Two dates are now circulating in every legal and compliance inbox: August 2, 2026 and December 2, 2027. Both are tied to the EU AI Act. Only one of them should drive your planning — and figuring out which requires understanding exactly what changed on May 7, and what didn’t.
On May 7, 2026, the European Parliament and Council of the EU reached a provisional agreement to overhaul the EU AI Act enforcement timeline as part of a broader Digital Omnibus legislative package. The headline was hard to resist: high-risk AI enforcement delayed by 16 months. For businesses staring down the August 2026 deadline with a half-finished compliance program, it sounded like a reprieve. But the agreement is provisional — not law — and it doesn’t delay everything. If you’re treating this as a clean bill of health, you’re reading it wrong.

What the August 2, 2026 Deadline Required
The EU AI Act (Regulation EU 2024/1689) entered into force on August 1, 2024, with obligations phased in across three years. Several requirements are already active. Bans on prohibited AI practices — government-run social scoring, real-time biometric surveillance in public spaces, AI designed to exploit psychological vulnerabilities — became enforceable on February 2, 2025. Transparency obligations for General-Purpose AI (GPAI) models went live on August 2, 2025. Large language model providers and other foundational model operators have been under active enforcement since that date.
The major wave scheduled for August 2, 2026 targets Annex III high-risk AI systems. This covers AI used in employment decisions (hiring, performance evaluation, termination recommendations), credit scoring, access to education, critical infrastructure management, law enforcement, and migration processing. According to an EU AI Act compliance analysis by VISTA InfoSec, a study of 106 enterprise AI systems found that 18% already qualified as high-risk and 40% had unclear risk classification — with most ambiguity concentrated in employment, critical infrastructure, and law enforcement use cases.
The penalty structure for non-compliance surpasses GDPR. Prohibited AI violations carry fines up to €35 million or 7% of global annual turnover, whichever is higher. Violations of high-risk AI obligations — missing technical documentation, failed conformity assessments, skipping EU database registration — trigger fines up to €15 million or 3% of global turnover, per the EU AI Act penalty framework under Article 99. These aren’t theoretical ceilings. They’re calculated on worldwide revenue — meaning a small EU infraction taxes your entire global operation.
The regulation also reaches well beyond EU borders. If your AI system’s output affects EU residents — a hiring algorithm screening EU applicants, a credit model processing EU customer data, a SaaS product accessible to EU users — you are in scope regardless of where your company is incorporated.
What the May 7 Provisional Agreement Actually Changed
The May 7 agreement would push Annex III high-risk obligations from August 2, 2026 to December 2, 2027 — a 16-month extension — and move obligations for AI embedded in regulated products such as medical devices to August 2, 2028. For organizations deploying AI in employment, education, credit, or law enforcement contexts, that’s meaningful breathing room, if the agreement is finalized.
But the extension has firm limits. Three things are not moving regardless of what the Omnibus delivers.
Prohibited AI is not covered. The bans on unacceptable-risk AI that took effect February 2025 are untouched by this proposal. If your system falls into a prohibited category, no extension helps you.
GPAI obligations are not covered. Transparency requirements for general-purpose AI models, active since August 2025, are not part of the extension. If you deploy LLMs or foundational models to EU markets, that enforcement is already running.
The agreement isn’t law yet. As of late May 2026, it remains a provisional political agreement requiring formal adoption by both the European Parliament and the Council. If the legislative process stalls before the original August 2 date, companies that banked on the extension could find themselves with no time and no coverage.
Two Clocks Are Running — One Is Already Late
The distinction between the legal clock and the customer clock is the part most compliance briefings skip, and it’s the one that matters most right now.
The legal clock is uncertain — August 2026 or December 2027, depending on how the trialogue resolves. The customer clock started moving months ago and isn’t slowing down. EU-based enterprises and globally operating procurement teams are already screening vendors and internal AI tools against EU AI Act requirements. Compliance documentation requests, conformity assessment inquiries, and risk classification questionnaires are appearing in vendor review processes today — not in 2027.
There’s also a grandfathering calculation most organizations haven’t run. The EU AI Act is not retroactive. AI systems already placed on the EU market before the enforcement date may benefit from transition provisions — but systems entering the market after that date must comply from day one. If December 2027 is confirmed and you spend those extra 16 months continuing to deploy non-compliant AI into EU markets, you may exit the grandfathering window just as enforcement begins, while competitors who used that time to comply hold a structural advantage.
The Brussels Effect reinforces this. Companies that built AI compliance programs ahead of enforcement deadlines are already using that readiness as a procurement signal — and enterprise buyers are paying attention.

5 Steps to Take Before Either Deadline
Whether you’re planning for August 2026 or December 2027, the foundational work is identical in its early stages.
