
The European regulation on artificial intelligence is no longer a distant prospect. The AI Act has been in effect since August 1, 2024, and its implementation timeline has just been definitively clarified.
On July 27, 2026, Regulation (EU) 2026/1744, known as the Digital Omnibus on AI, entered into force. It postpones the most stringent obligations—those concerning high-risk AI systems—from August 2, 2026, to December 2, 2027. This text is no longer a legislative proposal: it is now European law in force, published in the Official Journal of the European Union on July 24, 2026, following a political agreement between the Parliament and the Council reached in late June 2026.
Yet many organizations continue to view this legislation from a distance, convinced that it does not directly affect them. This is a mistake. The AI Act does not merely regulate technologies; it regulates actors, responsibilities, and roles within a value chain. And within this chain, virtually all companies that use, purchase, deploy, or distribute AI are affected.
Let’s break down what this regulation actually means in practice, beyond the simplified explanations.
The AI Act represents a world first: a comprehensive, structured regulatory framework that applies directly to all AI systems and stakeholders within the European Union. Its ambition goes far beyond technical compliance. The Act seeks to establish the conditions for a more robust, responsible, and sustainable development of AI.
But reducing the AI Act to a checklist of requirements would be a strategic mistake. It challenges us to rethink AI governance within the organization—a governance framework that, when well-designed, becomes a driver of performance and differentiation, not a hindrance.
The level of risk does not depend solely on the technology. It depends above all on how it is used.
Regulation (EU) 2024/1689 provides a precise definition of an AI system in Article 3:
"AI system": an automated system designed to operate at various levels of autonomy and capable of adapting after deployment, which, for explicit or implicit purposes, uses the inputs it receives to determine how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments.
This deliberately broad definition explains why the text applies to a very wide range of tools: from a simple recommendation algorithm to an AI-assisted medical diagnostic system.
Two extension deadlines are often confused: the extension to December 2027 applies to standalone systems listed in Annex III (HR, credit, education), while the extension to August 2028 applies to AI systems integrated into products that are already regulated under other provisions (Annex I). These are not the same thing, nor do they follow the same timeline.
The core of the framework is based on a classification of AI systems according to their potential risk to people’s safety, health, and fundamental rights.

These systems have been outright banned since February 2, 2025. They undermine the fundamental values of the European Union.
Examples include:
Two additional bans will take effect on December 2, 2026, as introduced by the Digital Omnibus: AI systems that generate non-consensual intimate content and AI-generated child pornography.
These systems are not inherently dangerous, but their potential impact on individuals places high demands on them. This is where most companies will need to take action, with a little more time than originally anticipated.
Examples include:
Regulation (EU) 2026/1744 postpones these obligations from August 2, 2026, to December 2, 2027. This postponement is now final and has been published in the Official Journal: it is no longer a parliamentary proposal but applicable law.
However, the postponement does not exempt entities from all obligations: three obligations remain fully enforceable immediately, regardless of the risk level of the system in question:
The postponement to 2027 should not be interpreted as a pause. Four actions remain a priority as of now:
These systems are free to use, but must clearly inform users that they are interacting with an AI. This requirement has been fully in effect since August 2, 2026, with no extension.
Examples include:
Only technical content marking (watermarking, Article 50(2)) is subject to a transition period, which was reduced from six to three months by the Digital Omnibus: systems already on the market before August 2, 2026, must comply by December 2, 2026. The other transparency requirements under Article 50 (informing users that they are interacting with an AI) have been in effect since August 2, 2026.
These systems are not subject to any specific requirements, but the voluntary adoption of best practices is strongly recommended.
Examples: spam filters, content recommendation systems, internal optimization AI that has no direct impact on individuals.
This is one of the most commonly misunderstood points, yet it is essential for determining your actual obligations.
An AI system is an operational application designed for a specific purpose: an automated recruitment tool, a scoring algorithm, or a diagnostic system. It is at the heart of the regulatory framework.
A general-purpose AI (GPAI) model, such as GPT or image-generation models, is a core technology that can be reused in multiple contexts. It is not limited to a single use. The requirements that have applied to such models since August 2025 primarily concern transparency, documentation, and compliance with copyright laws regarding training data.
What this means for you: If your company uses a GPAI model to build an internal or commercial AI system, you are subject to both the obligations related to the model AND those related to the system. The two sets of requirements apply cumulatively.
The AI Act does not treat all stakeholders the same. It identifies five roles, each carrying a different level of responsibility.
One point that is often overlooked: a single company can fulfill multiple roles simultaneously, depending on the systems it uses or sells. A B2B SaaS company that integrates AI into its product acts both as a provider to its customers and as a deployer for its internal use. This dual role creates cumulative obligations.
It is precisely at this stage that a structured governance framework, based on standards such as ISO 42001, helps clarify who is responsible for what under each system used.
The penalties for noncompliance are graded according to the severity of the violation:
This schedule has been in effect since August 2, 2025, regardless of the postponement of high-risk bonds to 2027.
It would be simplistic to view the AI Act solely as a regulatory burden. Organizations that prepare for this transformation reap tangible benefits:
ISO 42001, the first international standard for AI management, serves as a key enabler in this regard. It enables the implementation of this governance framework within a proven structure inspired by best practices in risk management. Our support for ISO 42001 certification helps you implement it effectively.
The AI Act is neither a theoretical document nor a distant concern. It is in effect, its timeline has just been definitively clarified by the Digital Omnibus, and the window of opportunity—though extended through 2027—continues to narrow for companies that have not yet begun to prepare.
The right question is no longer “Are we affected?” Virtually all companies that use AI are affected. The right question is: “What is the actual purpose of our AI systems, and what impacts might they have?”
It all starts with this answer.
👉 Watch the recording of our webinar: How to Secure Your AI Applications from A to Z
Your regulatory obligations are changing. Let’s work together to identify your compliance priorities.
Let's discuss your compliance →