Europe switched on half of the AI Act
August 2, 2026 was the day the EU AI Act was supposed to apply in full. Half of it did: fines of up to 3% of global revenue for model makers, and the hard chapter pushed to December 2027.

When the AI Act passed in 2024, the calendar was the selling point: prohibitions in February 2025, general-purpose AI rules in August 2025, and on August 2, 2026, full application, with a fringe of remaining deadlines in 2027. The planet's first comprehensive AI statute, with a public deadline attached.
The date arrived. The whole law did not.
What took effect this month is the half aimed at whoever builds models and whoever generates synthetic content. The other half, the one governing AI used to decide things about people, was pushed to December 2, 2027, and to August 2028 when the system is embedded in a regulated product.¹ ² This was not drift: it was negotiated, voted and signed, under the name "digital omnibus".
What survived is considerably more than critics suggest, and considerably less than the 2024 headline promised.
What actually switched on
Two concrete things.
The first is enforcement power over general-purpose models. The obligations for whoever trains them (technical documentation, a copyright policy, a public summary of training data, systemic-risk evaluation for the largest ones) have applied since August 2025. What was missing was the collector. Now the European Commission, through the AI Office, can request documentation, demand access to a model for technical evaluation, impose corrective measures, restrict or withdraw a model from the EU market, and fine.³ The omnibus also gave the AI Office exclusive competence over those models, which spares everyone 27 national regulators reading the same sentence in 27 ways.²
The second is Article 50, the labeling rule. Any system that talks to a person has to make clear it is a machine, and synthetic content has to be marked in a machine-readable way. A deepfake has to be identifiable as one. This part was not delayed, with one small exception: systems already running before August 2 got a four-month grace period to implement marking, until December 2, 2026.²
Notice who those two rules hit. Frontier models and generated content: precisely the companies based outside Europe. It is the part of the law with the most straightforward extraterritorial reach, and the cheapest to police, because the targets are few and all known by name.
The fines, in three tiers
Article 99 sorts punishment by severity, always taking whichever is higher, the fixed amount or the percentage of global turnover:⁴
| Violation | Cap |
|---|---|
| Prohibited practice (art. 5): social scoring, manipulation, banned biometrics | € 35 million or 7% of worldwide turnover |
| Other obligations, including general-purpose models and art. 50 transparency | € 15 million or 3% |
| Incorrect or misleading information to the regulator | € 7.5 million or 1% |
For SMEs and start-ups, the cap is whichever is lower, not higher.⁴ That subtlety changes everything at small scale: 3% of a start-up's revenue is a scare, € 15 million is the whole company.
For scale, 3% of a large AI company's annual revenue is not a symbolic fine. It is the kind of number that shows up on an earnings call. The ceiling was built to deter, and Europe got that part right.
What got postponed is the part that touches your life
Here is the hole. The high-risk chapter was the heart of the AI Act: the rules for AI used in résumé screening, credit scoring, school admissions, worker management, migration, law enforcement and critical infrastructure. A high-risk system needs a conformity assessment, documented risk management, human oversight, registration in an EU public database and auditable data quality.
That was supposed to apply from this month. It now applies from December 2, 2027 for stand-alone systems, and from August 2, 2028 for AI embedded in a regulated product.¹ ² Sixteen extra months in the first case.
The road to the delay was fast by Brussels standards: the Commission proposed it on November 19, 2025, Parliament and Council reached a provisional agreement on May 6, 2026, Parliament endorsed it on June 16, the Council gave the final green light on June 29 and the act was signed on July 8.¹ ² ⁵ Proposal to law in a little over seven months. The original AI Act took three years.
The stated reasons are uncomfortably reasonable. The harmonized technical standards that explain how to comply with the high-risk rules were not ready. Several member states had not designated a competent authority or conformity assessment bodies. Demanding compliance without publishing the answer key punishes the companies that try and rewards the ones that do not.
The unstated reason is not a secret either: competitive pressure. Europe spent 2025 and 2026 hearing, from inside and outside, that it regulates too much and builds too little.
The new prohibition almost nobody covered
Inside a package sold as simplification, a brand-new ban appeared: using AI to generate or manipulate non-consensual intimate imagery, video or audio, and child sexual abuse material, is prohibited.¹ ⁵ It joins the Article 5 list, the one with the € 35 million or 7% ceiling. The transition period runs to December 2, 2026.²
That is the most concrete thing to come out of the omnibus, and it arrived in the package that loosened everything else. A regulator tired of being called a bureaucrat delivered, in a single text, a 16-month delay and an enforceable ban on synthetic intimate imagery. It says a lot about what wins political consensus in 2026.