1. Build a complete AI system inventory. Map every AI system across every business unit — not just IT-owned tools. HR recruitment platforms, legal contract analysis software, SaaS products with embedded AI co-pilots, and customer-facing scoring models all belong on this list. The VISTA InfoSec study found that most compliance programs fail at this step specifically, before they ever reach policy writing.
2. Classify each system by risk tier. Once the inventory exists, each system needs to be assessed against the EU AI Act’s four tiers: unacceptable (prohibited), high-risk (Annex I or III), limited risk (transparency requirements only), and minimal risk (no specific obligations). Misclassification in either direction creates exposure — over-classifying wastes resources, under-classifying creates legal liability.
3. Audit for shadow AI. Employees across your organization are almost certainly using AI tools that bypassed procurement and compliance review. Organizations that haven’t mapped the unauthorized AI tools spreading quietly across business units are walking into enforcement with an incomplete picture of their own liability. A shadow AI audit — covering browser extensions, individually licensed SaaS tools, and AI-augmented workflow apps — is a non-negotiable prerequisite.
4. Establish a governance framework. For high-risk systems, this means documented risk management procedures, data governance protocols, human oversight mechanisms, and post-market monitoring workflows. Technical documentation required for conformity assessments cannot be assembled retroactively — it must be built into the deployment process from the start. Organizations evaluating purpose-built platforms for AI risk documentation and monitoring can significantly reduce the time to audit-ready.
5. Appoint an EU authorized representative if you’re based outside the EU. Non-EU companies placing high-risk AI on the EU market are required to designate an EU-based authorized representative who can interact with national regulatory authorities. This is a structural legal requirement, not a documentation checkbox — and it takes time to establish correctly.
Which Deadline to Plan Around
The practical answer: plan for the earlier date, use any confirmed extension as bonus runway.
If December 2027 is formally adopted, you’ll have more time to finalize conformity assessments and run post-market surveillance programs. You won’t have wasted anything by starting early — the inventory, classification, and governance infrastructure you build now will be required regardless of which date is binding.
If the extension fails and August 2026 holds, organizations that interpreted “provisional agreement” as “problem solved” will have nothing to show regulators and nothing to show their enterprise customers. The deadline is uncertain. The obligation isn’t.
Is the EU AI Act high-risk AI deadline really delayed to December 2027?
As of late May 2026, the EU has reached a provisional agreement through the Digital Omnibus package that would push Annex III high-risk AI system obligations from August 2, 2026 to December 2, 2027. However, this agreement must still be formally adopted by both the European Parliament and the Council of the EU before it becomes law. If the legislative process stalls before the original August 2 date, the original deadline remains binding. Organizations should treat August 2026 as the working deadline until a formal extension is confirmed.
Does the EU AI Act apply to companies based outside the EU?
Yes. The EU AI Act applies based on where AI outputs are used, not where a company is incorporated. Under Article 2, any provider or deployer whose AI system is placed on the EU market, put into service in the EU, or produces outputs used by EU residents is in scope — regardless of whether the company has a physical presence in Europe. US-based SaaS companies, API providers, and software vendors with EU customers are subject to the same requirements as EU-headquartered organizations.
What are the fines for non-compliance with the EU AI Act?
The EU AI Act uses a three-tier penalty structure under Article 99. Deploying prohibited AI systems carries fines up to €35 million or 7% of global annual turnover, whichever is higher. Violations of high-risk AI system obligations — such as missing conformity assessments or incomplete technical documentation — carry fines up to €15 million or 3% of global turnover. Providing incorrect or misleading information to authorities carries fines up to €7.5 million or 1% of global turnover. These penalties exceed GDPR’s maximums and are calculated on worldwide revenue.
What qualifies as a “high-risk” AI system under the EU AI Act?
High-risk AI systems are defined in Annex I and Annex III of the EU AI Act. Annex III covers AI used in eight specific categories: biometric identification, critical infrastructure management, education and training, employment and worker management, access to essential private and public services, law enforcement, migration and border control, and administration of justice. AI systems used in hiring decisions, credit scoring, medical diagnostics, or real-time risk assessments in these domains are typically classified as high-risk and subject to the most stringent compliance requirements.
What is the first practical step for EU AI Act compliance?
The most critical first step is building a complete AI system inventory across every business unit — not just systems managed by IT. HR teams, legal departments, finance, and customer-facing operations often deploy AI tools independently through SaaS subscriptions or third-party integrations. Without a full inventory, risk classification is impossible. An applied study of 106 enterprise AI systems found that 40% had unclear risk classification, primarily because organizations lacked visibility into where AI was actually operating across their own businesses.