August 2, 2026 has been circled on compliance calendars since the AI Act entered into force. It is the date the high-risk regime was supposed to bite: conformity assessments completed, technical documentation finalised, CE marking affixed, registration in the EU database done, and a penalty ceiling of €35 million or 7% of global turnover — substantially above the GDPR’s €20 million / 4%.

The date arrived. A large part of what everyone was waiting for did not.

What actually applies today

The AI Act’s architecture is staged. The prohibitions — the eight categories of AI practice banned outright, including social scoring and untargeted scraping of facial images — took effect in February 2025. General-purpose AI model obligations followed in August 2025.

As of today, the high-risk framework becomes enforceable for systems that are safety components of products already regulated under EU harmonised legislation — the Annex I route. Medical devices, machinery, lifts, vehicles, toys. If your AI is the thing keeping an industrial machine from crushing someone, the obligations are live.

Governance and penalty provisions are also now operative, which matters institutionally: national market surveillance authorities are supposed to be designated and functioning.

What got pushed to December 2027

The Annex III categories — the ones people mean when they say “high-risk AI” — have been moved. Following amendments adopted during the fight over the Commission’s simplification package, the rules for systems used in:

  • biometrics — remote biometric identification, biometric categorisation, emotion recognition
  • critical infrastructure
  • education and vocational training
  • employment and worker management
  • migration, asylum, and border control

now apply from December 2, 2027.

Read that list again. It is, almost exactly, the list of AI applications that a privacy-focused person would rank as most urgent. Police facial recognition. Emotion recognition in hiring and classrooms. Biometric categorisation — inferring protected characteristics from a face. Automated triage at borders. Algorithmic management of workers.

Sixteen additional months.

Why it happened

The delay did not come from nowhere, and the honest version is more complicated than “industry lobbied and won,” though industry did lobby and did win.

The genuine problem is that the Annex III compliance machinery was not ready. The high-risk regime depends on harmonised standards — the technical specifications, developed by European standards bodies, that tell a provider what “adequate” actually means for risk management, data governance, human oversight, accuracy, and robustness. Those standards ran badly late. Without them, a provider facing 7%-of-turnover exposure has no reliable way to know whether it is compliant, and the notified bodies that perform third-party conformity assessment for biometric systems were not accredited in sufficient numbers to handle the volume.

Enforcing a regime whose technical content does not yet exist produces either arbitrary enforcement or no enforcement. Neither is good.

The less generous half: the delay was bundled into the same simplification politics that produced the Digital Omnibus fight over the GDPR, where “we need more time to get this right” and “we would prefer this never applied to us” arrived in the same submissions, and were not always distinguishable.

What the delay actually costs

Here is the concrete consequence, and it is not abstract.

Between now and December 2027, deploying an emotion recognition system in a European workplace, or a biometric categorisation system that infers characteristics from faces, or an AI screening layer in hiring, carries no AI Act high-risk obligation. No conformity assessment. No mandated human oversight. No registration in the public EU database. No fundamental rights impact assessment.

Those systems are being procured and deployed right now. Sixteen months is long enough for a technology to become embedded in institutional practice, and embedded technology is much harder to regulate than proposed technology. Regulators know this; it is the reason implementation dates matter as much as substantive rules.

What still constrains these systems

The delay is real but it is not a vacuum, and this is the part most coverage gets wrong.

The prohibitions are already in force. Real-time remote biometric identification in publicly accessible spaces for law enforcement is banned, subject to narrow exceptions, and has been since February 2025. Emotion recognition in the workplace and in educational institutions is prohibited outright — not high-risk, prohibited. Biometric categorisation to infer race, political opinions, trade union membership, religious beliefs, or sexual orientation is prohibited. Untargeted scraping of facial images to build recognition databases is prohibited.

So the most alarming applications were never waiting on August 2, 2026. They are already illegal, and enforcement of the prohibitions is not delayed.

The GDPR applies in full. Biometric data is special category data under Article 9. Processing it requires an Article 9 condition, which for most commercial uses means explicit consent — a bar that facial recognition deployments routinely cannot clear. The GDPR has done far more work against biometric surveillance in Europe than the AI Act has yet had a chance to. Clearview AI was fined into oblivion under the GDPR, not the AI Act.

National law applies. Several member states have biometric restrictions that predate and exceed the AI Act.

The AI Act’s Annex III regime was always going to be a supplement to those, adding process obligations, documentation, and public registration to systems the GDPR already constrains. Its delay removes a layer. It does not remove the floor.

What this means if you’re in Europe

  1. Emotion recognition at your workplace or your child’s school is already prohibited. If you encounter it — attention monitoring in a classroom, sentiment analysis on employee calls, “engagement” scoring from webcam feeds — that is not a future violation. Report it to your national DPA now.

  2. Biometric processing still needs an Article 9 basis. If an employer or service is capturing your face or fingerprint, ask what the lawful basis is. “Consent” given as a condition of employment is not freely given and is not valid.

  3. Use your Article 15 access right against any system making automated decisions about you, and your Article 22 right not to be subject to solely automated decisions with legal or similarly significant effects. These are in force today, fully.

  4. The EU database of high-risk systems will eventually be public and searchable. For Annex III systems, that transparency now arrives in 2027.

The pattern

Regulatory dates are where the real fight happens, and almost nobody watches them.

The AI Act passed with enormous attention paid to what it prohibited and what it classified as high-risk. Very little attention went to the staging schedule, which is where a sixteen-month deferral of the surveillance-relevant categories could be inserted during a simplification package without a headline.

The rules did not get weaker. They got later. For a technology that becomes entrenched in eighteen months, those are not always different things.