Skip to main content
All articles
AI Policy and ComplianceAI StrategyEnterprise AI

The EU AI Act Is GDPR 2.0. Most Companies Are Reading the Delay Wrong.

The EU pushed the high-risk deadline to December 2027 and a lot of executives exhaled. That is the mistake. The bans are already live, the transparency rules hit August 2026, and the delay did not touch either one.

Kerrigan Baron (they/them), CTO & Co-Founder12 min read

Informational, not legal advice.

A Dutch town square with civic buildings around its edge, the kind of European institution that writes and enforces rules like the AI Act.

I am a US citizen who lives in the EU, so I have watched this regulation with both perspectives. I want to save the executives reading this, whether your company sits inside the EU or outside it, the mistake I am watching companies make in real time.

You remember GDPR. The cookie banners, the frantic 2018 scramble, and the consultants who showed up two months before the deadline charging a fortune. The AI Act is that story again. For companies outside Europe, the same "wait, this applies to us?" moment is coming. For companies inside it, the same temptation to underestimate how much work this actually is. Except the worst-case fines run much higher, and the thing it regulates sits deeper in your business than a cookie ever did.

Here is the part almost everyone got wrong last month when the EU updated its timeline.

The EU delayed the hardest deadline. The headlines said "AI Act pushed back." A lot of executives I talk to exhaled and moved it down the list. That is the mistake. The delay is not a reprieve, and it did not touch the parts of the Act that are already live.

What actually happened

On June 29, 2026, the EU gave its final sign-off to a package that pushes the deadline for standalone high-risk AI systems from this August out to December 2, 2027. That is a real sixteen-month extension, and for high-risk AI embedded in regulated products it runs further still, to August 2, 2028.

EU AI Act deadline timelineTimeline of EU AI Act deadlines. Bans live since February 2025, transparency August 2026, content labeling December 2026, high-risk December 2027. The high-risk deadline moved from August 2, 2026.Feb 2, 2025The bans. Live.Aug 2, 2026Transparency disclosureDec 2, 2026Content labelingDec 2, 2027High-risk (the one that moved)moved from Aug 2, 2026
The AI Act calendar is four dates, not one. Only the high-risk deadline moved.

The reason for the extension is not a loss of nerve. The technical standards companies need in order to comply, and the bodies that will certify them, were not ready in time, so the EU moved the date to match reality. Henna Virkkunen, the Commission's tech chief, framed the deal as making rules that are "easier to innovate without lowering the bar on safety." The rules did not get softer, the clock just got longer.

easier to innovate without lowering the bar on safety
Henna Virkkunen, Executive Vice-President, European Commission

Now the parts the headlines skipped.

Most of the transparency rules did not move. They took effect on August 2, 2026. That deadline has now passed. If your AI chats with customers, you disclose it is AI, and that clock did not reset. The marking rules for AI-generated content took effect on the same date for anything placed on the market from then on. Only systems already on the market before August 2, 2026 get a transitional period, and that runs out on December 2, 2026.

And the outright bans have been law since February 2, 2025, already live and enforceable, and they carry the largest fine anywhere in the regulation.

So the calendar is not one date. Anyone treating this as a single deadline that got pushed to 2027 is reading one line of a longer story.

Not sure which of these dates apply to you?

Answer a few questions about how your company uses AI and the AI Act risk check will show you which tier each system falls into, and what that tier requires.

The dates that belong in your calendar

What actually triggers a problem

Start with how enforcement begins, because it is more concrete than any fine number. In these early years the usual trigger is a complaint from one person who believes an AI decision harmed them, a rejected job applicant or a denied borrower for example, and that is all it takes to open the door. From August 2026, national authorities can act on the transparency obligations already in force, ask for your documentation, and investigate. The high-risk enforcement machinery ramps up as that tier comes into effect.

Now the numbers, so you can size the ceiling. The Act sets three penalty levels, and they rise with how serious the violation is:

EU AI Act fine tiers next to the GDPR ceilingEU AI Act fine tiers next to GDPR. Bans up to 35 million euros or 7 percent, high-risk and transparency up to 15 million or 3 percent, bad information up to 7.5 million or 1 percent, GDPR at 20 million or 4 percent.The bansUp to 35M EUR or 7% of global turnoverHigh-risk and transparencyUp to 15M EUR or 3%Bad information to regulatorsUp to 7.5M EUR or 1%GDPR: 20M EUR or 4%
The three AI Act penalty tiers, scaled by the percentage cap, with the GDPR ceiling of 20 million euros or 4% as the dashed reference. The top tier clears GDPR. The middle tier sits below it.

GDPR caps at 20 million euros or 4%. This raises it. Smaller companies pay the lower of the two figures rather than the higher, and the "up to" matters: a mid-market firm running a customer-service chatbot is not looking at a 35 million euro fine. What it is looking at is the documentation and assessment work, which applies in full regardless of size. Being small shrinks the fine. It does not shrink the work.

Where you sit is not the test

Start with the question every executive asks: does this even apply to me?

If your company is in the EU, yes, fully and directly. There is no scope argument to have. You are the clearest case the Act contemplates, and you are also closest to the national authority that will enforce it.

If your company is outside the EU, it very likely applies anyway. The Act reaches any company whose AI touches people in the EU, wherever that company is headquartered. A US, UK, or Asia-based firm with EU customers, EU users, or EU-facing AI is in scope. Where you are incorporated is not the test. Where your AI lands is the test.

