The EU AI Act hasn’t been delayed. Your governance responsibilities haven’t gone away.

July 28, 2026
Recent headlines about changes to the EU AI Act have led many organisations to believe they have been given additional time before taking action on AI governance and compliance. The reality is more nuanced.
EU AI Act Governance Responsibilities

While the European Union has extended certain deadlines for high-risk AI systems, the core framework remains firmly in place and several significant provisions become applicable from 2 August 2026. Organisations that interpret the recent changes as a reason to pause their AI governance initiatives risk finding themselves unprepared for the regulatory expectations that are already taking effect.

For boards, senior leaders and governance professionals, the question is no longer whether AI requires oversight. The question is whether sufficient governance arrangements are in place to demonstrate accountability, transparency and effective risk management.

What has changed?

The EU Council recently approved amendments to the AI Act through the Digital Omnibus package, introducing several important timing changes whilst retaining the Act’s risk-based regulatory architecture.

The most significant changes are:

  • Stand-alone high-risk AI systems now have until 2 December 2027 to comply.
  • High-risk AI systems embedded within regulated products now have until 2 August 2028 to comply.
  • New prohibited AI practices have been introduced relating to the creation of non-consensual intimate content and child sexual abuse material.
  • Certain implementation and supervisory provisions have been streamlined to support more consistent application across the EU.

However, the overall direction of travel has not changed. The AI Act remains a comprehensive governance framework designed to ensure AI systems are safe, transparent and accountable.

The key dates every organisation should know

Date Requirement
2 February 2025 Prohibited AI practices ban and AI literacy obligations apply
2 August 2025 General Purpose AI (GPAI) provider obligations apply
2 August 2026 Transparency obligations become enforceable and regulatory oversight expands, including enforcement powers relating to GPAI providers
2 December 2026 Additional synthetic content labelling and watermarking requirements apply, together with new prohibited practices relating to non-consensual intimate content
2 December 2027 Compliance obligations for stand-alone high-risk AI systems apply
2 August 2028 Compliance obligations for high-risk AI systems embedded in regulated products apply

 

Why 2 August 2026 still matters

Many articles discussing the recent amendments focus almost exclusively on the delayed high-risk deadlines. That risks overlooking why 2 August 2026 remains a major milestone.

The Act enters a significant new phase on this date, bringing both additional obligations and increased regulatory oversight.

Transparency requirements become enforceable

From 2 August 2026, key transparency obligations under Article 50 apply.

These include requirements to inform individuals when they are interacting with AI systems in circumstances where this may not be obvious and to disclose certain AI-generated or manipulated content. Organisations using chatbots, AI-enabled customer service tools, virtual assistants and synthetic media should already be considering how these requirements will affect their operations.

For many organisations, transparency is no longer simply good practice. It becomes a regulatory expectation.

Enforcement powers expand for GPAI providers

2 August 2026 is also significant because enforcement activity begins to expand in relation to General Purpose AI (GPAI) providers.

The obligations applicable to providers of GPAI models, including requirements relating to transparency, technical documentation and copyright compliance have applied since August 2025. However, August 2026 represents the point at which regulators gain greater ability to supervise and enforce those obligations.

Even where organisations are not developing foundation models themselves, they increasingly rely upon GPAI technologies through products such as Microsoft Copilot, ChatGPT and other AI-powered platforms. As a result, boards should be considering how they obtain assuranceregarding the governance and compliance arrangements of key AI suppliers.

AI literacy remains a current obligation

The requirement to ensure an appropriate level of AI literacy has applied since February 2025 and remains one of the most overlooked aspects of the legislation.

Organisations deploying or using AI systems must ensure relevant personnel understand the capabilities, limitations and risks associated with AI tools. This extends beyond technical teams and may include management, operational staff and board members.

What should organisations be doing now?

The additional time granted for certain high-risk systems should not be viewed as an opportunity to delay.

Instead, organisations should use this period to establish the governance foundations that will support long-term compliance and responsible AI adoption.

Practical actions include:

  1. Create an AI inventory

Many organisations cannot readily identify all AI tools being used across the business. Understanding what is in use, where it is being used and who owns it is the starting point for effective governance.

  1. Assess AI-related risks

Organisations should evaluate:

  • Data protection implications
  • Security considerations
  • Ethical risks
  • Potential bias and discrimination risks
  • Regulatory classification under the AI Act
  1. Establish governance frameworks

Boards should consider whether they have:

  • An AI governance framework
  • Defined accountability structures
  • Appropriate reporting mechanisms
  • AI-related policies and standards
  • Clear oversight arrangements for AI initiatives

These are areas where regulators increasingly expect evidence of governance and challenge.

  1. Invest in training and awareness

AI literacy is becoming a governance issue rather than simply a learning and development initiative. Organisations should ensure leaders and employees understand both the opportunities and risks associated with AI technologies.

  1. Build audit and assurance capability

As regulatory scrutiny increases, organisations should be able to demonstrate:

  • How AI decisions are governed
  • What controls exist
  • How risks are monitored
  • How compliance is evidenced

The ability to provide assurance may prove just as important as the controls themselves.

Final thoughts

The recent amendments to the EU AI Act should not be viewed as a delay to regulation. They are better understood as a recalibration of implementation timelines.

What has not changed is the growing expectation that organisations understand where AI is being used, how risks are being managed and who is accountable for oversight.

The organisations that will be best placed to take advantage of AI are unlikely to be those with the most advanced technology. They will be those with the strongest governance, clearest accountability and greatest confidence that they can demonstrate responsible, transparent and compliant use of AI.

The revised deadlines may provide additional time. They do not reduce the need to act now.

How Bridgehouse can help

One of the biggest misconceptions surrounding AI regulation is that compliance is primarily a technology challenge. In reality many of the requirements sit squarely within governance, risk, assurance and accountability frameworks.

At Bridgehouse, we help organisations establish practical governance structures that enable innovation whilst maintaining appropriate oversight and regulatory compliance.

Our support includes:

  • AI governance framework design
  • Board and executive briefings
  • AI policy development
  • AI risk registers and assessments
  • Governance and compliance reviews
  • Committee and Board reporting frameworks
  • Horizon scanning and regulatory monitoring
  • Secretariat support for AI governance committees
  • AI literacy and awareness sessions for Boards and senior leadership teams

 

Whether an organisation is at the start of its AI journey or seeking to strengthen existing governance arrangements, the focus should be on building sustainable oversight rather than simply preparing for regulatory deadlines. If you would like to explore what these developments could mean for your organisation, please contact us to speak with our team.

Get in touch

We would be pleased to answer any queries or have an informal chat to discuss your possible governance needs.