules will start to apply, especially around transparency: telling users they&#8217;re talking to AI, labeling deepfakes and certain content generated or manipulated by AI.<\/p><p class=\"wp-block-paragraph\"><a>Separately, a new ban is being introduced on so\u2011called nudifier apps\u2014systems that enable the generation of content<\/a> of a sexual nature. This isn\u2019t a postponement, but a strengthening of the AI Act. The Council of the EU indicates that systems that generate nude images of real people or &#8220;strip clothes off&#8221; photos are set to be banned as soon as December 2026.<\/p><p class=\"wp-block-paragraph\">The deadline for the so-called regulatory sandboxes for AI has also been pushed back. These are controlled environments where companies can test AI solutions under a regulator&#8217;s supervision. Member States have until August 2, 2027 to set them up.<\/p><p class=\"wp-block-paragraph\"><strong>Why is the EU pushing back deadlines?<\/strong><\/p><p class=\"wp-block-paragraph\">The official rationale is pragmatic: it\u2019s hard for companies to meet complex obligations when standards, implementation tools and clear guidelines are missing. The European Commission has presented the Digital Omnibus as a digital simplification package designed to cut administrative burdens, facilitate innovation and help companies operate in a more predictable environment. According to the Commission, the entire package could save companies up to \u20ac5 billion in administrative costs by 2029.<\/p><p class=\"wp-block-paragraph\">The Commission also notes that the European standardization organizations CEN and CENELEC didn\u2019t deliver standards for high-risk requirements by the originally planned deadline. Standards are voluntary, but they\u2019re crucial for legal certainty: they help companies understand exactly what they need to do, and supervisory authorities what to check.<\/p><p class=\"wp-block-paragraph\">In other words: you can enact a requirement, but if a company doesn&#8217;t know exactly how to meet it and the regulator doesn&#8217;t have clear tools to assess it, there&#8217;s a risk of ostensible compliance. On paper, everyone&#8217;s getting ready. In practice, everyone interprets the regulations in their own way.<\/p><p class=\"wp-block-paragraph\"><strong>Business: doing well, but not well enough<\/strong><\/p><p class=\"wp-block-paragraph\">Organizations representing industry and the digital sector welcomed the postponement as a necessary but insufficient move. The leading voice on this side is DIGITALEUROPE, the European digital industry association representing more than 56,000 companies operating and investing in Europe.<\/p><p class=\"wp-block-paragraph\">This organization argued there\u2019s an urgent need to delay obligations for high-risk systems, because the standards won\u2019t be ready, enforcement frameworks are incomplete and companies can\u2019t meet the requirements with those elements still missing. At the same time, it warned that simply pushing back the deadline won\u2019t solve the AI Act\u2019s deeper problems.<\/p><p class=\"wp-block-paragraph\">From a business standpoint, the interplay between the AI Act and other regulations is especially important. This concerns, for example, machine manufacturers, medical companies, providers of industrial software, and products covered by sector-specific safety regulations. If a product is already subject to detailed standards and also includes an AI component, the question becomes: which regulations apply, who\u2019s responsible for the conformity assessment, and whether the company has to go through a similar procedure multiple times.<\/p><p class=\"wp-block-paragraph\">That&#8217;s precisely why Omnibus VII isn&#8217;t just about dates. It also introduces adjustments to how the AI Act interacts with sector-specific regulations. The European Parliament emphasized, among other things, the need to avoid overlaps with machinery product safety rules, while the Council of the EU pointed to a mechanism that limits duplicated requirements in sectors such as medical devices, toys, elevators and watercraft.<\/p><p class=\"wp-block-paragraph\"><strong>Organizations: this is weakening the law<\/strong><\/p><p class=\"wp-block-paragraph\">On the other side are digital rights organizations that view the Omnibus less as streamlining the timeline and more as weakening the regulation before it&#8217;s had a chance to fully take effect. Among the critics is EDRi (European Digital Rights), a European network of organizations, experts, academics and activists focused on digital rights. Access Now (an international organization defending digital rights), ECNL (European Center for Not-for-Profit Law, which works to protect civic space) and Amnesty International are taking the same position.<\/p><p class=\"wp-block-paragraph\">Their argument is simple: AI systems are already used in workplaces, public services, education, healthcare, migration and the justice system. If the full obligations for high-risk systems are delayed, some of the accountability gets pushed back too. The systems will be running, people will feel their effects, but the full set of safeguards will kick in later.<\/p><p class=\"wp-block-paragraph\">EDRi also warns that a delay isn&#8217;t a neutral administrative move. According to the organization, Omnibus delays key safeguards, weakens transparency and creates a dangerous precedent: if a freshly adopted law can be reopened before its most important obligations take effect, powerful market players get the signal that the implementation phase of the regulation can become a second round of negotiations.<\/p><p class=\"wp-block-paragraph\"><strong>What does this mean for companies&#8230;<\/strong><\/p><p class=\"wp-block-paragraph\">For companies, the key takeaway is simple: pushing back deadlines doesn&#8217;t let you skip preparations. It mainly buys more time for the toughest part of the preparations.