EU AI Act deadline: 7 things firms have missed

The EU AI Act deadline of 2 August 2026 passed quietly, because the Digital Omnibus deal on 7 May made most companies believe the whole law had moved to 2027. Only part of it did, since the high-risk rules for Annex III were pushed to 2 December 2027 while Article 50 transparency and EU enforcement over general-purpose AI models started on schedule.12 Customers we spoke with over the summer raised the same seven gaps, and none of them needs a lawyer to close.
Which EU AI Act deadline applies right now?
Council and Parliament reached a provisional Digital Omnibus deal on 7 May 2026, which moved the use-case based high-risk rules to 2 December 2027 and the product rules to 2 August 2028.3 The deal was adopted as Regulation (EU) 2026/1744 on 8 July 2026 and entered into force on 27 July 2026, so the new dates are law and no longer a proposal.4 The official AI Act timeline now shows those dates, which gives a company with AI in hiring, credit or education about fifteen months. That is breathing room, not a pardon.1
Two things never moved, even though most headlines skipped them. Article 50 transparency rules have applied since 2 August 2026, and on the same day EU enforcement concerning general-purpose AI models started.1 The AI Office can now request technical documentation, evaluate models, require corrective measures and issue fines.2 Anthropic and OpenAI sit under that supervision, which raises what your vendors must show you.
Gap 1: believing the whole Act was postponed
Gap one is the easiest to fall into, because the delay was loud and the parts that stayed on schedule were quiet. Three dates matter for a management team: 2 August 2026 for transparency, 2 December 2026 for the new bans and for marking by systems already on the market before August, and 2 December 2027 for Annex III.13 Put them on one slide.
Six more gaps European companies missed this summer
The six below appear in roughly the order we see them, starting with the one that affects the most companies.
Gap 2: no AI literacy training in place
Article 4 has required providers and deployers of AI systems to take measures on the AI literacy of their staff since 2 February 2025, and the Omnibus rewrote the wording without removing the duty.51 A manufacturer with 60 staff rolled Claude out to the whole office, although nobody got more than an email with a login link. The hit rate of their first prompts sat below half, because nobody knew where the line ran between internal text and customer data. A two-hour workshop fixes the basics for most teams, and satori-launch builds the training into a standard package at €560 per user from eight users. All satori. prices are fixed and exclude VAT.
Gap 3: no chatbot disclosure on the website
If you build or brand a support bot, a sales bot on the website or an AI that answers email yourself, you are usually its provider under Article 50(1) and must tell people at the first interaction that they are dealing with an AI system.6 If you buy a finished bot, check that the supplier does it, and label deepfakes yourself under Article 50(4). One online retailer we spoke to ran a chat that introduced itself as a named staff member with no AI label at all, which is exactly the case the rule targets. The fix takes an afternoon, with one line of text in the first message and a clear route to a human. Someone still checks the wording in every language.
Gap 4: no classification despite the extra time
Many companies read the fifteen extra months as a reason to wait, while the point of the delay was time to classify and document properly before fines arrive. Annex III covers AI used for employment and management of workers, credit scoring and access to education, so an HR tool that ranks CVs is likely in scope.7 Plan two to three hours for a first self-assessment that lists each AI system and the decision it touches. The rest can wait.
Gap 5: no inventory of the AI tools actually in use
Most companies believe they know which AI tools their people use, and almost every one of them is wrong once they ask. Marketing drafts in ChatGPT, finance tests an assistant in Excel, and one sales rep pays for a private Claude Pro account because it is quicker than asking IT. None of that is banned, although none of it sits on a list the day an auditor asks which tools handle company data. A table with tool, department, licence type and type of data closes most of the gap in one afternoon.
Gap 6: no DPIA where AI touches personal data
GDPR and the AI Act are two separate laws, and they meet right here in daily use. A DPIA, meaning the impact assessment GDPR Article 35 asks for before high-risk processing, is required at least for systematic and extensive evaluation of people based on automated processing.8 Claude or ChatGPT connected to a CRM or a whole inbox often lands in that category. A colleague pasting in their own notes rarely needs more than a one-page risk note.
Gap 7: the wrong authority in the address book
Every Member State had to designate its market surveillance authorities for the AI Act by 2 August 2025, and where it named several, it must also name a single point of contact.9 The data protection authority that handles your GDPR questions is not automatically that body, so a general AI Act question sent to the wrong office can cost a week. A list of single points of contact sits on the Commission's digital strategy site, and checking it takes five minutes.
What does waiting cost?
Fines for prohibited AI practices reach €35 million or 7 per cent of worldwide annual turnover, and most other breaches reach €15 million or 3 per cent, whichever is higher.10 Small and medium-sized companies get the lower of the two figures instead.10 Even that sum would otherwise have gone to salaries, and a public finding follows it.
None of the seven gaps needs a project lasting months, since most take an afternoon each and several of them feed each other directly. The inventory in gap five is the input for the classification in gap four, which in turn shows where a DPIA is needed under gap six. Three or more open gaps usually justify outside help, priced in what an AI consultant costs.
The short version
The high-risk rules moved to December 2027, while transparency duties and the supervision of model vendors started in August 2026 as planned. Literacy duties have run since February 2025.
Open a blank document, write the seven gap headings above and put one name next to each, then mark every line as done, started or not started. The list takes under twenty minutes, and the count of lines marked not started is the number to bring to your next management meeting.
Sources
Footnotes
-
European Commission (2026). Timeline for the implementation of the EU AI Act. AI Act Service Desk. https://ai-act-service-desk.ec.europa.eu/en/ai-act/timeline/timeline-implementation-eu-ai-act ↩ ↩2 ↩3 ↩4 ↩5
-
European Commission (2026). AI Act, regulatory framework for AI. Shaping Europe's digital future. https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai ↩ ↩2
-
European Parliament (2026). AI Act: deal on simplification measures, ban on nudifier apps. https://www.europarl.europa.eu/news/en/press-room/20260427IPR42011/ai-act-deal-on-simplification-measures-ban-on-nudifier-apps ↩ ↩2
-
European Union (2026). Regulation (EU) 2026/1744 of the European Parliament and of the Council of 8 July 2026 (Digital Omnibus on AI). EUR-Lex. https://eur-lex.europa.eu/eli/reg/2026/1744/oj/eng ↩
-
European Commission (2026). Article 4: AI literacy. AI Act Service Desk. https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-4 ↩
-
European Commission (2026). Article 50: Transparency obligations for providers and deployers of certain AI systems. AI Act Service Desk. https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-50 ↩
-
European Commission (2026). AI Act, high-risk use cases. Shaping Europe's digital future. https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai ↩
-
European Commission (2026). When is a Data Protection Impact Assessment (DPIA) required? https://commission.europa.eu/law/law-topic/data-protection/information-business-and-organisations/obligations/when-data-protection-impact-assessment-dpia-required_en ↩
-
European Commission (2026). Market surveillance authorities under the AI Act. Shaping Europe's digital future. https://digital-strategy.ec.europa.eu/en/policies/market-surveillance-authorities-under-ai-act ↩
-
European Commission (2026). Article 99: Penalties. AI Act Service Desk. https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-99 ↩ ↩2
