The EU AI Act is the first comprehensive law on artificial intelligence, and it reaches well beyond Europe. It applies to any organisation that places an AI system on the EU market or whose AI output is used in the EU, wherever that organisation is based. For a US software vendor, an Indian services firm or a Gulf bank with European customers, it is already a live obligation.

This summer the EU amended the Act through its Digital Omnibus. The rules for high-risk AI systems, originally due on 2 August 2026, now apply from 2 December 2027, and from 2 August 2028 for AI built into regulated products. Many boards heard "the AI Act has been delayed". That is only half right. The bans on prohibited practices and the rules for general-purpose AI models already apply. Most transparency duties started on 2 August 2026, as planned.

7%Of global annual turnover: the maximum fine for prohibited AI practices
Dec 2027New date for high-risk rules on stand-alone AI systems
Aug 2026Transparency duties and national enforcement began
WorldwideApplies to any firm whose AI reaches the EU market

How the AI Act rolls out

Dates on which obligations apply, after the 2026 Digital Omnibus amendments

2 Feb 2025Prohibited practicesbanned; AI literacy2 Aug 2025General-purposeAI model rules2 Aug 2026Transparency rules;enforcement starts2 Dec 2027High-risk AI(stand-alone systems)2 Aug 2028High-risk AI inregulated products
Sources: European Commission AI Act Service Desk; Regulation (EU) 2024/1689 as amended by the Digital Omnibus on AI (in force 27 July 2026).

The fines are set as a share of worldwide revenue

Like the GDPR, the AI Act sets penalties against total worldwide turnover, not EU revenue alone. The top tier is €35 million or 7 per cent of global turnover, whichever is higher. For a company with US$2 billion in annual revenue, 7 per cent is about US$140 million. For small and medium-sized firms the lower of the two amounts applies.

Maximum fine by type of breach

Share of total worldwide annual turnover, or the fixed euro amount if higher

Prohibited AI practices7%Most other obligations, incl. high-risk3%Incorrect information to authorities1%
Source: Article 99, Regulation (EU) 2024/1689. Fixed caps are €35 million, €15 million and €7.5 million respectively.

Use the extra sixteen months well

The delay gives more time. It does not make the work any easier. The hard part of compliance is not the documentation template. It is finding every AI system the organisation uses, including the ones inside vendor software. After that, each one has to be classified against the Act's risk categories, with a named owner who can answer for it.

  • Build the inventory now. List every AI system you build, buy or embed, with the business process it touches and the markets it reaches.
  • Classify before you document. Most systems will not be high-risk. Knowing which ones are tells you where to spend your compliance budget.
  • Check your contracts. Obligations fall on providers and on deployers. Make sure your vendor agreements say which party carries each one.
  • Plan one programme for several laws. The same data map serves the GDPR and India's data protection law, whose main duties apply from May 2027. It also serves the AI rules emerging elsewhere.
The Omnibus changed the deadline. It did not change what you need to know about your own AI systems.

Sources

  1. European Commission, AI Act Service Desk: Timeline for implementation of the EU AI Act. ai-act-service-desk.ec.europa.eu
  2. Regulation (EU) 2024/1689 (the AI Act), Official Journal of the EU. eur-lex.europa.eu
  3. European Parliamentary Research Service: AI Act implementation timeline. europarl.europa.eu
  4. DLA Piper: the Digital Omnibus on AI and the deferral of high-risk obligations. knowledge.dlapiper.com

← Back to all insights