This is the exact GDPR lesson. Companies inside Europe adapted because they had no choice. Companies outside it learned, often the expensive way, that "we are not in the EU" was never the shield they thought it was. The AI Act works the same way, and the reach is if anything broader, because AI ends up embedded in more of your operations than data collection ever was.

Whether that is a clear yes or a maybe for your company,

the AI Act risk check sorts your systems into tiers and shows which obligations attach to each.

First, figure out your role

Before you size your exposure, answer one question: are you the provider or the deployer? Your obligations turn almost entirely on this, and most companies get it backward.

Provider versus deployer obligationsProvider versus deployer obligations under the EU AI Act. Providers carry documentation, conformity assessment, and registration. Deployers use the system as intended, keep a human in the loop, monitor it, and manage vendor contracts. Most mid-market firms are deployers.ProviderYou build itTechnical documentationConformity assessmentRegistrationDeep governanceDeployerYou use someone else'sUse as intendedHuman in the loopMonitoringVendor contractsmost mid-market firms are here
Your obligations turn on whether you built the system or deployed someone else’s.

If you build an AI system and put it on the market, you are a provider, and the heaviest load is yours: technical documentation, the conformity assessment, registration, and the deep governance the high-risk tier demands.

If you use someone else's AI, a vendor platform, a bought tool, a model behind an API, you are a deployer. Most mid-market firms sit here. That means a large share of the hardest obligations belong to the vendor who built the system, not to you. Your duties are real but different: use the system as intended, keep a human in the loop, monitor it, and for some public and essential-service uses, assess its impact on people's rights.

Here is the trap in that good news. You cannot assume your vendor did its part. If a high-risk system you deploy is not compliant, "the vendor built it" is not a clean defense. So the practical move is to map which of your AI systems you built versus bought, and to make your vendor contracts carry the obligations that are genuinely theirs. That single distinction decides how much of this actually falls on you.

Why the delay is time, not a gift

The sixteen months are real, so use them.

The hard part of this was never filling in a template. It is finding every AI system across your company, deciding which risk tier each one lands in, and keeping that current as new tools ship and new vendors get onboarded. None of that got easier because a date moved.

Start now, and you have well over a year to do it properly. Start in late 2027, and you have weeks and a scramble, and you are hiring the expensive last-minute help all over again. I watched companies do exactly this with GDPR, in Europe and outside it. The ones who moved early were calm. The ones who waited paid more and shipped worse.

There is a second reason not to wait. Not everyone reads the delay as harmless housekeeping. Agustin Reyna, who leads the European consumer group BEUC, argued the package "rolls back key consumer protections" that were barely a year old. You do not have to share that view to take the practical point. The risk does not follow the regulatory calendar. Ungoverned AI is exposure today: reputational hits, mishandled data, decisions nobody can explain, systems nobody is actually watching. That risk is in your business right now, regulator or no regulator. The Act put a date on the paperwork. It did not put a date on the risk.

rolls back key consumer protections
Agustin Reyna, Director General, BEUC (European consumer group)

What good actually looks like

The path is not complicated. It is sequential, and most companies have not started.

Inventory, Classify, Operationalize, MonitorFour-step AI governance process: Inventory, Classify, Operationalize, Monitor.1InventoryATOM: Assess2ClassifyATOM: Tailor3OperationalizeATOM: Orchestrate4MonitorATOM: Modernize
Inventory, Classify, Operationalize, Monitor. The same muscle as Fidget Labs' ATOM model.

If that still feels abstract, here is the first move in concrete terms: a scoped inventory of your customer-facing and decision-making AI, one named person to own the list, and a few weeks to finish it, not a quarter. Everything else in this piece follows from that list.

Look at what that actually is. Not a legal exercise bolted on at the end, but an operational discipline wired into how you run AI. That distinction is the whole game, and it is the thing the template-sellers miss.

Where Fidget Labs comes in

This is the work Fidget Labs does: getting enterprise AI into production and keeping it governed. Inventory, classification, operational governance, and monitoring. It is the same muscle the regulation is asking for, wired into how your teams already run AI rather than bolted on at the end.

Fidget Labs' method is called ATOM. Assess where your AI actually stands. Tailor the governance to your real systems and your real risk. Orchestrate the controls into how your teams already work. Modernize so the whole thing stays current instead of going stale the day after you file it. Fidget Labs is not a law firm and this is not legal advice. Get counsel for the legal call. What Fidget Labs builds is the engineering and operational reality that turns an obligation into a system that actually functions.

The full ATOM cycle, Assess, Tailor, Orchestrate, Modernize, is laid out on the How We Work page.

The deadline moved. The smart money is spending the time on the work, not waiting.

Want to know exactly where you stand?

Start with the AI Act risk check to see which tier your systems fall into, then book a call and we will walk through what the timeline actually asks of you.

This article is for information only and is not legal advice. Your obligations depend on your specific situation. Talk to qualified counsel about your circumstances.

Kerrigan Baron, CTO & Co-Founder at Fidget Labs

Kerrigan Baron (they/them)

CTO & Co-Founder

Kerrigan leads the technical side of Fidget Labs. Twenty years of enterprise delivery across composable architecture and AI enablement, most recently as Senior Technical Director for MACH and composable technologies at Valtech. They lead delivery for the MACH AI Exchange under contract with the MACH Alliance Tech Office, and write Focal Point.

Curious where your organization lands?

Take the free MACH & AI Readiness Assessment. Powered by the MACH Alliance Enterprise Technology Report 2026.

Take the Quiz