Resources for AI Governance
What the EU AI Act Means in Practice
Why the law matters now, why 2 August 2026 still matters, and why serious planning now stretches into 2027 and 2028
Official EU reference
“The AI Act entered into force on 1 August 2024, and will be fully applicable 2 years later on 2 August 2026, with some exceptions.”
The short version
The easy mistake is to treat 2 August 2026 as if it were the only date that matters.
It is still a critical date because the Commission continues to describe it as the
point of full applicability for the AI Act, but it is not the end of the story. The
current Commission timeline now makes clear that some obligations arrived earlier,
and some high-risk rules have moved later. For business planning, the better
approach is to treat the AI Act as a staged implementation programme, not a single
deadline.
The law entered into force on 1 August 2024. Prohibited AI practices and AI literacy
duties started applying from 2 February 2025. Governance rules and obligations for
general-purpose AI models became applicable on 2 August 2025. The broad application
point remains 2 August 2026, but the Commission now says certain high-risk Annex III
areas will apply from 2 December 2027 and product-integrated high-risk systems will
apply from 2 August 2028 following the AI Omnibus political agreement. That sequence
matters because it changes how companies should prioritise work.
Why 2 August 2026 still matters
It is still the main anchor date for most organisations. Transparency rules come
into effect in August 2026, and many companies will still be judged internally and
externally against the question: are we ready when the Act becomes broadly
applicable? If your organisation is using AI in customer-facing, workforce, or
operational contexts, this is the date procurement teams, legal teams, and
governance functions are likely to remember.
But operationally, readiness should not be framed as a single summer-2026 event. The
Commission’s own timeline now shows a longer runway into 2027 and 2028 for parts of
the high-risk regime. That means companies should build a phased compliance plan.
The first phase is understanding scope, system inventory, and governance ownership.
The second phase is documentation, evidence, and role clarity. The third phase is
deeper readiness for use cases that are likely to land in the higher-risk category
or sit inside regulated products.
What “in practice” means
In practice, the AI Act is not asking most companies to become legal theorists. It
is pushing them toward operational discipline. A business that does not know which
AI systems are in use, who owns them, what the systems are used for, what data they
rely on, and what evidence exists is already on the wrong footing. This is why the
Act lands operationally before it lands legally. The first pain point is not a
regulator. It is internal confusion.
That is also why the AI Act should not be read in isolation. The Act interacts with
procurement questionnaires, customer diligence, security reviews, GDPR exposure,
governance expectations from boards, and standards work that will shape how
companies prove discipline. Businesses do not need to wait for every guideline to be
perfect before starting. They need enough structure to stop AI adoption from
outpacing governance.
Practical takeaway. If your company is still relying on spreadsheets, email trails, and scattered documentation to explain its AI use, you are not early. You are late.
What companies should do now
First, build a clean inventory of AI systems in use or under development. Second, separate higher-attention use cases from low-risk background tools. Third, assign ownership. Fourth, centralise documentation and evidence. Fifth, prepare for staged compliance rather than a one-date scramble.
This is why 2 August 2026 still matters, but why it should not be oversimplified. It remains the key public milestone for broad applicability. It is also now part of a wider sequence that runs through December 2027 and August 2028. The right management response is not panic and not delay. It is a phased operating plan.
In brief
- • The AI Act is not one deadline. It is a phased implementation timeline.
- • 2 August 2026 remains important, but some high-risk rules now stretch to December 2027 and August 2028.
- • Operational readiness starts with inventory, ownership, documentation, and evidence.
Why companies should care
Because most organisations will feel the pressure through procurement, customer diligence, internal audit, and governance questions before they ever meet a regulator.