Six weeks ago, the EU AI Act's general rules became enforceable. In the same stretch, regulators quietly pushed the law's hardest provisions back sixteen months. Neither event changes what your organization should be doing right now.
On August 2, 2026, most of the remaining provisions of the EU AI Act became applicable: the general-purpose obligations, the transparency requirements (labeling AI-generated content, disclosing when someone is talking to a chatbot), and full enforcement authority for the EU AI Office. If your organization didn't mark the date, you're not alone. Unlike GDPR's rollout in 2018, this one arrived with almost no noise — because attention had already shifted to a different, more consequential story: the part of the law that just got pushed back.
The full timeline matters more than any single headline, because the details determine what you should actually be doing this quarter:
That last line is the one worth sitting with. The rules governing AI used in decisions about who gets hired, who gets a loan, and who gets flagged by a biometric system were originally scheduled to bind this past summer. Regulators just bought organizations sixteen more months of runway. When the deadline does land, the penalty exposure is real: fines up to €35 million or 7% of global annual revenue — whichever is higher — applied extraterritorially to any company serving EU citizens, regardless of where it's headquartered. That isn't a number to start planning around in month fifteen.
Most organizations will read "delayed to December 2027" as permission to wait. That's the mistake, and it's the same mistake we've documented across every AI initiative that stalls: treating a governance requirement as a technical checkbox to complete right before the deadline, instead of an organizational capability that has to be built, understood, and adopted by the people who'll actually run it.
MIT's AI Strategy and Leadership research frames this as "derisking by design" — the idea that responsible AI controls have to be embedded at every stage of a system's life, not bolted on after the fact. McKinsey's research behind that framework puts a number on what happens when organizations skip it: AI could add up to $13 trillion in global economic output by 2030, yet 80% of executives report their organizations are capturing only moderate value from it today. The gap between the opportunity and the outcome isn't a technology problem. It's a risk-management failure — the same failure pattern we broke down in 85% of AI Projects Will Fail on Bias, Not Code.
The organizations getting ahead of the December 2027 deadline aren't the ones with the best legal memo. They're the ones building a three-layer accountability structure before regulators force it:
That third layer is the one almost everyone skips — and it's precisely the ADKAR gap. A governance policy that nobody has the Awareness, Desire, Knowledge, Ability, or Reinforcement to actually follow isn't a governance model. It's a document that will fail an audit the same way an AI rollout fails without a change plan, a pattern we've tracked in The AI Execution Cliff and 60% of AI Projects Will Be Abandoned by 2026.
Workday is the case study worth studying here. The company committed to machine learning governance in 2019 and didn't reach ISO 42001 certification — the international standard for AI management systems — until June 2025. Six years. That's not a compliance sprint; it's the timeline of an organizational capability being built the right way, department by department, until responsible AI stopped being a cost center and became something Workday could sell as a differentiator. Organizations waiting until eighteen months before the December 2027 deadline to start are compressing a six-year build into a scramble.
Here's the part most US-based leaders miss: there is still no binding federal AI law in the United States. The EU chose hard law — enforceable, extraterritorial, backed by real fines. The US is still operating on soft law: voluntary NIST frameworks, a White House blueprint for an AI bill of rights, and self-regulation from companies like Microsoft and IBM who built their own ethics boards because no one made them. If your organization operates in both markets — or sells to customers who do — you're already accountable to the stricter standard, whether your internal policy reflects that yet or not.
The AI Efficiency Audit maps your current AI footprint against the accountability structure regulators expect — and builds the ADKAR-based rollout plan to get your people, not just your policy, ready before December 2027.
Start with an audit →Sources: European Commission. (2024). EU Artificial Intelligence Act. digital-strategy.ec.europa.eu | EU AI Act implementation timeline (2026). artificialintelligenceact.eu | Ammanath, B., & Bannister, A. (2021). Trustworthy and ethical tech. MIT Sloan. | McKinsey & Company. (2020). Derisking AI by design. mckinsey.com | As synthesized in: MIT xPRO. (2024). Module 5: Understanding the risks — AI strategy and leadership program. Massachusetts Institute of Technology.