SecurityBrief Ireland - Technology news for CISOs & cybersecurity decision-makers
Ireland
EU AI Act delays some rules, but others take effect

EU AI Act delays some rules, but others take effect

Wed, 2nd Sep 2026 (Today)
Sofiah Nichole Salivio
SOFIAH NICHOLE SALIVIO News Editor

The latest update to the EU AI Act has delayed some compliance deadlines for high-risk AI systems, but several transparency and enforcement rules are already in effect, ISOQAR said.

The changes leave businesses with a split timetable. Deadlines for standalone high-risk AI systems have moved to 2 December 2027, while product-embedded high-risk systems now face a later deadline of 2 August 2028.

At the same time, obligations linked to Article 50 took effect as planned. Those rules cover disclosure for chatbots, labelling of AI-generated content, and the marking of deepfakes.

Enforcement powers have also gone live for the EU AI Office in relation to general-purpose AI models. National authorities and the AI Office can now request technical documentation, evaluate models, order corrective action, and issue fines for non-compliance.

The latest revision also adds a prohibition on the unauthorised use of a person's likeness in AI-generated imagery. It also restores a requirement for providers claiming exemption from high-risk classification.

Shifted timeline

The EU AI Act has been introduced in stages since entering into force in August 2024. Prohibited practices and AI literacy requirements applied from February 2025, followed by governance rules and obligations for general-purpose AI models from August 2025.

Much of the remaining regime for high-risk systems and transparency obligations had originally been due from 2 August 2026. The recent simplification package has altered that schedule for some parts of the regime, but not all of it.

That distinction is central to the compliance picture facing companies that develop or deploy AI in Europe. Organisations that assumed the wider delay amounted to a broad reprieve may still be exposed if they have not addressed the rules already in force.

Businesses should continue classifying AI systems against the criteria set out in Annex I and Annex III, even where high-risk obligations have been deferred, ISOQAR said. It warned that conformity assessments can take up to 12 months, making late preparation risky.

It also urged organisations producing AI-generated content or operating public-facing AI systems to check whether disclosure and labelling measures are in place. Businesses that previously considered themselves exempt from high-risk classification should also revisit their registration status.

Enforcement focus

Attention is now shifting from the timetable itself to how regulators interpret the law in early cases. One unresolved issue is how broadly the high-risk category will be applied at the edges of the framework.

ISOQAR expects early enforcement activity to be more influential than the legislation's text alone in determining how companies are judged in practice. That is likely to matter for businesses whose systems sit close to the boundary of the high-risk definition.

Kirsty Wakefield, Information Security Sector Manager, ISOQAR, said: "What we're looking out for isn't another deadline, it's for how the enforcement actually plays out in practice. What is defined as high-risk is still being tested at the edges, and we expect the AI Office's early cases will do more to shape real-world compliance expectations than the legislation's text alone. Businesses that wait for a ruling or an enforcement notice to find out where they stand will already be behind. Our advice is to build governance that can flex as interpretation becomes clearer, rather than build something entirely around the rulebook of today."

ISOQAR pointed to structured governance frameworks such as ISO/IEC 42001 as one way to embed risk management, oversight, and documentation into routine operations. It argued that compliance work should not be treated as a final-stage exercise tied only to formal deadlines.

That view reflects a broader concern among advisers and compliance teams that AI regulation in Europe will be defined as much by supervisory practice as by statutory language. Companies operating across multiple jurisdictions may also need to prepare for differences in how national authorities approach enforcement alongside the role of the central AI Office.

For businesses, the immediate result is a more complex regulatory environment rather than a lighter one. Some of the most burdensome high-risk obligations have been postponed, but transparency duties, documentation demands, and regulator scrutiny are now part of the live framework.

The practical task is to separate what has been delayed from what now requires action. Wakefield said businesses that wait for a ruling or an enforcement notice to find out where they stand "will already be behind."