Brussels: The grace period is running out. When the European Union’s Artificial Intelligence Act passed, its toughest obligations were spread across a multi-year timeline that let companies and regulators breathe. That breathing room expires this summer, when on 2 August the rules governing high-risk AI systems and the enforcement of obligations on the most powerful general-purpose models come into force. After years of treating the Act as a distant compliance project, developers and deployers are discovering the deadline is now only weeks away.
The high-risk category is where the Act bites hardest. Systems used to screen job applicants, score creditworthiness, assist in policing or operate critical infrastructure fall into a tier that demands risk management, human oversight, documentation, transparency and rigorous data governance. From August these standalone high-risk uses must comply, and the burden is considerable. A firm deploying an AI hiring tool must be able to show how it works, prove it has been tested for bias, and keep a human meaningfully in the loop rather than rubber-stamping the machine’s verdict.
A parallel clock governs general-purpose AI, the foundation models that power chatbots and a sprawling ecosystem of downstream applications. Their core obligations took effect last year, but the Commission’s power to enforce them, to demand information, inspect models and ultimately order changes, switches on this August. Until now compliance has leaned on a voluntary Code of Practice drawn up by independent experts, which offers signatories a presumption of conformity. From this summer the regulator gains teeth, and the question of whether the largest model providers have genuinely met their commitments stops being academic.
Complicating the picture is a late attempt to ease the timetable. A so-called Digital Omnibus, still under negotiation between the institutions, proposes pushing some high-risk obligations back toward the end of 2027. The motive is partly competitiveness anxiety, the recurring European worry that heavy rules will smother a sector where the bloc already trails the United States and China. But the delay is not law, and lawyers are warning clients not to gamble on it arriving in time. If the Omnibus stalls, the original August date stands, and companies that paused their preparations betting on a reprieve will be caught short.
That uncertainty is itself a cost. Businesses crave predictability above almost everything, and a regime whose deadlines may or may not move depending on a separate legislative fight is the worst of both worlds. Industry groups argue that the constant reopening of timelines undermines the very legal certainty the Act was meant to provide, while digital rights advocates fear that each delay hollows out protections that took years to negotiate and that the public was promised.
The deeper argument is about whether Europe can regulate a fast-moving technology without strangling it. The Act was sold as the world’s first comprehensive AI law, a chance for the bloc to set global standards much as it did with data protection. Critics say it risks freezing a snapshot of the technology into rules that will age badly, loading compliance costs onto the startups least able to bear them while the genuine frontier labs sit outside the bloc entirely.
Supporters make the opposite case, that unregulated AI in hiring, lending and policing has already produced documented harms, and that clear rules give responsible developers a market advantage over those who cut corners. The summer deadline will be the first real test of which account is closer to the truth. After 2 August the Act stops being a debate about principles and becomes a matter of audits, documentation and the unglamorous work of proving that a system does what its makers claim.




