The headlines said the AI Act got delayed. For the high-risk systems most small firms never build, that is true. For the AI you actually use every day, nothing moved. Those rules go live on 2 August 2026.
The full guide plus the Monday-morning checklist, offline-ready. Join the Pulse newsletter and download it.
You probably read that the EU AI Act got delayed. For the heavy stuff, the high-risk systems most small firms will never build, that is true. For the AI you actually use every day, it is not. The chatbot on your website. The assistant drafting your emails. The tool screening your CVs. None of that moved. Those rules go live on 2 August 2026. And here is the part nobody is selling you: you almost certainly already own the tools to meet them.
This is a business translation, not a legal brief. I am not a lawyer. What I am is someone who puts AI to work inside real companies and watches what happens when the whole thing gets left to the legal team without anyone who understands how the tools actually behave. So let me tell you which deadline moved, which one did not, and what to do about it with software you are probably already paying for.
If your firm uses any AI, including off-the-shelf tools like ChatGPT or Copilot, you are a deployer under the Act. Transparency, AI literacy, and the day-one deployer duties apply from 2 August 2026. Those were not postponed. "The Act got delayed" is a misread of which deadline moved.
This summer the EU adopted the Digital Omnibus, a package that reshuffled the AI Act timeline. It pushed the high-risk deadlines out. The stand-alone high-risk systems now land at the end of 2027, the ones baked into physical products in 2028. Real relief, if you build those systems. Most firms do not.
What it left untouched is the part that reaches an ordinary business. Transparency. AI literacy. The duties you pick up the moment you use someone else's AI in your work. Those still start on 2 August 2026. So when someone tells you the Act got delayed, they are half right. About the half that was never going to touch them.
| Date | What applies | Status |
|---|---|---|
| Feb 2, 2025 | Prohibited AI practices banned. AI literacy required for staff who use AI. | ● IN FORCE |
| Aug 2, 2025 | General-purpose AI obligations active. Penalty regime begins. AI Office operational. | ● IN FORCE |
| Aug 2, 2026 | Article 50 transparency, the bulk of remaining obligations, and full enforcement. NOT delayed by the Omnibus. | ● APPLIES |
| Dec 2, 2027 | Stand-alone high-risk systems (Annex III: employment, credit, healthcare, education AI). Deferred by the Omnibus. | ✓ DELAYED |
| Aug 2, 2028 | Product-embedded high-risk systems (Annex I). Deferred by the Omnibus. | ✓ DELAYED |
The Digital Omnibus was adopted in summer 2026 and is awaiting publication in the Official Journal. It moved the high-risk deadlines to fixed dates in 2027 and 2028. It did not move transparency, AI literacy, or the deployer duties. Those are the ones a normal firm actually touches.
There is no headcount that gets you out of this. The Act sorts everyone by role. Build or brand an AI system and you are a provider. Use one in your work and you are a deployer. A twelve-person firm running ChatGPT is a deployer, and that is a legal role with real obligations, not a shrug.
Being small changes one thing. The fines are capped lower for SMEs, you pay the lower of the two figures instead of the higher, and you get access to regulatory sandboxes. That is the whole benefit.
| Violation | Maximum fine |
|---|---|
| Using a prohibited AI system | €35 million or 7% of worldwide turnover |
| High-risk or transparency (Article 50) breach | €15 million or 3% of worldwide turnover |
| Misleading information to authorities | €7.5 million or 1% of worldwide turnover |
For an SME the number is the lower of the two, not the higher. Smaller, yes. Still the kind of number that ends a small firm.
Article 50 is the transparency rule, and it is the one that lands on a normal business. Take out the legal language and it comes down to a handful of moments where you have to tell people they are dealing with a machine.
Your chatbot has to say it is a chatbot. If something is answering questions on your site or handling intake, the person needs to know they are talking to AI, from the first message.
AI-generated content shown to the public has to be marked as AI. The machine-readable watermark is mostly the vendor's job, but you pick the vendor, so pick one that actually does it.
Deepfakes get disclosed. Publish AI-made images, audio, or video of real-looking people or events and you say, clearly, that it is artificial.
Published text on matters of public interest gets a label, with one exception that matters for a law firm. If a human reviewed it and a named person or organisation holds editorial responsibility, the labelling duty falls away. So your client alerts and your thought-leadership are fine, as long as a real person signs off on them.
The practical read: drafting a contract or a memo that a lawyer reviews is generally not a public transparency trigger. Your exposure there is confidentiality, where the client's data ends up, not a label. The label rules bite on the client-facing surfaces. The chatbot, the marketing, anything photoreal.
No theory. Here is what a firm of twenty to a hundred and fifty people actually does.
Here is the part that should make a managing partner exhale. Read that checklist again. Inventory, classification, transparency records, oversight, logging, data governance, retention. If your firm runs on Microsoft 365, you already own the machinery for almost all of it. It is sitting in your tenant, mostly switched off.
Purview Compliance Manager ships with a built-in EU AI Act template. It walks you through the assessment and exports the report an auditor wants to see. Purview DSPM for AI finds the AI already in use, including the shadow AI nobody told you about, and flags where data is oversharing. Auditing, retention policies, and eDiscovery cover the logging, the record-keeping, and legal hold over AI activity. And Azure and Copilot can be set to keep data inside the EU, through EU Data Zones and the EU Data Boundary, once someone configures it that way.
These tools give you readiness, not a certificate that says you are compliant. They produce the evidence and the controls. The legal judgment, the risk classification, the human oversight, that stays with you. Anyone who tells you a piece of software makes you compliant is selling you something. What the software does is turn a scramble into a system.
"We're too small." Wrong test. It is about what you do, not how many of you there are.
"We only use ChatGPT." That makes you a deployer, and a deployer has duties. It is a role, not a loophole.
"The free version is fine for client work." Not when it lacks EU residency, admin controls, and audit logs, and you are holding privileged data.
"Data leaving the EU doesn't matter." It does, for this and for GDPR both, and it is a setting you can change.
"We'll write a policy." A policy you file once is not evidence. The Act expects something living.
The firms that will feel August coming are the ones still treating AI as a thing they bought. The ones that will not are the ones who sat down, listed what they use, switched on the controls they already pay for, and wrote it down in a way they can keep current. That is a weekend of clarity, not a year of consulting.
No. The Omnibus moved the high-risk system deadlines to 2027 and 2028. The transparency obligations under Article 50, AI literacy, and the deployer duties still apply from 2 August 2026. The part that reaches an ordinary firm was not delayed.
Yes. Using someone else's AI in a professional context makes you a deployer, a defined role with real duties: transparency where it applies, human oversight, AI literacy, and data governance. The Act does not ban a vendor. It assigns you responsibilities.
The inventory is free and it is the hardest part to skip. If you run on Microsoft 365, most of the evidence and controls the Act asks for are features you already pay for, waiting to be switched on and kept current. The bottleneck is rarely money. It is the decision to start.
That is the readiness assessment we run. What AI you are really using, what the Act asks of you, and how much of it your existing Microsoft licences already cover. No new platform to buy. Mostly switches to turn on, and a system to keep them honest.
Book a readiness call