The EU AI Act is the first comprehensive law on artificial intelligence, and it reaches well beyond Europe. It applies to any organisation that places an AI system on the EU market or whose AI output is used in the EU, wherever that organisation is based. For a US software vendor, an Indian services firm or a Gulf bank with European customers, it is already a live obligation.
This summer the EU amended the Act through its Digital Omnibus. The rules for high-risk AI systems, originally due on 2 August 2026, now apply from 2 December 2027, and from 2 August 2028 for AI built into regulated products. Many boards heard "the AI Act has been delayed". That is only half right. The bans on prohibited practices and the rules for general-purpose AI models already apply. Most transparency duties started on 2 August 2026, as planned.
How the AI Act rolls out
Dates on which obligations apply, after the 2026 Digital Omnibus amendments
The fines are set as a share of worldwide revenue
Like the GDPR, the AI Act sets penalties against total worldwide turnover, not EU revenue alone. The top tier is €35 million or 7 per cent of global turnover, whichever is higher. For a company with US$2 billion in annual revenue, 7 per cent is about US$140 million. For small and medium-sized firms the lower of the two amounts applies.
Maximum fine by type of breach
Share of total worldwide annual turnover, or the fixed euro amount if higher
Use the extra sixteen months well
The delay gives more time. It does not make the work any easier. The hard part of compliance is not the documentation template. It is finding every AI system the organisation uses, including the ones inside vendor software. After that, each one has to be classified against the Act's risk categories, with a named owner who can answer for it.
- Build the inventory now. List every AI system you build, buy or embed, with the business process it touches and the markets it reaches.
- Classify before you document. Most systems will not be high-risk. Knowing which ones are tells you where to spend your compliance budget.
- Check your contracts. Obligations fall on providers and on deployers. Make sure your vendor agreements say which party carries each one.
- Plan one programme for several laws. The same data map serves the GDPR and India's data protection law, whose main duties apply from May 2027. It also serves the AI rules emerging elsewhere.
The Omnibus changed the deadline. It did not change what you need to know about your own AI systems.
Sources
- European Commission, AI Act Service Desk: Timeline for implementation of the EU AI Act. ai-act-service-desk.ec.europa.eu
- Regulation (EU) 2024/1689 (the AI Act), Official Journal of the EU. eur-lex.europa.eu
- European Parliamentary Research Service: AI Act implementation timeline. europarl.europa.eu
- DLA Piper: the Digital Omnibus on AI and the deferral of high-risk obligations. knowledge.dlapiper.com