All insightsEU AI ActComplianceGovernance
The AI Act in autumn 2026: what applies now — and what's coming
Published 7 min read
The summer of 2026 changed the EU AI Act's timetable. The so-called digital omnibus — a package to simplify and harmonise regulation — entered into force on 27 July, deferring the obligations for high-risk AI. It's easy to misread the message: the date has moved, not gone. Here is the state of play in early autumn 2026.
What already applies
Three parts of the Act already apply, and they touch almost every organisation using AI:
AI literacy (since 2 February 2025). Providers and deployers of AI systems must ensure their staff have sufficient AI competence. A general awareness course isn't enough — competence must be proportionate to how AI is used. In practice: role-based training and documentation of who knows what.
Prohibited practices (since 2 February 2025). A set of use cases are banned — social scoring and imperceptible manipulation among them. Most Swedish companies aren't directly affected, but the rule sets the tone for the whole risk assessment.
Transparency for generative AI (since 2 August 2026). Systems interacting with people must be identifiable, synthetic content must be detectable/marked, and providers of generative models must meet documentation requirements. Since August, the member-state enforcement and sanction regime also applies — regulators now have the tools to act.
What's deferred — and why it isn't a pause
The big news is that the obligations for Annex III high-risk systems have moved from August 2026 to 2 December 2027, and product-embedded high-risk (Annex I) to August 2028. The European Commission's AI Act page confirms the timeline.
But leaning back would be a classic misjudgement. Classifying which systems are high-risk, and building the risk management, data governance, documentation and human oversight they require — all of this takes longer than the ~15 months left for Annex III. Organisations that start mapping their AI use now will handle December 2027 calmly. Those that wait until 2027 will do it in a panic, at higher cost and with worse decision bases.
The three traps we see right now
Trap 1: The inventory that never happens. You cannot govern AI you don't know about. Shadow AI — employees using unapproved tools — is meanwhile the most common security gap: in IBM's Cost of a Data Breach 2025, one in five organisations had experienced breaches linked to shadow AI.
Trap 2: Treating the Act as an IT matter. The AI Act is a business obligation, not a system setting. Accountability, documentation and human oversight must be built into how the business works — otherwise compliance becomes an event, not a state.
Trap 3: Governance in silos. AI governance built beside existing IT governance, risk processes and the ISMS becomes expensive and brittle. Those who connect their governance handle the AI Act, NIS2 (in Sweden: the Cybersecurity Act, in force since January 2026) and customer audits with the same foundation.
What we recommend for the autumn
- Inventory every AI use — ongoing, planned and shadow AI — and classify against the Act's risk tiers.
- Prioritise on both risk and business value. Not everything must be done at once, but everything must be known.
- Write the policy short and concrete, so it actually gets used.
- Build competence by role — leadership, developers, operations — and document it.
- Book the review before December 2027 — ideally with an external party who can see the blind spots.
Sources
- European Commission — AI Act (accessed 18 September 2026)
- IBM — Cost of a Data Breach Report 2025
- Government Offices of Sweden — New Cybersecurity Act (NIS2), December 2025
- OWASP — Top 10 for LLM Applications (2025), genai.owasp.org