The European Union's AI Act reached a milestone this week, and the way it was announced tells you less than the calendar does. On August 2, 2026, the law's transparency obligations became enforceable [1]. AI systems now have to disclose that they are AI, and synthetic media has to be marked as synthetic. Violations carry fines of up to 15 million euros or 3 percent of a company's global turnover [1].
Those are real duties with real penalties. They are also the lighter-touch half of the law.
The heavier half was quietly moved. The obligations governing high-risk AI, the category that covers biometrics, employment, education, and migration, asylum, and border management, were postponed from August 2, 2026 to December 2, 2027 [1]. That is a 16-month delay, and it lands on precisely the uses where an automated decision can reroute a person's life: whether a facial-recognition match flags you, whether an algorithm screens you out of a job, whether a border system routes your asylum claim.
The distinction matters because the two sets of rules protect against different things. Transparency rules address a labeling problem: you have a right to know when you are talking to a machine or looking at a generated image. High-risk rules address a decision problem: they set requirements on the systems that make or shape consequential calls about people, in hiring, in schooling, at the border. The requirement to tell someone an AI is involved took effect this week. The requirements on what that AI is allowed to do in the highest-stakes settings did not.
For the companies building those systems, the delay is 16 more months of operating under the prior rules before high-risk compliance costs arrive. For the people on the other side of those systems, a biometric scan, a hiring filter, an asylum screening, the specific protections that were meant to cover them now sit behind a December 2, 2027 date.
The framing that the AI Act "came into force this week" is accurate as far as it goes. The record is more specific: the disclosure duties came into force, and the protections attached to the most consequential automated decisions were pushed out by more than a year [1].