<\/p><p class=\"wp-block-paragraph\">A company using AI for basic office, marketing, analytical or creative tasks should get the fundamentals in place now: a list of tools, usage rules, data protection, accountability for the output and a baseline level of employee competency. AI literacy is already a requirement. It doesn&#8217;t require a certificate or a special role in the company, but it does require a sensible approach to how people use AI.<\/p><p class=\"wp-block-paragraph\">Any company that&#8217;s using AI in recruitment, education, customer assessment, finance, health, safety or in processes that affect people&#8217;s rights should treat the extra time as an opportunity to check whether its systems might be classified as high-risk systems. In practice, that means auditing the tools, talking to vendors and reviewing contracts, documentation, input data, oversight methods and error-response procedures.<\/p><p class=\"wp-block-paragraph\"><strong>\u2026 and for customers, employees and citizens?<\/strong><\/p><p class=\"wp-block-paragraph\">For customers, employees and citizens, the situation is more ambiguous. On the one hand, the most extreme uses of AI are already banned. An employee shouldn&#8217;t be subjected to an emotion recognition system in the workplace. A student shouldn&#8217;t be graded by a system analyzing their emotions at school. A user should also gradually get more information about when they&#8217;re interacting with AI or encountering AI-generated content.<\/p><p class=\"wp-block-paragraph\">On the other hand, full safeguards for many high-risk systems won&#8217;t arrive until later. That means someone evaluated by an AI system in hiring, education, access to services or a public process may, for a while, be living in a world where the technology is already being rolled out, but the whole oversight and accountability regime still isn&#8217;t fully in place.<\/p><p class=\"wp-block-paragraph\"><strong>Common sense or a concession?<\/strong><\/p><p class=\"wp-block-paragraph\">The most honest answer is: both.<\/p><p class=\"wp-block-paragraph\">It\u2019s common sense, because it\u2019s hard to enforce complex obligations without established standards, clear guidelines and effective regulators. But it\u2019s also a concession, because the European Union has acknowledged that its flagship AI regulation was too difficult to implement at the original pace. The AI Act was meant to prove that Europe can set global standards for responsible artificial intelligence. Now it concedes that even the most ambitious law has to contend with practice, costs, standards, market pressure and the pace of technological development.<\/p><p class=\"wp-block-paragraph\">This doesn&#8217;t mean the end of the AI Act. It&#8217;s more like the end of neat narratives about one magic date. August 2, 2026 is still important, but it&#8217;s no longer the only deadline. The AI Act has become a phased regulation: partly in force, partly forthcoming, partly deferred.<\/p>","protected":false},"excerpt":{"rendered":"<p>For months on end, August 2 loomed over companies as a hard deadline: the day after which using AI was set to become much more formalized. The European Union has just let a bit of air out of that balloon, which doesn&#8217;t mean it&#8217;s pulled the plug on the AI Act.<\/p>\n","protected":false},"author":465,"featured_media":19405,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"rank_math_lock_modified_date":false,"footnotes":""},"categories":[796,805],"tags":[],"popular":[],"difficulty-level":[],"ppma_author":[892],"class_list":["post-19545","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-hai-premium-2","category-law-and-ethics"],"acf":[],"authors":[{"term_id":892,"user_id":465,"is_guest":0,"slug":"kmironczuk","display_name":"Krzysztof Miro\u0144czuk","avatar_url":{"url":"https:\/\/haimagazine.com\/wp-content\/uploads\/2025\/10\/awatar-2.png","url2x":"https:\/\/haimagazine.com\/wp-content\/uploads\/2025\/10\/awatar-2.png"},"first_name":"Krzysztof","last_name":"Miro\u0144czuk","user_url":"","job_title":"","description":"Od lat zajmuj\u0119 si\u0119 nowymi technologiami w biznesie, edukacji i codziennym \u017cyciu. W centrum mojej uwagi pozostaje cz\u0142owiek \u2013 i to, by technologia wyr\u00f3wnywa\u0142a szanse, zamiast tworzy\u0107 bariery."}],"_links":{"self":[{"href":"https:\/\/haimagazine.com\/en\/wp-json\/wp\/v2\/posts\/19545","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/haimagazine.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/haimagazine.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/haimagazine.com\/en\/wp-json\/wp\/v2\/users\/465"}],"replies":[{"embeddable":true,"href":"https:\/\/haimagazine.com\/en\/wp-json\/wp\/v2\/comments?post=19545"}],"version-history":[{"count":1,"href":"https:\/\/haimagazine.com\/en\/wp-json\/wp\/v2\/posts\/19545\/revisions"}],"predecessor-version":[{"id":19546,"href":"https:\/\/haimagazine.com\/en\/wp-json\/wp\/v2\/posts\/19545\/revisions\/19546"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/haimagazine.com\/en\/wp-json\/wp\/v2\/media\/19405"}],"wp:attachment":[{"href":"https:\/\/haimagazine.com\/en\/wp-json\/wp\/v2\/media?parent=19545"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/haimagazine.com\/en\/wp-json\/wp\/v2\/categories?post=19545"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/haimagazine.com\/en\/wp-json\/wp\/v2\/tags?post=19545"},{"taxonomy":"popular","embeddable":true,"href":"https:\/\/haimagazine.com\/en\/wp-json\/wp\/v2\/popular?post=19545"},{"taxonomy":"difficulty-level","embeddable":true,"href":"https:\/\/haimagazine.com\/en\/wp-json\/wp\/v2\/difficulty-level?post=19545"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/haimagazine.com\/en\/wp-json\/wp\/v2\/ppma_author?post=19545"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}