A lot of noise has built up around the AI Act, and manufacturers get contradictory signals: one day "everything kicks in August 2026," the next "the deadlines got pushed anyway." Both are partly true, which is exactly why it's worth separating what actually applies now from what's still ahead. This piece sorts that out and gives you a concrete list of questions for your AI vendor.
A caveat up front: this isn't legal advice. It's a map that makes it easier to talk to a lawyer and a vendor, it doesn't replace either.
The AI Act doesn't arrive "all at once", it phases in
The AI Act entered into force on 1 August 2024, but its provisions apply in stages. That's the key: the question isn't "are we AI Act compliant," but "are we compliant with the obligations that apply today, and are we on track for the ones still to come."
What already applies by mid-2026:
- Prohibited practices, since February 2025. Systems deemed "unacceptable risk" (social scoring, subliminal manipulation, and others) are banned.
- Obligations for general-purpose AI models (GPAI), since August 2025. They fall on providers of large models: technical documentation, transparency, systemic-risk management.
- National supervisory authorities, designated and operational; enforcement has already begun.
The nearest real threshold is 2 August 2026, when the Article 50 transparency obligations start to apply. The penalties in Article 99 have applied to operators, deployers included, since 2 August 2025 (Article 113(b)): up to EUR 35 million or 7% of turnover for prohibited practices, EUR 15 million or 3% for most other breaches, EUR 7.5 million or 1% for supplying misleading information. What starts on 2 August 2026 are the Commission's fines and enforcement powers against providers of general-purpose AI models (Article 101), which concerns model vendors, not you. It is no longer, as originally planned, the date most remaining provisions land: the high-risk obligations have been pushed back, as set out below.
Digital Omnibus: the high-risk deadlines have moved, and it is now law
This is the freshest and most important change, and as of recently it is settled. The Council of the EU approved the Digital Omnibus on AI on 29 June 2026, and the package entered into force on 27 July 2026. The new dates are no longer a likely scenario; they are the law in force.
What changed:
- Annex III high-risk (recruitment, scoring, critical infrastructure, and more), compliance deadline moved from August 2026 to 2 December 2027;
- High-risk embedded in regulated products (Annex I), e.g. machinery, medical devices, moved to 2 August 2028;
- A new prohibition on AI generating non-consensual intimate material and CSAM, effective 2 December 2026;
- Watermarking of AI-generated content (Article 50(2)) for systems already on the market, postponed to 2 December 2026;
- Unchanged: prohibited practices (since February 2025), GPAI obligations and the penalty rules for operators, deployers included (both since August 2025), and the Article 50 transparency duties, which apply from 2 August 2026.
The practical takeaway for a manufacturer is slightly counterintuitive: the postponement is real, but it is not a reason to demobilise. December 2027 looks far away until you count how long risk classification, documentation clean-up and renegotiating a vendor contract actually take. And the transparency obligations landing on 2 August 2026 apply to you directly, while the penalty regime has been in force since August 2025. A Polish caveat worth knowing: the national AI systems act is not in force yet and the supervisory authority (KRiBSI) does not exist yet, so the obligation applies directly from the Regulation while the domestic enforcement machinery is still being built.
What this means for a typical manufacturer
Most manufacturers don't build their own models, they buy or deploy AI solutions. In practice your role is usually deployer, less often provider. That distinction decides which obligations fall on you and which on the vendor.
The second question is risk classification. Not every AI use in a factory is "high-risk." An assistant that helps search documentation or draft an offer usually isn't. But AI wired into a process that affects product safety or decisions about workers may fall under stricter requirements. Classification is the first step, and don't do it by gut feel.
A third thing, often overlooked: the AI Act isn't the only regulation in play. For entities under NIS2, the security and supplier-oversight requirements overlap with AI Act obligations. If you're preparing for a NIS2 audit, treat AI as part of the same landscape, not a separate island.
What to ask your AI vendor before you sign
The Omnibus has landed, but these questions are resistant to further date changes, and there will be more. If a vendor can't answer them concretely, that's a signal.
- Where is our data processed? On your infrastructure, in a dedicated instance, or in a shared public model? This is the data-sovereignty question, and what you'll tell an auditor.
- Who is provider and who is deployer in this relationship? The vendor should state clearly which AI Act obligations it takes on and which stay on your side.
- How do you classify the risk of our use case? A good vendor walks you through classification rather than waving it off with "it's not high-risk."
- Is there an auditable trail? Can you see which sources an answer was grounded in? Without it, demonstrating compliance and passing an audit is hard.
- How do you keep up with legal change? The AI Act is being amended (the Omnibus proves it). Ask how the vendor updates the solution against shifting dates and requirements.
These five questions don't require you to be a lawyer. They only require the vendor to treat compliance as part of the product, not as your problem to solve after deployment.
The practical bottom line
The AI Act in 2026 is a picture of "partly in force, partly coming, partly being moved right now." The worst strategy is either extreme: panic ("everything from August") or demobilisation ("they'll push it anyway"). The sensible path is to know your current obligation, prepare for the nearest threshold, and pick a vendor that understands this volatility and shoulders part of it.
Want to sort out which AI Act and NIS2 obligations actually apply to your plant? Book a 30-minute call with the founder and we'll walk through your case, including where the AI Act obligations overlap with NIS2.
