Home
RiskOnyx

Resources for AI Governance

What the EU AI Act Means in Practice

Why the law matters now, why 2 August 2026 still matters, and why serious planning now stretches into 2027 and 2028

Official EU reference

“The AI Act entered into force on 1 August 2024, and will be fully applicable 2 years later on 2 August 2026, with some exceptions.”

EU AI Act implementation timeline graphic

The short version

The easy mistake is to treat 2 August 2026 as if it were the only date that matters. It is still a critical date because the Commission continues to describe it as the point of full applicability for the AI Act, but it is not the end of the story. The current Commission timeline now makes clear that some obligations arrived earlier, and some high-risk rules have moved later. For business planning, the better approach is to treat the AI Act as a staged implementation programme, not a single deadline.

The law entered into force on 1 August 2024. Prohibited AI practices and AI literacy duties started applying from 2 February 2025. Governance rules and obligations for general-purpose AI models became applicable on 2 August 2025. The broad application point remains 2 August 2026, but the Commission now says certain high-risk Annex III areas will apply from 2 December 2027 and product-integrated high-risk systems will apply from 2 August 2028 following the AI Omnibus political agreement. That sequence matters because it changes how companies should prioritise work.

Why 2 August 2026 still matters

It is still the main anchor date for most organisations. Transparency rules come into effect in August 2026, and many companies will still be judged internally and externally against the question: are we ready when the Act becomes broadly applicable? If your organisation is using AI in customer-facing, workforce, or operational contexts, this is the date procurement teams, legal teams, and governance functions are likely to remember.

But operationally, readiness should not be framed as a single summer-2026 event. The Commission’s own timeline now shows a longer runway into 2027 and 2028 for parts of the high-risk regime. That means companies should build a phased compliance plan. The first phase is understanding scope, system inventory, and governance ownership. The second phase is documentation, evidence, and role clarity. The third phase is deeper readiness for use cases that are likely to land in the higher-risk category or sit inside regulated products.

What “in practice” means

In practice, the AI Act is not asking most companies to become legal theorists. It is pushing them toward operational discipline. A business that does not know which AI systems are in use, who owns them, what the systems are used for, what data they rely on, and what evidence exists is already on the wrong footing. This is why the Act lands operationally before it lands legally. The first pain point is not a regulator. It is internal confusion.

That is also why the AI Act should not be read in isolation. The Act interacts with procurement questionnaires, customer diligence, security reviews, GDPR exposure, governance expectations from boards, and standards work that will shape how companies prove discipline. Businesses do not need to wait for every guideline to be perfect before starting. They need enough structure to stop AI adoption from outpacing governance.


Practical takeaway. If your company is still relying on spreadsheets, email trails, and scattered documentation to explain its AI use, you are not early. You are late.

What companies should do now

First, build a clean inventory of AI systems in use or under development. Second, separate higher-attention use cases from low-risk background tools. Third, assign ownership. Fourth, centralise documentation and evidence. Fifth, prepare for staged compliance rather than a one-date scramble.

This is why 2 August 2026 still matters, but why it should not be oversimplified. It remains the key public milestone for broad applicability. It is also now part of a wider sequence that runs through December 2027 and August 2028. The right management response is not panic and not delay. It is a phased operating plan.

In brief
  • The AI Act is not one deadline. It is a phased implementation timeline.
  • 2 August 2026 remains important, but some high-risk rules now stretch to December 2027 and August 2028.
  • Operational readiness starts with inventory, ownership, documentation, and evidence.
Why companies should care

Because most organisations will feel the pressure through procurement, customer diligence, internal audit, and governance questions before they ever meet a regulator.