If you stopped tracking the EU AI Act after the headlines about delays, it's time for one more look. This year Brussels agreed amendments that push most high-risk obligations out to 2 December 2027 and 2 August 2028. What did not move is 2 August 2026: transparency duties for chatbots, AI-generated content, and deepfakes go live, and the Commission's enforcement powers for general-purpose AI activate the same day.
What You Need to Know
- The August 2026 deadline narrowed, it didn't disappear. Article 50 transparency obligations apply from 2 August 2026: users must be told when they're talking to an AI system, and AI-generated or manipulated content must be disclosed.
- High-risk obligations moved. Standalone high-risk systems (employment, credit, education, biometrics, critical infrastructure) now have until 2 December 2027; product-embedded systems until 2 August 2028.
- This reaches New Zealand and Australia. The Act applies to providers and deployers whose AI output is used in the EU, wherever the company sits.
- Doing nothing until 2027 is the wrong reading. Transparency duties land now, and the deferred deadlines are for compliance, not for starting.
What Actually Happens on 2 August 2026
Three things survive the reshuffle, and they're the ones most likely to touch an exporter's products first.
Chatbot disclosure. If people in the EU interact with your AI system, they must be informed they're dealing with AI, unless it's obvious from context. If your product has an assistant, a support bot, or a conversational interface with EU users, this is you.
AI-content marking. AI-generated or AI-manipulated content (text published to inform the public, images, audio, video) needs to be identifiable as such, with deepfakes explicitly labelled.
General-purpose AI enforcement. The Commission's enforcement toolkit for GPAI model providers activates. The GPAI obligations themselves have applied since August 2025; what changes now is that Brussels can act on them.
What Moved, and Why It Still Matters
The amendments, agreed in May 2026 as part of the EU's Digital Omnibus package, gave standalone high-risk AI systems until 2 December 2027 and product-embedded systems until 2 August 2028. If you build or deploy AI in hiring, lending, education, or biometric identification for the EU market, you have more runway.
Runway, not a reprieve. The high-risk requirements (risk management systems, data governance, technical documentation, human oversight, conformity assessment) are the kind of work that takes a year or more to do properly, because most of it depends on how your data and workflows are governed, not on paperwork you can produce at the deadline. We made this argument in AI governance beyond the checklist, and the extension doesn't change it: firms that treat December 2027 as a starting gun will be exactly as unready as the firms that were unready for August 2026.
The Reading for NZ and Australian Firms
Neither New Zealand nor Australia is legislating anything like this. New Zealand's national AI strategy is deliberately light-touch; Australia walked away from its mandatory guardrails proposal. That makes the EU AI Act the de facto ceiling for any NZ/AU firm with European customers, and a useful benchmark for everyone else.
Our practical advice hasn't changed, but the sequencing has:
- Map your EU exposure first. Do you have EU users, EU customers deploying your outputs, or EU marketplaces carrying your product? If no, file this and revisit annually. If yes, continue.
- Handle transparency now. Disclosure lines in chat interfaces and content labelling are small builds with an August deadline. Ship them.
- Classify against the high-risk categories honestly. If you're in scope, the 2027 date is your delivery date, and your data governance is the long pole.
Transparency about what your AI is and does is where every serious framework, from Brussels to our own Privacy Commissioner's guidance, has converged. Firms that build it in now are not complying early. They're just building trustworthy products.