AI Governance · September 11, 2026 · 4 min de lecture
The EU AI Act Split in Two in August. Almost Nobody Noticed Which Half Applies to Them.
On August 2, the EU AI Act's transparency rules went live, while its toughest obligations were quietly delayed to December 2027. Most companies only noticed one half of that story.
A client called us in early September, convinced her company had suddenly become non compliant overnight. She had read that the EU AI Act deadline passed in August and assumed her HR team's resume screening tool now needed a full compliance file, audits, the works. She spent a weekend worried about a fine that, as it turns out, does not apply to her yet. She had the right instinct and the wrong deadline.
What is actually happening: on August 2, 2026, the EU AI Act moved into its next phase, but not the phase most people expected. Article 50, the transparency layer, is now live. Any chatbot, AI agent or avatar that interacts directly with people has to disclose that the user is talking to AI. AI generated or manipulated content that resembles real people, places, objects or events, deepfakes in plain terms, has to carry a machine readable mark. Tools that recognize emotion or sort people by biometric data have to say so too. Fines for ignoring this layer reach 15 million euros or 3 percent of global turnover, whichever is higher, though the Commission notes that proportionality must be considered for SMEs. That reduces the size of a possible fine, not the obligation itself.
What did not happen: the high risk obligations, the ones that matter most for hiring, credit, education and essential services, the ones with the real paperwork, risk management files, human oversight design, bias testing, technical documentation. Those were quietly pushed back in May 2026, as part of what Brussels called the Digital Omnibus package, from August 2026 to December 2, 2027. The official reason was that the technical standards were not ready. The unofficial reading, shared by more than a few digital rights groups, is that industry lobbying bought sixteen months.
The reframe: most companies read one of two headlines this summer, the AI Act is now in force or the AI Act got delayed, and stopped there. Neither headline is complete on its own, and treating either as the whole story leads to the wrong response. If you assume everything is now mandatory, you panic and overspend on compliance work that is not due yet. If you assume the whole law got pushed back, you ignore a transparency requirement that is already enforceable today, and that already covers more of your business than you probably think, your website chatbot, your AI generated ad images, any voice assistant a customer might call.
The part that is live is small and specific. The part that is delayed is large and structural. Confusing which is which is the actual risk here, not the regulation itself.
Practical implications for an SME or leadership team.
First, check disclosure, not compliance. If your company runs a chatbot facing customers, a voice assistant, or generates marketing images or video with AI, the question this week is simple, does the person on the other end know they are talking to, or looking at, something AI made. That is not a legal audit. It is thirty minutes with your marketing and support teams.
Second, do not confuse delayed with cancelled. If AI touches hiring, credit decisions, or another consequential process in your business, the high risk clock is still running. December 2027 sounds far away in September 2026. It will not feel far away when you are assembling a risk file the month before the deadline. Documentation, human oversight design and testing take longer to build properly than to rush.
Third, push the question back to your vendors. Most SMEs do not build their own AI tools, they buy them, recruiting software, chatbot platforms, image generators. Ask each vendor directly whether their tool already meets the transparency requirement, and get the answer in writing. Their response, or their silence, tells you more about how seriously they take this than their marketing page does.
Fourth, treat this as a Meaning question before a compliance question. Before building a file for a 2027 deadline, ask why your organization is using AI in each of these processes in the first place. A tool that cannot clearly explain to a regulator why a decision was made usually cannot explain it to a customer either. Fixing that is worth more than the paperwork.
None of this requires panic, and none of it should be ignored either. The companies that will handle December 2027 calmly are the ones treating September 2026 as the start of a sixteen month project, not the ones waiting for a countdown timer.
Try this week
List every AI tool your customers or candidates interact with directly, chatbot, voice assistant, image generator, resume screener. For each one, spend under thirty minutes checking two things, does it disclose that it is AI, and do you actually know what your vendor has done to meet that requirement. If you cannot answer both questions for every tool on the list, you have just found your real starting point, and it took less time than reading this article.
Sources
- European Commission: Safer and more transparent AI
- Al Jazeera: What came into force with the EU's AI Act this week, and what didn't