+421 917 743 382
Free consultation

Knowledge · 15 September 2026

The AI Act: what applies today and what was postponed to December 2027

If you marked the August date as the day the AI Act would land on you, you were half right. The obligations for high-risk systems were postponed by more than a year — and the ones most organisations did not notice started applying on exactly that day.

If in 2025 you wrote 2 August 2026 in your calendar as the day the AI Act would land on you, you were half right. That date came and went — but it brought something other than what was expected.

The obligations for high-risk systems were postponed by more than a year. And the obligations most organisations had not noticed started applying on exactly that day.

What happened in the summer of 2026

The European Union adopted Regulation (EU) 2026/1744 of 8 July 2026, amending Regulation (EU) 2024/1689 — the so-called digital omnibus on artificial intelligence. It was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026, six days before the original deadline.

The reason was practical: the harmonised standards against which conformity with the requirements for high-risk systems was to be demonstrated were not ready. An obligation without a means of meeting it is an obligation that even a willing organisation cannot meet.

What applies today

The dates in this list and the next are the state as at 15 September 2026. This is a report about a change of the timetable, not a live overview — the figures here do not update themselves.

2 February 2025
Prohibited practices (Article 5) — social scoring or emotion recognition in the workplace, for example
2 February 2025
AI literacy (Article 4) — the duty to ensure a sufficient level of knowledge among the people who work with AI
2 August 2025
General-purpose AI models, governance and supervision, penalties
2 August 2026
Transparency (Article 50) — marking AI-generated content and telling people they are dealing with a machine
2 December 2026
End of the transitional period for marking content of systems placed on the market before 2 August 2026

What does not apply yet

2 December 2027
High-risk systems under Annex III — biometrics, critical infrastructure, education, employment, access to services, migration (originally 2 August 2026)
2 August 2028
High-risk systems embedded in regulated products under Annex I (originally 2 August 2027)

A postponement is not a cancellation. It is a moved deadline with a fixed date — and for systems in employment, which concern the largest number of organisations, it means you have a year longer — not a year less to do.

What it means for a company that uses AI rather than builds it

Most organisations are not providers of an AI system. They are deployers — they use a tool somebody else built. And that is where they most often get wrong what applies to them.

Three obligations already fall on a deployer today:

The prohibitions apply regardless of who built the system. If a tool does something Article 5 prohibits, the fact that you bought it does not help. The most common case in an ordinary company is emotion recognition in the workplace — a feature that turns up in tools for scoring calls, for tracking attention during training and in some recruitment systems.

AI literacy was softened but did not disappear — and what is assessed has changed. The original Article 4 required organisations to ensure a sufficient level of knowledge. The omnibus replaced it entirely: what is now required is to take measures to improve literacy, with an express addition that the obligation does not require guaranteeing a particular level of knowledge in a particular person.

For an organisation that is good news and one change of approach: what is assessed is the measures you took, not whether somebody understood them. So you cannot fail because one employee did badly in a test — but you have nothing to show if you did nothing at all. Training and a record of it remain the simplest way to evidence a measure.

Alongside that came Article 4a, which permits processing of special categories of personal data for the purpose of detecting bias — and which likewise says expressly that no obligation to carry out such detection arises. It is therefore a permission, not an order; whoever relies on it is processing under Article 9 GDPR and must be able to justify it.

Transparency has applied since August 2026. If you deal with customers through a system that comes across as human, they must know that it is not. If you publish content created or altered by AI, it has to be marked.

The omnibus barely touched this duty — it changed a single paragraph, the one on codes of practice. The obligations themselves were left unchanged and their date did not move. Anyone who expected everything to be postponed expected wrongly.

"We do not use AI"

That sentence is almost always untrue — and almost always said in good faith.

AI today is not a separate tool bought by a decision of the management. It is a feature that has appeared in software you already have, usually without anyone being asked:

  • sorting CVs and pre-selecting candidates in the HR system,
  • transcribing and summarising meetings in the communication platform,
  • drafting a reply to an e-mail or to a customer request,
  • a translator built into the document system,
  • evaluation of camera recordings,
  • call-scoring tools in customer support.

So the first step is not a risk assessment. It is finding out what you actually have. And that is done by asking your suppliers, not by walking through the server room.

What to do now, in this order

1. An inventory. Which systems with AI features are used in the organisation, who introduced them, what they are for, and whether their output feeds into a decision about a person. That last column is the most important one — everything else follows from it.

2. The prohibitions. Go through the inventory against Article 5. This cannot be postponed or mitigated by a measure; a prohibited practice has to stop.

3. Literacy. Find out who works with those systems and evidence that they understand them. Evidence is the operative word — an obligation you cannot demonstrate does not count in an inspection.

4. Transparency. Go through the places where a customer or the public comes into contact with AI and add the marking.

5. High-risk systems only after that. You have until December 2027 and you will also have the standards that make it possible to do it once and properly. Doing it blind today means doing it twice.

The AI Act and ISO/IEC 42001 are not the same thing

They are confused often, and the confusion costs money.

The AI Act is legislation. It applies whether you want it to or not, and failing to comply has consequences. It does not say how to organise your work — it says what must be the case.

ISO/IEC 42001 is a management system standard. It is voluntary and it says how to organise it: roles, policies, assessment, management review, improvement.

A certificate under 42001 does not relieve you of obligations under the AI Act and does not in itself demonstrate conformity with it. What it does is give you a structure in which those obligations can be met repeatedly and demonstrably — and with legislation that phases in over three years, that is worth more than a one-off check.

If you are deciding what to do first: the inventory and the prohibitions, then the decision about a management system. Not the other way round.

Where our work ends

  • We do not assess whether a particular model works correctly. We assess whether its use complies with the legislation and whether that is documented.
  • We do not carry out conformity assessment of high-risk systems — that is done by a notified body where the legislation requires it.
  • We neither develop nor supply AI systems, so we have no reason to recommend one over another.
  • A certificate under ISO/IEC 42001 is issued by an accredited certification body, not by a consultant.

Verified on 15 September 2026 against Regulation (EU) 2026/1744 and the analyses published on it. The AI Act timetable changed once in 2026; this date will be updated at the next change.

Legal position verified as of 15 September 2026. With legal content, an outdated article is worse than none — if you find a discrepancy, write to us at info@iosec.eu.

Sources

Milan Mračko · Lead Auditor for ISO/IEC 27001 and ISO 22301 · Qualifications →

Tell us what you are dealing with.

Thirty minutes with a consultant who knows your industry. The output is a one-page summary with a recommended approach and an indicative scope — we send it to you even if we do not reach an agreement.

info@iosec.eu
+421 917 743 382

Please fill in your name.
Please fill in your organisation.
Please give an address we can reply to.
Please choose a topic.
Please confirm you have read the privacy notice.

No newsletter, no sales sequence — we answer the question you asked.

Call us Free consultation