Brazil, which still has no AI law at all
While Europe argues over which half to enforce, Brazil is still arguing over whether to have a law. PL 2338/2023, which copies the European risk-tier structure, passed the Senate floor unanimously on December 10, 2024 and has sat in the Chamber of Deputies since March 2025, waiting on a rapporteur's report in a special committee.⁶ ⁷
The vote was expected at the end of 2025, slipped to 2026, and landed in an election year, when a contentious bill usually starves. The sticking points are familiar: copyright in model training and how wide the exceptions for high-risk systems should be.⁷
The paradox is worth sitting with. If the Brazilian text follows the European one, it inherits the same dependency: risk tiers defined in law, but compliance resting on technical standards, a designated authority and actual enforcement capacity. Europe just proved that this is the hard part, and it is the part that never shows up in floor debate. Meanwhile, the digital enforcement that is genuinely moving in Brazil is the data authority's work on child protection, which already has a published schedule, as we covered in the New Mexico ruling against Meta.
What both sides are saying
The optimistic reading, which is also the official one, holds that delay is not retreat. The law exists, the AI Office got teeth and exclusive competence over models, synthetic-content labeling is live, and a ban on non-consensual intimate content was created. Moving high-risk to a date when technical standards actually exist is legislative engineering, not capitulation.
The pessimistic reading, argued by digital rights organizations since the November proposal, holds that this engineering carries a hidden cost. The delayed part is precisely the one protecting ordinary people from automated decisions about jobs, credit and schooling, and the delay arrived after months of industry pressure. If the date slipped once because standards were not ready, nothing guarantees it will not slip again in 2027 on the same argument.
There is a third group, made of the people who have to comply: legal and compliance teams that spent two years preparing for August 2026 and are now rebuilding their roadmaps. For a company that already invested in AI governance, a moved deadline is not relief, it is rework.
Verdict
Europe did not give up on regulating AI. It chose which half to regulate first, and the choice is revealing: it switched on the part aimed at a handful of large, foreign, highly visible companies, and postponed the part that would touch thousands of systems European firms run every day inside HR, banking, schools and hospitals.
You can defend that choice with an honest technical argument, and the honest technical argument is real. The practical effect is still that, in August 2026, the AI Act matters more to whoever trains a model than to whoever uses one to decide someone's future. If you ship generative AI to users in Europe, your deadlines are now: documentation, synthetic-content labeling, and answering when the AI Office asks. If you were waiting for protection against the algorithm reading your résumé, that appointment moved to December 2027.
For Brazil, the lesson is not to copy faster. It is to notice that the expensive part of regulation is not writing the law. It is building the regulator, publishing how to comply, and holding the date when pressure arrives. Europe wrote the law before anyone else and still had to move its own deadline. A country that has not even voted on the text at least gets to learn from someone else's rehearsal.
Sources
- Artificial intelligence: Council gives final green light to simplify and streamline rules · Council of the European Union · https://www.consilium.europa.eu/en/press/press-releases/2026/06/29/artificial-intelligence-council-gives-final-green-light-to-simplify-and-streamline-rules/ · 2026-06-29.
- EU AI Act Omnibus Agreement: Postponed High-Risk Deadlines and Other Key Changes · Gibson Dunn · https://www.gibsondunn.com/eu-ai-act-omnibus-agreement-postponed-high-risk-deadlines-and-other-key-changes/ · 2026.
Show 7 more sourcesHide sources
- EU AI Act Enforcement Phase Begins · Wilson Sonsini · https://www.wsgr.com/en/insights/eu-ai-act-enforcement-phase-begins.html · 2026-08.
- Article 99: Penalties · EU Artificial Intelligence Act (consolidated text) · https://artificialintelligenceact.eu/article/99/ · 2024.
- Digital Omnibus on AI · European Parliament, Legislative Train Schedule · https://www.europarl.europa.eu/legislative-train/package-digital-package/file-digital-omnibus-on-ai · 2026.
- PL 2338/2023 legislative record · Brazilian Federal Senate · https://www25.senado.leg.br/web/atividade/materias/-/materia/157233 · 2024-2026.
- Votação do marco da IA fica para 2026 em meio a impasses políticos e críticas ao texto · Desinformante · https://desinformante.com.br/votacao-do-marco-da-ia-fica-para-2026-em-meio-a-impasses-politicos-e-criticas-ao-texto · 2025.
- Implementation Timeline · EU Artificial Intelligence Act · https://artificialintelligenceact.eu/implementation-timeline/ · 2026.
- AI Act · European Commission, Shaping Europe's digital future · https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai · 2026.
— Redação