EU AI Act takes effect this week: what applies and what is delayed
John Kjorstad
The EU's AI Act entered a new phase on 2 August, requiring chatbots and AI-generated content to be clearly labelled, with fines for non-compliance. Meanwhile, high-risk rules on biometrics, migration, and employment have been postponed to December 2027, drawing criticism from rights groups.
On 2 August, the next phase of the European Union's AI Act formally came into force, which the bloc describes as the world's first comprehensive law on artificial intelligence. Like the General Data Protection Regulation (GDPR) before it, the new legislation does not replace existing digital rules but complements them.
While the GDPR governs how organisations collect and use personal data, the AI Act regulates how AI systems are developed and deployed. The GDPR shaped privacy practices well beyond Europe, setting a benchmark for many multinational corporations. The question now is whether the AI Act will exert a similar influence on AI governance.
What takes effect this week?
Article 50 of the AI Act applies from 2 August, adding a layer of transparency to the EU's general AI rulebook. Chatbots and AI systems that interact directly with users must disclose that people are talking to an AI, unless it is obvious from the context.
Providers of AI systems that generate or manipulate images, audio, video, or text must ensure that synthetic content is machine-readable and labelled as such when required by law. Emotion recognition systems or those that classify individuals using biometric data must inform people concerned. Some law enforcement activities are partially exempt from these obligations.
The key point is that these rules require disclosure, not a ban on the technology, and violations can result in fines of up to €15 million ($17.3 million) or 3% of annual global turnover, whichever is higher.
For businesses, the immediate impact is mainly operational rather than transformative. The rules do not force them to abandon AI systems or seek approval before use; they just add a compliance layer. The real challenge is identifying where AI is embedded in products, customer interactions, and internal processes – including third-party tools – and ensuring those systems meet the new transparency requirements.
What has been delayed and why?
The most significant obligations of the AI Act – the high-risk requirements for systems in biometrics, employment, education, essential services, migration, asylum, and border management – were initially due to apply on 2 August alongside the transparency rules.
However, in May 2025, EU lawmakers agreed to postpone these until 2 December 2027 as part of the Digital Omnibus package. These systems remain subject to existing laws such as the GDPR and sector-specific regulations, but they do not yet have to comply with the AI Act's own governance, risk management, and oversight requirements.
The European Commission frames the delay as a deployment adjustment, not a retreat from AI regulation. Executive Vice-President Henna Virkkunen said the goal was to “make innovation easier without lowering safety standards,” as businesses and regulators need clearer guidance, technical standards, and support tools before the most stringent obligations take effect.
The Commission also linked this to a competitiveness agenda, citing Mario Draghi's 2024 report on European competitiveness, which argued that regulatory burdens were holding back growth. European Parliament negotiators supported the compromise, noting that technical standards supporting compliance for high-risk systems were not yet ready.
Digital rights groups have objected, saying that reopening recently adopted legislation could weaken protections and set a precedent for further delays.
Who is most affected and what do critics say?
Annex III of the AI Act classifies certain AI systems in migration, asylum, and border management as “high risk,” reflecting concerns that these technologies can affect vulnerable people. This includes risk assessment tools, decision support for asylum, visa, residence, and detection or identification of individuals at borders.
If the AI Act were fully applied, these systems would need to meet additional requirements on risk management, documentation, data governance, traceability, and human oversight. But those obligations are delayed until December 2027, leaving people affected by automated decisions without the AI Act's strongest protections for 16 more months. The GDPR and national laws still apply, but activists say they do not address every risk from AI systems that are opaque or potentially discriminatory.
Stefi Richani, policy advocacy lead at the Equinox initiative for racial justice, said the delay would “increase surveillance and discrimination, even leading to unlawful denial of asylum applications based on personal characteristics or racial profiling.” She argued that predictive and automated systems in this area should be banned rather than regulated, and resources should go toward safe pathways and social support.
Impact beyond EU borders
On transparency, companies building AI systems that comply with EU rules often apply the same standards globally instead of operating separately. This is the “Brussels effect” that made the GDPR a global privacy benchmark. But for high-risk applications, the EU's influence runs in the opposite direction.
The EU funds border surveillance technology deployed in third countries – for example, at transit points along migration routes into Europe – and these deployments fall outside the AI Act's scope, no matter what the high-risk rules require inside the EU. Transparency requirements may go global, but the strongest protections stop at the EU's border.
What comes next?
The AI Act is being implemented in stages. Bans on dangerous AI practices and AI literacy rules took effect in February 2025. Obligations for general-purpose AI models apply from August 2025. Transparency requirements started this week. And the delayed high-risk obligations are expected to apply from December 2027.
The phased rollout reflects the complexity of governing a fast-moving technology sector. Critics say every delay helps the industry escape scrutiny for longer, while systems that affect migrants and job seekers remain insufficiently regulated.